Over on Slashdot, CmdrTaco shares timely and exciting news for law-abiding Americans who don’t care for involuntary three-way calls with the NSA (it’s big news for anyone in the world who likes to keep private conversations private):
Philip Zimmermann, creator of PGP wrote in to tell me about Zfone, his new system for encrypting any SIP VoIP voice stream. His first release is Mac & Linux only. I tested it with him using Gizmo as our client and it was pretty trivial to use. While it should work on most any SIP compatible VoIP client, he hopes that clients like OpenWengo and Gizmo will incorporate Zfone directly into the UI. Zfone has no centralization, and has been submitted to the IETF. He hasn’t yet determined a license, but he believes strongly in releasing source code for all encryption products. A windows client is forthcoming.
Link. ETA on a Windows XP release: mid-April. And on philzimmermann.com, Philip explains:
I think it’s better than the other approaches to secure VoIP, because it achieves security without reliance on a PKI, key certification, trust models, certificate authorities, or key management complexity that bedevils the email encryption world. It also does not rely on SIP signaling for the key management, and in fact does not rely on any servers at all. It performs its key agreements and key management in a purely peer-to-peer manner over the RTP packet stream. It interoperates with any standard SIP phone, but naturally only encrypts the call if you are calling another Zfone client. This new protocol has been submitted to the IETF as a proposal for a public standard, to enable interoperability of SIP endpoints from different vendors.
Link. (Thanks, Jake Appelbaum!)