What are the advantages compared to Tox?
I see one advantage of Tox compared to Jitsi. Account management is decentralized on Tox and federated on the protocols Jitsi supports.
Are there plans to support Tox as a backend?
What are the advantages compared to Tox?
I see one advantage of Tox compared to Jitsi. Account management is decentralized on Tox and federated on the protocols Jitsi supports.
Are there plans to support Tox as a backend?
We are also inter-operable with existing SIP infrastructure such as corporate phone system and classical phone provider with optional SIP accounts. We will continue to be as standard compliant as we can rather than create/support yet another custom communication protocol. What Ring bring to this existing mesh of technologies is the ability to connect people using a decentralized peer-to-peer network.
As of now we have no plan to support Tox. We initially evaluated
this and decided against.
I'm rather interested in the reasons of this decision. Ring is based on open standards (...).
Tox is open as well.However, I see a difference between the protocols you've given and Tox: Tox is not standardized.
What Ring bring to this existing mesh of technologies is the
ability to connect people using a decentralized peer-to-peer network.
This technology for peer-to-peer discovery is also not standardized, I assume.So, why creating your own protocol instead of using Tox for this?
DHT has been used in the wild for more than a decade now, it is very well understood. SIP over DHT idea has also been studied[1] academically for a long period of time, even if it was never really implemented in commercial products. Finally, our P2P "protocol" is still using the standards mentioned above for cryptographic identity and other negotiation details, so there is very little that isn't fully standard.
[1] Example: http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.183... (not used for the current Ring implementation)
DHT has been used in the wild for more than a decade now,
it is very well understood.
Tox also uses DHT for contact discovery [1].Does Ring support communication without having to register any type of account on any third-party server?
[1]: https://jenkins.libtoxcore.so/job/Technical_Report/lastSucce...
However, the DHT-based account-less p2p part seems to redoing work Tox has done.
Why not use their efforts and experience? They offer their core separately and Ring could be a client for it.
That would duplicate most of our code
You wouldn't have had to write that code if using Tox were chosen in the first place. will switch to a closed one based on the cryptographic chain of trust
This could differentiate the decentralized part of Ring from Tox. Can you give more details on this?Anyway, I still think you should try to join efforts.
First of all, it is important to understand that Ring is based on SFLphone. Our team have over 10 years of experience (and code) working with the existing SIP infrastructure. Have an inter-operable SIP based decentralized network is really the whole point of doing what we do.
> Can you give more details on this? (please note that this section talk about features in development, it can still change)
The classical phone network is an open system. Everybody call call everybody, some for emails. This can cause some issues, such as tele-marketing and scam (+ spam, called "SPIT" in the VoIP community). Some other IM networks (MSN messenger, Skype, in fact, most of them) use the opposite. You can only open communication with people who are whitelisted. Traditional SPAM methods are mostly useless on most VoIP media such as voice and images as there is no "ahead of time" processing (everything is RTC). A distributed server-less network also cannot ban accounts, there is none. With IPv6, an IP based blocklist is also impossible.
There is a bunch of ways to fix those issues. One is to build a validation network be asking the peers you currently trust to validate new persons. The downside of this is some serious anonymity issues. You basically tell the world who is calling you. The second option is to use a chain of trust. There is multiple ways this can be implemented. First, it can be done on the DHT itself. You only talk to nodes that are signed by a certificate authority you whitelisted and use TLS revocation and other protocol features to manage a pseudo-clean distributed closed-network from which intruders are banned. The second way is to use the full "global" DHT, but only allow calls signed by a trusted authority. For example, this allow a small startup to sign a bunch of certificates, place them on the DHT and let employees call each other. This network will be about as insulated from unwanted external calls as a private SIP server.
Obviously, those 3 strategies are complementary and can be combined to eliminate SPIT and to a certain extent third party meta-data collection.
I only referred to the code that implements the p2p DHT part. That part was duplication of effort.
Now, you are talking about a serious and interesting problem in open systems: spam/spit/...
However, Tox faces the same problem. Their network was attacked at least once from the 4chan community. And they came up with a solution. Their solution doesn't force you to tell anybody your contacts and doesn't need certificate authorities.
How about talking with them about the problem to join efforts?
The Tox people are very open to other people using Tox just as a transportation core.
I'd just be unhappy to have another DHT-based communication platform that didn't talk to the other players first.
However, do you have a link about the Tox 4chan DOS? A quick Google search failed to turn interesting results.
the decision is final
I think here is a misunderstanding. First, if you feel offended, then please note that I didn't mean to. Second, what decision are you talking about?You stated that the technology used by Ring to combat unwanted communication is still not finalized. I asked you
How about talking with them about the problem to join efforts?
I'm not asking you to throw away all what you've done in the area of DHT-based p2p communication and to start to use Tox. However, how about talking to them, since they fought the same battle? Maybe they have valuable ideas or experiences. Or you might help them with your ideas. However, do you have a link about the Tox 4chan DOS?
I have no interesting link available. I'd suggest to take a look at their nospam ID's or to ask them.On a more general note, I think defining some decision as final to silence criticism is deeply harmful. You might want to consider that.
Thank you for your information.
this discussion start to feel like "Microsoft should use WebKit".
I'm not asking you to use Tox, but to look at what they are doing and to talk to them. Microsoft is for sure looking at what WebKit is doing.Yes, competition is a good thing. But you should also learn from your competition, right?
Thank you.
Federated: Provide a little better anonymity as many operations are done behind firewalls/NAT/VPNs rather than using public data and point to point sockets. However it has a single point of failure for each nodes and switching from one federated node to another is either problematic or impossible. The federated node can also fall and shut down at anytime.
Distributed: Doesn't required accounts. Base identity on cryptography rather than a web service. It use point to point or point to proxy to point communication. Some meta datas, such who talk to who, when and for how much time are available to anyone (cough...) who can tap on ISP connection metadatas. This service is more robust and cannot really be taken down in ways that cannot be fixed.
Ring support both federated SIP networks and the distributed DHT network (and a mix of both).
(the anonymity problem can be mitigated using tor like onion routing for the negotiation, but it is unrealistic to use real time communication over an onion network. [D]DOS attacks can be handled in a variety of ways, so are DHT trashing ones, bittorrent is still alive and well).