7 ms·
Yea, the UI blows but one of the biggest concerns with Skype is that it is a leaky box. I know a lot of friends who have left skype because of government tappin
by electic 10y ago
Yea, the UI blows but one of the biggest concerns with Skype is that it is a leaky box. I know a lot of friends who have left skype because of government tapping. By tapping, I mean multiple governments all over the world seem to have unfettered access to every call and chat on the system.
When you are using the tool for business, that is a deal breaker.
- skrebbel 10y agoWhat alternatives do you suggest for business?
- warbler2012 10y agohttps://switch.co https://switch.co works pretty well
- whyoh 10y agoIt says nothing about encryption, so I assume it's not encrypted.
- warbler2012 10y agoLooks like they changed their name, but heres their doc on encryption: https://storage.googleapis.com/switch_static/Cloud_Security_Overview_1110-2.pdf https://storage.googleapis.com/switch_static/Cloud_Security_...
- atmosx 10y agohttps://jitsi.org/ https://jitsi.org/
- fataliss 10y agoSlack? Might not fully replace Skype as I don't think there is screen sharing. But for calls and chat, Slack does an outstanding job. Plus all the possible integrations with their API etc.
- FullMtlAlcoholc 10y agoSlack has screen sharing through Screenhero
- 1wd 10y agoIs that any good? It seems to be quite weirdly not-integrated. (Separate accounts, apps and contact lists...)
- toomuchtodo 10y agoIt's not integrated, but it's fantastic. Have used it extensively for code pairing sessions, undetectable latency on the screen and crystal clear audio.
- riffraff 10y agoit is somewhat integrated, namely you can do `/hero @handle` and it will work. But SH doesn't work on linux, and it slows to a crawl when sharing with more than one person. Still the best thing available if it works for your case.
- toomuchtodo 10y agoSuggest Zoom if you need to share a screen to more than one person. I don't have a solution for Linux users.
- dorfsmay 10y agoThere is a Zoom.us client for Linux. Also appear.in works on Linux.
- toomuchtodo 10y agoTIL on both counts! Thank you for educating me!
- elcct 10y agoThere is Skype for Business :)
- jonlucc 10y agoIf I'm not mistaken, it's a completely different product with the same name. It was lync for a long time, and they just basically changed the name but kept all the innards intact. I'm fairly sure it's on prem.
- douche 10y agoYup, completely different products. Skype for Business is pretty much just a rebranding of Lync 2013 - for the longest time, the Skype for Business client was still calling itself Lync 2013 on it's about page. It's been pretty confusing, to be honest, since the two different Skypes are completely different products, talking different protocols that just barely communicate with each other. Skype through Office 365 is also Skype for Business/Lync.
- EarthIsHome 10y agoAnd before Lync, it was called Office Communicator.
- whyoh 10y agoWire, maybe. I haven't used it much, but it's supposed to be end-to-end encrypted and supports audio/video/text. No phone requirement either. Still a centralized service, though, so they get access to metadata.
- ckozlowski 10y agoI've been enjoying it quite a bit. I've been successful in getting a good number of my friends over to it; mainly in part due to it's attractive UI and good media support. YouTube and Spotify links preview well in Wire, and there's good gif support. Video calls were excellent quality.
- walexander 10y agoCisco Spark: www.ciscospark.com It provides end to end encryption with customer owned keys. High level data on the security model: https://www.ciscospark.com/content/dam/ciscospark/eopi/country/usa/assets/pdf/Cisco%20Spark%20Security%20Infographic.pdf https://www.ciscospark.com/content/dam/ciscospark/eopi/count... Draft of the KMS technology behind it: https://tools.ietf.org/html/draft-abiggs-saag-key-management-service-00 https://tools.ietf.org/html/draft-abiggs-saag-key-management...
- atmosx 10y agoI think Snowden revelations showed Cisco in bed with the NSA, I wouldn't trust them if government surveillance is a concern. There are many open source for teleconference these days, e.g. https://jitsi.org/ https://jitsi.org/ - I recall a few appearing on HN as well.
- walexander 10y agoOne of the points of the E2E security model used here is so that you don't have to trust Cisco.
- Ninlil 10y agoOnly if the enryption is done properly. Is that an open source project? Did someone you trust security review this?
- sbierwagen 10y agoThere's a distinction between trusting a company not to look at your data when you hand it to them in plaintext, (Skype) and trusting them to have completely flawless, bugfree code that the NSA hasn't backdoored. (Dual_EC_DRBG)
- oneloop 10y agoYou still have to trust that the encryption is indeed E2E as they claim, no? I mean, whatsapp claims it has E2E encryption, but I've never checked...
- lexy0202 10y agoDisclaimer: I worked for this company. StarLeaf (https://www.starleaf.com/ https://www.starleaf.com/) is a great alternative for businesses.
- PeterStuer 10y agoWhat makes you think comparable services are not equally compliant with intercept regulations?
- nothrabannosir 10y agoE2E encryption. So whatsapp and FaceTime.
- ptaipale 10y agoIn principle, yes; in practice, most users are completely unable to assess whether the E2EE is effective in any way. How can you review the implementation does what the vendor says it does?
- gtirloni 10y agoSay WhatsApp receives a request from some government saying they need the data. Period. WhatsApp complies by setting some flag on your account and now your client isn't doing proper E2E encryption anymore and it's all up to be intercepted. And when someone not on an intercept list goes to audit the network traffic, it all looks fine. Infinite possibilities here. What makes people trust the advertised E2E encryption is really happening when they most need? Faith in these companies?
- erkkie 10y agoPeer review. And it's a moving target, skype used to be the recommended one back in the day, when it was decentralized. Right now openwhisper based systems are one of the better ones we have (so whatsapp and signal) that are sanely accessible with decent features.
- okwhatthe2 10y agoDo you actually know the peers doing the review, or are you conducting the review yourself?
- ekianjo 10y ago
- ZanyProgrammer 10y ago'When you are using the tool for business, that is a deal breaker.' People say stuff like this all the time, implying that their business transactions are completely sacrosanct. At some point bog standard enterprise tech is going to be leaky someplace. I can't imagine the government would give a shot about my companies work. But then again I'm not the average paranoid HNer when it comes to this
- ghostly_s 10y agoAgreed, my logic is entirely the opposite. This would be a dealbreaker in my personal life, but why would I care what the gov't knows about my work life? Of course, I don't run the business...
- pooper 10y agoThe "government" like the "cloud" is just an abstraction. The cloud is at the end someone else's computer. No, I'm sure Microsoft CEO isn't interested in sabotaging my business just like I'm sure the POTUS doesn't actively decide to kill innocent civilians. However, they make compromises (something we all do in engineering) and some of those compromises could end up with us as collateral damage. What I'm getting at is even if all government agencies have purest of pure hearts, someone somewhere will eventually leave a door unlocked. Nobody can tell me with 100% certainty that this won't happen in the US and I trust their competence more than some outside contractor working for the Qatari emir. This is my point of view on why we shouldn't have a dragnet. I don't have to argue that my government is evil. I don't even have to say my government is incompetent. But who in my government will testify for the other 200+ governments and their agents?
- electic 10y agoYou don't know what the government cares about and what it doesn't. Over the last decade, many people used enterprise systems and hardware only to find out they weren't secure and the mundane information that traversed those systems were valuable to the government...and that they were compromised. [1] You just don't know whose tapped the line, whose listening, and what systems your text is being indexed into. So reliable E2E is key. [1] https://theintercept.com/2014/12/13/belgacom-hack-gchq-inside-story/ https://theintercept.com/2014/12/13/belgacom-hack-gchq-insid...