Live data from Hacker News

Zoom meetings aren’t end-to-end encrypted, despite marketing

theintercept.com

251–260 of 351 posts

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#251
post #13

End-to-end encryption has been named as a required feature for telehealth in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks for obvious reasons. So I've been trying really hard to work out if Zoom is E2E, and reached the same conclusions as the article. First, it isn't, and second, Zoom are really going out of their way to obscure that fact. It's great that The Intercept is t…

I don't know that Zoom is really going out of its way to obscure that it is not E2E. I never for a second thought they were doing E2E when I enabled the encryption. It was very clear from how the features was described that you got TLS to Zoom's servers, not E2E.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#252
post #13

End-to-end encryption has been named as a required feature for telehealth in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks for obvious reasons. So I've been trying really hard to work out if Zoom is E2E, and reached the same conclusions as the article. First, it isn't, and second, Zoom are really going out of their way to obscure that fact. It's great that The Intercept is t…

I don't know that Zoom is really going out of its way to obscure that it is not E2E. I never for a second thought they were doing E2E when I enabled the encryption. It was very clear from how the features was described that you got TLS to Zoom's servers, not E2E.

Right - if you have used signal - I have - zoom is obviously not that. The pain to do call mixing, call recording, join a call late and do playback, join a call at all - does E2E even work in telehealth? I do virtual visits in the US and it doesn't look at all E2E to me.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#253
post #13

End-to-end encryption has been named as a required feature for telehealth in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks for obvious reasons. So I've been trying really hard to work out if Zoom is E2E, and reached the same conclusions as the article. First, it isn't, and second, Zoom are really going out of their way to obscure that fact. It's great that The Intercept is t…

I don't know that Zoom is really going out of its way to obscure that it is not E2E. I never for a second thought they were doing E2E when I enabled the encryption. It was very clear from how the features was described that you got TLS to Zoom's servers, not E2E.

They literally call it "an end to end encrypted connection" and "secure with end to end encryption".

How is this "clear" that it is not E2E?

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#254
post #45

Earlier quoted context omitted.

Honest question, what do you find is better about zoom? Compared to webex, skype, slack call… What do people like about zoom?

It works. 1. It's actually cross-platform: - Still can't use Webex across Linux, Windows and Mac in 2020. - Same goes for Skype, plus half the users who have Skype don't realise it's Linc and the two are completely different. 2. It's far more bandwidth efficient than things like Slack. The codecs are much more resilient, this applies (from what I can tell) to all the embedded options that are just using the browser.…

> It works.

Crazy theory, so just hear me out for a second. Maybe the fact that they do some things that violate security is the reason that "it just works". I'm not saying Zoom shouldn't do better here, I'm just saying that there are probably legitimate product/business reasons.

From Steve Yegge's platform rant:[0]

Like anything else big and important in life, Accessibility has an evil twin who, jilted by the unbalanced affection displayed by their parents in their youth, has grown into an equally powerful Arch-Nemesis (yes, there's more than one nemesis to accessibility) named Security. And boy howdy are the two ever at odds.

But I'll argue that Accessibility is actually more important than Security because dialing Accessibility to zero means you have no product at all, whereas dialing Security to zero can still get you a reasonably successful product such as the Playstation Network.

[0] - https://gist.github.com/chitchcock/1281611

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#255
post #166

Earlier quoted context omitted.

e2e always meant e2e. What you are referring to is transport encryption, which as seen doesn't mean execatly the same thing.

Absolutely. What zoom is providing is really a P2P encryption using TLS.

No, they are providing "P2S" encryption. Peer-to-Server. Huge difference.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#256
post #151

Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted. Like it's fine to point out that the bar has been raised in the security community and that…

I think the answer to your first question is yes.

It puts the negative reporting on all other tech companies that start to see success in context.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#257

Earlier quoted context omitted.

Don't forget another marketing favorite: "Bank-level encryption"

"Bank-level cryptography" with some of them still storing passwords in cleartext, and others made a very painful transition to unsalted md5 within the last 5 years because they "couldn't budget it in" any earlier. No, thanks.

Why hire a software engineer when you can just run some ads about the dangers of identity theft instead?

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#258
post #188

Another day, another Zoom issue. I've resolved to not using Zoom - when it was suggested at work I just posted links to the issues (mostly gotten from HN actually) so we decided against it.

Because you think of the millions of streams going on, Zoom will snoop on yours? I mean as a security issue it isn’t black or white, you are always having some detrimental issue trade off and by chance. Use face time, have janky video cut offs etc lose productivity, man hours. That’s a trade off. Use zoom, Zoom may broad cast your video to your competitors and you lose money, what is more likely though?

Security through obscurity is a fantasy, and a dangerous one. You start thinking your screen door matters to the bear sauntering by, smelling what you're cooking, and coming in for a snack.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#259
post #193

Earlier quoted context omitted.

You could argue whether the attack on Zoom is warranted. But don't start revising history to make your point. E2E has never meant that. There's no such "old notion". I can't find any sources saying HIPAA would use that deviating definition. Most sources I see use Whatsapp as an example, which is E2E under the proper definition.

> I can't find any sources saying HIPAA would use that deviating definition. That's because HIPAA does not define any implementation details. Google "Hipaa end to end encryption" and you'll quickly realize the Hipaa world uses a much looser definition than the security world. "End-to-end" in the context of Hipaa is typically used to indicate encryption (specifically SSL/TLS) of on-the-wire data through the entire req…

Instead of asking people to Google it, your argument would hold more weight if you provided the specific sources you mean readers to go Google and find themselves. It'll save readers some time and improve your argument.

Several people have tried to "google it" and tried to find alternative definitions of end-to-end encryption in the context of HIPAA and have so far failed. If end to end encryption really does mean something else in the context of HIPAA, what is your evidence/source?

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#260

Earlier quoted context omitted.

It's true that you need an out-of-band verification to determine who the other party is in an end-to-end encrypted system. But it is not true that the absence of such a verification means you don't have end-to-end encryption. It means only that you don't know for sure who the other party is. You are only put at risk if there is an active MITM attack in progress. Depending on your threat model that's an enormous chang…

Just semantics at this point. A system that distributed the keys to all participants in the clear from a central server is still encrypted end to end in some sense. As pointed out by someone else in this comment section, the expression "end to end encryption" comes from the early day of PGP. PGP specifically protects against MITM with a fairly sophisticated web of trust system. So it is entirely legitimate to assume…

PGP's "Web of trust" doesn't actually scale and so it doesn't meaningfully improve upon just doing out-of-band verification with a handful of your closest peers and nothing for everybody else.

Web of trust can give an illusion of scaling because it uses sleight of hand to persuade you to accept transitivity of trust. If you see someone who took this seriously you'll find that almost all contacts show as "unverified" (when I've had PGP setups in the past that's what happened). If they just click blindly along accepting trust transitivity then everything is "verified" but based on trust beliefs that have no basis in reality.

The sleight of hand goes like this. You trust Alice. Alice says this is Bob and she trusts Bob. The correct inference is that this is indeed Bob (Alice says so and we trust her) but we still don't trust Bob. PGP tries hard to persuade you that you in fact now trust Bob. Bob says another contact is Carol, and he trusts Carol. The correct inference is null, we don't trust Bob so we don't care what Bob says. But PGP encourages us to accept that this is Carol and we should trust Carol too.

Post reply on HN