I'm not Zooming, but everyone I know is, and it looks pretty damn slick and seems to work great. I can't think of any service that has had as fast and huge an adoption, which is obviously due to blind luck/things beyond their control (no one saw global apocalypse coming and hoping for such would be a horrible business plan). Of course there's been other services working just as well or better for at least 10 years no…
Zoom is the deluge du jour (literally—today has been the day of Zoom deluge complaints), but Occam called and wanted to let us know that we don't need any sinister explanations. It's obviously (or at least, explicable) as an effect of the covid crisis. https://news.ycombinator.com/item?id=22754135 https://news.ycombinator.com/item?id=22751116
SpaceX bans Zoom over privacy concerns
291–300 of 301 posts
Re: SpaceX bans Zoom over privacy concerns
#292Earlier quoted context omitted.
> Not really because Zoom makes fairly extensive use of the decrypted video streams on their servers, e.g. to detect who is talking, pause video for people with slow connections, etc. You could maybe do it for meetings with a few people in, but good luck doing it for meetings with 100 people. You encrypt audio and video streams separately. If your connection is slow you stop grabbing the video stream. Detecting who i…
I presume they also resize video, so that you download small streams for thumbnails, plus a bigger one for the main view. If it's just two sizes you could do it before uploading, but this would be harder if it's actually 10 different qualities.
Re: SpaceX bans Zoom over privacy concerns
#293Earlier quoted context omitted.
Sorry, let's be explicit here, as you seem intent on muddying the issue. Where, other than the endpoints, is the message decrypted when people use iMessage? Your succinct answer to that will clear this up for everyone.
I have linked it several times in this thread. Here it is again: "If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices." https://support.apple.com/en-us/HT202303
Re: SpaceX bans Zoom over privacy concerns
#294Earlier quoted context omitted.
I have linked it several times in this thread. Here it is again: "If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices." https://support.apple.com/en-us/HT202303
Sorry, and where exactly outside the endpoints are the messages being decrypted?
What we know is that they can and do decrypt iMessages from iCloud backups in response to law enforcement requests[1]. This proves that they hold the keys, if their own support pages weren't enough evidence for you.
[1] https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
Re: SpaceX bans Zoom over privacy concerns
#295Earlier quoted context omitted.
I doubt non-technical users are savvy enough to find out about this problem and they probably won't remember to blame you for something clearly beyond your control. I know it's the kind of thing that can randomly keep a person up at night, but I think you can probably safely forget about this awkwardness and move on.
Thing is - this story is all over the mainstream news. It's got multiple stories on the yahoo front page, it's reported via multiple sources in my fbook feed, but also with our regular tv news station. People are seeing this about zoom that have never seen zoom. People that I suggested use zoom are going to notice the word even if they would normally scroll past some gomeeting story.
Re: SpaceX bans Zoom over privacy concerns
#296Earlier quoted context omitted.
Sorry, and where exactly outside the endpoints are the messages being decrypted?
Only Apple can know exactly when or where or how often they decrypt people's messages from their backups, because once they have the keys they have the means to do it at any place and time, for any reason, without anyone's knowledge or consent. What we know is that they can and do decrypt iMessages from iCloud backups in response to law enforcement requests[1]. This proves that they hold the keys, if their own suppor…
Re: SpaceX bans Zoom over privacy concerns
#297Earlier quoted context omitted.
Apple can, of course, do whatever it likes, up to simply recording the screen and sending that to weird & wonderful government agencies. Like almost everything in mainstream security, it comes down to who you trust. It doesn't mean it isn't E2E though.
> It doesn't mean it isn't E2E though. E2E encryption simply means that messages are only decrypted at the endpoints. That certainly isn't true of iMessage in China, and it might not even be true for some users in the US — we have no way of knowing because the protocol makes no guarantee against it.
Re: SpaceX bans Zoom over privacy concerns
#298Earlier quoted context omitted.
Eh, haven't large companies leaked private details from their customers time and time again, in basic ways like forgetting that they have backups on S3 buckets with zero protection? Being incompetent has nothing to do with the size or prominence of the company. Big/prominent companies fuck up/are sloppy all the time.
This is not a fuck up or negligence, Zoom deliberately used "end-to-end" with a completely different meaning than the rest of the world. I can't describe this as anything else than malicious and fraudulent. Their intention was to deceive users that the communication was encrypted, when in reality it wasn't.
I'm in no way saying it's impossible that Zoom did say E2E encryption while knowing that's not true, but I could imagine a scenario where a security person says "Yeah, we're encrypting connections to our backend" and a marketing person researching E2E and then saying to themselves "Yeah, sounds like we're doing E2E, let's write that", because this stuff happens all the time in the industry.
> Their intention was to deceive users
You sound so sure about their intentions, do you have any actual proof of this that others are missing? Again, I'm not saying it's impossible that their intention was to deceive users, but as an engineer, I always favor proof over guessing.
Re: SpaceX bans Zoom over privacy concerns
#299Earlier quoted context omitted.
"Fraudulent", at least as far as I know, is reserved for "intentional deception". It could be that Zoom is indeed doing this intentionally, but without proof of it being intentional, I don't think we should assume so. insert Hanlons razor quote here
The IT guys in the industry know very well what constitutes an E2E encryption. Those two ends must be "trusted" which means it's either you yourself - your computer, or the other party which you want to talk to. Everything in between is third party and must get only encrypted data. If they redefine one of the "ends" as Zoom server, that's definitely intentional, blatant, and therefore fraudulent.
But just because someone uses a word wrong doesn't give you any proof about their intentions. See https://news.ycombinator.com/item?id=22767447 for further elaboration on that point.
Again, it's harmful to use words incorrectly, _especially_ when it comes to E2E, so they should rightly get flak for getting it wrong. You all seem to be so sure that it was intentional though, while I've seen the same problem so many times before in the industry without it being intentional. If you do have proof it's intentional, please share it with the rest of us so we can be on the same page.
Re: SpaceX bans Zoom over privacy concerns
#300Earlier quoted context omitted.
Thing is - this story is all over the mainstream news. It's got multiple stories on the yahoo front page, it's reported via multiple sources in my fbook feed, but also with our regular tv news station. People are seeing this about zoom that have never seen zoom. People that I suggested use zoom are going to notice the word even if they would normally scroll past some gomeeting story.
If they read tech news this week, but not if they happen to skip it until next week.
People in Tennessee watching regular news on free over the air antenna (non-cable news) -> https://www.wsmv.com/news/security-experts-warn-about-zoom-h...
any anyone who is within earshot of such 'non-tech news' is hearing how unsecure zoom is.
Sure most of my clients are unlikely to read HN at all, and most are unlikely to read tech crunch regularly if at all - but I bet some have TC or something similar in their fbook feed.
People watching TV news in Utah see: https://fox17.com/news/nation-world/zoom-call-with-utah-elem...
However people who don't even own computers are seeing this debacle.
So, anyone I've advised to use zoom for privacy and security, citing the encryption and use by US gov - is going to have to wonder - how do these things happen on a secure, private, encrypted system - must not be what it was purported to be by that guy Steve. Then they are going to wonder what kind of damage could be done with the info that was 'securely' shared with the service.