Earlier quoted context omitted.
There are 2 different kinds of video calls: 1:1 and group calls. For 1:1 calls, e2e encryption incurs negligible processing and bandwidth. Do you worry about the processing and bandwidth increase when using HTTPS/SSL? Probably not. Same goes for 1:1 calls. For group calls, it depends on how it's implemented, but many group calls are implemented using what's called a Selective Forwarding Unit (SFU). One benefit of SFU…
Recording will work fine locally, no (albeit perhaps more fiddly)? It does push some things off the server obviously, but arguably none of those things should be happening on the server in a situation when E2E is mandated, anyway.
Zoom meetings aren’t end-to-end encrypted, despite marketing
291–300 of 351 posts
Re: Zoom meetings aren’t end-to-end encrypted, despite marketing
#292Short version: Zoom video is encrypted to external attackers but not to Zoom (the company) itself. This is important because the company could be compelled to release such videos if subpoena'ed, or they could also simply be hacked.
Re: Zoom meetings aren’t end-to-end encrypted, despite marketing
#293Earlier quoted context omitted.
I'm concerned that the exigencies of pandemic will cause people to get used to a system that tosses privacy out the door. Not sure how to stop this. A couple of nits to pick: > in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks Slight exaggeration; wouldn't you call the royal flying doctors service telehealth? And HIPPA is a US law.
I'm not sure that you can really say "a system that tosses privacy out the door". There's lots of privacy protections in place. Sure, it requires trustworthy providers, but that's largely true of a non-open source E2E solution as well. Nit: HIPPA is not a US law, but HIPAA is. ;-)
Touché! I'm even HIPAA trained and have to deal with it all the time yet I chronically make that error. I can't even see it when proof reading. Ouch.
Re: Zoom meetings aren’t end-to-end encrypted, despite marketing
#294So sad, still getting this wrong after so many years. I was part of a startup Sococo some 8 years ago. We had end-to-end encryption right out of the box. Plus video, document sharing, chat. All encrypted, end to end with rotating keys. Up to 100 people in a meeting, sharing and chatting indiscriminately. Its gone now, and the new folks are starting way down the feature ladder from where we were. It's disappointing. N…
Re: Zoom meetings aren’t end-to-end encrypted, despite marketing
#295If Zoom implements proper E2E like Facetime, would it be more laggy, less able to handle meetings of more than 50 people, etc.? Will the general user experience degrade noticeably?
Re: Zoom meetings aren’t end-to-end encrypted, despite marketing
#296Earlier quoted context omitted.
From the actual HIPAA regulations, one must "Implement technical security measures to guard against unauthorized access to electronic protected health information that is being transmitted over an electronic communications network." Then you can follow along the official HHS guide[0] to see if you're abiding by these rules. If the intended recipient of your protected health information is another client, then SSL/TLS…
> As a sibling comment mentions, your company shouldn't be using random articles found through a search engine for HIPAA advice. Trust me. I am not. I'm simply trying to demonstrate colloquial usage of the term within the Hipaa community. > If the intended recipient of your protected health information is another client, then SSL/TLS would not be HIPAA compliant. If the intended recipient is the server, then SSL/TLS…
And sorry, I meant client-to-client with the assumption that there's a server between the two. And sure. I think it's safe to assume that SSL/TLS is perfectly fine for a client-to-server situation. But like I said, let the company read the actual regulations and consult their IT team.
Re: Zoom meetings aren’t end-to-end encrypted, despite marketing
#297Earlier quoted context omitted.
Just an FYI, two weeks ago, CMS announced it would be suspending enforcement of telehealth tools used in good faith during the COVID pandemic. [0] Basically, if you are a family doc that's been thrown into the telehealth ringer, you can get started with everyday tools for video chat, like Facetime, Google Hangouts, Skype, etc - regardless of that tool's Hipaa compliance. Overtime I do expect they'll want to see provi…
As a note, HIPAA does not require end-to-end encryption as long as you have a BAA with the provider. Zoom has an option for a BAA starting at $200/month. edit: Server-client communication does need to be encrypted which zoom does.
Re: Zoom meetings aren’t end-to-end encrypted, despite marketing
#298Does anyone know of a video conferencing system (3++++ participants) that actually does do end-to-end encryption?
Re: Zoom meetings aren’t end-to-end encrypted, despite marketing
#299Re: Zoom meetings aren’t end-to-end encrypted, despite marketing
#300So sad, still getting this wrong after so many years. I was part of a startup Sococo some 8 years ago. We had end-to-end encryption right out of the box. Plus video, document sharing, chat. All encrypted, end to end with rotating keys. Up to 100 people in a meeting, sharing and chatting indiscriminately. Its gone now, and the new folks are starting way down the feature ladder from where we were. It's disappointing. N…
When our company picked up Zoom we did a test and had 100 users all on camera and it worked flawlessly.