Ostel: Encrypted Phone Calls
A tool for having end-to-end encrypted phone calls. This is a public testbed of the Open Secure Telephony Network (OSTN) project, with the goal of promoting the use of free, open protocols, standards and software, to power end-to-end secure voice communications on mobile devices, as well as with desktop computers.
- Sign up for a free account today on https://OStel.co
- Find out more on our Wiki.
- Download a supported app (Android, iPhone, Blackberry, Nokia, Windows, Mac OS X, GNU/Linux).
- Setup your App.
- View the source code.









First of all thank you for a great product and system
I am currently testing the OSTN /OSTEL sip app. I have one installed on a Google Nexus S with Android 4.12 and another on a Samsung Galaxy tablet with Android 2.2.
The following are my observations:
1. On both devices when I make a sip call I notice that the padlock is locked but on looking at the logs it says SRTP is not active. Does that mean that the call between the two accounts is not secured? There is no 4 character code showing app anywhere on the client screen.
2. When i make a successful connection to each other, I do not go through any process where a 4 character code comes up and there is a cross confirmation of the received common code. It never happens. This is in contrast to when I make a successful call to the 1003 number.
3. How do i know I am having a secured conversation?
4. for both devices the OSTEL version shows as 0.04-00. On the Samsung tablet the application file size is 8.77. On the Nexus S, OSTEL version is same, however the OSTEL application file size reads as 8.88MB
5. On many occasions I could not stop a sip call on the Samsung galaxy tablet even when the other client, the Nexus phone has successfully ended a call. I have on several occasions had to go to the app manager and forcefully end the OSTEL app
The ultimate intention is to build something to be used by several different church campuses, hence security is very high priority
Ostel Servers are US-based. Are there any OSTN servers outside the US?
Not yet, but we are working on it, as well better instructions for how to setup your own server. That is a primary goal, as we understand that US-based services are not ideal for everyone (or perhaps for anyone!)
I am really pleased with the ostel system that you have implemented.
Great work!!!
I was just wondering if you could add a useful feature in your future release.
Since, at times the connection drops due to network or other issues with hardware issues the speech is cut off but the other party is unaware that the call has disconnected and continues speaking to a disconnected line.
To deal with this shortcoming , If you could add the function of a simple alert (audible and/or vibration)in case of an unexpected call disconnect event it would be perfect. Even if the alert sounds during a normal call termination it would be a welcome confirmation. An solid experience somewhat similar to what skype will then be just a stone thow’s away
Thanks again,
AJ
Thou should not use US american servers any more.
Unfortunately the answer is not as simple as that. Many countries’ governments have systems for invasive monitoring, and many countries also have courts that issue secret orders. Judging by your email address, you’re in Germany, and Germany is such a country. There is a good overview of that in this article: Europe won’t save you: Why e-mail is probably safer in the US
And this just in: new Snowden leak info about how Germany, France, Spain, and Sweden also have mass-surveillance programs: http://www.theguardian.com/uk-news/2013/nov/01/gchq-europe-spy-agencies-mass-surveillance-snowden
If the encryption is end to end, it shouldn’t matter where the servers are. They are just relaying encrypted packets. You can also run your own Ostel server(s) if you wanted.
I was wondering if there is a way to create a conference room (or something like that) in ostel.
I’d like to create a multi-user call for some of my meetings.
Thanks in advance.
Hello, I am from Israel, I was using this program, but now ther is problem the ostel is red and it’s writh error while registering- service unavailable, what I need to do?
Yes, I have the same question, i.e., if the encryption is end2end then the physical location of the server doesn’t make any difference or does it? I have heard wiki leaks chose Sweden for their servers? Would that country be better?
Also ostel runs ZRTP only? Is it true that for complete call content encryption both SRTP and ZRTP should be running? Actually I am not knowledgable regarding these protocols and how they work so please throw some light on it. I wanna ensure that if I have matched the SAS on ostel.co using CSipSimple then my call content is heard by myself and the other person only – bulletproof end2end call encrypted!!
Hi,
I have noticed on this wiki OSTN webpage in the osted VoIP Services¶ section:
https://dev.guardianproject.info/projects/ostn/wiki?title=OSTN
that it says SRTP is No whereas ZRTP is Yes. If ZRTP only initiates the session key for SRTP then both protocols must be required to have a real end-2end encyption call session.
I mean to ask in that case the matching of both 4 letters would only mean that session key has been exchanged securely but the call content is still not encrypted if SRTP is not there?
Thanks.
The idea is that it is not plain SRTP without ZRTP to securely negotiate the keys. You are correct that ZRTP is used to initiate an SRTP stream.
The irony of trusting American companies and software to protect your secrets
If you think that other countries besides the USA are not also trying to monitor everything on the internet, you are sadly mistaken. The USA certainly spends the most money doing it, but basically all governments are doing it now, and the USA’s laws are still relatively protective as compared to most of the world. Yes, even Germany, Switzerland, etc.
I want to know about the OSTel installation steps for Ubuntu.
In this solution the calls are not peer-to-peer (like skype). All the encrypted data are relayed by the Ostel server. Am I getting it right?
Yes, exactly. We provide media proxying in order to more easily handle firewall/NAT issues that are often faced.
is not right servers in seychellen or malaysia are better for privacy!!