Skip to content

2026

Signal Login and the payment trail it leaves

A wallet on a wooden table with cash and cards sticking out, next to a smartphone and a set of keys
A wallet, a phone and keys, standing in for a registration that swaps the phone number for a payment and a key. Photo by Towfiqu barbhuiya on Pexels (Pexels License).

In Taiwan, Hong Kong and Macau, every mobile number, prepaid SIMs included, is registered to a real identity, and the same holds across most of East and Southeast Asia. A Signal account is opened against a phone number, so however strong the encryption, the carrier's registration record ties the account to a named person. For journalists' sources, activists working across borders, and anyone who does not want their account traced back to them, the phone number has long been the most cited limitation of Signal.

In September 2026 Signal's Android beta opened a way to register without a phone number, called Signal Login, in exchange for a small one-time payment. The obvious worry followed: doesn't the payment record bring your identity right back? Signal reuses the zero-knowledge credentials from its donation system so that an account cannot be matched to a specific purchase. The payment date still travels with the account, however, and Google keeps a record that you bought it. Whether to use Signal Login, and how to pay, depends on which kind of tracing you need to defend against.

Docs site update review, September 2026

Docs site update review

The previous release went out on 2 September. Between then and the 20th, the docs site merged 140 pull requests. The Lab went live, the utilities grew from 9 tools to 15, nine worked examples string those tools into paths you can follow end to end, a settings drawer collects controls that used to be scattered, and the surveillance page gained a fifth tier. On the content side, three regional pages went up, one of them taking forty-nine public sources to pull apart identity binding and the data market beside it. The last two sections are for readers who acted on the old guidance.

Four cases in Anthropic's September 2026 threat report involve Taiwan, and here are the page numbers

Header image from Anthropic's report Detecting and countering misuse of AI: September 2026
Image from Anthropic's report page Detecting and countering misuse of AI: September 2026. Copyright Anthropic.

On 10 September 2026 Anthropic published Detecting and countering misuse of AI: September 20261, a 154-page account of misuse it detected and disrupted between December 2025 and August 2026. The report is English-only and our community does not have the capacity to translate it in the near term, so we took on something smaller: a complete write-up of the sections that involve Taiwan and the Chinese state, each marked with its page number so readers can check the original.

The sections below aim to give readers who never open the report the full picture rather than fragments. Tables, figures and terminology follow the original as closely as possible.

What Tor VPN Beta's first year looks like across seven Asia-Pacific regions

This post builds on the Tor Project announcement below. We also publish full translations of it:

Tor VPN beta promotional image showing availability on download.torproject.org with F-Droid and Google Play badges, and a phone displaying the connected screen with upload and download counters

The Tor Project's retrospective on the first year of Tor VPN Beta contains one finding that reframes the whole product. The team expected to learn from real-world use, and what they learned was that the primary use case is unblocking the internet — not the privacy features a commercial VPN would lead with. Early adoption concentrated in heavily censored regions, and that shaped what got built next.

That finding is the interesting part for us, a community based in Taiwan, because the regions we cover sit at very different points on that spectrum. This post checks the announcement against measurement data for seven Asia-Pacific regions, and sets out what the regulatory picture looks like in each.

Storing the whole docs site and its tools on a device, so they open with the network off

When the network drops, the page you most want to open is often the one that will not open. On a flight, in the mountains, in a new country before you have found a SIM, that is an inconvenience. Where the network is cut, throttled or blocked, the same thing costs something else entirely.

From 4 to 6 September we were at Global Gathering 2026 in Estoril, Portugal. Alongside our booth on the last day we joined the Circles, where we talked about how the privacy material on the docs site is written and how it is layered. The conversation kept returning to one premise: the moment a reader needs these pages is not reliably a moment with a working connection.

