Ring: FOSS encrypted P2P voice, video and chat platform
ring.cx
ring.cx
The main difference is that Ring.cx is built on top of open standards and only add the minimal additional infrastructure (the decentralized DHT layer) to allow it to work without a server. It is SIP compliant and can be used as work phone or your average VoIP provider, but you lose some the the privacy and advantages provided by decentralization.
For more info, I wrote this blog post a while back https://elv13.wordpress.com/2015/09/05/what-is-ring-and-how-...
You can configure Ring to be "more anonymous" by adding some proxies/middleman-server and messing with the connection sequence, but it cannot really be used in the default configuration or it would not "just work". Adding proxies for voice stream also add audio latency.
Edit: Our NAT punching is IETF compliant STUN/TURN/ICE/UPnP, so you can always just pick a third party you trust in the rare few cases you need one (we don't support IPv6 that well yet, so no luck there, it will come at some point).
The big problem right now is the scope of the app. They want to do too much at the same time (text, voice and video).
Anyway, I like the effort and I hope it succeeds.
Ew.
The problem with public registries is that anyone can spam them. Checking the key would involve retrieving it via multiple sources which is tedious.
> doesn't apt-key already do that when adding the key?
Man page doesn't say, nor can I find quickly on Google if apt-key does any additional verification. It doesn't seem likely though, because if verification step did occur the entire command would be redundant as the same mechanism that verified the key could be used to verify source list entry.
Also, everytime someone builds something now, it seems to be the first comment out there "it needs to be self-hosted". I get that this is a security oriented communication app, so it needs to be audited and open sourced so we can trust it, but now that this part is OK, people are finding something more to ask: the self-hosting part.
0: https://projects.savoirfairelinux.com/projects/ring/wiki/How...
It is also not immediately apparent from Ring's website and wiki. The developers of Ring are quite helpful in replying here on HN though.
[1] https://ring.com
"Ring is a secure and distributed voice, video and chat communication platform that requires no centralized server and leaves the power of privacy in the hands of the user."
I don't think most people actually care about any of this. The app is ugly, too.
I want a Skype killer, but everyone who writes this type of software panders to security and tech people, when really these applications should pander to people people.
Belongs in the same crowd of apps like Tox.
What do they all lack? What's the common pattern? They all pale in comparison to Skype's invitingness regardless of how horrible Skype has become over the years.
Here is a break down of the permissions:
- microphone: used to capture your voice to communicate with someone
- phone: you can send sms throught the app
- contacts: to associate a ring id with a contact (and have the phone number to send sms
- storage: to store your private key
- location: I admit, that one is weird
I also can't distinguish between giving Ring permission to access all my contacts' details and send them to some third party, and giving Ring permission to associate ring IDs with contacts without exposing other details about that contact to Ring.
Also, you don't need storage permission to store app-specific data, only to access the "external" storage. (In general, this is the storage you see when you mount the phone over USB.) Presumably, this permission is to support copying an existing key from a PC.
Note that these problems are not Ring's fault, but caused by Android's permissions system. Fixing it in Ring would require splitting the app up into pieces for voice, sms, text, etc. Possible, but a lot of effort.
I haven't gone through the entire tech of it, but i'm guessing because you've said it is serverless, does it follow it similar to a DHT model? Are encryption and decryption of messages/data only possible and source and target and not by anyone intercepting it?
It use the DHT model, but not the mainline DHT (anymore).
> Are encryption and decryption of messages/data only possible and source and target and not by anyone intercepting it?
It would fail its purpose quite badly if it didn't ;)
I linked it elsewhere in the thread, you take a look at https://elv13.wordpress.com/2015/09/05/what-is-ring-and-how-... . It is outdated, but I hope it will give you the "big picture" of how Ring.cx work. Some parts are still incomplete and/or disabled by default, but 90% is there.