Live data from Hacker News

SpaceX bans Zoom over privacy concerns

reuters.com

141–150 of 301 posts

Re: SpaceX bans Zoom over privacy concerns

#141

Earlier quoted context omitted.

Yes, it does. The messages are 'end to end' encrypted in the iMessage service, but then iMessage backs up its encryption key in the iCloud backup service, defeating the point. "If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices." https://support.apple.com/en-us/H…

There’s a good HN thread from earlier this year about that, but basically, you can disable iCloud Backup and enable Messages in the Cloud, so that all of the messages are still backed up and synced between your devices but the keys are not, so that Apple can not read them. Then you can back up to your Mac/PC instead.

But unless everyone you correspond with does this too, Apple can still read your messages to them.

Re: SpaceX bans Zoom over privacy concerns

#142

Guys, I'm starting to think this company isn't worth a P/E ratio of 1600.

I'm surprised by the concerns raised by the HN commenters. When Zoom filed their S1, HN was nothing but complimentary about their product and business model.

The time to pull out might be after their next quarterly report.

Re: SpaceX bans Zoom over privacy concerns

#143
post #81

Earlier quoted context omitted.

Apple does the same thing, where they claim iMessage is ETE encrypted, but the keys (so capabilities to read) are stored on their servers.

This is not true. Don't spread FUD. Apple does not have the ability to read your messages. All messages stored on their servers are encrypted with keys that live only on the phone. iMessage doesn't store your decryption keys on Apple's servers unless you opt into iCloud backup which is a whole different service and security concern.

This is both true and false. Apple stores keys on the device so they can't read your old messages, but say they want to start reading messages of a particular user, they can simply issue a new key and store it on the device and the server and start decrypting the new messages using it.

This is why WhatsApp for example notifies users when the key of the recipient changes, and they give you a way of verifying that the both keys at both ends are identical.

Re: SpaceX bans Zoom over privacy concerns

#144

Earlier quoted context omitted.

That is true of any end-to-end solution. If you back up your private keys, anyone who has access to your backup would be able to access the encrypted messages. Remember, you can turn off iCloud backup if you're worried about Apple accessing your keys. Ultimately, it's false to equate iMessage's encryption scheme, which is end-to-end, to an encryption scheme that requires a server to relay decrypted data.

> That is true of any end-to-end solution. Utterly false. Real end-to-end encryption would encrypt the backup with a key that is not available to the backup service (e.g. derived from a passphrase not sent to the server). Of course this system has better usability, which is why Apple does it. But it's still a farce to call a system where Apple has the ability to decrypt the majority of messages "end-to-end" encrypted…

> The fact that it's through the backup servers instead of the iMessage servers makes no difference.

It makes a big difference. If I print out the texts I receive, it doesn't change whether the texting program is end-to-end encrypted. The same goes for backups. An unencrypted system-level backup doesn't mean that the program being backed up is failing at security.

It's bad that Apple doesn't let you encrypt your backups properly, but it's a separate issue.

Re: SpaceX bans Zoom over privacy concerns

#145
post #49

Earlier quoted context omitted.

To be fair it does perform better than everything else, which is why people are so forgiving of it, but it still doesn't excuse their ineptitude on privacy and security.

In my experience Google's Hangout Meetings have been at least as good or better quality and the interface is far superior in my opinion. For example it works in the browser without any plugins (even in Firefox.)

I haven't used Hangouts on a professional setting in a while. Does it finally support tile view? Another feature I find really valuable is allowing two windows. One for participant view and a separate one for shared screen.

Re: SpaceX bans Zoom over privacy concerns

#146
post #130
post #2

I looked into adding Zoom to our Slack workspace this morning, and was beside myself with the set of permissions they requested — reading the contents of every channel and private chat they're included in? For a slash command? That's a hard no. Turned me off the service entirely.

We have Zoom on our Slack workspace and we'd remove it immediately if this were the case, but it appears to be false. The full list of permissions required by the official Zoom Slack integration is at www.slack.com/apps/A5GE9BMQC-zoom, and doesn't have read access to any channels, private or public, except for "some URLs in messages".

