Live data from Hacker News

Zoom meetings aren’t end-to-end encrypted, despite marketing

theintercept.com

281–290 of 351 posts

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#281

Earlier quoted context omitted.

Hold on, E2E encryption is now required for telehealth in Australia, yet the Australian government passed laws that required LEO's to have access to E2E encrypted data [1]? How are tech companies supposed to comply with that? [1]: https://www.wired.com/story/australia-encryption-law-global-...

The server is one of the "ends" in "end to end". The law didn't contemplate that you would use a service but not want that service to access your data.

> The server is one of the "ends" in "end to end".

Not in the phrase "end to end encryption", which is specifically used to refer to schemes and services where the service provider does not have the ability to access the communications (a-la Signal).

If that wasn't the case then any site with TLS would be called "end to end encryption".

> The law didn't contemplate that you would use a service but not want that service to access your data.

This law in particular does. The only restriction (relevant here) is that TCNs must not result in the creation of a "systemic vulnerability". The meaning of this term is not outlined in the legislation -- my understanding is that it is meant to mean something like "backdooring OpenSSL and thus making most of the internet insecure" rather than "backdooring all communications using a particular service provider". If that understanding is accurate, then it's a meaningless restriction.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#282

Earlier quoted context omitted.

> I can't find any sources saying HIPAA would use that deviating definition. That's because HIPAA does not define any implementation details. Google "Hipaa end to end encryption" and you'll quickly realize the Hipaa world uses a much looser definition than the security world. "End-to-end" in the context of Hipaa is typically used to indicate encryption (specifically SSL/TLS) of on-the-wire data through the entire req…

Instead of asking people to Google it, your argument would hold more weight if you provided the specific sources you mean readers to go Google and find themselves. It'll save readers some time and improve your argument. Several people have tried to "google it" and tried to find alternative definitions of end-to-end encryption in the context of HIPAA and have so far failed. If end to end encryption really does mean so…

I'm suggesting people should Google it because a list of singular examples does not indicate widespread usage. It's a case of "you need to see for yourself" to understand how this term is actually used in the wild.

The problem is people are trying to find definitions for things that Hipaa literally doesn't define. You won't find a definition for "end-to-end" because Hipaa doesn't actually define it. "end-to-end" is an implementation detail. Hipaa does not define or green-light implementations.

This is both a blessing and a curse of Hipaa.

On the blessing side, it means companies can use tools they see fit and follow industry best practices as long as they can demonstrate the compliance of those tools. This is great because it means companies don't need to wait for Hipaa to explicitly say "you can now use TLS 1.x" or "this widely accepted algorithm is cool for disk encryption".

On the curse side, it means there's no explicit guidance and a lot of leeway. It's on individual companies to demonstrate their implementation patterns are secure.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#283
post #151

Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted. Like it's fine to point out that the bar has been raised in the security community and that…

I’m annoyed by pile on culture and hate when a company goes from darling to demon. But as distasteful as I find that element of our society, I don’t think this is an example of pile on culture. Rather, I think that in this case, Zoom is using a false message with real life implications.

If you have a level of technical sophistication, you can see the shades of grey in all security. So maybe this usage of E2E can be overlooked in HIPAA or other threat contexts. But a wider array of people, including senior decision makers in sensitive organizations believe that E2E means ‘gooder’. :)

When I look at it through this lens, I’m not comfortable with the implications of their marketing message. I’m not sure this makes Zoom a demon, but I definitely trust them less as a result. Is that reasonable or am I overreacting to something? If I am, I would love to know where I’m wrong!

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#284

Earlier quoted context omitted.

Right - if you have used signal - I have - zoom is obviously not that. The pain to do call mixing, call recording, join a call late and do playback, join a call at all - does E2E even work in telehealth? I do virtual visits in the US and it doesn't look at all E2E to me.

As far as I know, there's nothing special about telehealth that prevents it from using e2e encryption.

You mean, other than requirements that service provides track & preserve an audit trail for all data. ;-)

I believe this is a similar problem with financial trading systems with ETS.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#285

Earlier quoted context omitted.

End-to-end encryption is hard to implement, might cost more processing or bandwidth or storage (depending on the product) and does not yield benefits for companies interested in processing user data. If it's not clearly advertised on the front page, _emphasized_ and not a foot note, then it's NOT e2e encrypted. Example: https://signal.org

There are 2 different kinds of video calls: 1:1 and group calls. For 1:1 calls, e2e encryption incurs negligible processing and bandwidth. Do you worry about the processing and bandwidth increase when using HTTPS/SSL? Probably not. Same goes for 1:1 calls. For group calls, it depends on how it's implemented, but many group calls are implemented using what's called a Selective Forwarding Unit (SFU). One benefit of SFU…

Recording will work fine locally, no (albeit perhaps more fiddly)? It does push some things off the server obviously, but arguably none of those things should be happening on the server in a situation when E2E is mandated, anyway.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#286

Earlier quoted context omitted.

