Decreases what info Signal needs to collect and retain about a user. When using an SMS verification as a proof, Signal needs to log the phone number, because if they didn't, one spammer could use one phone number to create 10^99 accounts.
When using payment as proof, they can verify that payment occurred, validate the account and then immediately forget about the transaction. One spammer would still have to pay 10^99 times to create that many accounts.
You buy a Mullvad scratch card on Amazon and you redeem the token string.
Mullvad also offer the option to put your card number into the Mullvad website, and I'm sure many privacy conscious people would be very reluctant to do that.
Card payments these days leave far too big a trail. The bank knows, the intermediary (e.g. Stripe) knows, and the merchant (e.g. Mullvad) has to keep records for accounting/tax requirements.
It's still often cheaper (and faster) to grab a one-time verification number than to go through payment-based verification. Especially for anything that only needs a single SMS confirmation.
If your concern is "muh phone number", then you can pay and not have to give the phone number to sign up.
It's already the case today (and has been for years) that you don't need to give strangers your phone number to chat on Signal. My username is soatok.45; try to get my phone number if you can.
If you want absolutely no info to be collected, ever, and there to be zero cost on the end user too, be prepared to welcome your new spam overlords. Because the people who will benefit the most from a zero cost signup that only requires a username are spammers.
I'm a bit surprised by this dismissal. Of course some info must be collected, or there must be some cost to enter (probably both I mean phone number is also a cost, but one most people already sunk). But we can still debate the best way, right?
For example:
* Are you absolutely positive signal will never have a bug that let attackers reveal contact phone numbers? I really trust in their secure coding skills, but this class of vulnerabilities (like 2fa leaj) happened to even the biggest players.
* One of the reasons signal collects phone numbers (and asks for a contacts permission) is to check which contracts are already on signal. For some people or in some governments even having a signal account is an opsec problem (to be fair, they have a secure privacy-preserving protocol for this - as you know - and it's possible to avoid this footgun if necessary)
Replacing the need to register with a phone number with a requirement to pay is a better option how, exactly ?