Live data from Hacker News

Zoom rolled their own encryption scheme, transmit keys through servers in China

citizenlab.ca

11–20 of 316 posts

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#13
post #8

Zoom deserves a lot of animosity for its privacy issues like sharing data with Facebook. On the other hand I am mystified by all the security hype. Yes I might be able to guess a Zoom meeting ID, just as if I might guess your phone number and prank call you. In a Zoom meeting you can see who is connected . In the old days of conference calls do you remember asking “who’s on the line?”. What are you talking about that…

> What are you talking about that requires encryption?

The UK are using it for Cabinet meetings - https://www.bbc.co.uk/news/technology-52126534

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#14
post #10

> Zoom’s most recent SEC filing shows that the company (through its Chinese affiliates) employs at least 700 employees in China that work in “research and development.” Wow. What could all of these people possibly be doing? It can't be development and QA; what's going on over there?

Machine learning on everyone's video feeds to make better deep fakes of common people?

You get the face and the voice of people talking directly to the camera. You get the people who they constantly talk to so you know their relations. You know the content of what they are saying.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#15
post #8

Zoom deserves a lot of animosity for its privacy issues like sharing data with Facebook. On the other hand I am mystified by all the security hype. Yes I might be able to guess a Zoom meeting ID, just as if I might guess your phone number and prank call you. In a Zoom meeting you can see who is connected . In the old days of conference calls do you remember asking “who’s on the line?”. What are you talking about that…

> What are you talking about that requires encryption? The UK are using it for Cabinet meetings - https://www.bbc.co.uk/news/technology-52126534

> In a crisis, communication at speed is the priority.

And UK officials say the risks of not communicating in the middle of fast-moving events far outweigh the possible security risks of using such a system.

They add most government work to do with the coronavirus is unclassified and anything highly classified is communicated over secure systems

Government meetings use the paid-for version of the system and are password protected to prevent "Zoom-bombing", when uninvited individuals intrude on calls.

The UK Ministry of Defence also said Zoom should not be used for classified conversations.

And it is understood Nato's policy not to use Zoom for any meetings, briefings or conversations between member state ambassadors if classified or sensitive information is shared.

Nato staff are understood to be using "more stable and secure" means of communication.

=====

They seem to be perfectly well aware of their threat model

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#16
post #10

> Zoom’s most recent SEC filing shows that the company (through its Chinese affiliates) employs at least 700 employees in China that work in “research and development.” Wow. What could all of these people possibly be doing? It can't be development and QA; what's going on over there?

Machine learning on everyone's video feeds to make better deep fakes of common people? You get the face and the voice of people talking directly to the camera. You get the people who they constantly talk to so you know their relations. You know the content of what they are saying.

Deep fakes can only work for so long. When it becomes ubiquitous people will naturally learn that anything can be deep faked. We would need some process of verification, then.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#17
post #10

> Zoom’s most recent SEC filing shows that the company (through its Chinese affiliates) employs at least 700 employees in China that work in “research and development.” Wow. What could all of these people possibly be doing? It can't be development and QA; what's going on over there?

That's actually the most interesting fact about Zoom I feel like I've learned so far!

Edit: I looked it up... thought it seemed crazy high but it obviously includes all the support staff too. So they might have only 300 engineers total, for example. I guess that's more reasonable. [1]

"As of January 31, 2020, we had 2,532 full-time employees. Of these employees, 1,396 are in the United States and 1,136 are in our international locations."

"We also operate research and development centers in China, employing more than 700 employees as of January 31, 2020."

[1] https://investors.zoom.us/static-files/09a01665-5f33-4007-8e...

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#18
post #10

> Zoom’s most recent SEC filing shows that the company (through its Chinese affiliates) employs at least 700 employees in China that work in “research and development.” Wow. What could all of these people possibly be doing? It can't be development and QA; what's going on over there?

Why can't 700 people do development and QA?

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#19
post #10

> Zoom’s most recent SEC filing shows that the company (through its Chinese affiliates) employs at least 700 employees in China that work in “research and development.” Wow. What could all of these people possibly be doing? It can't be development and QA; what's going on over there?

You do realize development include software engineering, right? 700 people doing programming isn't even remotely surprising.

Not to defend them against the recent security fiasco, but innuendos such as this that links "employees working in China" directly with "shady business" makes me at least uncomfortable.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#20

I really don't think this counts as rolling your own crypto. They just used a weak implementation of existing methods. No more rolling your own crypto than if I were to use DES.

It's "rolling your own crypto", not "rolling your own encryption algorithm". That includes using "secure" low-level primitives incorrectly to build an insecure higher-level protocol. In this case, using ECB mode has been known for years (decades?) to be a bad move regardless of the underlying encryption algorithm.

As the classic article says, if you type the letters A-E-S, you're doing it wrong.

Post reply on HN