6 ms·
Ghost Call – Secure, Encrypted, Anonymous Calling
- ncza 11y agoSite seems dead. Is it free software? What differentiates it from Signal/TS?
- patcon 11y agoAgreed. Google cache: https://webcache.googleusercontent.com/search?q=cache:CoDOYafinxQJ:https://ghostcall.io/+&cd=1&hl=en&ct=clnk&gl=ca https://webcache.googleusercontent.com/search?q=cache:CoDOYa...
- tedks 11y ago* It is free software, or rather, the client they recommend is Linphone, an existing open-source VoIP client. * Specifically, the value add is an introduction/routing layer over SIP. They recommend connecting via Tor. * The encryption is stock ZRTP. In comparison, Signal/TS is free software, but uses novel crypto for text messages. I believe RedPhone/Signal voice is still just ZRTP. RedPhone/Signal will convert the SAS code to two frequently-amusing phrases, whereas LinPhone will just display the raw code. There doesn't seem to be an easy way to use RedPhone with Tor, or to anonymously register with RedPhone, though I could be wrong.
- Canada 11y agoRedphone/Signal has its own signaling protocol for voice calls as well. This service uses SIP. The Redphone protocol is simple in design, while SIP is the opposite.
- Squale 11y agoOk on Tor but no https so anyone could get your number/password and steal your identity http://hc3sz3i2rb5dljqq.onion/ http://hc3sz3i2rb5dljqq.onion/ Edit: my bad it's late...of course there is no risk of mitm as it's a tor service, so no risk of bad exit node -_-' sorry guys
- lambada 11y agoThat's not how Tor Hidden Services work. They're encrypted end-to-end (well, from your node to the host of the Hidden Service. So accessing via that address leaves no room* for anyone to get your number/password or steal your identity. * (Usual caveats about that being the correct .onion address, about the encryption not flawed etc)
- tvirelli 11y agoWe're moving it to a new server with lots more bandwidth!
- tvirelli 11y agoOK, we have moved to a server that can handle the load. It may take a bit for DNS to propagate for everyone!
- chatmasta 11y agoIf you are going to recommend users connect to you via a proxy or Tor, don't recommend tor2web. The whole point of tor2web is that it's a non-anonymous way to access Tor. Your traffic goes through tor2web servers, which are not part of the onion routing. Anyway, nice business. If I'm understanding correctly, you are basically an SIP hosting provider that assumes your clients will use Linphone to connect. Am I correct in this? If so, it's an interesting model, but I think you need to put more effort into clarifying that you are a host, not a security provider. Also, you might want to apply some of that hosting expertise to your website....
- kseistrup 11y agoSo by registrating I get (1) a number, (2) a password, and (3) a country code. What do I enter as username etc. in Linphone?
- patcon 11y agopresumably the country code + phone number is your username... but I can't see the tutorial videos while the site is struggling
- kseistrup 11y agoI've tried both with and without the country code, but the SIP client fails to register. The server could be overloaded, tough — perhaps I should try again tomorrow.
- john8675309 11y agoMake sure you are using TLS, it will always fail if you don't have TLS on (port 5061)
- fenesiistvan 11y agoWith regular SIP you might have a look at mizutech SIP encryption. It has multiple encryption methods (the standard TLS/SRTP and non standard RSA based) and also a nice obfuscation to bypass VoIP blockages. They are also running a distributed network to mask the VoIP servers. http://www.mizu-voip.com/Software/VoIPTunnel.aspx http://www.mizu-voip.com/Software/VoIPTunnel.aspx
- kseistrup 11y agousername = phone number (sans international prefix), domain = call.ghostcall.io, transport = tls.
- patcon 11y agoHm. I'm not sure I get it. (from the Google cache) > Q: Can I call any number I want? > A: No. Ghost Call can only call other Ghost Call numbers. > Q: How can we contact you? > A: You can email us at info@ghostcall.io, or Ghost Call us: (490)-628-2381 So it's a ZRTP SIP provider that uses regular phone number format as the identifier? It strikes me as rather much like OSTN/OSTel, but using a phone-number-looking identifier rather than a username... and if that's the case, the whole ostn stack is opensource/auditable and federated, so I'm unsure of the improvement here, aside from the branding. Heck, I would prefer if they used the OSTN chef cookbooks and contributed back. EDIT: Nooo! I'm the downer top commenter! I have become all that I am mildly irritated by. To clarify, I like that this service was created, and commend the interest of the devs, regardless of my outstanding questions :)
- wildster 11y agoSeems better than Skype.
- unicornporn 11y ago"Better" is a broad claim. Have you compared SIP/Skype call quality and reliability.
- john8675309 11y agoSo the project was built for a hobby, I wanted an encrypted phone service. But I wanted every aspect of it to be encrypted, from the signaling to the RTP. I wanted to make sure that no unencrypted client could connect to the platform. I would be interested in peering with oslec though.
- chatmasta 11y ago"You can do this with open source, X, Y and Z" is the classic initial criticism of successful companies. What critics forget to consider is that 99.9% of people do not enjoy doing complicated things. If private calls were as easy as public calls, why wouldn't someone make a private call? I think there is even an XKCD for this phenomenon.
- crypt1d 11y agoLooks cool but the 'About' part might be 'too much' for the average Joe. I'd put it in layman terms if I were you, maybe make a simple diagram...etc
- KFW504 11y agoAgreed - this is amazing, but speed to scale comes with clarity for the masses
- 0x006A 11y agohow does it compare to OSTN/OSTel (https://ostel.co/ https://ostel.co/)
- john8675309 11y agoI have never personally used the service, but the design from the ground up on ghost call is encryption, using all open source phones/etc (I think ostel does this as well) I also wanted to prevent any unencrypted client from connecting either intentionally or by misconfiguration.