The top of the offline reading page: storage totals, the automatic-storage and inline-image switches, and the Save everything, Update what is stored and Clear all offline content buttons

How 292 Asian loanwords ended up in an English passphrase wordlist

We are a group of volunteers working on anonymity networks and internet freedom, based in Taiwan. We maintain this documentation site. The community also built asian-diceware, a 7,776-word English passphrase wordlist that drops straight in for the EFF Large Wordlist, with one difference: it pins 292 Asian loanwords that English dictionaries already carry. tofu, oolong, boba, and kimchi are all in there.

The tool page already covers how to use it, and the passphrase generator in the tools section is one click away. This post covers the other half: how the words were picked, and what got rejected along the way.

How 292 Asian loanwords ended up in an English passphrase wordlist

We print this zine only for events and hand it out at Global Gathering

The two sides of the wrapper laid flat side by side. On the left a plain typographic cover, on the right a world map set in characters with a solid block marking Taiwan at the centre

From 4 to 6 September we have a booth at Global Gathering 2026 in Estoril, Portugal, where we hand out a printed zine. Four A4 sheets folded in half inside a wrapper, A5 when folded. We printed 150 copies, they go until they run out, and there is no digital edition.

anoni.net is a volunteer community based in Taiwan, working on documentation, measurement tools, and self-hosted services for anonymity networks and networked freedom.

  • Booth slot: Sunday 6 September, 13:00 to 15:00
  • Where: Booth 6
  • What you can do there: take a zine, try eight browser-side tools that work offline and three interactive 3D pieces about Tor (the onion routing network), discuss anonymous payments
  • We are around all three days, so stop us anywhere at the venue outside the booth slot

Who the zine is for: anyone working on cross-border disbursement, donor anonymity, or a project blocked by financial controls. One of the sheets is written for you.

This article is the design record, written for people interested in typesetting and print, including the places we got wrong and fixed. For why we are attending, why the booth topic is anonymous payments, which sessions overlap with our work, and five other ways to find us, read anoni.net at Global Gathering 2026. The full event information is in that earlier post.

Eight new tools on the docs site, all running in the reader's own browser

We are a group of volunteers working on anonymity networks and internet freedom, based in Taiwan. We maintain this documentation site, a practical guide to privacy and anonymity sorted by scenario for everyday life, sensitive work and high risk.

The articles on this site explain how to protect yourself. The tools section holds the things you can actually press. All eight compute in the reader's browser, send nothing anywhere, and keep working with the network off once stored on a device.

The tools index, eight cards each naming a tool and what it is for

The Anonymity Networks Community Is Going to Global Gathering 2026

Global Gathering 2026, hosted by Team CommUNITY, runs from 4 to 6 September in Estoril, Portugal. We applied for a booth and the slot is now confirmed.

  • Date and time: 6 September, 13:00 to 15:00 WEST (UTC+1, Portugal local time during the event)
  • Location: Booth 6, 3 x 3 meters
  • Booth title: anoni.net Hub: Sinophone Asia-Pacific Networked Freedom

Event details are at Global Gathering 2026.

Brave flattens GPU fingerprints two opposite ways

Open a web page and the JavaScript on it can read your graphics card model, its driver details, and the hardware features it supports. Those answers barely change on a given machine, so a tracking company can combine them with other device traits into an identifier that needs no cookie, asks for no consent, and follows you between sites.

The graphics card is one source among many. Font lists, screen dimensions, time zone, and audio processing all feed the same identifier. A browser fingerprint cannot be cleared the way a cookie can covers how the whole mechanism works, why clearing cookies does nothing, and where each browser currently stands. This piece stays with the graphics card.

Brave has handled these signals since version 1.93, on by default on desktop and Android, rolling out in stages1. Three protections ship together: the WebGL vendor and renderer strings become one generic string shared by every Brave user, the WebGPU hardware description fields are cleared, and the list of supported WebGL extensions gets noise added to it.

The first two make every user look alike. The third makes one user look different on every site. Two opposite techniques arrived in the same release, each assigned to a different API, and where that line falls is also where Brave and Tor Browser part company on fingerprinting.