Has anyone done any real security analysis on Zfone or ZRTP?
Yes. Andy Clark’s security analysis company, Detica Forensics, did a report in January 2008, available here as a PDF file: Forensic Analysis of Zfone. We stood up pretty well in this report. Riccardo Bresciani at Trinity College in Dublin has also done a formal security analysis of ZRTP, using some special purpose security protocol analysis tools. His report The ZRTP Protocol – Analysis on the Diffie-Hellman Mode (PDF) concludes “The analysis performed on the protocol has formally proven that ZRTP is a safe key agreement protocol”.