No more rolling your own crypto than if I were to use DES.
Zoom rolled their own encryption scheme, transmit keys through servers in China
11–20 of 316 posts
Re: Zoom rolled their own encryption scheme, transmit keys through servers in China
#12Keynote: Zoom’s encryption and decryption use AES in ECB mode
Re: Zoom rolled their own encryption scheme, transmit keys through servers in China
#13Zoom deserves a lot of animosity for its privacy issues like sharing data with Facebook. On the other hand I am mystified by all the security hype. Yes I might be able to guess a Zoom meeting ID, just as if I might guess your phone number and prank call you. In a Zoom meeting you can see who is connected . In the old days of conference calls do you remember asking “who’s on the line?”. What are you talking about that…
The UK are using it for Cabinet meetings - https://www.bbc.co.uk/news/technology-52126534
Re: Zoom rolled their own encryption scheme, transmit keys through servers in China
#14> Zoom’s most recent SEC filing shows that the company (through its Chinese affiliates) employs at least 700 employees in China that work in “research and development.” Wow. What could all of these people possibly be doing? It can't be development and QA; what's going on over there?
You get the face and the voice of people talking directly to the camera. You get the people who they constantly talk to so you know their relations. You know the content of what they are saying.
Re: Zoom rolled their own encryption scheme, transmit keys through servers in China
#15Zoom deserves a lot of animosity for its privacy issues like sharing data with Facebook. On the other hand I am mystified by all the security hype. Yes I might be able to guess a Zoom meeting ID, just as if I might guess your phone number and prank call you. In a Zoom meeting you can see who is connected . In the old days of conference calls do you remember asking “who’s on the line?”. What are you talking about that…
> What are you talking about that requires encryption? The UK are using it for Cabinet meetings - https://www.bbc.co.uk/news/technology-52126534
And UK officials say the risks of not communicating in the middle of fast-moving events far outweigh the possible security risks of using such a system.
They add most government work to do with the coronavirus is unclassified and anything highly classified is communicated over secure systems
Government meetings use the paid-for version of the system and are password protected to prevent "Zoom-bombing", when uninvited individuals intrude on calls.
The UK Ministry of Defence also said Zoom should not be used for classified conversations.
And it is understood Nato's policy not to use Zoom for any meetings, briefings or conversations between member state ambassadors if classified or sensitive information is shared.
Nato staff are understood to be using "more stable and secure" means of communication.
=====
They seem to be perfectly well aware of their threat model
Re: Zoom rolled their own encryption scheme, transmit keys through servers in China
#16> Zoom’s most recent SEC filing shows that the company (through its Chinese affiliates) employs at least 700 employees in China that work in “research and development.” Wow. What could all of these people possibly be doing? It can't be development and QA; what's going on over there?
Machine learning on everyone's video feeds to make better deep fakes of common people? You get the face and the voice of people talking directly to the camera. You get the people who they constantly talk to so you know their relations. You know the content of what they are saying.
Re: Zoom rolled their own encryption scheme, transmit keys through servers in China
#17> Zoom’s most recent SEC filing shows that the company (through its Chinese affiliates) employs at least 700 employees in China that work in “research and development.” Wow. What could all of these people possibly be doing? It can't be development and QA; what's going on over there?
Edit: I looked it up... thought it seemed crazy high but it obviously includes all the support staff too. So they might have only 300 engineers total, for example. I guess that's more reasonable. [1]
"As of January 31, 2020, we had 2,532 full-time employees. Of these employees, 1,396 are in the United States and 1,136 are in our international locations."
"We also operate research and development centers in China, employing more than 700 employees as of January 31, 2020."
[1] https://investors.zoom.us/static-files/09a01665-5f33-4007-8e...
Re: Zoom rolled their own encryption scheme, transmit keys through servers in China
#18> Zoom’s most recent SEC filing shows that the company (through its Chinese affiliates) employs at least 700 employees in China that work in “research and development.” Wow. What could all of these people possibly be doing? It can't be development and QA; what's going on over there?
Re: Zoom rolled their own encryption scheme, transmit keys through servers in China
#19> Zoom’s most recent SEC filing shows that the company (through its Chinese affiliates) employs at least 700 employees in China that work in “research and development.” Wow. What could all of these people possibly be doing? It can't be development and QA; what's going on over there?
Not to defend them against the recent security fiasco, but innuendos such as this that links "employees working in China" directly with "shady business" makes me at least uncomfortable.
Re: Zoom rolled their own encryption scheme, transmit keys through servers in China
#20I really don't think this counts as rolling your own crypto. They just used a weak implementation of existing methods. No more rolling your own crypto than if I were to use DES.
As the classic article says, if you type the letters A-E-S, you're doing it wrong.