Jami: GNU end-to-end encrypted alternative to Zoom and Jitsi
git.jami.net
git.jami.net
Jami’s major advantages are that it’s end-to-end encrypted and completely peer-to-peer, requiring no server in-between.
The major disadvantage is that it doesn’t support calls from the browser.
See also: https://jami.net
Also, being able to just use any OS with a modern browser you please.
For a tool like this though I'm not sure what a native app would add. Most of what it does builds on the functionality of a modern web browser.
Jami uses a fully distributed network (DHT) to initiate connections.
This is also true for typical p2p protocols though, isn't it? Normal torrent clients for example have hardcoded servers to start their dht search from.
[0]: https://stackoverflow.com/questions/1332107/how-does-dht-in-...
This is a feature, not a bug.
Also, I already have an GNU Ring account saved in my password manager but can't seem to login (or even find a place to). However, if I try to create a new account using my old username it (correctly) states it is taken.
I'll also through Jitsi out there as a very capable FLOSS alternative to Zoom. If you tried it a few years ago it's changed dramatically in the last while. It's now WebRTC based and runs in browser without any download. It's not quite end to end encryption because the stream needs to be decoded on the server before being re-encoded for the other clients, but since you can easily self host it on a cheap VM I find this acceptable.
[1]: https://www.html5rocks.com/tutorials/webrtc/basics/ "Getting Started With WebRTC"
It also needs one or several STUN servers as part of the hole punching scheme, but this one doesn't even exchange anything with anyone, so there aren't many issues here (and you don't need to roll your own: you can use Google's one)
For more than two users, you mainly have three options:
* MCU (Multipoint Control Unit), which IIRC does need to decrypt your video, as it will post-process it and possibly re-encode it to send a single stream to the other participants.
* SFU (Selective Forwarding Unit), which in theory doesn't need to decrypt your video, but does need some metadata about it in order to make smart decisions as to what streams to forward to whom (for example, forwarding only the stream of the person who is talking). In practice, I believe some (many?) SFUs will do decryption, thought it's not a strict requirement.
* Dumb peer-to-peer-to-peer-to-... multi-forwarding. You can of course theoretically stream your video to each other participant, and they can all do the same, but that quickly fails to scale. It might be ok for three, maybe four participants, but even then there will likely be problems.
I'd be really curious if this is a viable option for videoconferencing for say >10 people.
As an aside, I don't believe in the virtues of P2P anymore. It's clear to me that centralised systems scale further and faster, and what we need are benign organisations to run them. Legal forms like cooperatives and community benefit societies (nonprofits in the US I guess) are the way forward. I'd choose a community instance of Jitsi as being the best approximation of this for now.
I belong to cooperatives that are politically partisan, that engage in sharp practice, and that aren't as democratic as I'd like. I'd prefer cooperatives to concentrate on treating stakeholders fairly, representing members equally and effectively, and prudent stewardship of their assets.
Cooperatives might lose their focus on their main purposes and discourage some non-progressives from becoming members/customers by pursuing too wide a range of progressive causes.
O RLY?
https://git.jami.net/savoirfairelinux/ring-client-android/is...
https://security.stackexchange.com/a/171461/43688
I looked through their code to see where data is being encrypted/decrypted, and was unable to locate it.
Since their issue indicated they use 4096-bit RSA, I really wanted to see if they were vulnerable to Bleichenbacher's 1998 padding oracle attack.
https://git.jami.net/savoirfairelinux/ring-project/wikis/tec...
> The SHA-1 fingerprint (160-bits) of this public certificate is the JamiId.
this-is-fine.mp4
I do not see any issue with this.
Right now we use Briar and are pretty happy with it. There's also signal as a better option.
Either way, IMO, Jami sucks.
https://support.wire.com/hc/en-us/articles/360001019225-Star...
It's actually much more standard-compliant than most alternatives.
I would love to see a messenger/audio call/video call app built on the zerotier SDK, I never had connection problems with zerotier.
Not a big issue since I don't carry the tablet around, just to let the developers know if they read here.
Or, raise the issue with them for investigation, since a comment on an unrelated site isn't a reasonable way to provide feedback
This has been around for a while. Why isn't it in the Ubuntu repository?
What happened to 80's glorious days where company and product names were super cool.
- DynaMax
- Ultron
- Trinitron
- Hypersystems
- Logicore
- Supra
- Intertech
- UniversalSystems
- NationalTech
- Automark
- Spectra
- Pentatype
- PolyMatrix
- MicroSpace
- RotoCore
Now we have things such as Flikr, Waymo, Skype, Jitsi and this thing... Jamo or Jami. :-/ Human race is regressing.I'm sure there are meanings behind a lot of the other names you listed, too.
> The letter “K” had been a favorite of Eastman’s, he is quoted as saying, “it seems a strong, incisive sort of letter.” He and his mother devised the name Kodak with an anagram set. He said that there were three principal concepts he used in creating the name: it should be short, one cannot mispronounce it, and it could not resemble anything or be associated with anything but Kodak
(For reference, that's Foobar2000 over there rolling its eyes...)
- Self-hosting Jitsi is not the optimal use case for everyone.
People are free to choose between Jami and Jitsi, and it’s great to be able to have different options based upon your use case.
Would I be wrong to be concerned about the potential for contractors to review private video that was captured/re transmitted by the central servers, e.g. for machine learning training purposes or other "internal" service quality checks? And potentially capturing some of that video if they find it interesting and potentially sharing it anonymously on viral social media? It seems that would be a rare occurrence, but possible.
Would end-to-end encryption be an appropriate way to eliminate that risk?