- doomrobo 11y agoCould anybody explain what ZRTP hash is and why it's insecure?
- KFW504 11y agoThis might help: http://blog.cryptographyengineering.com/2012/11/lets-talk-about-zrtp.html http://blog.cryptographyengineering.com/2012/11/lets-talk-ab...
- xbryanx 11y ago"Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety." I used to use this quote all the time too...until I realized it originally meant something entirely different. http://techcrunch.com/2014/02/14/how-the-world-butchered-benjamin-franklins-quote-on-liberty-vs-security/ http://techcrunch.com/2014/02/14/how-the-world-butchered-ben...
- jessriedel 11y agoI don't see how it means something entirely different. At most, Franklin and the other founding fathers had a more expansive notion of liberty than is now common. Both the sanctity of private property and the right to privacy are aspects of that sort of liberty.
- usefulcat 11y agoI think the point is that the context is fundamentally different: "In short, Franklin was not describing some tension between government power and individual liberty. He was describing, rather, effective self-government in the service of security as the very liberty it would be contemptible to trade. Notwithstanding the way the quotation has come down to us, Franklin saw the liberty and security interests of Pennsylvanians as aligned." http://www.lawfareblog.com/2011/07/what-ben-franklin-really-said/#.UvvR12RDtZs http://www.lawfareblog.com/2011/07/what-ben-franklin-really-...
- jessriedel 11y agoThis is a vastly better article, and actually makes a reasonable case. Thanks. Still, I don't think it's fair to say the context is "fundamentally different". In Franklin's situation, the trade-off was to give up a degree of the colony's self-governance (with power taken by the unelected governor) in order to get safety from the war being fought on their frontier. Yes, in his case it wasn't so much personal (individual) liberty as it was the notion of colonial self-governance. But I don't think it's so vastly different as to say the quote's original meaning has been greatly distorted. Here's the original letter: http://franklinpapers.org/franklin/framedVolumes.jsp?vol=6&page=238a http://franklinpapers.org/franklin/framedVolumes.jsp?vol=6&p...
- ericfontaine 11y agoWill this be available on f-droid? Many people don't like having google play on their phone, especially those concerned with privacy and open-source. I know the user can always compile this themselves.
- patcon 11y agoPeanut gallery here: It's just a service that will work with most any SIP client app that supports ZRTP -- csipsimple, linphone, etc :)
- dataker 11y agoSeems like a great project, but I'd argue governments would heavily try to undermine it.
- dataker 11y ago> A:During the beta period logs are kept for 24 hours, once beta is complete there will be no call log records. Is there a particular reason to do so during their beta?
- iaw 11y agoNot associated with Ghost Call but my expectation is that they'd use the logs for debugging major bugs during the beta period. Kind of hard to identify and reproduce transient issues without those logs.
- john8675309 11y agoYou hit it on the head. I am not interesting in anything but calls not working. After that I have no need or want for the data.
- iaw 11y agoI think anyone that's built a complicated system before gets it implicitly.
- DSMan195276 11y agoIf logs include useful call information, then it might be useful for debugging purposes. Without a log, you'd have no idea what happened. That said, that's just a guess.
- joepie91_ 11y agoIf there are logs to be kept to begin with, I'd be very skeptical about any "anonymous" and "secure" claims. If it requires trust, then it isn't.
- patcon 11y agoEvery computer has logs. If you interact with a server, you can't avoid it. Until we have decentralized apps, trust on this is unavoidable. ZRTP and the sign-up process means it will be hard to connect the little metadata they have, so they've narrowed down the amount they're trusted with by a large margin
- drussell 11y agoAnonymity is quite the growing market segment. And the NSA is as unpopular as ever. It's fascinating how the public responds to the government.
- amelius 11y agoIs that true? I hear bitcoin is gaining market share, and it is the antithesis of anonymity.
- andrewchambers 11y agoI think you are confusing anonymity with something else. Bitcoin is entirely anonymous, but all transactions are public. You can create as many wallets and keys as you want, and you don't have to tell anyone you own them.
- olefoo 11y agoThis only allows you to stay anonymous if you can get your money out of bitcoin anonymously. Whether by buying dollars/yen/whatever on an exchange or purchasing goods and services. And it's damn hard to buy a yacht anonymously regardless of the unit of account the transaction is done with.
- aboutus 11y agoThe most important aspects of bitcoin is that it's decentralized (cannot be controlled by governments and banks) and inflation-proof. It's not anonymous, but certainly more private than using a debit or credit card!
- andrewchambers 11y agoYou can get bitcoin anonymously by mining. The weakness is in trading, even then, there are anonymous goods such as digital goods, and probably ways to perform anonymous escrow when trading real goods. In practice, people don't care, because they aren't doing anything illegal.
- deleted 11y ago
- john8675309 11y agoHey everyone, the site is having a hard time responding (obviously), I am working to get it back going, Thanks for hanging in there!
- tvirelli 11y agoWe updated the site with a video showing video chat!
- howtoplayhuman 11y agoHmmmm? 1st: Ghost Call recommends ZRTP media encryption 2nd: ZRTP hash allows a MITM (Man In The Middle) and creates a risk of decryption. Why recommend it then? Am I missing something?
- MrSheen1812 11y agoHave gone through the setup for Android, manage to make calls but they're not secured, TLS and ZRTP enabled, STUN server correct.....