[jitsi-users] JitMeet and GHCQ/NSA peeping


#1

Hi!

In the wake of the revelation that the Five Eyes have been
videotapping Yahoo video chat, and most likely all the other
commercial video chat apps as well, how does JitMeet measure up?

Is the video and other data stream encrypted, with good key exchange et al?

..m


#2

Hi!

Well it's definitely not RC4!

* SSL connection using ECDHE-RSA-AES256-GCM-SHA384
* Server certificate:
* start date: 2013-12-07 09:23:02 GMT
* expire date: 2016-12-07 09:23:02 GMT
* subjectAltName: meet.jit.si matched
* issuer: C=US; ST=Arizona; L=Scottsdale; O=GoDaddy.com, Inc.; OU=
http://certificates.godaddy.com/repository; CN=Go Daddy Secure
Certification Authority; serialNumber=07969287
* SSL certificate verify ok.

compared to gmail:
SSL connection using ECDHE-ECDSA-AES128-GCM-SHA256
* Server certificate:
mail.google.com
* start date: 2014-02-12 15:20:21 GMT
* expire date: 2014-06-12 00:00:00 GMT
* subjectAltName: mail.google.com matched
* issuer: C=US; O=Google Inc; CN=Google Internet Authority G2
* SSL certificate verify ok.

···

* subject: OU=Domain Control Validated; CN=meet.jit.si
* subject: C=US; ST=California; L=Mountain View; O=Google Inc; CN=

On 28 February 2014 11:40, Mark Atwood <me@mark.atwood.name> wrote:

Hi!

In the wake of the revelation that the Five Eyes have been
videotapping Yahoo video chat, and most likely all the other
commercial video chat apps as well, how does JitMeet measure up?

Is the video and other data stream encrypted, with good key exchange et al?

..m

_______________________________________________
users mailing list
users@jitsi.org
Unsubscribe instructions and other list options:
http://lists.jitsi.org/mailman/listinfo/users

--
-------
inum: 883510009902611
sip: jungleboogie@sip2sip.info
xmpp: jungle-boogie@jit.si


#3

Hey Mark,

JitMeet supports DTLS/SRTP which means that as long as you control the
bridge, you are OK.

Does this answer your question?
Emil

···

On Fri, Feb 28, 2014 at 9:40 PM, Mark Atwood <me@mark.atwood.name> wrote:

Hi!

In the wake of the revelation that the Five Eyes have been
videotapping Yahoo video chat, and most likely all the other
commercial video chat apps as well, how does JitMeet measure up?

Is the video and other data stream encrypted, with good key exchange et al?

..m

_______________________________________________
users mailing list
users@jitsi.org
Unsubscribe instructions and other list options:
http://lists.jitsi.org/mailman/listinfo/users

--
https://jitsi.org