Live data from Hacker News

Zoom meetings aren’t end-to-end encrypted, despite marketing

theintercept.com

121–130 of 351 posts

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#121

Earlier quoted context omitted.

> The Intercept didn't care about Zoom a few months ago and wouldn't have without Corona. The 2019 Zoom vulnerability[1] was a much bigger deal and did get picked up by the media. Zoom already had a terrible reputation before COVID-19. [1] https://news.ycombinator.com/item?id=20387298

Yeah, it was picked up because it was a much bigger deal. Now the issues are a smaller deal but are still being picked up. Most people I work with haven't even heard about Zoom until those last months when they've been forced to use a teleconference for the first time in their lifes. They also probably didn't even hear about the issue last year too.

I'm still not convinced this coverage is in any way related to Zoom's current popularity or COVID-19, I just think a company that keeps fucking up is a better story than a one-off.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#122
post #84

Another day, another Zoom issue. I've resolved to not using Zoom - when it was suggested at work I just posted links to the issues (mostly gotten from HN actually) so we decided against it.

Well, they became the popular go to solution because the other popular solutions suck. Now they are also in the focus of privacy interested media and therefore end up becoming stories. The Intercept didn't care about Zoom a few months ago and wouldn't have without Corona.

I must say that Google Meet has been a smooth experience at work, but if I had to go with a privacy-focused solution, that'd be Jitsi and not Zoom.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#123

Earlier quoted context omitted.

A requirement for e2e is that the company doesn't hold the keys, otherwise it's just regular transport encryption + a promise that they'll never peak at the your data, even though they can. So yes, it's very much incompatible technically.

You just have two modes, one with e2e enabled and one not. e2e is enabled normally but when LE requests access, the user client receives a message telling it not to use e2e. That may not satisfy you as someone who wants secure encryption (and it probably shouldn't), but it is e2e when it's actually enabled.

Does it inform the user or otherwise stop functioning for telehealth once the signal is received? If not, then does that mean that someone is considered e2e encrypted if it in theory can support e2e encryption even if it isn't using it right now?

It looks like the situation has not been fully thought through and the government is creating a Kafka trap when its laws.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#124
post #13

End-to-end encryption has been named as a required feature for telehealth in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks for obvious reasons. So I've been trying really hard to work out if Zoom is E2E, and reached the same conclusions as the article. First, it isn't, and second, Zoom are really going out of their way to obscure that fact. It's great that The Intercept is t…

I'm concerned that the exigencies of pandemic will cause people to get used to a system that tosses privacy out the door. Not sure how to stop this.

A couple of nits to pick:

> in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks

Slight exaggeration; wouldn't you call the royal flying doctors service telehealth? And HIPPA is a US law.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#126

Earlier quoted context omitted.

> I'm pretty sure that Google Meet isn't end-to-end encrypted either. Nothing that Google does is. To the best of my understanding, they say that it is https://support.google.com/a/answer/7582940?hl=en EDIT: On rereading they actually just say that it is encrypted, not neccesarily end-to-end encrypted.

Google provides close captioning for meet calls. That means it's not E2E. Also pretty much no service can provide multi-party video call with adaptive quality without completely destroying your bandwidth.

I'm interested in knowing more about why closed captions would imply not end-to-end encrypted. Wouldn't it be possible to build a model and distribute the model with the client-side application, and run it at the edge?

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#127
post #59
post #48

Original title: "Zoom Meetings Aren't End-to-End Encrypted, Despite Misleading Marketing" For some reason, the title was trimmed an hour after submission to omit the "misleading marketing" part. The ranking also appears to have artificially been lowered. Now it is below some other posts that are older and with fewer points.

The story is about the deception, not about whether Zoom has a particular feature or not. I am disappointed in the moderators.

It looks like the title was modified again, to include "despite marketing". Thank you, moderators! Please feel free to delete this comment and my comment above it.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#128
post #124
post #13

End-to-end encryption has been named as a required feature for telehealth in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks for obvious reasons. So I've been trying really hard to work out if Zoom is E2E, and reached the same conclusions as the article. First, it isn't, and second, Zoom are really going out of their way to obscure that fact. It's great that The Intercept is t…

I'm concerned that the exigencies of pandemic will cause people to get used to a system that tosses privacy out the door. Not sure how to stop this. A couple of nits to pick: > in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks Slight exaggeration; wouldn't you call the royal flying doctors service telehealth? And HIPPA is a US law.

The key point is that a video consult with a doctor is now (as of last week) available to most of the population, including those in the city, and can be claimed on Medicare. That’s a huge change from previously where it only applied in specific scenarios. I’m sure the RFDS did some video/phone consults but their patients are literally remote - some hundreds of kilometres from the next property.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#130
post #58

Earlier quoted context omitted.

Where does it say they have e2e video encryption? I can only find something about chats.

https://zoom.us/healthcare "Achieve HIPAA (signed BAA) and PIPEDA/PHIPA compliance with complete end-to-end 256-bit AES encryption."

What if one pays $200/mo for the HIPAA-compliant plans?
Post reply on HN