10 ms·
Show HN: Talk – A free group video call app with screen sharing
- usaphp 6y agoIs there a way for multiple people to simultaneously share their screen with each other
- CameronNemo 6y agoIs this different from or better than Jitsi Meet? Not intending to criticize the effort, just curious if I should switch my goto choice of video conferencing software. https://meet.jit.si/ https://meet.jit.si/
- zucker42 6y agoJitsi is built to run with a server managing the call. This is peer to peer, it appears.
- 0x0 6y agoIt still needs a server to relay the webrtc peer discovery stuff, at least by looking at server.js ?
- Stratoscope 6y agoYou can't avoid that if you want to punch through NAT like all of us have to do. Or can you?
- travbrack 6y agoDon't need NAT with IPv6
- rambojazz 6y agoBut it's still used nonetheless (even if less than with IPv4).
- canofbars 6y agoI have 2 routers and one by default blocks incoming connections on ipv6 and the other one give you the choice between drop and reject for incoming connections.
- can16358p 6y agoMore than half of the world still can't use IPv6 (including my whole country) due to ISPs not implementing it, so relying on that is not a good choice for now.
- forgot_again_2 6y agohuh, interesting. I’m sure there’s a use to this extra layer of “obscurity” after the sibling comment.
- kelnos 6y agoIt's not even that. Well, it is, but it's two separate things: you need a publicly-addressable server to host this code, for all the peers to connect to in order to discover each other and exchange session information. You could also host this locally and use something like ngrok to provide the publicly-addressable endpoint. The NAT hole punching is done by the STUN servers listed in script.js. They appear to be public third-party STUN servers, so that could be a vector for a malicious actor. There are also third-party TURN servers listed, which will relay media in the case that NAT traversal fails. That should be ok too, but could also be another attack vector.
- 0x0 6y agoAnd it seems to contain hardcoded usernames and password for those STUN/TURN servers too...
- daffy 6y agoSetting up a Jitsi server is non-trivial; this is simple (git clone / cd talk / npm install / npm start). And, if you don't want to trust the programme, you can do this from a dedicated unpriviledged user.
- d0100 6y agoI thought so as well. Ended up rolling my own and encountering too many sync and error-handling issues. Ended up deciding to spend the week configuring jitsi, but all it took was 1 hour to install and configure the server and I was done
- adrianoconnor 6y agoGetting Jitsi running is actually trivial (depending on your definition of trivial). I went from zero to fully running in about 30 minutes on a fresh Ubuntu server when I wanted to check something one time. It might even be dockerized, but my memory isn't 100% on that.
- daffy 6y agoMaybe on Ubuntu. I'm talking about the ``manual'' installation to which everyone not using Ubuntu must resort.
- zucker42 6y agoJitsi not being p2p is advantage in my book. I'd imagine p2p group video calling is subpar.
- mulcahey 6y agoIIRC Jitsi is P2P if you have 2 people.
- moron4hire 6y agoAnd configurable to allow more
- barbs 6y agoLooks like you can use it with mobile without downloading an app, so there's that
- john_alan 6y agoDoesn’t look too secure.
- thih9 6y agoCould you elaborate?
- kelnos 6y agoQuite the contrary; if you host this yourself, remove the TURN server list, and host your own STUN server, it's much more secure than pretty much any of the third-party-hosted services out there. Assuming you trust your browser, that is. Obviously I haven't audited the code, but it's pretty small, and wouldn't be hard to thoroughly audit. It's surprisingly light on dependencies, just pulling in express as the webapp server, and socket.io for the call signaling. Personally I'd probably roll my own signaling over websocket to avoid that dependency (socket.io is an awful protocol, though for generally understandable reasons), but that would likely more than double the amount of code the author would've had to write.
- Kiro 6y agoWhy is socket.io awful?
- lioeters 6y agoI was curious too, since I'm generally fond of socket.io. I've written my own small library around bare WebSocket API, and there are many aspects to consider, like fallbacks and reconnection. In my opinion, socket.io provides a simple and smallish interface that takes care of most needs. Here's an article I found, with opinions on the good and the bad. https://dzone.com/articles/socketio-the-good-the-bad-and-the-ugly https://dzone.com/articles/socketio-the-good-the-bad-and-the... (2018)
- kelnos 6y agoThe interface is nice (from Javascript; it's impossible to write something type-safe in any language where you like to care about type safety); the protocol and implementation itself is horrifying. Some of the protocol's handshaking gymnastics was necessary 15 years ago when you couldn't rely on there being a standards-conforming Websocket implementation, but those days are long gone. Documentation is sparse, and when you find some docs, half the time it isn't clear which (incompatible) version of the protocol they're talking about. Source: I was working on writing an interoperable server implementation of socket.io a couple years ago, and it was way more work than it should have been.
- mixedbit 6y agoUp to how many participants P2P WebRTC video calls work well in browsers?
- kelnos 6y agoRight from the first paragraph of the README: > The sweet number is somewhere around 6 to 8 people in an average high-speed connection.
- mpartel 6y agoThe JS code is under 500 lines so this is at least simple and auditable. I didn't see anything about encryption based on a cursory read. Does WebRTC have some built in or is this unencrypted?
