Live data from Hacker News

Zoom meetings aren’t end-to-end encrypted, despite marketing

theintercept.com

301–310 of 351 posts

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#301

So sad, still getting this wrong after so many years. I was part of a startup Sococo some 8 years ago. We had end-to-end encryption right out of the box. Plus video, document sharing, chat. All encrypted, end to end with rotating keys. Up to 100 people in a meeting, sharing and chatting indiscriminately. Its gone now, and the new folks are starting way down the feature ladder from where we were. It's disappointing. N…

I remember using sococo in a Boston based Startup Accelerator with around 30 employees - it head incredibly good performance even running from the browser and with all employees participating. You could see a virtual layout of rooms and where you could knock and see who was in which room. It was such an innovative approach and a wow moment that is really rare. I miss Sococo until today and have never found anything l…

Yeah he spent all our runway on hiring marketing buddies then got fired. Then we got bought and had to switch to WebRTC junk. I volunteered to be downsized (I had written the audio/video/chat/control transport that was discarded).

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#302
post #244

Earlier quoted context omitted.

You can send faxes to someone without the telco running a local webserver on your fax machine, and you don't run thousands of other applications on your fax machine, and your fax machine doesn't usually come with a nifty record feature, nor a camera and a microphone.

I hesitate to point this out, but quite a lot of fax machines come with a microphone. (And, noting the prevalence of articles from a few years ago talking about "update your fax machine firmware", I suspect you could fuzz their telco line-parser for very interesting results!)

Good point--you're talking about the embedded handset or something else? That said, as you hint at: not quite the same thing from a threat model perspective :)

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#303
post #34

Earlier quoted context omitted.

That's terrible for national security. Zoom engineers are based in China: https://www.cnbc.com/2019/03/26/zoom-key-profit-driver-ahead...

It doesn't matter where they're based. What matters is that Zoom isn't safe by any measure and tells you about that if you spend a little time reading critically.

If they're based in Australia they can be legally coerced into installing any code the Australian government feels like telling them to insert. So I'm not sure that China is much worse.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#304
post #2

Zoom has received a fair bit of critical feedback lately. Has anyone given other platforms such as Vidyo identical levels of scrutiny?

TBF it's mostly short sellers doing this, because the complaints have been... poor. The first one was about an advertisement pixel, which everybody is doing but for some reason surfaced only for Zoom. The second one is end-to-end encryption, which is not expected at all for VC apps. NOBODY does it!

> NOBODY does it!

Google Duo does.

https://support.google.com/duo/answer/9280240?hl=en

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#305
post #277
post #231

Earlier quoted context omitted.

Atlassian is an Australian company, headquartered in Sydney, though the current plc is legally in the UK. (I have no idea if that means they're bound by said backdoor law.)

They are because they provide services to Australians and have an Australian subsidiary -- just as anyone in Australia must comply with a warrant or any other lawful request by law enforcement.

If they employ a single Aussie developer, or have foreign developers on Australian soil, the government can coerce those developer to insert anything they like.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#306
post #13

End-to-end encryption has been named as a required feature for telehealth in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks for obvious reasons. So I've been trying really hard to work out if Zoom is E2E, and reached the same conclusions as the article. First, it isn't, and second, Zoom are really going out of their way to obscure that fact. It's great that The Intercept is t…

Hold on, E2E encryption is now required for telehealth in Australia, yet the Australian government passed laws that required LEO's to have access to E2E encrypted data [1]? How are tech companies supposed to comply with that? [1]: https://www.wired.com/story/australia-encryption-law-global-...

Same in the EU: service providers that provide services that allow people to share content must install content filters that screen for illegal (read: copyrighted by large corps) content.

You can't operate an E2E encrypted communication service in Europe without breaking the law.

caveat: I'm not sure whether this has actually been adopted/ratified by either the EU or member states yet.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#307
post #11
post #5

I guess Zoom says they're end-to-end encrypted because they're using WebRTC, which probably means traffic is end-to-end encrypted after signaling, but users need to trust that zoom's signaling server doesn't do anything fishy. Edit: I do not understand the reason for the downvotes. I am not defending the practice but am just describing their potential line of explanation. Please let me know explicitly if my comment i…

Yeah somewhere in their documentation they state that they are end-to-end encrypted because the connections peer1 zoom and zoom peer2 are encrypted. I cant find the page anymore but they really tried to redefine the name for end to end encryption...

middle-out encryption

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#308
post #302

Earlier quoted context omitted.

I hesitate to point this out, but quite a lot of fax machines come with a microphone. (And, noting the prevalence of articles from a few years ago talking about "update your fax machine firmware", I suspect you could fuzz their telco line-parser for very interesting results!)

Good point--you're talking about the embedded handset or something else? That said, as you hint at: not quite the same thing from a threat model perspective :)

Indeed!

That depends entirely on whether the handset is physically disconnected by the on-hook switch, or if a firmware exploit could remotely enable it.

Threat modeling a fax machine in the era of fuzzing-RCEs is a particularly interesting thing to consider.

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#309

Earlier quoted context omitted.

As a note, HIPAA does not require end-to-end encryption as long as you have a BAA with the provider. Zoom has an option for a BAA starting at $200/month. edit: Server-client communication does need to be encrypted which zoom does.

It's a bit more nuanced. Hipaa (two a's) does not require the type end-to-end encryption that most devs come to think of. Generally, Hipaa does require transport encryption from the client to the server processing the request. The importance here is SSL/TLS should be terminated at the app server.

[deleted]

Re: Zoom meetings aren’t end-to-end encrypted, despite marketing

#310

Earlier quoted context omitted.

The explanation for their popularity is that it isn't a constant struggle to use zoom for meetings. Their software may have other problems, but people can run it and get into a meeting with minimal effort. Yesterday by comparison half the people on a Skype meeting had to dial into an audio bridge with their cell phones because their computer audio didn't work for no fucking reason, and screen sharing kept lagging unl…

>The good marketing for zoom is that webex is awful. 100% this. We switched to zoom as stay home orders came out. And only because it worked 100% every time, with little to no fiddling. The non-tech literate employees at my place are patting themselves on the back for being able to set up and host a zoom meeting. Because it's one button. And that's why they're used so much. They are the literal definition of it just…

I would never call them "just works." I had it completely lock up my macbook (no mouse movement or anything until it finally black screened) on joining a conference this afternoon. No program has done that to me in the past year.
Post reply on HN