[guardian-dev] WebRTC

Timur Mehrvarz timur.mehrvarz at riseup.net
Wed Jul 31 10:29:43 EDT 2013


On 07/30/2013 04:17 PM, Nathan of Guardian wrote:
> While the idea of peer-to-peer always seems great initially, if you are
> unable to route that through Tor, or bounce it off a middle mix server
> of some sort to mask end-points, I hesitate from adopting that as a tool
> for activists and journalists, say, who need to protect their networks
> and sources.

Actually, WebRTC traffic does *not have* to travel peer-to-peer. It can
also be pushed through proxies. Probably even through TOR. (Does TOR
route UDP?)

Let's only look at the encryption side for a moment. Are there maybe
some known shortcomings with RFC5764? Or maybe with the way it is being
implemented in browsers today? (And can browsers be trusted?)

-Timur

RFC5764: "Datagram Transport Layer Security (DTLS) Extension to
Establish Keys for the Secure Real-time Transport Protocol (SRTP)"


More information about the Guardian-dev mailing list