Live data from Hacker News

Zoom meetings aren’t end-to-end encrypted, despite marketing

theintercept.com

181–190 of 351 posts

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#181
post #151

Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted. Like it's fine to point out that the bar has been raised in the security community and that…

??? In IT, E2E has always meant End-to-End, as in, nothing in between can decrypt the content. HIPAA, or brazillian telcos, or the FAA, or my local beer tasting club are fine to come up with whatever interpretation they want, but that doesn't change what it has always been the obvious meaning. No real room for ambiguity here...

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#182
post #151

Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted. Like it's fine to point out that the bar has been raised in the security community and that…

That's messed up, how could the security community have allowed such ambiguity in terminology?

The "security community" was always clear and unambiguous, but the marketing department aren't quite so precise.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#183
post #169

Earlier quoted context omitted.

The point is that the term "E2E encryption" was never used for "there is TLS involved". Because that's not what end-to-end means. E2E encryption was always clearly defined as "only the two communicating parties can access the information". Using the term "E2E encryption" in other ways is deliberately confusing. Edit: and pretending that E2E encryption meant something else in some unspecified past is revising history.

With true E2E encryption, could you support features like recording a video and making it available for download? If yes, does that reflect how their video recording features work now?

That’s not the point. If it’s not truly E2E, they shouldn’t market it as such.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#184

Zoom’s HIPAA product documentation does define Zoom’s “end-to-end encryption” as: https://zoom.us/docs/doc/Zoom-hipaa.pdf > Meeting data transmitted across the network is protected using a unique Advanced Encryption Standard (AES) with a 256-bit key generated and securely distributed to all participants at the start of each session. It does not guarantee that the key is withheld from the server, which is unsurprising…

As a note, to be HIPAA compliant you also need to sign a BAA with Zoom. This, interestingly, disables cloud capture and a bunch of other things.

https://support.zoom.us/hc/en-us/articles/207652183-HIPAA-Bu...

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#185
post #13

End-to-end encryption has been named as a required feature for telehealth in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks for obvious reasons. So I've been trying really hard to work out if Zoom is E2E, and reached the same conclusions as the article. First, it isn't, and second, Zoom are really going out of their way to obscure that fact. It's great that The Intercept is t…

Hopefully we've reconsidered the laws of mathematics in the last few years ... https://www.newscientist.com/article/2140747-laws-of-mathema... "“The laws of mathematics are very commendable, but the only law that applies in Australia is the law of Australia,” said Turnbull. Turnbull’s comments came as he proposed a new law to force tech companies to give security services access to encrypted messages." "The UK home s…

> ... the [former] UK prime minister Theresa May has said that the big internet companies give terrorists “safe spaces” to communicate.

Yes, IIRC she also said wanted to enter a dialogue about this "with the people that know the right hashtags"!

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#186

Earlier quoted context omitted.

With true E2E encryption, could you support features like recording a video and making it available for download? If yes, does that reflect how their video recording features work now?

That’s not the point. If it’s not truly E2E, they shouldn’t market it as such.

“Military grade encryption” might’ve sold better too.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#187
post #151

Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted. Like it's fine to point out that the bar has been raised in the security community and that…

End-to-end encryption is traditionally defined as a means to stop man in the middle attacks. If there's a man always in the middle it defeats the point a little bit.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#188

Another day, another Zoom issue. I've resolved to not using Zoom - when it was suggested at work I just posted links to the issues (mostly gotten from HN actually) so we decided against it.

Because you think of the millions of streams going on, Zoom will snoop on yours? I mean as a security issue it isn’t black or white, you are always having some detrimental issue trade off and by chance. Use face time, have janky video cut offs etc lose productivity, man hours. That’s a trade off. Use zoom, Zoom may broad cast your video to your competitors and you lose money, what is more likely though?

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#189
post #151

Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted. Like it's fine to point out that the bar has been raised in the security community and that…

You make a useful point about older definitions and/or the world of HIPAA, and nothing else you say dilutes or undermines that. However, I take issue with your opening ad hominem abuse. People are looking for abuses of trust. That has nothing to do with “being mad at zoom.” That has everything to do with uncovering dishonest behaviour that is detrimental to the industry. You positioning it as some kind of emotional c…

The “fact” that E2E has an older meaning in industry seems very hard to chase down right now. We also have the problem that if we accept this as honest or acceptable marketing language, then Apple and Google should be allowed to engage in similar standards of marketing language.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#190
post #166
post #151

Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted. Like it's fine to point out that the bar has been raised in the security community and that…

e2e always meant e2e. What you are referring to is transport encryption, which as seen doesn't mean execatly the same thing.

Absolutely. What zoom is providing is really a P2P encryption using TLS.
Post reply on HN