Live data from Hacker News

Zoom rolled their own encryption scheme, transmit keys through servers in China

citizenlab.ca

91–100 of 316 posts

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#91

Earlier quoted context omitted.

Have read the whole article myself, I did not see that explicitly stated. Could you provide the quote?

> In addition, we identify potential areas of concern in Zoom’s infrastructure, including observing the transmission of meeting encryption keys through China.

Thanks! Indeed that was in their opener, but their clarifying statement is broader.

FTA "We suspect that keys may be distributed through these servers. A company primarily catering to North American clients that sometimes distributes encryption keys through servers in China is potentially concerning, given that Zoom may be legally obligated to disclose these keys to authorities in China."

"We suspect" is not the same as "we are certain".

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#92
post #88

Earlier quoted context omitted.

It's definitely a terrible choice for uncompressed images or video. I'm arguing it probably isn't that bad for highly compressed video. That being said, if you're encrypting any data stream you should use an appropriate stream cipher.

Compression does not introdoce entropy to a stream. Please refer to Shannon's source coding theorm. If anything, it reduces entropy.

But it does increase the entropy per byte, thus making patterns harder to spot.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#93
post #29
post #26

Earlier quoted context omitted.

I didn't read it as suggesting it was "shady business". I read it as an insinuation that the company didn't know what it was doing from the top down, so they didn't hire smartly or manage well; they just threw numbers of people at the problem (and got predictably bad results). With good management, a team of 50 should be able to provide what Zoom provides.

Yeah, moments after replying I realized there is a more charitable read :-) Of course, with this read comes the age old question of "I can build Google/FB with 20 good men, what are they doing?"

> Of course, with this read comes the age old question of "I can build Google/FB with 20 good men, what are they doing?"

Well, this would explain Google's pattern of constantly churning out new products on the theory that hey, maybe someone somewhere wants it.

If you need 20 people to run your actual operations but you've hired 20,000 people, what are the other 20,000 people supposed to do?

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#94

Earlier quoted context omitted.

Using code without understanding its implications would fall in the gross incompetence category.

And my point is that this happens all the time. Natural selection seems to favor the type of company that would just copy&paste from SO (then spend their resources on some fancy viral marketing) instead of the one that would stop to think about it.

People shouldn't be surprised, but they should be upset.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#95

Seriously, all people who are surprised about this type of news should really understand that most "successful" (as in, popular) tech/.com/SV "startups" these days are like this. If you "waste" time on the real important stuff such as a good design, user security, or the like, you will lose over to a competitor who didn't and therefore was able to spend more time on marketing. If you waste your time on user privacy y…

I agree this isn't uncommon, but that does nothing to make it acceptable.

Bad security design is unacceptable and this is sort of indicative of a large dissonance when it comes to SV startups. "Disruption" isn't ignoring requirements - if you are able to under price your competitors because you fail to adhere to good practices (or, more importantly, regulations[1]) you're not building a lean and useful product - you've just built a half-assed competitor that can undercut prices because it is incomplete... You're selling something as a competing solution when it only does half the stuff.

There is a lot of good to be said about identifying the 90/10 value components of a problem space and discarding expensive features that would just add complexity for little value - but if those features are requirements you're just failing to actually meet the points consumers (or markets ala regulations) expect and making your profit off of deceit.

1. Looking at you Uber.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#96
post #65
post #63

Earlier quoted context omitted.

This is a great article, but as an educational provider it fails to answer one question: Why should I care? The only concerning thing for me is, why would they lie about using AES-256 when none of my users (and I assume most of their users) would care in any way about AES-256 vs. AES-128 in ECB mode. Why would they lie? Even after this, having my users conducting university lessons over something that might be decryp…

Because a company doing an RFP with a checklist of features is going to rank them against their competitors, and it would look bad in the spreadsheet.

I assume this is your answer to "why would they lie?". It does not answer the question to why should an educational provider care though.

And assuming I'll consider switching to webex the response to encryption in webex is this: https://www.webex.com/content/dam/Webex/eopi/Americas/USA/en...

Which 404's and basically represents my experience with Cisco: "We don't give a shit about you, you already payed us.". Frankly Webex could host the next coming of Jesus and I would not give them any more money.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#97
post #21
post #10

> Zoom’s most recent SEC filing shows that the company (through its Chinese affiliates) employs at least 700 employees in China that work in “research and development.” Wow. What could all of these people possibly be doing? It can't be development and QA; what's going on over there?

"Wow. What could all of these people possibly be doing?" There are 20,000 google engineers working in "research and development", what could all of these people possibly be doing?

Violating humanity's privacy?

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#98
post #74

Earlier quoted context omitted.

Those cost more.

Much cheaper than trying to put out the fires caused by not using them. Experience costs more because it pays off.

There is little to no penalty if your software is crap from a security or privacy point of view and you are popular enough.

The example I used is Whatsapp. On the early days, but definitely after their popularity was already high in Europe, you could still impersonate any user on the platform trivially. Their only real security was obfuscation of the client source code, obfuscation of the protocol. Doesn't help much when you still have a Java (J2ME) client that is trivial to decompile. They still became hugely popular.

People quickly forget about this type of issues, or they don't assign blame where it belongs. They will just shrug over it and start believing that it is normal for computers to get hacked from time to time. After all, it appears all the time on TV.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#99

Earlier quoted context omitted.

Much cheaper than trying to put out the fires caused by not using them. Experience costs more because it pays off.

Yes, but people are short sighted. They also probably think “I’d rather grow quickly and be able to afford this down the line than do it right and risk missing out.”

Is this maybe a side effect of leadership in these startups being more junior themselves and not realizing the value they're missing out on by not pulling in some of that experience?

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#100

Earlier quoted context omitted.

Agree, but I want to add something: the usability of Zoom is good, even for casual computer users. Strategically, they focussed on what they considered to be the things that would give them sales. Not saying it is good, but it certainly worked for them (at least until now).

I agree. My SO ist currently studying from home due to the pandemic. A lot of professors and tutors use what they find first. There is no standard. She already had to use MS Teams, Slack, Jitsu and Zoom. Her take was that Zoom was by far the most usable tool. And most of her 20 years younger co-students agree. Sadly most people don't even know about the problematic status of Zoom. And if one tells them, most do not u…

The students are all forced to agree to these abusive third party TOS simply to receive the education to which they are entitled/for which they have already paid.

That’s a bait and switch on the part of the university. “You’ve already paid, but now you have to give up your civil rights against this third party you’ve never heard of to get the service.”

There should be liability for the schools for doing this. A class action, perhaps?

Post reply on HN