Jitsi Meet: open-source video conferencing
meet.jit.si
meet.jit.si
See https://github.com/jitsi/jitsi-meet/issues/409#issuecomment-....
Yes, that is correct (except the Atlassian bit, we are owned by 8x8 now).
Currently WebRTC does not provide the necessary tools to make E2EE possible while still being able to use smart video routing techniques such as simulcast and SVC.
There is hope! In order to be able to have E2EE 2 things are needed:
* some metadata must be available without decrypting packets, this is (mostly?) available as RTP packet extensions, called "frame markings" * an API is necessary to be able to inject one's own encrypting engine in the WebRTC chain, Google is working on this API and hopefully it's available later in the year. Google is calling this "insertable streams": https://www.chromestatus.com/feature/6321945865879552
Happy to answer any questions!
That's really good news: then we'll have a very easy to use and reasonably secure option for video conferencing.
By the way, thank you for making this software.
Source: https://techcrunch.com/2018/10/29/atlassian-sells-jitsi-an-o...
https://github.com/nextcloud/spreed/issues/37
He says that video/audio in calls are end-to-end encrypted when the server is using the default PHP backend, but not the high-performance backend (an optional paid and proprietary enterprise upgrade).
> video/audio is already end-to-end encrypted
> By default with the internal signaling backend audio/video calls (no matter if 1:1 or group) are end-to-end encrypted.
> and without the HPB its always paar-to-peer [sic] and therefor end-to-end encrypted.
> Chat is currently not end-to-end encrypted, only the audio/video of calls are.
Someone mentioned Jitsi's statement and the developer responded:
>> But I don't understand why the Jitsi people write, "WebRTC today does not provide away of conducting multiparty conversations with end-to-end encryption." That would only be true if I decided to use an additional HPB solution, wouldn't it? But not out of the box.
> Exactly, I guess for better user experience and performance they have a SFU or MCU in place (our HPB is an SFU), and therefor it stops being end-to-end encrypted
As others have pointed out, we use jitsi.riot.im, which is provided by New Vector (the company behind Riot) rather than anything to do with Atlassian/Jitsi/8x8.
So completely under Five-Eyes mass surveillance (and questionable Australian jurisdiction regarding that) :(
I would love to use something like Mumble but with video, although that may just be Jitsi.
Our problem was that we had way too much echo/reverb, especially when people were not using headsets. Just having one non-headset user killed it for us. IIRC even one user talking into their phone normally (i.e. no "loudspeaker" setting activated on their phone) killed our conversations because people heard themselves talking. I've tried finding a setting that would be OK to use when no headset is available, but I just couldn't get it to become bearable.
I'd really like to use something self-hosted, but I can't control what devices people use, and users are way too used to simple interfaces. I've also tried a self-hosted Jitsi meet instance more than a year ago, which for some reason has much better echo reduction, but it sometimes didn't work for one or two of our colleagues for unknown reasons, maybe because most of us have Firefox, not Chrome, or mobile browsers. The android app didn't work on my Sony Z1, but I've since changed phones and it seems to work now.
These days anyone with a bit of programming knowledge can now open WebRTC sessions from the server, decrypt the contents, and multiplex streams back to clients (great for large group video chats). A great capability IMO, but immense potential for abuse by bad actors. I think now is a perfect time for people "in the know" to start educating the public on this.
When I shared [2] a lot of people gave me flack for enabling malware. I don't come from that background, so hard to think 'how can people abuse this technology'
It is too late now to roll back all the WebRTC stuff in the browser now though :) Definitely would be mind blowing how much data is flowing because of it (and how much money is being made because of it).
[0] https://webrtchacks.com/dear-ny-times/
[1] https://trac.torproject.org/projects/tor/wiki/doc/Snowflake/...
How is jit.si able to do this for free where many other companies charge? Are they monetizing user data? Or trying to upsell some parent company services? Is this an honest-for-goodness non-profit because someone was fed up with video conferencing?
None of these are potentially deal-breakers, but they need to be transparent about why they are doing this for free and what they are getting out of it. In 2020, the understanding of "free" is much more sophisticated than it was in say 2010.
Jitsi is now owned by 8x8, which has a clear business model. We recently launched 8x8 Meetings, which is a rebranded Jitsi Meet with a few extra bells and whistles.
We (Jitsi) have remained Open Source while navigating through 2 acquisitions (Atlassian and 8x8) and being Open Source is in our DNA. Thus, remaining in this state was always a non-negotiable item during acquisition talks.
> If Jitsi doesn’t make any money, how can it continue to support the project?
> We are fortunate that our friends at 8×8 fully fund the project. 8×8 uses Jitsi technology in products like Virtual Office. The open source community and meet.jit.si service help to make Jitsi better, which makes 8×8 products better, which helps to further fund Jitsi. This virtuous cycle has worked well in the past and should continue to for many years to come.
with several high profile cases in the linux kernel i think this belief has been shown to be overcautious and maybe this has led to a relaxation of the position.
The idea of assignment to FSF is not merely to guarantee to the world that the original copyright holder won't offer competing licenses or something.
That seems like it would be potentially incredibly disruptive (e.g. if a contributor decides several years after a lot of work has been built on top of the contributed code to claw back the rights), especially because as far as I'm aware there isn't a separate license you give the FSF on a contribution, just the assignment. AFAICT it wouldn't even make sense to give the FSF a license because you don't own the code anymore, the FSF does.
I can't find anything on the FSF website that allows this.
(Source: I work for 8x8)
The nice thing about about Jitsi is it's the most simple process I've seen: just tell people to go to a simple vanity URL (URL you get to design) and that's all. I sometimes find Hangouts confusing with all the invitation, accepting, etc.
For people I videochat with often, I just say "jump on Jitsi?", then start typing in URL bar which autocompletes and boom, we're chatting
If you want better video quality and can live with multi-second latency you need to look at different technologies like RTMP or HLS, which is what youtube/facebook streams do.
But I did want to toss this out there as an alternative to jit.si as it is functional to h.264 and sip clients and with some other software fronting it (like Kamailio) could be made to do SRTP and WebRTC with a html5/js sip client.
Is there any reason jitsi or any other project would be faster / have better perf than peerjs.com?
All join as many as you can.
Also note that Fx isn't a "fully supported browser" apparently...
1) proprietary solutions in the age of surveillance capitalism.
2) offer in-browser cryptography to ensure security. I don't see any end-to-end encryption elements in that. Your data gets essentially delivered to the service. Do we really want that? Haven't the companies like FB already shown you should never trust them with your data? I mean, I'm baffled to see people would go in circles and instead of realizing the fundamental fault (lack of privacy by design), they go for the next vendor who promises not to abuse their data. Well no surprise there, for these services the business model IS the data. And it will never change unless they prove it won't be used by switching on E2EE and allowing anonymous registration and use via Tor.
At least back in the day Jitsi offered E2EE for VoIP and video with ZRTP + SRTP. I'm not sure what the case is now but people, think twice before you sign up to these "free" and fun one-click sites.