Live data from Hacker News

Zoom meetings aren’t end-to-end encrypted, despite marketing

theintercept.com

151–160 of 351 posts

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#151
Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted.

Like it's fine to point out that the bar has been raised in the security community and that the term E2E now requires that only the participants be able to decrypt the content and they should change their copy but it ignores the fact that E2E in healthcare means exactly what Zoom is doing. In the HIPPA world providers are trusted entities.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#152
post #26

Earlier quoted context omitted.

Zoom has always been shady as hell. Between the ridiculous web server on MacOS, web client anti-patterns and other endless nonsense the only explanation for their popularity is good marketing.

The explanation for their popularity is that it isn't a constant struggle to use zoom for meetings. Their software may have other problems, but people can run it and get into a meeting with minimal effort. Yesterday by comparison half the people on a Skype meeting had to dial into an audio bridge with their cell phones because their computer audio didn't work for no fucking reason, and screen sharing kept lagging unl…

>The good marketing for zoom is that webex is awful.

100% this. We switched to zoom as stay home orders came out. And only because it worked 100% every time, with little to no fiddling. The non-tech literate employees at my place are patting themselves on the back for being able to set up and host a zoom meeting. Because it's one button.

And that's why they're used so much. They are the literal definition of it just works. People aren't worried about anything else right now.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#153
post #13

End-to-end encryption has been named as a required feature for telehealth in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks for obvious reasons. So I've been trying really hard to work out if Zoom is E2E, and reached the same conclusions as the article. First, it isn't, and second, Zoom are really going out of their way to obscure that fact. It's great that The Intercept is t…

Just an FYI, two weeks ago, CMS announced it would be suspending enforcement of telehealth tools used in good faith during the COVID pandemic. [0] Basically, if you are a family doc that's been thrown into the telehealth ringer, you can get started with everyday tools for video chat, like Facetime, Google Hangouts, Skype, etc - regardless of that tool's Hipaa compliance. Overtime I do expect they'll want to see provi…

Extremely loose in Canada as well. Facetime, skype, phone calls are all fair game currently

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#154
Zoom’s HIPAA product documentation does define Zoom’s “end-to-end encryption” as:

https://zoom.us/docs/doc/Zoom-hipaa.pdf

> Meeting data transmitted across the network is protected using a unique Advanced Encryption Standard (AES) with a 256-bit key generated and securely distributed to all participants at the start of each session.

It does not guarantee that the key is withheld from the server, which is unsurprising given that e.g. the recording and chat history features are implemented server-side.

EDIT: For comparison, the Australian government provides a telehealth platform that clearly states it does not allow the server to inspect the call video/audio:

https://help.vcc.healthdirect.org.au/about-healthdirect-vide...

> Data shared in actual calls between participants is only ever available in decrypted form to the participating endpoints of the call. All other intermediaries that forward the call can only see encrypted data.

For those looking to hold Zoom accountable, the question to ask is: “Does your country’s law permit Zoom’s servers to be considered an ‘endpoint’ capable of decrypting a telehealth call?”.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#155
post #13

End-to-end encryption has been named as a required feature for telehealth in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks for obvious reasons. So I've been trying really hard to work out if Zoom is E2E, and reached the same conclusions as the article. First, it isn't, and second, Zoom are really going out of their way to obscure that fact. It's great that The Intercept is t…

I have a telehealth appointment (in Australia) this week, and they are using https://doxy.me/ Anybody know much about that one?

My wife uses this when talking to clients (shes a psychologist), but she has the upgraded version that is HD.

If your doctor is on the free plan, it is highly pixelated, and because they offer a hippa-compliant free plan, most providers are on the free plan.

They had a 3-4 hour outage recently. Assuming because of the number of new free users.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#156
post #34

Earlier quoted context omitted.

> The UK home secretary Amber Rudd has previously called encryption "completely unacceptable" ... Theresa May has said that the big internet companies give terrorists "safe spaces" to communicate. Ironically, the UK government in fact uses Zoom for all its meetings depsite privacy and security implications. Saudi Arabia, take note. Ref: https://www.businessinsider.com/coronavirus-boris-johnson-zo...

That's terrible for national security. Zoom engineers are based in China: https://www.cnbc.com/2019/03/26/zoom-key-profit-driver-ahead...

Zoom raises the possibility of this perception in their S-1 filing [0]:

"we have a high concentration of research and development personnel in China, which could expose us to market scrutiny regarding the integrity of our solution or data security features"

[0]: https://www.sec.gov/Archives/edgar/data/1585521/000119312519...

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#157
post #115

Earlier quoted context omitted.

Zoom has been doing shady shit forever. Last year it was for installing a web server on localhost to save a click then dragging their feet on a fix when told how stupid that is.

They may have been doing that forever but that doesn't change anything about my argument. They just were not as popular as they are these days which makes them much more newsworthy and which is why we're seeing constant new articles about them now about issues that have been there for a long time but which were not newsworthy a few months ago. Edit: no, I'm not defending them. I just explain why they are all over the…

Not sure what your point is... are you defending Zoom's behavior here?

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#158
post #151

Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted. Like it's fine to point out that the bar has been raised in the security community and that…

I've always understood E2E to mean that it's encrypted from one end to the other, without any intermediate decryption stops. This is how https://en.wikipedia.org/wiki/End-to-end_encryption defines it, and has since it was a stub in 2007 (https://en.wikipedia.org/w/index.php?title=End-to-end_encryp...).

Do you have any links for E2E being used in this "older" way?

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#159
post #13

End-to-end encryption has been named as a required feature for telehealth in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks for obvious reasons. So I've been trying really hard to work out if Zoom is E2E, and reached the same conclusions as the article. First, it isn't, and second, Zoom are really going out of their way to obscure that fact. It's great that The Intercept is t…

Hold on, E2E encryption is now required for telehealth in Australia, yet the Australian government passed laws that required LEO's to have access to E2E encrypted data [1]? How are tech companies supposed to comply with that? [1]: https://www.wired.com/story/australia-encryption-law-global-...

The server is one of the "ends" in "end to end".

The law didn't contemplate that you would use a service but not want that service to access your data.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#160

Earlier quoted context omitted.

I'm still not convinced this coverage is in any way related to Zoom's current popularity or COVID-19, I just think a company that keeps fucking up is a better story than a one-off.

Most of the articles over here in Germany don't even mention the last fuck up and the news about the company are now beyond the tech media. You may not be convinced even after you attributed to my argument but it won't change anything about the facts. Edit: since I can't post in god knows how long due to the wonderful stfu tech here on hn here are sources for german media: https://www.google.ch/search?q=zoom&complete…

> the news about the company are now beyond the tech media.

I searched around a little and neither this nor the recent Facebook story have been covered by Danish non-tech media at this time.

EDIT: The story is still new, it might get coverage later this week.

Post reply on HN