> leaving your calls unencrypted, barebacking the web
btw. most of the time only the session is unencrypted, not the media. when sip uses sips it will encrypt both the session and the media. but the latter is pretty uncommon and most often you wil see unencrypted session and an encrypted rtp stream. this is still the default, even deutsche telekom does it like that by default, even in their commerical offerings like "cloud pbx", because you would need to pay extra for the encrypted session.
and btw. sip over tls mostly means that the call is encrypted, but the sip messages aren't.