TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ring, officially a GNU package

169 pointsby terraformingover 8 years ago

13 comments

alpbover 8 years ago
Little bit off-topic but:<p>&gt; respects freedoms and privacy of its users<p>It downloads the binary over http on <a href="http:&#x2F;&#x2F;ring.cx" rel="nofollow">http:&#x2F;&#x2F;ring.cx</a>, makes it susceptible to tampering. Is serving binaries over HTTP a GNU thing because the expectation is that you would check the signature?
评论 #12881312 未加载
snvzzover 8 years ago
While I&#x27;m sure it&#x27;s well-intended, it does have a couple of fatal flaws.<p>* Lack of full forward secrecy means logged network logs can be decrypted in the future if an endpoint key is ever compromised.<p>* e2e encryption is optional, due to legacy SIP support. This is extremely dangerous as it will no doubt lead to false sense of security, with users assuming they&#x27;re safe just because Ring is the program they&#x27;re talking through.<p>Due to these two I cannot actually recommend it to anyone.<p>Note that Tox got these two right, and is a pretty active project which gets commits semi-daily, regardless of the nonsense about it being dead that some party seems to be spreading.
评论 #12894397 未加载
评论 #12882768 未加载
reitanqildover 8 years ago
Official web page seems to be <a href="https:&#x2F;&#x2F;ring.cx&#x2F;" rel="nofollow">https:&#x2F;&#x2F;ring.cx&#x2F;</a>
评论 #12879176 未加载
Ruud-v-Aover 8 years ago
This appears to be something phone-related, not the Ring cryptography library written in Rust based on Boringssl. (<a href="https:&#x2F;&#x2F;github.com&#x2F;briansmith&#x2F;ring" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;briansmith&#x2F;ring</a>)
评论 #12879426 未加载
irl_over 8 years ago
The DHT system for identities is cool, but the thing that gets me is that they don&#x27;t have support for SRTP with ZRTP, only SRTP with SDES. There&#x27;s no perfect forward secrecy, and a bunch of other features that ZRTP has.<p><a href="https:&#x2F;&#x2F;www.silentcircle.com&#x2F;products-and-solutions&#x2F;technology&#x2F;zrtp&#x2F;#why-is-the-zrtp-protocol-better" rel="nofollow">https:&#x2F;&#x2F;www.silentcircle.com&#x2F;products-and-solutions&#x2F;technolo...</a>
评论 #12880088 未加载
评论 #12882178 未加载
metildaover 8 years ago
Has ring improved much? I remember a few months back it used 28gb of background data over LTE (which was fine since I&#x27;m uncapped) on my phone, and was less stable than sflphone, which would randomly stop registering occasionally.<p>I can recommend pjsip though, very reliable so long as you read its docs before writing a script to leverage it.
评论 #12879719 未加载
评论 #12880375 未加载
frumiousircover 8 years ago
What stops attackers from poisoning the DHT? Could one publish false name &lt;--&gt; IP address associations?
评论 #12880070 未加载
评论 #12880682 未加载
davidcollantesover 8 years ago
I could not find this anywhere; do Ring uses a server (NAT traversal, or similar)? Thanks!
评论 #12882155 未加载
qwertyuiop924over 8 years ago
Why this over Tox, Psyc, or Matrix? There doesn&#x27;t seem to be much benefit...
评论 #12880260 未加载
fulafelover 8 years ago
There seems to be no browseable source code around, what are the implementation language(s)? I want to know whether the protocol implementations are written in a memory-safe language.
评论 #12879741 未加载
评论 #12879708 未加载
themihaiover 8 years ago
Is there a well-known discovery document or any other way to create shortcuts for the ringID? (i.e. mapping it somehow to web or email address) I doubt many fancy spelling ringIDs.
Mindless2112over 8 years ago
Seems like it&#x27;s not possible to change your password after you use it to create a Ring ID...
geofftover 8 years ago
What&#x27;s the advantage of being a GNU project these days? It seems like it ties you very strongly to the FSF&#x27;s political opinions and in particular Richard Stallman&#x27;s political opinions (e.g., eugenics) and restricts your technical decision-making options (e.g., limited plugin architecture, limited support for non-free OSes, mandatory support for things like GNUTLS), while not giving you very much in return - with the existence of GitHub and a wide variety of competitors, it&#x27;s pretty easy to attract a healthy development community independent of GNU. What am I missing?
评论 #12880120 未加载
评论 #12880273 未加载
评论 #12880123 未加载
评论 #12881214 未加载