Ask anything about this article
Hi! I've read this article.
What would you like to know?
@farhan

On September 14, 2026, Signal posted on Hacker News that registration without a phone number will use zero‑knowledge proofs. The announcement arrived just as the industry is wrestling with the privacy fallout of SMS‑based OTPs and the rising demand for frictionless onboarding. In less than 48 hours the headline was trending on Twitter, Reddit, and developer forums, sparking a debate that goes beyond a single app: Can we finally ditch phone numbers as the default identity anchor?
"If Signal can make ZK‑based registration practical, the whole ecosystem will have to rethink the OTP model."
This post dives deep into the technical underpinnings, the developer implications, and the broader privacy trend that Signal is now leading.
Phone numbers have been the de‑facto identifier for mobile apps since the early 2010s. They offer:
But the model shows serious cracks:
Developers have been looking for alternatives: email‑based magic links, social logins, and hardware tokens. Yet each carries trade‑offs in usability or privacy. Signal’s ZK approach promises to keep the best of both worlds.
A zero‑knowledge proof (ZKP) lets a prover convince a verifier that a statement is true without revealing the underlying data. In authentication terms, a user can prove they own a secret (e.g., a private key) without sending the secret itself.
Key properties:
Modern ZK constructions (e.g., zk‑SNARKs, Bulletproofs) have become fast enough for mobile devices, with verification times measured in milliseconds.
Signal’s blog post outlines a three‑step flow:
The proof includes a nullifier – a one‑time identifier that prevents double‑registration while preserving anonymity. If a user tries to register again with the same key, the server detects the repeated nullifier and rejects the attempt.
| Feature | SMS OTP | Email Magic Link | ZK Registration |
|---|---|---|---|
| User friction | Medium (enter code) | Low (click link) | Low (single tap) |
| PII exposure | Phone number | Email address | None (key only) |
| Vulnerability to SIM‑swap | High | None | None |
| Server load | Low (SMS gateway) | Medium (email service) | Low (cryptographic verification) |
| Regret risk (user can delete) | Medium | High (email persists) | High (key can be revoked) |
Regulations like GDPR and CCPA treat phone numbers as sensitive data. By eliminating the need to store them, developers can reduce compliance overhead and lower the risk of data‑breach penalties.
Signal is releasing an open‑source SDK that abstracts the ZK flow into a single register() call. This encourages other apps to adopt the same pattern without deep cryptographic expertise.
The nullifier can be mapped to traditional user IDs, allowing seamless integration with existing user databases. Developers can keep their legacy user tables while offering a privacy‑first signup path.
For apps that already rely on phone numbers for contact sync, a hybrid approach is possible: keep the phone number as an optional field for users who want it, but default to ZK registration for everyone else.
Signal is not alone. Recent developments include:
Collectively, these moves signal a shift from identity as a phone number to identity as a cryptographic credential. Developers who adapt now will be positioned to build the next generation of privacy‑preserving services.
Signal’s zero‑knowledge registration is more than a headline; it is a proof‑of‑concept that the industry can move beyond SMS OTPs without sacrificing security or user experience. For developers, the takeaway is clear:
If the community embraces this change, we could see a cascade of privacy‑first products, reduced data‑breach surface, and a healthier relationship between users and the services they trust.
Feel free to share your thoughts on Twitter with #SignalZK and join the conversation on Hacker News.