Earlier quoted context omitted.
Number one reason we dropped JIRA.
Why? How is it related to Jira?
Zoom meetings aren’t end-to-end encrypted, despite marketing
231–240 of 351 posts
Re: Zoom meetings aren’t end-to-end encrypted, despite marketing
#232Re: Zoom meetings aren’t end-to-end encrypted, despite marketing
#233I am willing to chalk this up to an honest mistake considering "end-to-end" encryption as being from the client's end to the server, although that's not the accepted use of the term. This appears to be their explanation. I hope their marketing team fixes this now that it's been pointed out to them though.
https://www.google.com/search?q=narsil+kloudless
Kloudless is currently promoting security solutions on their twitter timeline.
Re: Zoom meetings aren’t end-to-end encrypted, despite marketing
#234Do people still remember Telegram don't have E2E encryption on by default? and does not work across multiple platforms when E2E is on? I am annoyed because those are my favorite apps and they don't have what's important.
Re: Zoom meetings aren’t end-to-end encrypted, despite marketing
#235Earlier quoted context omitted.
> I'm pretty sure that Google Meet isn't end-to-end encrypted either. Nothing that Google does is. To the best of my understanding, they say that it is https://support.google.com/a/answer/7582940?hl=en EDIT: On rereading they actually just say that it is encrypted, not neccesarily end-to-end encrypted.
Isn't 128-bit AES and SHA-1 fairly weak encryption nowadays?
Perfectly fine...
>SHA-1
You missed the important bit:
>SHA-1 HMAC
Also perfectly fine...
Re: Zoom meetings aren’t end-to-end encrypted, despite marketing
#236This is important because the company could be compelled to release such videos if subpoena'ed, or they could also simply be hacked.
Re: Zoom meetings aren’t end-to-end encrypted, despite marketing
#237Earlier quoted context omitted.
I'm interested in knowing more about why closed captions would imply not end-to-end encrypted. Wouldn't it be possible to build a model and distribute the model with the client-side application, and run it at the edge?
If they did that, everyone would have the model (meaning you would see closed captions in a lot more places, because it would absolutely be stolen).
Re: Zoom meetings aren’t end-to-end encrypted, despite marketing
#238Earlier quoted context omitted.
“Military grade encryption” might’ve sold better too.
Don't forget another marketing favorite: "Bank-level encryption"
No, thanks.
Re: Zoom meetings aren’t end-to-end encrypted, despite marketing
#239Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted. Like it's fine to point out that the bar has been raised in the security community and that…
It seems that HN is flooded with commenters trying to redefine the well-established meaning of strong E2E encryption. I ask myself if there is any motivation for such comments?
Re: Zoom meetings aren’t end-to-end encrypted, despite marketing
#240Basically you would join a meeting by going to zoom.us/meeting-id-number#secrethashtag
The "secrethashtag" is never sent to the server, but can be accessed by javascript on the client end. Im not sure if this would be acceptable for security nuts though, as I am sure they would make the argument zoom could insert some nefarious js to intercept the url fragment.