Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think they just use the encryption and key exchange that WebRTC has cooked in https://datatracker.ietf.org/doc/html/rfc5764


tl;dr: One peer generates a self-signed certificate and sends the fingerprint of that over the signalling channel; the other connects to it as a "client".

The resulting DTLS keying material is subsequently used for SRTP encryption (for media) and SCTP over DTLS (for the data channel, which is presumably what's being used here).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: