Re: [liberationtech] WebRTC - voice authentication to the rescue

2014-01-23 Thread shootak...@riseup.net
All WebRTC needs to be as secure as a service like ostel.me is a browser extension implementing ZRTP authentication between you and the callee. This approach does not rely on PKI and does not need a server in between caller and callee. Also the ZRTP authentication string some of you are

Re: [liberationtech] Encrypted Pastebins: Attack Vectors against ezcrypt.it and 0bin.net

2014-01-21 Thread shootak...@riseup.net
Hi Lucas, I tried to set up a secure WebRTC server about one month ago using Kamailio with the Mediaproxy-ng to bridge text, audio, and video with appropriate ciphers which provided random public keys per session. The main security problem I found was with WebRTC's reliance on PKI to secure the