Live data from Hacker News

SpaceX bans Zoom over privacy concerns

reuters.com

261–270 of 301 posts

Re: SpaceX bans Zoom over privacy concerns

#261

Earlier quoted context omitted.

No. "End-to-end encryption" does not protect metadata necessary to route the data over a network, just the contents of the communication. The clients could negotiate keys to protect the contents of a meeting end-to-end. In other words, Zoom servers could deduce who was speaking, when they spoke, and for how long, but not what they said. Your internet service provider can deduce the same about your HTTPS connections.

> The clients could negotiate keys to protect the contents of a meeting end-to-end. Not really because Zoom makes fairly extensive use of the decrypted video streams on their servers, e.g. to detect who is talking, pause video for people with slow connections, etc. You could maybe do it for meetings with a few people in, but good luck doing it for meetings with 100 people. Hell the cryptography of group end-to-end en…

All communication via Signal is e2e. They have not shipped anything that does not.

Re: SpaceX bans Zoom over privacy concerns

#262

Earlier quoted context omitted.

No. "End-to-end encryption" does not protect metadata necessary to route the data over a network, just the contents of the communication. The clients could negotiate keys to protect the contents of a meeting end-to-end. In other words, Zoom servers could deduce who was speaking, when they spoke, and for how long, but not what they said. Your internet service provider can deduce the same about your HTTPS connections.

> The clients could negotiate keys to protect the contents of a meeting end-to-end. Not really because Zoom makes fairly extensive use of the decrypted video streams on their servers, e.g. to detect who is talking, pause video for people with slow connections, etc. You could maybe do it for meetings with a few people in, but good luck doing it for meetings with 100 people. Hell the cryptography of group end-to-end en…

> WhatsApp doesn't do it and that's just for text. I'm pretty sure Signal doesn't either.

Wow this is news to me. Glad I'm not using whatsapp since forever.

Signal definitely encrypts group chats since forever: https://signal.org/blog/the-new-textsecure/

Re: SpaceX bans Zoom over privacy concerns

#263
post #249

Earlier quoted context omitted.

The problem is, that then you have to send all video streams to all client, that doesn't scale very well.

The clients could control which video streams they want to subscribe to without the server decrypting them. If you want to support thumbnail/fullscreen versions of streams, the clients could just send along two streams or use a codec that supports this kind, like h.264 SVC.

Yes, with effective 2 streams per client, the client could tell the server to send max. 1 full resolution stream and any number of low res streams. If you want full encryption, they have to be send as separate streams from each client. Also, the encryption would need to be negotiated between each pair of participants separately, that is doable, but scales with the square of all participants. So yes, full end-to-end encryption is possible, but quite an effort. But as I wrote before, just having encrypted connections to the server should be fine, if the server provider is trustworthy.

Re: SpaceX bans Zoom over privacy concerns

#264
post #199
post #114

Earlier quoted context omitted.

So, SpaceX.com at least uses an IP address owned by Amazon: https://www.abuseipdb.com/whois/50.112.120.214 slenk@Enterprise:~$ host spacex.com spacex.com has address 50.112.120.214 [output truncated]

Well, there is no security problem to host a public web site on e.g. AWS. I think the restrictions more affect internal, confidential data.

You're probably right. Just proving that broad blanket statement wrong

Re: SpaceX bans Zoom over privacy concerns

#265

Earlier quoted context omitted.

No. "End-to-end encryption" does not protect metadata necessary to route the data over a network, just the contents of the communication. The clients could negotiate keys to protect the contents of a meeting end-to-end. In other words, Zoom servers could deduce who was speaking, when they spoke, and for how long, but not what they said. Your internet service provider can deduce the same about your HTTPS connections.

> The clients could negotiate keys to protect the contents of a meeting end-to-end. Not really because Zoom makes fairly extensive use of the decrypted video streams on their servers, e.g. to detect who is talking, pause video for people with slow connections, etc. You could maybe do it for meetings with a few people in, but good luck doing it for meetings with 100 people. Hell the cryptography of group end-to-end en…

> Hell the cryptography of group end-to-end encryption hasn't really been worked out yet. WhatsApp doesn't do it and that's just for text.

That doesn't seem to be accurate: https://faq.whatsapp.com/en/android/28030015/

Maybe you're thinking of this issue?: https://medium.com/@haniahshafi/are-whatsapp-group-chats-vul...

Re: SpaceX bans Zoom over privacy concerns

#266
post #248

Earlier quoted context omitted.

> The clients could negotiate keys to protect the contents of a meeting end-to-end. Not really because Zoom makes fairly extensive use of the decrypted video streams on their servers, e.g. to detect who is talking, pause video for people with slow connections, etc. You could maybe do it for meetings with a few people in, but good luck doing it for meetings with 100 people. Hell the cryptography of group end-to-end en…

> Not really because Zoom makes fairly extensive use of the decrypted video streams on their servers, e.g. to detect who is talking, pause video for people with slow connections, etc. You could maybe do it for meetings with a few people in, but good luck doing it for meetings with 100 people. You encrypt audio and video streams separately. If your connection is slow you stop grabbing the video stream. Detecting who i…

I presume they also resize video, so that you download small streams for thumbnails, plus a bigger one for the main view. If it's just two sizes you could do it before uploading, but this would be harder if it's actually 10 different qualities.

Re: SpaceX bans Zoom over privacy concerns

#267

Earlier quoted context omitted.

Not just "deceptive" nor "unlikely", it's blatant false advertising.

This bothers me so much - as I have personally recommended zoom to many people and customers. People that have likely seen that I spend an unusual amount of time focused on computer security, backups, and care in communications. If I remember correctly, zoom used to have on the front page - use this it's encrypted, and 'even used by us govt something-something' - so I assumed it was completely secure. I actually refu…

I doubt non-technical users are savvy enough to find out about this problem and they probably won't remember to blame you for something clearly beyond your control.

I know it's the kind of thing that can randomly keep a person up at night, but I think you can probably safely forget about this awkwardness and move on.

Re: SpaceX bans Zoom over privacy concerns

#268
post #88

Earlier quoted context omitted.

No, it doesn't. https://support.apple.com/guide/security/how-imessage-sends-...

Yes, it does. The messages are 'end to end' encrypted in the iMessage service, but then iMessage backs up its encryption key in the iCloud backup service, defeating the point. "If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices." https://support.apple.com/en-us/H…

> defeating the point

Have you considered that some people trust Apple but don't trust Zoom? At some point you have to trust somebody, right?

Re: SpaceX bans Zoom over privacy concerns

#269

Earlier quoted context omitted.

Not just "deceptive" nor "unlikely", it's blatant false advertising.

This bothers me so much - as I have personally recommended zoom to many people and customers. People that have likely seen that I spend an unusual amount of time focused on computer security, backups, and care in communications. If I remember correctly, zoom used to have on the front page - use this it's encrypted, and 'even used by us govt something-something' - so I assumed it was completely secure. I actually refu…

https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u...

Re: SpaceX bans Zoom over privacy concerns

#270
post #209
post #91

Earlier quoted context omitted.

Fraudulent is the word i would use.

"Fraudulent", at least as far as I know, is reserved for "intentional deception". It could be that Zoom is indeed doing this intentionally, but without proof of it being intentional, I don't think we should assume so. insert Hanlons razor quote here

The IT guys in the industry know very well what constitutes an E2E encryption. Those two ends must be "trusted" which means it's either you yourself - your computer, or the other party which you want to talk to. Everything in between is third party and must get only encrypted data. If they redefine one of the "ends" as Zoom server, that's definitely intentional, blatant, and therefore fraudulent.
Post reply on HN