> I can't find any sources saying HIPAA would use that deviating definition. That's because HIPAA does not define any implementation details. Google "Hipaa end to end encryption" and you'll quickly realize the Hipaa world uses a much looser definition than the security world. "End-to-end" in the context of Hipaa is typically used to indicate encryption (specifically SSL/TLS) of on-the-wire data through the entire req…

From the actual HIPAA regulations, one must "Implement technical security measures to guard against unauthorized access to electronic protected health information that is being transmitted over an electronic communications network." Then you can follow along the official HHS guide[0] to see if you're abiding by these rules. If the intended recipient of your protected health information is another client, then SSL/TLS…

> As a sibling comment mentions, your company shouldn't be using random articles found through a search engine for HIPAA advice.

Trust me. I am not. I'm simply trying to demonstrate colloquial usage of the term within the Hipaa community.

> If the intended recipient of your protected health information is another client, then SSL/TLS would not be HIPAA compliant. If the intended recipient is the server, then SSL/TLS is totally fine.

This is not correct, though. Both of those use cases CAN be fine. They can both also NOT be fine.

* Client-to-client (assuming we're talking about a computer client) over SSL/TLS is completely fine if the usage case allows for it. You don't need a server involved to exchange ePHI.

* Conversely, client-to-server does not automatically make the use case allowable.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#287

Does anyone know of a video conferencing system (3++++ participants) that actually does do end-to-end encryption?

It looks like WebRTC doesn't support it, so basically no-one can because all these browser-based technologies end up just being WebRTC in the end. From the Jitsi Meet README: > WebRTC does not (yet) provide a way of conducting multi-party conversations with end-to-end encryption. Unless you consistently compare DTLS fingerprints with your peers vocally, the same goes for one-to-one calls.

It depends on what you mean by "WebRTC". There's the mobile/native library (at webrtc.org) and the standard (at https://www.w3.org/TR/webrtc/). The library does support it (although you have to write your own signaling and media forwarding server). The standard does not (yet). But it's being worked on ine the W3C (for example, Insertable Media Processing like this: https://www.w3.org/2019/09/18-mediaprocessing-harald-inserta... or something more low-level like this: https://github.com/WICG/web-codecs/blob/master/explainer.md).

But the web standard not being there yet doesn't prevent someone from making a mobile or desktop app with e2ee conferencing, like Duo does: https://support.google.com/duo/answer/9280240?hl=en.

(I used to work at Google on WebRTC, Duo, Hangouts, and WebCodecs, but now work on video calling at Signal).

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#288

Earlier quoted context omitted.

First of all, there are 2 different kinds of video calls: 1:1 and group calls. For 1:1 calls, e2e encryption doesn't cause any problem at all. For group calls, it depends on how it's implemented, but many group calls are implemented using what's called a Selective Forwarding Unit (SFU) and the sending clients send multiple resolutions (either independent, called "Simulcast" or dependent, called "SVC"). In that case,…

That would seem to require significantly more upload bandwidth & compression capacity from clients, which is often not broadly available to consumers. I guess you could drop down to the lowest resolution only when sending to the service if you have a bandwidth challenge, but that seems less than ideal.

Lots of video conferencing systems already work this way (the SFU way). Compared to just sending the full resolution all the time, adding the smaller resolutions doesn't add that much bandwidth and compression because they are so much smaller.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#289
post #151

Are people just looking for things to be mad at Zoom for at this point? When Zoom says E2E encryption they're using older notion when it was common for services to not use encryption at all for these kinds of things and it was somewhat of a technical accomplishment that every client-server-server-client leg was all encrypted. Like it's fine to point out that the bar has been raised in the security community and that…

[deleted]

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#290
post #136
post #48

Original title: "Zoom Meetings Aren't End-to-End Encrypted, Despite Misleading Marketing" For some reason, the title was trimmed an hour after submission to omit the "misleading marketing" part. The ranking also appears to have artificially been lowered. Now it is below some other posts that are older and with fewer points.

Regarding the ranking: This post is currently #1 on the front page. It was posted around 08:00 UTC. In my experience it is generally very hard to get traction for a post that is posted before ~14:00 UTC. This is a site with lots of US users, and it’s still early on the west coast (07:18 PDT). This post managed to climb to the top despite that, probably because Zoom is a company that is interesting to techies, the art…

Interesting. It reached #2 an hour after submission, and then it suddenly dropped to position #13 within the same hour, around the same time when it was renamed by the mods.

#2: https://imgur.com/a/qgKQWxU

Sudden Drop to #13: https://imgur.com/a/6beWUHG

Post reply on HN