Live data from Hacker News

SpaceX bans Zoom over privacy concerns

reuters.com

251–260 of 301 posts

Re: SpaceX bans Zoom over privacy concerns

#251

Earlier quoted context omitted.

They are using the same language as Apple talking about iMessage and FaceTime. Apple talks about end to end encryption, but one end is iCloud which is why you can get your messages simultaneously on all devices.

It's entirely possible to do multi-device end-to-end encryption. See Signal or XMPP+OMEMO.

Isn't that just for text? I know Signal uses WebRTC for Audio & Video and doesn't yet support group chats, (unless something changed recently)?

Re: SpaceX bans Zoom over privacy concerns

#253

Earlier quoted context omitted.

This bothers me so much - as I have personally recommended zoom to many people and customers. People that have likely seen that I spend an unusual amount of time focused on computer security, backups, and care in communications. If I remember correctly, zoom used to have on the front page - use this it's encrypted, and 'even used by us govt something-something' - so I assumed it was completely secure. I actually refu…

Only recommend free software, this way you minimize reputation drama

Generally speaking, free software UX is so bad that I would never recommend it to most people I talk to because

1) I don't want to train them on it

2) I don't want to support them on it

3) It isn't good enough for them to use without 1-2

So I pick the shiny costly commercial version that comes with training and support.

I mean, I've done the recommend my parents and older coworkers use difficult OSS software thing in my past, and I honestly regret it. No one won.

Re: SpaceX bans Zoom over privacy concerns

#254
post #10
post #3

SpaceX is strategic national defense, so this makes sense. I expect many similar companies to follow suit.

Seems like any organization under ITAR should prefer in-house solutions in areas relating to dissemination of sensitive design notes.

That is a recipe for a disaster. Microsoft Teams and Google Meet are backed by real security organizations. Enterprises use them for a reason.

Re: SpaceX bans Zoom over privacy concerns

#255
post #249

Earlier quoted context omitted.

The server does not have to decrypt or process the video, it can just send the same encrypted video to other clients (or you can use p2p communication without a server involved). There may be advantages to processing video at the server, but it's definitely not a hard requirement.

The problem is, that then you have to send all video streams to all client, that doesn't scale very well.

There are some (ongoing) solutions though: https://crypto.stanford.edu/craig/easy-fhe.pdf

Re: SpaceX bans Zoom over privacy concerns

#257

Earlier quoted context omitted.

This bothers me so much - as I have personally recommended zoom to many people and customers. People that have likely seen that I spend an unusual amount of time focused on computer security, backups, and care in communications. If I remember correctly, zoom used to have on the front page - use this it's encrypted, and 'even used by us govt something-something' - so I assumed it was completely secure. I actually refu…

Only recommend free software, this way you minimize reputation drama

Sadly, my experience has been the opposite, because open-source stuff usually takes more work to run and is seldom as polished, and users hate that. I rarely, if ever, recommend open-source anything for end-user use. Zoom did well because it had the least hassle of any solution, hands-down. I'm not saying it's impossible to subscribe to a hosted open-source service that's as good, but it doesn't exist yet.

Re: SpaceX bans Zoom over privacy concerns

#260
post #81

Earlier quoted context omitted.

Apple does the same thing, where they claim iMessage is ETE encrypted, but the keys (so capabilities to read) are stored on their servers.

This is not true. Don't spread FUD. Apple does not have the ability to read your messages. All messages stored on their servers are encrypted with keys that live only on the phone. iMessage doesn't store your decryption keys on Apple's servers unless you opt into iCloud backup which is a whole different service and security concern.

iCloud Backup is opt out, not opt in. Apple has backed up iMessage keys for the vast majority of its users.

https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

Post reply on HN