Live data from Hacker News

Zoom meetings aren’t end-to-end encrypted, despite marketing

theintercept.com

191–200 of 351 posts

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#191
post #80
post #46

Earlier quoted context omitted.

My problem with this is Zoom's misleading claims. If Zoom can't implement end-to-end encryption, it shouldn't claim that it does.

I think they would claim the terminology is ambiguous. If the connection is encrypted between all clients and the central server, a business person might say that's end-to-end, ie all traffic in flight. The real test is peer-to-peer or not.

> If the connection is encrypted between all clients and the central server, a business person might say that's end-to-end,

I think that's the problem being described. That is not end-to-end encrypted. It is, however, encrypted.

Zoom simply needs to drop the "end-to-end" part.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#192
post #151

Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted. Like it's fine to point out that the bar has been raised in the security community and that…

"When Zoom says E2E encryption they're using older notion "

This is not the case. End-to-end encryption was popularized as a computing term in the 90's with PGP, and it meant that when sending eg email messages, no computer or server in the middle could decrypt the content. Only the the personal computers of the sender and recipient could. The computing field always used the term that way.

If you think about the expression "end-to-end", it carries its own meaning. The only way you could become confused about this is by exposure to totally crazy marketing spiel that will sell you black as white.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#193
post #151

Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted. Like it's fine to point out that the bar has been raised in the security community and that…

You could argue whether the attack on Zoom is warranted. But don't start revising history to make your point. E2E has never meant that. There's no such "old notion".

I can't find any sources saying HIPAA would use that deviating definition. Most sources I see use Whatsapp as an example, which is E2E under the proper definition.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#194
post #176

>if you'd like to dial into the Cabinet tomorrow, the Zoom meeting ID has helpfully been included in this screenshot https://twitter.com/matthewchampion/status/12449891398896640...

Most Zoom meetings should have passwords these days. Unless whoever created the meeting disabled that.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#196
post #138

the statement: The encryption that Zoom uses to protect meetings is TLS, the same technology that web servers use to secure HTTPS websites. This means that the connection between the Zoom app running on a user’s computer or phone and Zoom’s server is encrypted in the same way the connection between your web browser and this article (on https://theintercept.com) is encrypted. This is known as transport encryption, whi…

Please don't use code blocks for quotes. It makes it very hard to read text on mobile, narrow viewports or via screen readers.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#197
post #169

Earlier quoted context omitted.

The point is that the term "E2E encryption" was never used for "there is TLS involved". Because that's not what end-to-end means. E2E encryption was always clearly defined as "only the two communicating parties can access the information". Using the term "E2E encryption" in other ways is deliberately confusing. Edit: and pretending that E2E encryption meant something else in some unspecified past is revising history.

With true E2E encryption, could you support features like recording a video and making it available for download? If yes, does that reflect how their video recording features work now?

You can always record at either end.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#198
post #151

Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted. Like it's fine to point out that the bar has been raised in the security community and that…

That's messed up, how could the security community have allowed such ambiguity in terminology?

It didn’t. OP is making a claim which was never at any point since at least the mid-90s correct. Various marketing teams have tried to redefine it but that’s always been criticized rather than accepted.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#199
post #151

Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted. Like it's fine to point out that the bar has been raised in the security community and that…

> Are people just looking for things to be mad at Zoom for at this point?

I guess when they're being one of the most popular video conferencing platform right now, it invites attention. Doesn't help that people are Zoombombing, and their privacy track record certainly does not help.

I mean, nice new unicorn, but very shady dealings ala Facebook. Not a good look.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#200
post #57

Earlier quoted context omitted.

"Zoom for the Enterprise Secure and reliable End-to-end 256-bit AES encryption, data sovereignty, and role-based access control" Right on the front page. So, it would seem dishonest, yes.

There's the technical definition of "end-to-end" that we all know here—encrypted at one endpoint and decrypted at the other—but I'm wondering how well-understood that term is in broader context. I could see someone saying "end-to-end" encrypted meaning that each segment in the path is encrypted, but with the intermediate nodes decrypting and re-encrypting the payload. Perhaps we should try to come up with a more spec…

It seems that HN is flooded with commenters trying to redefine the well-established meaning of strong E2E encryption. I ask myself if there is any motivation for such comments?
Post reply on HN