Live data from Hacker News

Zoom meetings aren’t end-to-end encrypted, despite marketing

theintercept.com

221–230 of 351 posts

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#222
post #13

End-to-end encryption has been named as a required feature for telehealth in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks for obvious reasons. So I've been trying really hard to work out if Zoom is E2E, and reached the same conclusions as the article. First, it isn't, and second, Zoom are really going out of their way to obscure that fact. It's great that The Intercept is t…

Just an FYI, two weeks ago, CMS announced it would be suspending enforcement of telehealth tools used in good faith during the COVID pandemic. [0] Basically, if you are a family doc that's been thrown into the telehealth ringer, you can get started with everyday tools for video chat, like Facetime, Google Hangouts, Skype, etc - regardless of that tool's Hipaa compliance. Overtime I do expect they'll want to see provi…

FaceTime is E2E, fwiw, although it might not comply with other requirements.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#223
post #216

Earlier quoted context omitted.

As a note, HIPAA does not require end-to-end encryption as long as you have a BAA with the provider. Zoom has an option for a BAA starting at $200/month. edit: Server-client communication does need to be encrypted which zoom does.

What is a BAA?

A BAA is a Business Associate Agreement. It's a standard HIPAA document where an entity with PHI (typically a Covered Entity, which is an entity specifically mentioned by HIPAA, such as e.g. a healthcare facility) effectively puts a vendor on notice: we may stuff PHI in your service, you agree to abide by this set of rules and regulations. A big one is that the vendor agrees to disclose when they've been breached, and the timeline on which that happens.

Even though a lot of online sources suggest BAAs are only for Covered Entities, that's not strictly speaking true. The standard form document doesn't require the buyer to certify they're a CE. It makes tons of sense for vendors of CEs, themselves bound by BAAs, to bind _their_ vendors to BAAs! If there's a decent chance your customers put PHI in your service, there's a decent chance they put PHI in your support system, and they don't really care if your support system is something in-house or Zendesk when that happens. There's also a good chance that PHI might end up in your logging system, and from there in your Slack instance, and... before you know it everyone's signed a BAA with everyone.

The life-hack consequence for that is that you can just collect BAAs from anyone who will sign them and now you have disclosure timeline guarantees.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#224
post #151

Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted. Like it's fine to point out that the bar has been raised in the security community and that…

>> Are people just looking for things to be mad at Zoom for at this point?

Having been a really happy user of Zoom for more than couple of years - I have referred many friends to use it succesfully. Despite that it looks like Zoom has legit issues that are surfacing. However I have to say it cannot be ruled out there might be some negative PR going on too since I can't help see using any Zoom alternative! Everything else pretty much sucks.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#225
post #216

Earlier quoted context omitted.

As a note, HIPAA does not require end-to-end encryption as long as you have a BAA with the provider. Zoom has an option for a BAA starting at $200/month. edit: Server-client communication does need to be encrypted which zoom does.

What is a BAA?

Business Associate Agreement.

A contract which defined how protected health information will be dealt with by the provider and how HIPAA provisions will be followed (ie: provider will do X but you need to do Y to be compliant).

https://www.hhs.gov/hipaa/for-professionals/covered-entities...

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#226
post #216

Earlier quoted context omitted.

As a note, HIPAA does not require end-to-end encryption as long as you have a BAA with the provider. Zoom has an option for a BAA starting at $200/month. edit: Server-client communication does need to be encrypted which zoom does.

What is a BAA?

Business Associate Agreement, which defines the legal requirements between two parties sharing HIPAA data.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#227

Earlier quoted context omitted.

Just an FYI, two weeks ago, CMS announced it would be suspending enforcement of telehealth tools used in good faith during the COVID pandemic. [0] Basically, if you are a family doc that's been thrown into the telehealth ringer, you can get started with everyday tools for video chat, like Facetime, Google Hangouts, Skype, etc - regardless of that tool's Hipaa compliance. Overtime I do expect they'll want to see provi…

As a note, HIPAA does not require end-to-end encryption as long as you have a BAA with the provider. Zoom has an option for a BAA starting at $200/month. edit: Server-client communication does need to be encrypted which zoom does.

The Security Rule and Transmission Control Standard mention encryption, but as Addressable, not Required, if memory serves. That means you have to do it if it's "reasonable and appropriate", and in this context they just mean transport encryption like TLS, not Signal-style actual E2E.

Not that you shouldn't, of course. And you better have an excuse for not doing it (e.g. we don't re-encrypt after the load balancer terminates TLS is a common one). But doctor's offices fax stuff to each other all the time, and that certainly is not encrypted. Perhaps you're thinking of a HITRUST control?

(Minor nit: HIPAA, not HIPPA.)

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#228

This really is false marketing , but technically what they're doing seems reasonable. Key quote: > Matthew Green, a cryptographer and computer science professor at Johns Hopkins University, points out that group video conferencing is difficult to encrypt end to end. That’s because the service provider needs to detect who is talking to act like a switchboard, which allows it to only send a high-resolution videostream…

the audio processing can be done fine on consumer hardware, not really an issue. You can't mix the audio streams in the traditional sense, but you can multiplex the packets, demux them client side and decrypt/mix.

It's not ideal for a number of reasons.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#229
Zoom seems to have adopted the "Move fast and break things" mentality and it's catching up with them.

Don't have real E2E encryption? Don't say you do. Don't wave away a giant security vulnerability as "a feature". Don't explain monitoring and tracking as something you need to do for advertising when you don't show advertising.

Their product may be superior in quality compared to the competition but their Marketing and PR teams comes across as bush league at best.

The only incident I can give them any credit for is the Facebook reporting. They handled that well in my opinion by admitting the problem existed and immediately resolved that issue.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#230
post #87
post #82

Earlier quoted context omitted.

> LD video TIL: there is a quality below SD.

How is a doctor supposed to do a video consultation if the blotches on your bum, purely for example, are all blurry because the definition is less than HD?

Perhaps the system could allow users to send high resolution still photographs alongside the low-quality video stream.
Post reply on HN