Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ever since early in the pandemic, i've pointed friends who were worried about certain things- in the direction of Jitsi so they coudl safely discuss options without a time limit(which Zoom and Meet implemented) with others.

Think conversations like discussion of abortion, and other things where the service in certain locations needed to be private to the point subpoenas wouldn't be a threat. This is also why they've been waiting for insertable streams to be fully implemented in Firefox- those tickets were pushed most heavily because of Jitsi's videocalling.

This was driven by when they implemented an end to end encryption option- and being open source , something people could feel safer about than trusting Meet's (the former Duo)'s one on one calls.

The best part is this was something you could bring up on any computer. Signal , you need to own the device- Jitsi was more free than Signal in some ways- and of course it helps not being tied to a identifier(Signal has not yet implemented removing phone numbers as an identifier)

-Does this mean there's no free, end to end encrypted anonymous alternative that would be useful for those who are not technically inclined- but worry about Subpoenas, and need end to end encryption? That's as accessible(Jitsi was from a simple web interface no matter your device, alternatives like Jami and Meet aren't - and the account thing hurts)

Because trusting a Github, Google ,or Facebook login to not be vulnerable to subpoenas - is a nonstarter. ( I am aware of the efforts of Google, Facebook, etc to mass E2EE communications from test messages to all messenger messages - I don't think this is immune to legal/coercive efforts such as you might see in the UK/Australia, and also think the anonymity layer is going to be the crucial for some people. ...I'm aware ease of use plays a role in abuse- but i'll point out bad actors(who are technically capable at least a little apparently) have the resources to still abuse Jitsi(if someone had an axe to grind against Jitsi) regardless of these additions- [example:Google accounts can be still mass created anonymously via Android phones/burner phones /etc]

I dislike this, having been banging my head against the wall given my efforts over the past few years to teach end to end encrypted options and their usage to those who need them most, for the mentioned reasons.

For now I will resort to bugging people to switch to other instances at https://jitsi.github.io/handbook/docs/community/community-in... - but we badly need more options just as accessible- what other E2EE anonymous web-browser accessible tool is as available to the masses, that they can be convinced to use?



> but we badly need more options just as accessible- what other E2EE anonymous web-browser accessible tool is as available to the masses, that they can be convinced to use?

Just stand up your own instance and make it available to the anonymous public?

Jitsi itself isn't going away, just their anonymously-accessible instance.

By all accounts it's very easy to operate and requires very little in terms of resources. Hell, DO even has a droplet available.

So what's the problem?


>So what's the problem?

We're not all sysadmins that can set up such a thing.


Sure, but if your use case is that critical, you figure it out. That's what people have to do.

Is it inconvenient? Sure. Nobody is claiming it's not. But to say the option doesn't exist because the public instance doesn't allow it is a bit of a stretch.


You can still selfhost right? Is the authentication required if self hosted?


To most people this is like having a complaint about a hotel, and someone saying "you can still build your own house, right?"


There’s no expectation that a hotel provides free rooms.

This is more like a homeless shelter, who’s clientele are not actually homeless, adding a policy of asking for id at door.


Exactly. And then you complain about the id policy saying it was better without that, and then someone tells you: "I don't understand the complaint. You could trivially download some building blueprints from the internet and build your own homeless shelter."

It would be technically a correct statement just like the self-hosting suggestions here.


> what other E2EE anonymous web-browser accessible tool is as available to the masses, that they can be convinced to use?

https://element.io/blog/element-call-beta-3/ maybe?


This appears to be the possible only other tool left in this vein- though at the moment, they have their security off for a short while.

"Element Call is temporarily not end-to-end encrypted while we test scalability."


E2EE is back on, on the develop branch. Just needs a release.


If the users actually achieve end to end encryption then why does it matter that the creator of the group has to authenticate?


It creates risk that whomever that registered person connected to could be tracked by association, especially if the registered party is under surveillance.


matrix.org

Convincing is a different matter, though.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: