TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Authentication on meet.jit.si

228 pointsby muxatorover 1 year ago

39 comments

koito17over 1 year ago
I was getting login pages last week when attempting to start meetings.<p>Ironically, this led me to self-hosting Jitsi with the Jitsi Helm chart and putting it behind oauth2-proxy so my friends and I can use it. Deploying Jitsi with the Helm chart is remarkably simple and does not consume that much memory.<p>If anyone is interested in self-hosting: 2 GB is my RAM usage on idle when running videobridge, web-ui, prosody, and oauth2-proxy atop k3s in its default configuration. You do have to open a stupidly large range of ports to UDP traffic for videobridge, though. With that said, it&#x27;s been a reliable solution and does not need me or my friends to create $BIGTECH account.
评论 #37320247 未加载
评论 #37325549 未加载
评论 #37317377 未加载
评论 #37320924 未加载
评论 #37325320 未加载
gnicholasover 1 year ago
&gt; <i>Earlier this year we saw an increase in the number of reports we received about some people using our service in ways that we cannot tolerate. To be more clear, this was not about some people merely saying things that others disliked.</i><p>That’s only slightly more clear, since it just says what’s not happening. Does anyone know what <i>is</i> happening? Does it involve potential violations of law, or is it just the TOS?
评论 #37317312 未加载
评论 #37318971 未加载
评论 #37318450 未加载
评论 #37317789 未加载
评论 #37317437 未加载
评论 #37317626 未加载
otachackover 1 year ago
This is rough for Jitsi &#x2F; 8x8. Requiring a login puts them at a level of &quot;why not just use Google Meet?&quot; to me unless you go through hoops to self host.<p>I&#x27;m down to experiment with self hosting, I just feel that most users out there won&#x27;t be and it&#x27;ll ding their user count. It might be for the best if it squashes the malpractice they are seeing.
评论 #37318175 未加载
评论 #37320084 未加载
评论 #37320795 未加载
评论 #37326631 未加载
p-e-wover 1 year ago
Why exactly do I still need a middleman in 2023 to talk to someone else&#x27;s computer? Is NAT the only reason?<p>Also, why exactly did we introduce IPv6 again? Everything today is NAT-within-NAT-within-NAT (much of it using IPv4), and almost nobody has a publicly routable IP address. Was the whole transition just a massive waste of effort?
评论 #37320777 未加载
评论 #37319175 未加载
评论 #37319034 未加载
评论 #37320790 未加载
评论 #37318789 未加载
评论 #37318443 未加载
评论 #37320816 未加载
评论 #37321237 未加载
评论 #37320342 未加载
sourcepluckover 1 year ago
<a href="https:&#x2F;&#x2F;www.fsf.org&#x2F;associate&#x2F;about-the-fsf-jitsi-meet-server" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.fsf.org&#x2F;associate&#x2F;about-the-fsf-jitsi-meet-serve...</a><p>If one becomes an associate member of the FSF, one of the perks is access to a Jitsi server that they run.<p>It&#x27;s two clicks and you&#x27;re in, easy peasy. I&#x27;m very grateful. I give classes over webcam and it does not let me down.
评论 #37322760 未加载
评论 #37322517 未加载
saghulover 1 year ago
Hey all Jitsi dev here. It hasn’t been an easy few days, thanks a lot for the empathetic comments I’ve seen here.<p>We’ll keep moving forward making (hopefully) the best open source meetings tool out there.<p>To answer a few recurring questions:<p>- Only the first user needs to be authenticated<p>- This change does not affect the self-hosted deployments, you can choose what auth (or none at all) to use
评论 #37324624 未加载
solarkraftover 1 year ago
Ouch, ouch, ouch.<p>The beauty of Jitsi Meet was that <i>any</i> URL was a valid room. That was such great UX.<p>Of course, other Jitsi Meet instances still exist. But this will probably still influence the project&#x27;s direction.
评论 #37320141 未加载
评论 #37325663 未加载
评论 #37321177 未加载
Roark66over 1 year ago
Wait, isn&#x27;t jitsi open source? If so anyone can host their own server and disable the auth right? If so, why the anger?
评论 #37318985 未加载
评论 #37318978 未加载
评论 #37318328 未加载
评论 #37325699 未加载
toastalover 1 year ago
A bonus to self-hosting is now you’ll have an XMPP server you &amp; your chatmates &amp; org can use for decentralized, federated chat—may as well add a new virtualhost &amp; ditch that proprietary chat option.
评论 #37317595 未加载
istillwritecodeover 1 year ago
I just stopped using it. I can understand that they might have had problems with abuse, but I won&#x27;t use any of their authentication options.
dathinabover 1 year ago
I hadn&#x27;t really used it recently but I&#x27;m honestly surprised that they went that long without requiring authentication. If you know a bit about mitigation of various abuse patterns it&#x27;s kinda crazy that they managed to not needing to require it until now.<p>Through I hope they have a way for registered people to invite someone to join a meeting without a login (through with a bunch of limitations, like them being responsible for the person joining).<p>For example so that in case of a remote job interview the company can give them to the interviewee.
评论 #37320170 未加载
pietroppeterover 1 year ago
&gt; we will no longer support the anonymous creation of rooms on meet.jit.si, and will require the use of an account<p>if I understand correctly the creator of the meeting needs to have an account but other people can still join without it?
评论 #37320617 未加载
hilbert42over 1 year ago
I no longer have any Big Tech accounts and I&#x27;ve not had a Zoom account for all the reasons why many of us want to rid ourselves of those environments. It&#x27;s people like me who actually need Jitsi.<p>What makes it worse, I&#x27;ve been almost successful in weening friends and colleagues off Zoom and that&#x27;s no easy task. Now it&#x27;s all for nought.<p>Damn nuisance really.
评论 #37320197 未加载
playdayover 1 year ago
Unfortunate but not surprising. It’s impossible to put up a 0 cost service on the net without it getting abused.
评论 #37319629 未加载
superkuhover 1 year ago
Does this mean that Riot.im&#x2F;Element.io Matrix.org homeserver accounts on the web application won&#x27;t be able to use the service automagically for video calls of greater than 2?
评论 #37317886 未加载
enkursigiloover 1 year ago
You can still create room without login. Just click &quot;book a meeting URL&quot; at <a href="https:&#x2F;&#x2F;meet.jit.si&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;meet.jit.si&#x2F;</a> which redirects to <a href="https:&#x2F;&#x2F;moderated.jitsi.net&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;moderated.jitsi.net&#x2F;</a> and there you can create room without any authorization.
评论 #37323229 未加载
jokoonover 1 year ago
What can&#x27;t they provide their own login instead of using Facebook Google GitHub?
评论 #37318785 未加载
评论 #37319144 未加载
评论 #37325168 未加载
wrpover 1 year ago
I had a video conference scheduled a few days ago with Jitsi. Ran into this problem so we quickly searched for an alternative. We couldn&#x27;t get www.experte.com working. Tried we.team and it worked great. In fact, it didn&#x27;t have the frequent freezing we had been experiencing with Jitsi.
saurikover 1 year ago
As seen at <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=37258646">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=37258646</a> (along with some helpful suggestions).
CatWChainsawover 1 year ago
People will just start making&#x2F;using dummy accounts to create meetings if they don&#x27;t want them tied to their real identities.<p>KYC has gotten wildly out of control.
fswdover 1 year ago
we moved over to talk.brave.com
评论 #37323063 未加载
rvzover 1 year ago
&gt; Starting on August 24th, we will no longer support the anonymous creation of rooms on meet.jit.si, and will require the use of an account (we will be supporting Google, GitHub and Facebook for starters but may modify the list later on).<p>So Jitsi loses the case for privacy and goes and requires Big tech logins such as Google, GitHub (Microsoft), Facebook (Meta).<p>Oh dear.
评论 #37317291 未加载
评论 #37317329 未加载
评论 #37317410 未加载
评论 #37320892 未加载
评论 #37319578 未加载
brightlancerover 1 year ago
They only require ONE person to have an account. The other participants can join as before.<p>The meeting continues even if the person with the account leaves; as long as someone stays in the room, it persists and people can (re)join.<p>I don&#x27;t like this change but their free (beer) service is still more respectful than GOOG Meet or MSFT Teams.
jesprenjover 1 year ago
Maybe a list of community hosted jitsi servers could be put in place.<p>One instance that our national educational network organization hosts is at <a href="https:&#x2F;&#x2F;vid.arnes.si.&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;vid.arnes.si.&#x2F;</a>
评论 #37321928 未加载
pabloarteelover 1 year ago
<a href="https:&#x2F;&#x2F;keet.io&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;keet.io&#x2F;</a> seems like an interesting replacement. P2P has it&#x27;s hurdles but removes the centralized point of failure.
jimwormover 1 year ago
The popup window login with the many different domains doesn&#x27;t work with isolation on. Hope they don&#x27;t take the random meeting name (the last anonymous option) away.
seydorover 1 year ago
Just wish it was easier to setup a self-hosted server. It was easier to setup a red5 server in the 2000s than it is to setup a webrtc server in 2023
vasanthvover 1 year ago
Checkout <a href="https:&#x2F;&#x2F;tlk.li" rel="nofollow noreferrer">https:&#x2F;&#x2F;tlk.li</a> which is free, p2p and open source.
teekertover 1 year ago
Hmm missed opportunity for a passkey method.
j45over 1 year ago
Does this mean the self-hosted version of Jitsi will have authentication by default and not a free to use instance?
