Live data from Hacker News

Zoom meetings aren’t end-to-end encrypted, despite marketing

theintercept.com

171–180 of 351 posts

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#171
post #151

Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted. Like it's fine to point out that the bar has been raised in the security community and that…

> E2E now requires that only the participants be able to decrypt the content

That is the literal meaning of the phrase "end to end"... There is not much room for ambiguity there

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#172
post #34

Earlier quoted context omitted.

That's terrible for national security. Zoom engineers are based in China: https://www.cnbc.com/2019/03/26/zoom-key-profit-driver-ahead...

It doesn't matter where they're based. What matters is that Zoom isn't safe by any measure and tells you about that if you spend a little time reading critically.

It’s certainly no less safe than the backdoored-for-decades phone/fax networks used by medical professionals to discuss medical secrets with patients and send prescriptions to pharmacies. It’d be nice if it was more safe, but it’s hard to sink lower than a telco line.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#173
post #45

Earlier quoted context omitted.

Honest question, what do you find is better about zoom? Compared to webex, skype, slack call… What do people like about zoom?

It works. 1. It's actually cross-platform: - Still can't use Webex across Linux, Windows and Mac in 2020. - Same goes for Skype, plus half the users who have Skype don't realise it's Linc and the two are completely different. 2. It's far more bandwidth efficient than things like Slack. The codecs are much more resilient, this applies (from what I can tell) to all the embedded options that are just using the browser.…

I don't think "it's going to be around" is the main reason people are using Zoom instead of Hangouts: regardless of how you interpret Google's confusing messaging here, Hangouts is clearly not going to disappear while lots of people are relying on it in the middle of a pandemic.

Instead I think it's that Zoom is better: easier to join, it can show you more faces at once, more controls for the meeting owner, lower CPU usage, etc.

(Disclosure: I work for Google, speaking only for myself)

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#174
post #140

Fuck these guys. This isn't the first time they've been caught being dishonest and deceptive: https://www.howtogeek.com/fyi/daily-news-roundup-mac-exploit...

> If you have Zoom installed and visit that website, you will be auto-joined to a call, and your webcam activated without any interaction on your part—even if you closed Zoom before clicking the link.

> Worse yet, uninstalling Zoom doesn’t remove the web server. The web server can reinstall Zoom on its own as well. So if you visit a malicious link, it can reinstall Zoom, join you to a call, and start your webcam, all without any interaction from you.

What the &@$##!! How long has Zoom been around, how did it become popular (or did it ever), and why are people still using it?

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#175

So sad, still getting this wrong after so many years. I was part of a startup Sococo some 8 years ago. We had end-to-end encryption right out of the box. Plus video, document sharing, chat. All encrypted, end to end with rotating keys. Up to 100 people in a meeting, sharing and chatting indiscriminately. Its gone now, and the new folks are starting way down the feature ladder from where we were. It's disappointing. N…

I remember using sococo in a Boston based Startup Accelerator with around 30 employees - it head incredibly good performance even running from the browser and with all employees participating.

You could see a virtual layout of rooms and where you could knock and see who was in which room. It was such an innovative approach and a wow moment that is really rare. I miss Sococo until today and have never found anything like it again.

I got to know your CEO over dinner in Boston and am not surprised he threw it all under the bus. My boss at the time who introduced us tuned out to be a major scam artist who got rich peddling grey market pharmaceuticals online but claimed it was from selling a pre-web chat/gaming platform to Murdoch - he was also infamous for being the main investor of StartCom which we all know what happened to them (WoSign). The 2 guys got on like a house on fire.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#177

Earlier quoted context omitted.

I'm pretty sure that Google Meet isn't end-to-end encrypted either. Nothing that Google does is. WhatsApp does claim that videos are end-to-end encrypted as well, although given Facebook announced they'll implement client-side agents for processing user data and given its proprietary nature, I avoid WhatsApp for anything very sensitive as well.

Google Duo is end-to-end encrypted [0]. I don't know about Meet. Disclaimer: Working at Google, in the same org as Duo. [0] http://support.google.com/duo/answer/9280240?hl=en

Very well explained, too. Great work.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#178

Earlier quoted context omitted.

I'm pretty sure that Google Meet isn't end-to-end encrypted either. Nothing that Google does is. WhatsApp does claim that videos are end-to-end encrypted as well, although given Facebook announced they'll implement client-side agents for processing user data and given its proprietary nature, I avoid WhatsApp for anything very sensitive as well.

> I'm pretty sure that Google Meet isn't end-to-end encrypted either. Nothing that Google does is. To the best of my understanding, they say that it is https://support.google.com/a/answer/7582940?hl=en EDIT: On rereading they actually just say that it is encrypted, not neccesarily end-to-end encrypted.

Isn't 128-bit AES and SHA-1 fairly weak encryption nowadays?

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#179
post #169

Earlier quoted context omitted.

A simple example could be something like using TLS or DTLS between all nodes in the network. But that doesn't mean data on a Zoom server sitting in the middle of a call is encrypted.

The point is that the term "E2E encryption" was never used for "there is TLS involved". Because that's not what end-to-end means. E2E encryption was always clearly defined as "only the two communicating parties can access the information". Using the term "E2E encryption" in other ways is deliberately confusing. Edit: and pretending that E2E encryption meant something else in some unspecified past is revising history.

With true E2E encryption, could you support features like recording a video and making it available for download? If yes, does that reflect how their video recording features work now?

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#180
post #151

Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted. Like it's fine to point out that the bar has been raised in the security community and that…

If the article is accurate, this is clearly not "end-to-end" in the way that most people believe it. If Zoom was considered "end-to-end" encrypted, then any site that uses HTTPS should be able to claim so as well.

I interpret end-to-end encrypted to mean only the participants have access to the content, the intermediary couldn't spy on my calls even if they wanted to. This appears to NOT be the case with Zoom.

Post reply on HN