- kelnos 6y agoWebRTC requires DTLS (the UDP version of TLS) for the media streams; it doesn't even allow unencrypted. The signaling for call setup / maintenance / teardown can be whatever, though. It looks like this uses socket.io with HTTPS long-polling. So you need a publicly-addressable IP (or a proxy service like ngrok) in order to host this yourself. Assuming you host it yourself, all clients should have encrypted signaling with your server, and encrypted voice/video packets between each other. If someone else hosts it for you, they can see your signaling traffic, but -- unless they change the code to forward the media stream elsewhere in order to MitM it -- your media should still be encrypted. However, this does make use of public STUN servers to help with NAT/firewall hole punching, which will leak your IP addresses and possibly make it so an adversary can figure out the IPs of the people who were talking to each other, based on the timing of connections. There are also public TURN servers listed which will act as media relays if the NAT traversal fails. Usually the TURN servers are dumb packet forwarders and won't terminate the DTLS sessions, so that should be fine, but I don't remember how the protocol works well enough (it's been a good 7 years since I was knee-deep in this stuff) to say that for certain.
- algesten 6y agoDTLS is only the first part of the encryption. The actual media is transferred of SRTP which is encrypted RTP. DTLS provides the keying material to derive keys for SRTP. DTLS is however fully used for SCTP, which the protocol for data channels alongside the media streams.
- kelnos 6y agoYes, I'm aware (I've implemented a WebRTC stack before); I didn't think diving into the finer details of SRTP would be necessary at this point.
- haroldegibbons 6y agoI thought WebRTC was the coolest thing since sliced bread until I ran into the whole TURN and STUN thing. I feel catfished.
- rambojazz 6y agoThose are not specific to WebRTC though. They are needed protocols if you want a chance to traverse NATs. They're used by WebRTC and other VOIP stacks too.
- pmlnr 6y agoYep, same here. Especially when one takes a step back, loads a h323 softphone that, unlike browsers on linux, uses hw encode/decode, and suddenly my laptop doesn't want to fry itself.
- daffy 6y agoWhat are TURN and STUN?
- SamWhited 6y agoWays for punching through NAT. STUN lets you discover NAT addresses and the like to try and establish a connection with a port on the WAN IP, or some other connection mechanism. TURN is effectively a proxy that can be used by both sides to establish a connection through NAT.
- Benjamin_Dobell 6y agoIs this hosted anywhere? I created https://omen.tv/ https://omen.tv/ just last weekend. Similar in that it's powered by WebRTC, but it's designed for casting your screen (e.g. Jackbox Games) to other people's TVs. My greatest annoyances with WebRTC were: 1. WebRTC requires a STUN server, and despite the spec initially supporting default ICE servers, it has since been pulled out into an extension because browser vendors don't want to provide servers[1]. There are free STUN servers (Google etc.) but... 2. Double NAT clients. STUN is inevitably going to discover double NAT clients. The only way to connect these clients is through a proxy. Specifically a TURN server. Unlike STUN servers, these are not light-weight, and I can totally understand why browser vendors don't offer them by default. So inevitably any WebRTC use still requires a self-hosted TURN server. 3. Inconsistent access to streams across browsers. In particular the getDisplayMedia[2] API provides poor availability of the audio stream. Courtesy of Apple doing Apple things, I don't believe it's even possible to implement this API on macOS as there's no audio loopback device. I worked around this for my use-case by installing BlackHole[3] (which is great software!) However, the loopback device appears as an input e.g. like a microphone, so isn't technically the display audio. For this all to be smooth I think all these pain points need to be addressed. Issue 1 and 2 require NAT to be kicked to the curb, come on IPv6! Issue 3, requires Apple to expose a loopback device and browsers to implement support. These aren't insurmountable issues, but they're unfortunately out of our hands as day-to-day devs. [1] https://developer.mozilla.org/en-US/docs/Web/API/RTCPeerConnection/getDefaultIceServers https://developer.mozilla.org/en-US/docs/Web/API/RTCPeerConn... [2] https://developer.mozilla.org/en-US/docs/Web/API/MediaDevices/getDisplayMedia https://developer.mozilla.org/en-US/docs/Web/API/MediaDevice... [3] https://github.com/ExistentialAudio/BlackHole https://github.com/ExistentialAudio/BlackHole
- tonetheman 6y agoFor your points 1 and 2... you need those servers to be hosted away from your end points. ICE will not work otherwise and they are ultimately legit servers that someone has to work to keep running or pay for. The STUN one is easy really but the TURN servers need to be able to proxy traffic. Twillio provides STUN/TURN servers and they are fairly cheap. I am sure there are others.
- esaym 6y ago
- rambojazz 6y agoCould you add some screenshots on the README?
- amitheonlyone 6y agoI don't know anything about STUN or TURN servers. I saw some credentials in the script.js file. Is it dummy or is it okay to make this public?
