4 ms·
I believe that voice and video calls work using WebRTC, which is a P2P technology
by giords 5y ago
I believe that voice and video calls work using WebRTC, which is a P2P technology
- capableweb 5y agoWebRTC (still) requires a centralized server in order to setup the connection (via STUN/TURN), so if so, Signal could be forced to turn over any logging they have of those setup requests.
- sfifs 5y agoVery likely they don't log. Otherwise they'd have had to disclose
- kodablah 5y agoYou can use existing decentralized systems, e.g. bittorrent DHT or IPFS DHT, to handle signaling and not require a centralized server. STUN is only needed to retrieve the public IP, which you may not need to use (and didn't have to be centralized). In some heavily NATd cases, you'd need a TURN proxy, but not often.
- capableweb 5y agoBoth of those DHTs are using centralized signalling servers to first be able to establish any P2P connections. Maybe there has been some recent invention in DHTs, but AFAIK, 100% P2P discovery is still not "there" (meaning "accessible, fast, not using too much resources and can find other peers")
- dane-pgp 5y agoI don't know if any systems actually work like this, but wouldn't it be possible to include in the client a short hardcoded list of entry points to the network which are all run by different entities (in different jurisdictions)? Each entity could have their own public key (also hardcoded into the client), and the client could pick one at random and then bootstrap you up to the entire P2P network, where it would find the other hardcoded identities (or N out of M of them) to confirm you were seeing the whole network.
- capableweb 5y agoYes, this is essentially how "P2P bootstrapping" works today. BitTorrent does it via "trackers", IPFS does it via their "bootstrapping" list (known IPFS nodes with static IP/DNS) and Bitcoin used to do it via IRC. Probably is that all of those techniques, are still centralized.
- dane-pgp 5y agoIs it still centralized if the tracker/bootstrapper nodes are all operated by different entities in separate jurisdictions? I suppose you could argue that the list itself is centralized, if there is only one list, but if the protocol is an open standard then different clients could ship with different lists. Would you say that the web PKI is "centralized" because most browsers agree on which CAs to trust?
- tialaramex 5y agoThe options are, either you do peer-to-peer and so your peer must learn the IP address they can reach you on, or Signal sits in the middle of the traffic relaying between the parties. This trades two different privacy risks, would you prefer that a hypothetical adversary who has successfully seized control of Signal can see which IP addresses are communicating or would you prefer if people you accept realtime calls from or make calls to learn your IP address? You get to pick which you prefer in the Signal app preferences. [Edited to add: Specifically, if either of you insists on having Signal relay the traffic, then that's what has to happen, otherwise it is peer-to-peer.] As with anything else involving IP addresses, you could choose to go via Tor, with all the consequences of that.