Here is a break down of the permissions:
- microphone: used to capture your voice to communicate with someone
- phone: you can send sms throught the app
- contacts: to associate a ring id with a contact (and have the phone number to send sms
- storage: to store your private key
- location: I admit, that one is weird
I also can't distinguish between giving Ring permission to access all my contacts' details and send them to some third party, and giving Ring permission to associate ring IDs with contacts without exposing other details about that contact to Ring.
Also, you don't need storage permission to store app-specific data, only to access the "external" storage. (In general, this is the storage you see when you mount the phone over USB.) Presumably, this permission is to support copying an existing key from a PC.
Note that these problems are not Ring's fault, but caused by Android's permissions system. Fixing it in Ring would require splitting the app up into pieces for voice, sms, text, etc. Possible, but a lot of effort.
I haven't gone through the entire tech of it, but i'm guessing because you've said it is serverless, does it follow it similar to a DHT model? Are encryption and decryption of messages/data only possible and source and target and not by anyone intercepting it?
It use the DHT model, but not the mainline DHT (anymore).
> Are encryption and decryption of messages/data only possible and source and target and not by anyone intercepting it?
It would fail its purpose quite badly if it didn't ;)
I linked it elsewhere in the thread, you take a look at https://elv13.wordpress.com/2015/09/05/what-is-ring-and-how-... . It is outdated, but I hope it will give you the "big picture" of how Ring.cx work. Some parts are still incomplete and/or disabled by default, but 90% is there.