news.volyx.in

Proof of concept: end-to-end encryption in Jitsi Meet (jitsi.org)

617 points by jrepinc · 2368 days ago · 155 comments on HN

Article summary

Jitsi Meet has implemented end-to-end encryption (E2EE) using a new Chrome WebRTC API called Insertable Streams, allowing for a second layer of encryption on media streams. The feature is currently limited to audio, video, and screen-sharing, and is available for testing on meet.jit.si. The implementation is still a work in progress, with authentication and key management being the next steps. The goal is to provide an additional layer of security and protection for users' meetings.

Main themes

  • End-to-end encryption
  • Key management
  • UX challenges
  • Security trade-offs
  • Trust models
  • Encryption implementation
  • WebRTC API
  • Jitsi Meet development

What commenters say

  • E2EE is useless without proper key verification to prevent MITM attacks.
  • The UX of E2EE key management is a major obstacle to its adoption.
  • Some argue that E2EE is not necessary for most users, and that hop-by-hop encryption is sufficient.
  • Others believe that E2EE is essential for security and that the UX challenges can be overcome with better design.
  • Managing encryption keys is a significant burden for users and may not be feasible for non-technical individuals.
  • E2EE can still provide some security benefits even without key verification, as it makes passive listening more difficult.
  • The trust model of E2EE is still the same as traditional encryption, as users must trust the service provider or client software.
  • Solving the UX problem of E2EE key management is crucial for its widespread adoption.