KingOfCodersover 1 year ago
Just moved there from Zoom, what a nasty suprise these days that I need to register when I wanted a meeting.
throwaway290over 1 year ago
Just as I started using it from Zulip. I guess they encountered some kind of abuse.
skeptruneover 1 year ago
This sucks
victorbjorklundover 1 year ago
Too bad but not suprised.
TobyTheDog123over 1 year ago
Well on the bright side, hopefully this incentivizes Jitsi to finally put first-class OIDC support into the codebase, which it still lacks.<p>I don&#x27;t want to set up an entire LDAP server when I already have Authelia running.
quickthrower2over 1 year ago
Are JaaS user’s users affected?
LWIRVoltageover 1 year ago
Ever since early in the pandemic, i&#x27;ve pointed friends who were worried about certain things- in the direction of Jitsi so they coudl safely discuss options without a time limit(which Zoom and Meet implemented) with others.<p>Think conversations like discussion of abortion, and other things where the service in certain locations needed to be private to the point subpoenas wouldn&#x27;t be a threat. This is also why they&#x27;ve been waiting for insertable streams to be fully implemented in Firefox- those tickets were pushed most heavily because of Jitsi&#x27;s videocalling.<p>This was driven by when they implemented an end to end encryption option- and being open source , something people could feel safer about than trusting Meet&#x27;s (the former Duo)&#x27;s one on one calls.<p>The best part is this was something you could bring up on any computer. Signal , you need to own the device- Jitsi was more free than Signal in some ways- and of course it helps not being tied to a identifier(Signal has not yet implemented removing phone numbers as an identifier)<p>-Does this mean there&#x27;s no free, end to end encrypted anonymous alternative that would be useful for those who are not technically inclined- but worry about Subpoenas, and need end to end encryption? That&#x27;s as accessible(Jitsi was from a simple web interface no matter your device, alternatives like Jami and Meet aren&#x27;t - and the account thing hurts)<p>Because trusting a Github, Google ,or Facebook login to not be vulnerable to subpoenas - is a nonstarter. ( I am aware of the efforts of Google, Facebook, etc to mass E2EE communications from test messages to all messenger messages - I don&#x27;t think this is immune to legal&#x2F;coercive efforts such as you might see in the UK&#x2F;Australia, and also think the anonymity layer is going to be the crucial for some people. ...I&#x27;m aware ease of use plays a role in abuse- but i&#x27;ll point out bad actors(who are technically capable at least a little apparently) have the resources to still abuse Jitsi(if someone had an axe to grind against Jitsi) regardless of these additions- [example:Google accounts can be still mass created anonymously via Android phones&#x2F;burner phones &#x2F;etc]<p>I dislike this, having been banging my head against the wall given my efforts over the past few years to teach end to end encrypted options and their usage to those who need them most, for the mentioned reasons.<p>For now I will resort to bugging people to switch to other instances at <a href="https:&#x2F;&#x2F;jitsi.github.io&#x2F;handbook&#x2F;docs&#x2F;community&#x2F;community-instances&#x2F;" rel="nofollow noreferrer">https:&#x2F;&#x2F;jitsi.github.io&#x2F;handbook&#x2F;docs&#x2F;community&#x2F;community-in...</a> - but we badly need more options just as accessible- what other E2EE anonymous web-browser accessible tool is as available to the masses, that they can be convinced to use?
评论 #37318240 未加载
评论 #37318128 未加载
评论 #37318536 未加载
评论 #37319700 未加载
评论 #37320709 未加载
评论 #37318125 未加载
BaseballPhysicsover 1 year ago
Fascinating reading the angry comments here.<p>Don&#x27;t blame Jitsi. Blame the people abusing their previously wide open service. They&#x27;re why we can&#x27;t have nice things.<p>As for expecting them to run their own auth service instead of relying on a third party, that is a hell of a lot more complex than it looks. I can&#x27;t blame them for not wanting to take that on.<p>If you really disagree that much, go ahead and fire up your own Jitsi service and open it up for anonymous use by the public. Let&#x27;s see how long <i>you</i> can run it before you encounter the exact same problems.
评论 #37318289 未加载
评论 #37318334 未加载
评论 #37318376 未加载
评论 #37320128 未加载
评论 #37319081 未加载
评论 #37318293 未加载
turbletyover 1 year ago
I&#x27;m certain this is just an excuse so they can monetize and then sell out.<p>First step auth, second step payments&#x2F;subscriptions&#x2F;premium&#x2F;whatever, third step sold to a big corp where it will be destroyed.<p>But anyway, for anyone wanting an alternative peercalls has been really reliable for us.