Live data from Hacker News

Zoom meetings aren’t end-to-end encrypted, despite marketing

theintercept.com

71–80 of 351 posts

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#71
post #23

I am willing to chalk this up to an honest mistake considering "end-to-end" encryption as being from the client's end to the server, although that's not the accepted use of the term. This appears to be their explanation. I hope their marketing team fixes this now that it's been pointed out to them though.

A single honest mistake in the privacy/security area is already close to inexcusable. Zoom has a proven terrible track record in anything security and privacy related. So letting this one go would be very very naive.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#72
post #27

how can you have end-to-end encryption with server side processing in conference calls with 50 participants?

You can't, without having every client process all the video and mix all audio. In other words, with current consumer hardware and internet coverage, you can't.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#76
post #54
post #51

Earlier quoted context omitted.

It goes far further than stupid comments by our (former) prime minister. The current legislation (passed in 2018) allows the government to force the installation of backdoors through a process that doesn't have any judicial overview or substantial public scrutiny whatsoever.

Number one reason we dropped JIRA.

Out of curiosity, what did you switch to?

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#77

Earlier quoted context omitted.

Now I know why it was the only video conferencing service that worked in Dubai. Others, like meet, WhatsApp - video are not working for censorship reasons.

I'm pretty sure that Google Meet isn't end-to-end encrypted either. Nothing that Google does is. WhatsApp does claim that videos are end-to-end encrypted as well, although given Facebook announced they'll implement client-side agents for processing user data and given its proprietary nature, I avoid WhatsApp for anything very sensitive as well.

Google Duo is end-to-end encrypted [0]. I don't know about Meet.

Disclaimer: Working at Google, in the same org as Duo.

[0] http://support.google.com/duo/answer/9280240?hl=en

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#78
post #13

End-to-end encryption has been named as a required feature for telehealth in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks for obvious reasons. So I've been trying really hard to work out if Zoom is E2E, and reached the same conclusions as the article. First, it isn't, and second, Zoom are really going out of their way to obscure that fact. It's great that The Intercept is t…

I have a telehealth appointment (in Australia) this week, and they are using https://doxy.me/

Anybody know much about that one?

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#79
post #34

Earlier quoted context omitted.

> The UK home secretary Amber Rudd has previously called encryption "completely unacceptable" ... Theresa May has said that the big internet companies give terrorists "safe spaces" to communicate. Ironically, the UK government in fact uses Zoom for all its meetings depsite privacy and security implications. Saudi Arabia, take note. Ref: https://www.businessinsider.com/coronavirus-boris-johnson-zo...

That's terrible for national security. Zoom engineers are based in China: https://www.cnbc.com/2019/03/26/zoom-key-profit-driver-ahead...

Components of the GB 5g network are also being outsourced to China. Some of the ruling party's MP's are not happy about it.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#80
post #46
post #27

how can you have end-to-end encryption with server side processing in conference calls with 50 participants?

My problem with this is Zoom's misleading claims. If Zoom can't implement end-to-end encryption, it shouldn't claim that it does.

I think they would claim the terminology is ambiguous. If the connection is encrypted between all clients and the central server, a business person might say that's end-to-end, ie all traffic in flight.

The real test is peer-to-peer or not.

Post reply on HN