Earlier quoted context omitted.
They are using the same language as Apple talking about iMessage and FaceTime. Apple talks about end to end encryption, but one end is iCloud which is why you can get your messages simultaneously on all devices.
There is a big difference there though. In transit, iMessage and FaceTime backups are end-to-end encrypted, it's just the iMessage backups on iCloud that also store the key. FaceTime chats, though, truly are end-to-end encrypted and the calls aren't backed up like iMessages are.
SpaceX bans Zoom over privacy concerns
201–210 of 301 posts
Re: SpaceX bans Zoom over privacy concerns
#202The fact that they show end users (no pun intended) an "end-to-end encrypted" badge on the meeting window itself, and elsewhere explain how a Zoom server (not Zoom client) is what constitutes an "end" despite the whole rest of the electronic communication industry using "end-to-end" to refer exclusively to user agents, is bonkers.
They are using the same language as Apple talking about iMessage and FaceTime. Apple talks about end to end encryption, but one end is iCloud which is why you can get your messages simultaneously on all devices.
Re: SpaceX bans Zoom over privacy concerns
#203Earlier quoted context omitted.
The quiet part? You mean "the only people we should let spy on us is our own government"?
The quiet part is "American citizens of Chinese descent can't be trusted". This is as obvious of a dogwhistle as when people "innocently" point out that the CEO of some maligned Wall Street firm is Jewish and I have no idea why it's getting upvotes on this site.
Re: SpaceX bans Zoom over privacy concerns
#204The problem is, that the actions of Zoom doesn't make them look like a trustworthy provider. They lied about the end-to-end encryption. What they should have done instead is to be transparent on how unencrypted data is used on their servers and what their protocols are to prevent unauthorized access to that data. Which is especially important in a business context, because the business users themselves have confidentiality agreements, they need to guarantee and using an external provider for confidential data required that provider passing the neccessary scrutiny.
And of course, the huge pile of security issues coming up with their client, the web server, the mac installer, the script host, give any reason to believe that they either don't know what they are doing or completely reckless at least. And the term "reckless" doesn't fit in a conversation about security :).
Re: SpaceX bans Zoom over privacy concerns
#205Earlier quoted context omitted.
Not sarcasm. Sources please.
Let's not use sarcasm or sources..... Let's puzzle it out. You don't use a password to encrypt your iCloud backups... They're specific to the hardware your backing up. If you have an itouch for example it's backups are separate from your phone. So now you have these backups in the cloud and you lose your iPhone, you remote wipe it. Now your new one arrives and you restore from backup... Your iMessage private keys are…
2) What about your iCloud account and password that are required to encrypt, store, access, and decrypt the backups there? Is that not a factor worth consideration?
Re: SpaceX bans Zoom over privacy concerns
#206Earlier quoted context omitted.
This is completely ridiculous. iMessage is encrypted by my device and remains encrypted until it gets to the recipient device. That is what end-to-end encryption means. That I may have given Apple my private key through a different message in no way affects that end-to-end encryption, because it is trivial to decide not to give Apple that key.
iCloud isn't some separate entity from iMessage. It's all Apple. And you have no option to use a different cloud backup provider. You can decide not to give your keys to Apple, but you can't decide for all your friends to not give their keys to Apple, and the result is the same: Apple can read your messages. And the marketing is so misleading that hardly anyone knows that Apple can read most iMessages.
Re: SpaceX bans Zoom over privacy concerns
#207Earlier quoted context omitted.
iCloud isn't some separate entity from iMessage. It's all Apple. And you have no option to use a different cloud backup provider. You can decide not to give your keys to Apple, but you can't decide for all your friends to not give their keys to Apple, and the result is the same: Apple can read your messages. And the marketing is so misleading that hardly anyone knows that Apple can read most iMessages.
Sorry, let's be explicit here, as you seem intent on muddying the issue. Where, other than the endpoints, is the message decrypted when people use iMessage? Your succinct answer to that will clear this up for everyone.
Re: SpaceX bans Zoom over privacy concerns
#208Earlier quoted context omitted.
Agreed. It's unlikely they stumbled onto an industry standard phrase like that alone, then innocently used it without knowing the generally accepted meaning. This is deceptive advertising.
Not defending zoom here -- they done fucked up -- but there is a huge disconnect between the marketing folks and the technical folks. It's possible that E2E Encryption was something they planned on implementing but haven't, and the marketing department either didn't get the memo or didn't understand and still kept the wording.
Re: SpaceX bans Zoom over privacy concerns
#209Earlier quoted context omitted.
Not just "deceptive" nor "unlikely", it's blatant false advertising.
Fraudulent is the word i would use.
insert Hanlons razor quote here
Re: SpaceX bans Zoom over privacy concerns
#210Earlier quoted context omitted.
Sorry, let's be explicit here, as you seem intent on muddying the issue. Where, other than the endpoints, is the message decrypted when people use iMessage? Your succinct answer to that will clear this up for everyone.
On GCBD's servers in China. Possibly on Apple's servers in the US if they are running a wiretap. Due to the way key distribution works for iMessage, it is trivial for Apple and GCBD to do so. https://news.ycombinator.com/item?id=22755903