5 ms·
Folks please try Discretio for Android (https://play.google.com/store/apps/details?id=com.discretio.android https://play.google.com/store/apps/details?id=com.d
by vadiml 14y ago
Folks please try Discretio for Android (https://play.google.com/store/apps/details?id=com.discretio.android https://play.google.com/store/apps/details?id=com.discretio....)
Open source (GPLv3) secure VOIP solution. For the moment only Android version is available but iOS and desktop
vresions are in the queue...
- StavrosK 14y agoThat doesn't sound very convincing. You can't just have some icons tell you that you're secure, how do they know if someone's MITMing you? You can use the already-available ZRTP, that requires each user to speak a phrase to the other, so you can verify by hearing the other person's voice. Discretio doesn't do any of that, so how does it know you're not talking to some random attacker?
- vadiml 14y agoThe client side source code is available: https://bitbucket.org/repo/all?name=discretio https://bitbucket.org/repo/all?name=discretio
- StavrosK 14y agoI saw that, but I didn't see any explanation on how it works, and I'm pretty sure it's impossible to have security without verification. I can't read the code to verify that, sadly.
- Discretio 14y agoCurious to hear from someone working in a company who says things but not show it's true. In fact, if i say i am rich, tall, blond with a famous sense of humour, you are ready to believe me, but if i don't say anything but i prove it, you refuse to believe me... strange. Discretio doesn't say anything of this kind but show the entire client software source code. Do the same please.
- StavrosK 14y agoSo how do you protect against MITMs?
- Discretio 14y agoYou still ask for words, i still ask for your source code...
- StavrosK 14y agoI don't own the company, thus I can't give you the code. You can give me an explanation, but won't. Why?
- vadiml 14y agoBasically the client connects to SIP server using ssl connection authenticated on both sides. When placing calls the clients A and B are negotiating SRTP session key using DH key exchange. It is done over SIP (and not over RTP channel as in ZRTP). Each client upon registration generates public/private key pair and submits a CSR to the registration service which signs it and stores the public key (which is later used to authenticate the above mentionned ssl connections) in the SIP server's DB... The server has no access to the client's private key nor to the SRTP session key
- StavrosK 14y agoHmm, it sounds resistant to random MITM but the server can still listen in on the calls if it wants, by MITMing the clients itself...
- vadiml 14y agoYes, with the cooperation from CA the MITM is still possible. We however will provide server code to especially paranoid clients so they can build and run the software on their own machines... This way they can have garanties against certificate tampering. And we're working on an alternative solution when even cooperating CA will not allow MITM...