Live data from Hacker News

Zoom meetings aren’t end-to-end encrypted, despite marketing

theintercept.com

211–220 of 351 posts

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#211
post #202
post #52

I used wire before is opensourced parts of the backend. I thought it was well designed and interesting. They claim to be the only video conferencing with end to end encryption that is opensource. https://wire.com/en/features/encrypted-voice-video/ Has anyone followed wire more closely?

I've heard nothing about Wire recently. Wickr.com is another similar service that claims to be end-to-end encrypted, but again I haven't seen much about them at all.

I think no news is good news in this case. And a positive for Wire is that since it's all open source, you can go right to their github and see how active their development is.

It would be nice if The Intercept and other journalists would include these actually E2E-encrypted alternatives besides the Mac/iOS-only FaceTime.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#212

This really is false marketing , but technically what they're doing seems reasonable. Key quote: > Matthew Green, a cryptographer and computer science professor at Johns Hopkins University, points out that group video conferencing is difficult to encrypt end to end. That’s because the service provider needs to detect who is talking to act like a switchboard, which allows it to only send a high-resolution videostream…

It would be extraordinarily difficult for me to sell consulting services, and guarantee 100% on time delivery with zero defects.

Which is why, when I was consulting, I did not promise these things, nor did I say things that could be easily misunderstood to imply them.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#213
post #54
post #51

Earlier quoted context omitted.

It goes far further than stupid comments by our (former) prime minister. The current legislation (passed in 2018) allows the government to force the installation of backdoors through a process that doesn't have any judicial overview or substantial public scrutiny whatsoever.

Number one reason we dropped JIRA.

Why? How is it related to Jira?

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#214
post #151

Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted. Like it's fine to point out that the bar has been raised in the security community and that…

Remember what they did with Facebook?

It’s how the outrage made operates

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#215

Earlier quoted context omitted.

Hopefully we've reconsidered the laws of mathematics in the last few years ... https://www.newscientist.com/article/2140747-laws-of-mathema... "“The laws of mathematics are very commendable, but the only law that applies in Australia is the law of Australia,” said Turnbull. Turnbull’s comments came as he proposed a new law to force tech companies to give security services access to encrypted messages." "The UK home s…

I realize HN will think much the same of it either way, but AFAICT that second quote of yours is a lie; she called WhatsApp's encryption unacceptable, not encryption in general.

"Encryption we can't backdoor isn't acceptable"

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#216

Earlier quoted context omitted.

Just an FYI, two weeks ago, CMS announced it would be suspending enforcement of telehealth tools used in good faith during the COVID pandemic. [0] Basically, if you are a family doc that's been thrown into the telehealth ringer, you can get started with everyday tools for video chat, like Facetime, Google Hangouts, Skype, etc - regardless of that tool's Hipaa compliance. Overtime I do expect they'll want to see provi…

As a note, HIPAA does not require end-to-end encryption as long as you have a BAA with the provider. Zoom has an option for a BAA starting at $200/month. edit: Server-client communication does need to be encrypted which zoom does.

What is a BAA?

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#217

Earlier quoted context omitted.

That’s not the point. If it’s not truly E2E, they shouldn’t market it as such.

“Military grade encryption” might’ve sold better too.

Don't forget another marketing favorite: "Bank-level encryption"

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#218
post #34

Earlier quoted context omitted.

> The UK home secretary Amber Rudd has previously called encryption "completely unacceptable" ... Theresa May has said that the big internet companies give terrorists "safe spaces" to communicate. Ironically, the UK government in fact uses Zoom for all its meetings depsite privacy and security implications. Saudi Arabia, take note. Ref: https://www.businessinsider.com/coronavirus-boris-johnson-zo...

That's terrible for national security. Zoom engineers are based in China: https://www.cnbc.com/2019/03/26/zoom-key-profit-driver-ahead...

Charles tells me that when I installed Zoom, my iPhone made four HTTPS connections to zoom.com.cn/69.174.108.252

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#219
post #45
post #17

It's disappointing to see a company that has better tech than its rivals playing these games. I have been singing Zoom's praises, but this really makes me want to look elsewhere. What a bummer.

Honest question, what do you find is better about zoom? Compared to webex, skype, slack call… What do people like about zoom?

Gallery view, you can see everyone at once - we have All Hands where you can flick through the whole company (~75 people) seeing 25 at a time.

Hangouts hides people in meetings with more than about 5, so psychologically you don't even realise they are there.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#220
post #201
post #151

Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted. Like it's fine to point out that the bar has been raised in the security community and that…

It seems that HN is flooded with commenters trying to redefine the well-established meaning of strong E2E encryption. I ask myself if there is any motivation for such comments?

Yeah, without a single citation supporting the existence of this imaginary "older definition" of E2E encryption.
Post reply on HN