- Benjamin_Dobell 6y agoThe original ICE credential APIs make approximately zero sense. Basically the clients need the password, so there's nothing stopping them redistributing it, making the whole thing rather pointless. There's now support for third-party auth (i.e. oauth). It's not really fool-proof on its own, however you can at least then disable access to those who abuse the system. However, for this to work you need to have an oauth provider i.e. sign-in, which may be non-desirable.
- d3nj4l 6y ago> credential: 'd0ntuseme' Might just be an example.
- pkz 6y agoIt would be great with a similar solution that also packaged you own STUN/TURN setup. Maybe there is someone who did that for Jitsi meet?
- j1elo 6y agoOpenVidu.io packs everything needed: an all-in-one Docker image that you can deploy and use to build any videoconference project upon it (or use the ready made Call app that is provided as a real-world project example) Disclaimer: I am coworker with the people that write OpenVidu. Check it out!
- pmlnr 6y agoGreat. Can I has hw encoding/decoding on linux, please? I don't need another software, I need my laptop not to boil.
- moron4hire 6y agoThat's not the developer of this app's fault.
- abhayhegde 6y agoAmazing! I think this is the better open-source alternative to Google Meet and Zoom. Of course, this may not be filled with all the features offered by them, but this is more than enough for meeting 6-8 people at a time.
- deleted 6y ago[deleted]
- _heimdall 6y agoIs this pretty similar to zipcall.io? I've used it a few times and was surprised with how well it worked for video calls and screen sharing. Only problem I had with it was one client that couldn't get his mic working. I'm assuming it was a browser permissions issue but I called him on Signal instead rather than trying to track it down remotely.
- theanirudh 6y agoAnother fully featured group video chat: https://talky.io https://talky.io It's based on this open source app https://github.com/simplewebrtc/simplewebrtc-talky-sample-app https://github.com/simplewebrtc/simplewebrtc-talky-sample-ap... They also run https://www.simplewebrtc.com https://www.simplewebrtc.com which is an SDK for building custom WebRTC apps. They also provide TURN and SFU servers.
- e12e 6y agoThis appear to be client side only (it can even be statically deployed) - the project in the submission is a client + server that handles signalling. And,i dont quite understand this bit: > To get started, you will first need to edit public/index.html to set your API key. So, for any service using talky, I can just steal the Api key rather than subscribing? I mean, it's in the index file, not even protected by login, but sent to all clients (and bots..)?
- paulcarroty 6y agoAnother open source, WebRTC-based chat - https://brie.fi/ng https://brie.fi/ng Also open source. Discussion: https://news.ycombinator.com/item?id=23523830 https://news.ycombinator.com/item?id=23523830
- h43z 6y agoTo share just one screen (mostly for my mom and me) I created https://screenshare.43z.one/ https://screenshare.43z.one/ in just a few lines of client side js.
- hn3333 6y agoStop giving away great software for free. Sell it! :) (P.S:: Didn't check out the source code. It's just a general sentiment of mine lately.)
- upofadown 6y agoHow does the identity management work here? How do you know that you are talking to who you think you are talking to?
- falcor84 6y agoCan't we just manage this on layer 8?
- ArtWomb 6y ago>>> quality of the call is inversely proportional to the number of people on the cal Interesting experiment would be to run locally on high speed LAN with LOTS of participants. Whats the limit to what the browser can handle? Thanks for building, vasanthv ;)
- rdlecler1 6y agoThere are lots of free options. We use zoom because it has the best and most consistent quality.
- SamWhited 6y agoFrom a tech-org perspective I've had the opposite experience. Zoom crashes, behaves weird, has issues on some peoples machines but not others, does weird javascripty things to hide the "join by web" link which we get complaints about, etc. From a non-technical persons perspective, my piano teacher was using Zoom but ended up having to switch to Jitsi Meet because (anecdotally) the audio quality was better and more consistent.
- ComputerGuru 6y agoIt’s not anecdotal, Zoom applies significant audio filtering and “enhancement” as well as selectively attenuating “non-primary” speakers.
- SamWhited 6y agoMy casual observations of it were anecdotal, that is. Glad to see someone else has noticed similar behaviour.
- canada_dry 6y agoCouldn't the double NAT STUN/TURN thing be eliminated if the solution was modified to utilize Wireguard on all the endpoints?
- cloogshicer 6y agoIs there a video call app with screen sharing that doesn't use WebRTC? I often host online lectures and with screen sharing, it always uses up 100% of my CPU resources.
- redindian75 6y agoHere is a demo: http://talk.vasanthv.com http://talk.vasanthv.com
- fonosip 6y agohere's a similar webrtc app, but free of node.js dependency https://ba.net/screen-share-party https://ba.net/screen-share-party
- rajbiswas125 6y agoIs there anything which doesn't use webrtc?
- moron4hire 6y agoWebRTC is amazing, until you start getting users on iPads. The complaints of the Firefox users are easy to ignore (there are so few of them, after all), but the iPad users are too numerous (especially within my company).
- nyxtom 6y agoNice! The WebRTC samples tend to be a bit convoluted. This sample project is a great demonstration of simplicity. Going to use this for some data channel work.
- badalsurana 6y agoI am surprised to see a video call and screensharing app build with less than 500 lines of JS code. Did not know that.