Following your link brings me to the same list of permissions that I was talking about. Here are (some) of them:

* View some URLs in messages

* View messages and other content in public channels, private channels, direct messages, and group direct messages that Zoom has been added to

* View basic information about direct and group direct messages that Zoom has been added to

* View basic information about public channels in your workspace

* View basic information about private channels that Zoom has been added to

* View files shared in channels and conversations that Zoom has been added to

* View pinned content in channels and conversations that Zoom has been added to

* View messages and files that Zoom has starred

* View emoji reactions and their associated content in channels and conversations that Zoom has been added to

Re: SpaceX bans Zoom over privacy concerns

#147

Earlier quoted context omitted.

This is not true. Don't spread FUD. Apple does not have the ability to read your messages. All messages stored on their servers are encrypted with keys that live only on the phone. iMessage doesn't store your decryption keys on Apple's servers unless you opt into iCloud backup which is a whole different service and security concern.

Most people use iCloud backup. Even if you don't, your messages are still sent to Apple by the recipient. And Apple prohibits third party backup services. > Apple does not have the ability to read your messages. iCloud backup is an Apple service and it has the ability to read most of your messages even if you don't use it, which makes this statement categorically false.

This is completely ridiculous. iMessage is encrypted by my device and remains encrypted until it gets to the recipient device. That is what end-to-end encryption means.

That I may have given Apple my private key through a different message in no way affects that end-to-end encryption, because it is trivial to decide not to give Apple that key.

Re: SpaceX bans Zoom over privacy concerns

#148

Being the Linux geek, I use MS Teams. I even use it with its Linux client, and works astonishingly well. My only 2 grievances with it are: 1. Teams steals focus to make the next message on a group, rather than in the threat ALL THE TIME. Ive been there for a dozen comments because Teams stole cursor focus. 2. Its easy to make an invite to a one-shot room, rather than use an existing room. Doing so loses all history a…

I have to use MS Teams and hate it.

The fact that I lived with the bug described in https://news.ycombinator.com/item?id=22741348 for a long time with no idea how to fix it didn't help.

Re: SpaceX bans Zoom over privacy concerns

#149

Earlier quoted context omitted.

> That is true of any end-to-end solution. Utterly false. Real end-to-end encryption would encrypt the backup with a key that is not available to the backup service (e.g. derived from a passphrase not sent to the server). Of course this system has better usability, which is why Apple does it. But it's still a farce to call a system where Apple has the ability to decrypt the majority of messages "end-to-end" encrypted…

> The fact that it's through the backup servers instead of the iMessage servers makes no difference. It makes a big difference. If I print out the texts I receive, it doesn't change whether the texting program is end-to-end encrypted. The same goes for backups. An unencrypted system-level backup doesn't mean that the program being backed up is failing at security. It's bad that Apple doesn't let you encrypt your back…

What if the texting program has a built in feature to print the texts you receive and mail a copy to the company that wrote the program, and it nags you to enable this feature all the time, and most of your friends have it enabled? Because that's a lot closer to the scenario here.

> An unencrypted system-level backup doesn't mean that the program being backed up is failing at security.

iOS programs can choose how their data is backed up. iMessage isn't just getting its data stolen by iCloud accidentally. These backups are a feature of iMessage as much as iCloud. And besides, iCloud is made by the same company, it's not a separate entity.

Re: SpaceX bans Zoom over privacy concerns

#150

Earlier quoted context omitted.

Most people use iCloud backup. Even if you don't, your messages are still sent to Apple by the recipient. And Apple prohibits third party backup services. > Apple does not have the ability to read your messages. iCloud backup is an Apple service and it has the ability to read most of your messages even if you don't use it, which makes this statement categorically false.

This is completely ridiculous. iMessage is encrypted by my device and remains encrypted until it gets to the recipient device. That is what end-to-end encryption means. That I may have given Apple my private key through a different message in no way affects that end-to-end encryption, because it is trivial to decide not to give Apple that key.

iCloud isn't some separate entity from iMessage. It's all Apple. And you have no option to use a different cloud backup provider.

You can decide not to give your keys to Apple, but you can't decide for all your friends to not give their keys to Apple, and the result is the same: Apple can read your messages.

And the marketing is so misleading that hardly anyone knows that Apple can read most iMessages.

Post reply on HN