Live data from Hacker News

Zoom meetings aren’t end-to-end encrypted, despite marketing

theintercept.com

81–90 of 351 posts

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#81
post #45
post #17

It's disappointing to see a company that has better tech than its rivals playing these games. I have been singing Zoom's praises, but this really makes me want to look elsewhere. What a bummer.

Honest question, what do you find is better about zoom? Compared to webex, skype, slack call… What do people like about zoom?

It works.

1. It's actually cross-platform:

- Still can't use Webex across Linux, Windows and Mac in 2020.

- Same goes for Skype, plus half the users who have Skype don't realise it's Linc and the two are completely different.

2. It's far more bandwidth efficient than things like Slack.

The codecs are much more resilient, this applies (from what I can tell) to all the embedded options that are just using the browser.

3. It's going to be around.

- Google Hangouts has previously been renamed and deprioritised. They also dropped their low-bandwidth codecs and cpu usage went through the roof in my personal experience.

I'm unclear on some of the items against Zoom. But there's a lot of hate and emotion around it in the last 10 days - my sense is that some people have an axe to grind - I'm always cautious of a crowd with pitchforks.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#82
post #13

End-to-end encryption has been named as a required feature for telehealth in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks for obvious reasons. So I've been trying really hard to work out if Zoom is E2E, and reached the same conclusions as the article. First, it isn't, and second, Zoom are really going out of their way to obscure that fact. It's great that The Intercept is t…

I have a telehealth appointment (in Australia) this week, and they are using https://doxy.me/ Anybody know much about that one?

> LD video

TIL: there is a quality below SD.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#83

Does anyone know of a video conferencing system (3++++ participants) that actually does do end-to-end encryption?

Wire[0][1] does it according to their blog post[2]. This has an impact on FPS and CPU usage+power consumption, but it is secure.

[0]: https://wire.com/en/ [1]: https://github.com/wireapp [2]: https://medium.com/@wireapp/video-conferencing-end-to-end-en...

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#84

Another day, another Zoom issue. I've resolved to not using Zoom - when it was suggested at work I just posted links to the issues (mostly gotten from HN actually) so we decided against it.

Well, they became the popular go to solution because the other popular solutions suck. Now they are also in the focus of privacy interested media and therefore end up becoming stories.

The Intercept didn't care about Zoom a few months ago and wouldn't have without Corona.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#85
post #79
post #34

Earlier quoted context omitted.

That's terrible for national security. Zoom engineers are based in China: https://www.cnbc.com/2019/03/26/zoom-key-profit-driver-ahead...

Components of the GB 5g network are also being outsourced to China. Some of the ruling party's MP's are not happy about it.

The noisy back-benchers are a little silly as all of Huawei's work is scrutenised: https://www.wired.co.uk/article/huawei-gchq-security-evaluat...

Of course, in the UK, calling Tory back-benchers "a little silly" is an understatement.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#86
Inherent to any e2e encryption scheme is the question; are you talking to who you think you are talking to? In other words; are you the victim of a man in the middle attack?

So if you ever encounter a system that has the ease of use feature where you don't have to verify the identity of the other participant(s) with something like a identity fingerprint number then you already know you do not have all the protection that e2e encryption can provide. This is particularly relevant in a case like Zoom, where all the data goes through servers that Zoom controls making a MITM attack trivial.

So we really should of known that Zoom doesn't provide complete e2e encryption already just from the lack of the identity check.

Skipping the identity verification step seems to be common these days. Even Signal does that by default, but they at least make the verification of what they call "safety numbers" fairly easy and straightforward.

Added: So can true e2e encryption ever be practical for conferences involving a large number of participants? Perhaps Zoom is claiming the impossible... The issues surrounding the addition of OMEMO encryption to XMPP conferences make for an entirely relevant example. What do you do if one of the participants is not known to all the others? There are lots of possible answers to that question.

Added2: >The only feature of Zoom that does appear to be end-to-end encrypted is in-meeting text chat.

I don't see how this can be true either based on the same thinking.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#87
post #82

Earlier quoted context omitted.

I have a telehealth appointment (in Australia) this week, and they are using https://doxy.me/ Anybody know much about that one?

> LD video TIL: there is a quality below SD.

How is a doctor supposed to do a video consultation if the blotches on your bum, purely for example, are all blurry because the definition is less than HD?

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#88
post #13

End-to-end encryption has been named as a required feature for telehealth in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks for obvious reasons. So I've been trying really hard to work out if Zoom is E2E, and reached the same conclusions as the article. First, it isn't, and second, Zoom are really going out of their way to obscure that fact. It's great that The Intercept is t…

Hold on, E2E encryption is now required for telehealth in Australia, yet the Australian government passed laws that required LEO's to have access to E2E encrypted data [1]? How are tech companies supposed to comply with that?

[1]: https://www.wired.com/story/australia-encryption-law-global-...

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#89
post #45

Earlier quoted context omitted.

Honest question, what do you find is better about zoom? Compared to webex, skype, slack call… What do people like about zoom?

It works. 1. It's actually cross-platform: - Still can't use Webex across Linux, Windows and Mac in 2020. - Same goes for Skype, plus half the users who have Skype don't realise it's Linc and the two are completely different. 2. It's far more bandwidth efficient than things like Slack. The codecs are much more resilient, this applies (from what I can tell) to all the embedded options that are just using the browser.…

Also it's simple. If I want to add someone to a meeting, I just punch in their cell phone number. They get a call and the AI voice thing says "Press 1 to enter the meeting.". And they press 1. And boom they are in.

No extra software to download, no jumbling around with meeting codes, no "are you the meeting leader" bs. Straightforward and simple UX.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#90
post #27

how can you have end-to-end encryption with server side processing in conference calls with 50 participants?

1. Clients negotiate end-to-end encryption session key between themselves the same way as a chat app would. 2. Each client sends the server two (or more) encrypted video streams, varying in bandwidth and keyframes per second, with unencrypted markers showing where they can be sliced and joined. If you can upload a 1080p stream, chances are you've got the bandwidth to send a 360p stream too! 3. Each client tells the s…

a few problems:

>Clients negotiate end-to-end encryption session key between themselves the same way as a chat app would.

how are you doing this exactly? a 50 way diffie-hellman that renegotiates every time a user leaves or joins? How do you plan on doing that without any substantial lag?

>2. Each client sends the server two (or more) encrypted video streams, varying in bandwidth and keyframes per second

you have managed to double your egress for almost no value.

Post reply on HN