Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Jitsi Meet users may be thrown at Google/Amazon/Microsoft/Cloudflare without knowing #47

Open
JupiterRowland opened this issue Aug 8, 2023 · 0 comments

Comments

@JupiterRowland
Copy link

Many instances on the Jitsi Meet list use commercial services provided by Google/Alphabet, Amazon, Microsoft and/or Cloudflare which are suspected or even out-right known to spy on their users.

jitsi.random-redirect.de has a high chance of landing users on an instance with Google's STUN/TURN service and even a chance of sending them straight into Cloudflare or onto a Google or Amazon server. The users don't know about this. They don't know beforehand where they'll land. They don't know that the instance they land on is "dirty". And even if they knew, they couldn't do anything about it.

There is a way of knowing which instances are "dirty", and which are safe: The Jitsi Meet Handbook has a list of community-run instances with two columns which are important to check. One marks instances which don't use Google STUN/TURN; not even half of them avoid it.

The other one marks instances which run on Google, Amazon or Microsoft servers and/or through Cloudflare. This is the case with two instances on the random-redirect list: meet.ffmuc.net runs its Web frontend through Cloudflare which is relevant because it's the Web frontend which random-redirect redirects to. And meet.jit.si runs on Amazon AWS and uses Google STUN/TURN.

If data privacy protection is of any concern for random-redirect, all these instances should be removed from the list, and new instances should be checked before being added.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant