Live data from Hacker News

Zoom rolled their own encryption scheme, transmit keys through servers in China

citizenlab.ca

101–110 of 316 posts

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#101

Seriously, all people who are surprised about this type of news should really understand that most "successful" (as in, popular) tech/.com/SV "startups" these days are like this. If you "waste" time on the real important stuff such as a good design, user security, or the like, you will lose over to a competitor who didn't and therefore was able to spend more time on marketing. If you waste your time on user privacy y…

But when I see "roll their own encryption," it tells me that they went out of their way to create something subpar. There are some things that one should never* roll one's own of, and encryption has to be the top of the list.

* OK, if you're an encryption expert, you obviously would roll your own to advance the state of the art, but Zoom are quite obviously not encryption experts.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#102
post #96
post #65

Earlier quoted context omitted.

Because a company doing an RFP with a checklist of features is going to rank them against their competitors, and it would look bad in the spreadsheet.

I assume this is your answer to "why would they lie?". It does not answer the question to why should an educational provider care though. And assuming I'll consider switching to webex the response to encryption in webex is this: https://www.webex.com/content/dam/Webex/eopi/Americas/USA/en... Which 404's and basically represents my experience with Cisco: "We don't give a shit about you, you already payed us.". Frankly…

lol, nice job finding a link that 404s and basing your entire argument on it. Here is another one for your next post: https://www.webex.com/sdvfebdwq3433t8hjaxcxqadxe

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#103
post #73
post #63

Earlier quoted context omitted.

This is a great article, but as an educational provider it fails to answer one question: Why should I care? The only concerning thing for me is, why would they lie about using AES-256 when none of my users (and I assume most of their users) would care in any way about AES-256 vs. AES-128 in ECB mode. Why would they lie? Even after this, having my users conducting university lessons over something that might be decryp…

"... and then they came for me". Obviously that poem was written about something rather more serious than your privacy but the point stands.

As I alluded to in another post I am from Germany and certain people I work with actually went through the "... they came for me" phase.

Your point does not stand on its own.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#104

Seriously, all people who are surprised about this type of news should really understand that most "successful" (as in, popular) tech/.com/SV "startups" these days are like this. If you "waste" time on the real important stuff such as a good design, user security, or the like, you will lose over to a competitor who didn't and therefore was able to spend more time on marketing. If you waste your time on user privacy y…

I think you might be missing the bigger picture. You have a company that the "Ministry of State Security of the People's Republic of China" can easily hack to spy on American children and businesses. What could go wrong?

Not just American. Someone posted a screenshot on HN yesterday or the day before of the prime minister of the United Kingdom having a video chat with about 16 other top government officials over Zoom.

Anyone want to wager how many of their computers are now p0wned.cn?

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#105
post #10

> Zoom’s most recent SEC filing shows that the company (through its Chinese affiliates) employs at least 700 employees in China that work in “research and development.” Wow. What could all of these people possibly be doing? It can't be development and QA; what's going on over there?

That's actually the most interesting fact about Zoom I feel like I've learned so far! Edit: I looked it up... thought it seemed crazy high but it obviously includes all the support staff too. So they might have only 300 engineers total, for example. I guess that's more reasonable. [1] "As of January 31, 2020, we had 2,532 full-time employees. Of these employees, 1,396 are in the United States and 1,136 are in our int…

Is "Support" traditionally categorized under research & development? Possibly enterprise support or solutions engineers?

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#106
post #74

Earlier quoted context omitted.

Those cost more.

Much cheaper than trying to put out the fires caused by not using them. Experience costs more because it pays off.

There's a reason airlines don't put a freshly minted, cheap pilot in command of a 747.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#107

Seriously, all people who are surprised about this type of news should really understand that most "successful" (as in, popular) tech/.com/SV "startups" these days are like this. If you "waste" time on the real important stuff such as a good design, user security, or the like, you will lose over to a competitor who didn't and therefore was able to spend more time on marketing. If you waste your time on user privacy y…

I more suspect it is a problem stemming from hiring people who are all new to professional programming. Avoiding these issues means hiring some older, experienced professionals.

Or hiring people solely based on Leetcoding interviews. Seriously, every interview I've had in the last decade focused on algorithms/data structures but it was very rare to get any questions on security. This applies to startups and larger enterprise companies alike.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#108
post #88

Earlier quoted context omitted.

Compression does not introdoce entropy to a stream. Please refer to Shannon's source coding theorm. If anything, it reduces entropy.

But it does increase the entropy per byte, thus making patterns harder to spot.

....so your argument us to hope an adversary only sees part of your video and not all of it?

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#109

Seriously, all people who are surprised about this type of news should really understand that most "successful" (as in, popular) tech/.com/SV "startups" these days are like this. If you "waste" time on the real important stuff such as a good design, user security, or the like, you will lose over to a competitor who didn't and therefore was able to spend more time on marketing. If you waste your time on user privacy y…

It is easier for Zoom to apologize and fix than for zoom to have no customers but a solid stack.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#110
post #96

Earlier quoted context omitted.

I assume this is your answer to "why would they lie?". It does not answer the question to why should an educational provider care though. And assuming I'll consider switching to webex the response to encryption in webex is this: https://www.webex.com/content/dam/Webex/eopi/Americas/USA/en... Which 404's and basically represents my experience with Cisco: "We don't give a shit about you, you already payed us.". Frankly…

lol, nice job finding a link that 404s and basing your entire argument on it. Here is another one for your next post: https://www.webex.com/sdvfebdwq3433t8hjaxcxqadxe

Frankly, Cisco can post whatever they like I will not give them any more money. You are certainly right that I was disingenuous and I do not care what they do with Webex. My link was cherry picked from their press release for encryption in Webex that I though it was funny that that link would 404.

Good job discrediting my post though. It's not like Cisco basically told everybody in a KB that if you want to use the same features Zoom provides (or a Linux client, or desktop sharing or breakout rooms or audio transcription or waiting rooms or...) you would have to give up every encryption feature Webex provides. But I assume you are a seasoned Webex admin and can provide us some insight into why you are using webex in contrast any other solution. Or you are trolling, whatever.

Post reply on HN