Live data from Hacker News

Zoom meetings aren’t end-to-end encrypted, despite marketing

theintercept.com

11–20 of 351 posts

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#11
post #5

I guess Zoom says they're end-to-end encrypted because they're using WebRTC, which probably means traffic is end-to-end encrypted after signaling, but users need to trust that zoom's signaling server doesn't do anything fishy. Edit: I do not understand the reason for the downvotes. I am not defending the practice but am just describing their potential line of explanation. Please let me know explicitly if my comment i…

Yeah somewhere in their documentation they state that they are end-to-end encrypted because the connections peer1zoom and zoompeer2 are encrypted. I cant find the page anymore but they really tried to redefine the name for end to end encryption...

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#12
post #8
post #2

Zoom has received a fair bit of critical feedback lately. Has anyone given other platforms such as Vidyo identical levels of scrutiny?

I'm usually not the one for conspiracy theories and this is most likely just media outlets fixating on one topic for clicks, but sometimes this just feels like a smear campaign against Zoom. I'm sure a lot of these issues could be found for other providers as well.

If you fucked up bad enough multiple times people will find lore. Years ago it was constant news about uber now its zoom. If a company is dishonest enough you will find enough more bad news, and as long as bad news get clicked...

But i am happy theres media attention for this exact topic because it was dishonest all the time and people have chosen zoom over other solutions because zoom is the only one claiming end to end encryption.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#13
End-to-end encryption has been named as a required feature for telehealth in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks for obvious reasons. So I've been trying really hard to work out if Zoom is E2E, and reached the same conclusions as the article. First, it isn't, and second, Zoom are really going out of their way to obscure that fact.

It's great that The Intercept is taking a look at this, because it's absolutely beyond the capabilities of healthcare practitioners and the professional bodies to get to the bottom of. There's a ridiculous amount of confusion here, compounded by "you need to get the HIPAA version because HIPAA means privacy".

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#14
post #11
post #5

I guess Zoom says they're end-to-end encrypted because they're using WebRTC, which probably means traffic is end-to-end encrypted after signaling, but users need to trust that zoom's signaling server doesn't do anything fishy. Edit: I do not understand the reason for the downvotes. I am not defending the practice but am just describing their potential line of explanation. Please let me know explicitly if my comment i…

Yeah somewhere in their documentation they state that they are end-to-end encrypted because the connections peer1 zoom and zoom peer2 are encrypted. I cant find the page anymore but they really tried to redefine the name for end to end encryption...

end-to-middle-to-end encrypted...

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#15
post #7
post #5

I guess Zoom says they're end-to-end encrypted because they're using WebRTC, which probably means traffic is end-to-end encrypted after signaling, but users need to trust that zoom's signaling server doesn't do anything fishy. Edit: I do not understand the reason for the downvotes. I am not defending the practice but am just describing their potential line of explanation. Please let me know explicitly if my comment i…

Video conferences via WebRTC usually have a central server that distributes all the video streams and are therefore not end-to-end encrypted.

End to End encryption in conferences of >2 participants causes substantial quality degradation for the same bandwidth use, since you can't have a central server re encoding streams to produce low quality streams for those participants who need it.

I believe zooms reputation as being more likely to 'just work' in part hinges on that,

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#16
post #9
post #8

Earlier quoted context omitted.

I'm usually not the one for conspiracy theories and this is most likely just media outlets fixating on one topic for clicks, but sometimes this just feels like a smear campaign against Zoom. I'm sure a lot of these issues could be found for other providers as well.

Name one provider that claims to provide end-to-end encrypted video calls but doesn't.

GoToMeeting claims end to end encryption[1] and in the same sentence say it's just SSL just like Zoom. Never the less they offer call-in as well so end to end becomes impossible right there. I have serious doubts about any conference software offering real end to end encryption as it's unrealistic for clients to be dealing with that many av streams.

1. https://support.goto.com/meeting/help/security-faqs-g2m05001...

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#18
post #7

Earlier quoted context omitted.

Video conferences via WebRTC usually have a central server that distributes all the video streams and are therefore not end-to-end encrypted.

End to End encryption in conferences of >2 participants causes substantial quality degradation for the same bandwidth use, since you can't have a central server re encoding streams to produce low quality streams for those participants who need it. I believe zooms reputation as being more likely to 'just work' in part hinges on that,

That's a fair technical tradeoff, but you can't have it both ways.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#19
post #2

Zoom has received a fair bit of critical feedback lately. Has anyone given other platforms such as Vidyo identical levels of scrutiny?

TBF it's mostly short sellers doing this, because the complaints have been... poor. The first one was about an advertisement pixel, which everybody is doing but for some reason surfaced only for Zoom. The second one is end-to-end encryption, which is not expected at all for VC apps. NOBODY does it!

>NOBODY does it!

Irrelevant. That as nothing to due with the fact that they say they are. Zoom is being completely dishonest, and as some other commented here, some orgs like in health care area, have E2E encryption as requirement, Zoom says they have, but don't. It's literally fraud.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#20
post #13

End-to-end encryption has been named as a required feature for telehealth in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks for obvious reasons. So I've been trying really hard to work out if Zoom is E2E, and reached the same conclusions as the article. First, it isn't, and second, Zoom are really going out of their way to obscure that fact. It's great that The Intercept is t…

Hopefully we've reconsidered the laws of mathematics in the last few years ...

https://www.newscientist.com/article/2140747-laws-of-mathema...

"“The laws of mathematics are very commendable, but the only law that applies in Australia is the law of Australia,” said Turnbull.

Turnbull’s comments came as he proposed a new law to force tech companies to give security services access to encrypted messages."

"The UK home secretary Amber Rudd has previously called encryption “completely unacceptable” and the UK prime minister Theresa May has said that the big internet companies give terrorists “safe spaces” to communicate."

Going to have to get over this first :/

Post reply on HN