Live data from Hacker News

Zoom rolled their own encryption scheme, transmit keys through servers in China

citizenlab.ca

151–160 of 316 posts

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#151
post #136

Earlier quoted context omitted.

Hi dang, Thanks in advance for all your moderation efforts that make HN the site we all love to use on a regular basis. I'm curious if you've ever considered writing a blog post about some of the things you've learned from your years of moderation? You spend so much time on HN, you must have seen lots of patterns and have lots of insights on...well, everything that gets posted on HN to everybody that posts on HN. I'd…

While you wait for his response: https://www.newyorker.com/news/letter-from-silicon-valley/th...

I wonder how that approach can continue to make sense unless they hire more Lisp moderators.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#152
post #103

Earlier quoted context omitted.

As I alluded to in another post I am from Germany and certain people I work with actually went through the "... they came for me" phase. Your point does not stand on its own.

Your point does not stand on its own. No, but it will when the next generation of Nazi, Stalinist, and Maoist regimes arise and gain access to the data in question because we weren't fanatical enough about E2E privacy today. And just as Niemoeller's verse warns, by then it will be too late.

> And just as Niemoeller's verse warns, by then it will be too late.

But, this is just wrong. In Germany we did speak out when they came for the communists, the socialists, the unions and the jews. Niemöllers argument was relevant in 1937 when he was arrested and I appreciate that you picked up on it but frankly it's different here in Germany. We do still speak out against discrimination against all of them. Maybe E2E encryption in a chat application is just not as pressing as the things Niemöller talked about at the time.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#153

Earlier quoted context omitted.

Is compressed audio/video actually high-entropy (in the time domain) though?

Compressed anything is high entropy

Untrue. Many performance trade-offs have to be made and the entropy has to vary drastically with time. See for example B-Frames vs I-frames in compressed video. Couple that with the very low entropy video conference data and bam.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#154
post #103
post #73

Earlier quoted context omitted.

"... and then they came for me". Obviously that poem was written about something rather more serious than your privacy but the point stands.

As I alluded to in another post I am from Germany and certain people I work with actually went through the "... they came for me" phase. Your point does not stand on its own.

Doesn’t Germany have specific data privacy laws based on the massive surveillance state that operated in the East up through 1990 or so? And you’re not concerned with using services that go through a country that, by all accounts, is trying to outdo the old Stasi with modern technology?

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#155

On Ubuntu would installing Zoom via Snap be preferable than as a normal package when it comes to security / sandboxing, should the case be that they turn evil?

Yes, that would be vastly preferable. Normally, the client would still have access to quite a bit (Lots of $HOME for example, minus security sensitive files). It would be possible for the packager to turn off that access too and completely lock it down, turning off those interfaces and providing a fake $HOME etc. A good reason for the packager to not be Zoom Corp, but getting a distribution license might be tricky.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#156
post #96

Earlier quoted context omitted.

I assume this is your answer to "why would they lie?". It does not answer the question to why should an educational provider care though. And assuming I'll consider switching to webex the response to encryption in webex is this: https://www.webex.com/content/dam/Webex/eopi/Americas/USA/en... Which 404's and basically represents my experience with Cisco: "We don't give a shit about you, you already payed us.". Frankly…

In the general case, it’s bad practice to do business with liars. That’s one reason why an educational institution would care.

Correct, and if a Zoom representative would have lied to me that would factor into my decision. Frankly though, for student lectures and faculty meetings I don't care about their encryption (as long as they do TLS for client->server to protect my users in a public wifi situation) and a certain encryption level was never a basis for my decision. As long as they provide transport security I don't really care.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#157
post #3

Earlier quoted context omitted.

I think of it as a warning to future companies who take these kind of liberties...

The warning being that it doesn't matter because it doesn't affect their share price right? So far I haven't seen any tangible damage to them when it comes to $$.

Let's see where they are in 6 or 12 month's time and what they go through to get there.

Other nascent companies will tip their "We want to grow like Zoom" hat and it'll serve as a warning sign as to what the growth mentality is.

Anyway, my point was... I don't think they've taken too much grief yet, for what they've done. They deserve all the lumps they're getting, and that may (hopefully) be instructive.

[And yeah, there are always companies that do this kind of thing... some are Facebook, and some trip into a hole.]

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#158
post #116

Is it possible to use Zoom on Linux from an ordinary user without sudo rights?

I just downloaded their binary build and it worked without sudo (you need to run "ZoomLauncher" file). That being said, I did not get the impression of an easy to use app that "just works" (at least with my tiling window manager), things were confusing, clunky and rather idiosyncratic (e.g. sharing a screen was weird, and the whiteboard did not work).

Did you use it to talk to someone? I ran it too, but wanted to make sure it really works without being installed.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#159
post #100

Earlier quoted context omitted.

I agree. My SO ist currently studying from home due to the pandemic. A lot of professors and tutors use what they find first. There is no standard. She already had to use MS Teams, Slack, Jitsu and Zoom. Her take was that Zoom was by far the most usable tool. And most of her 20 years younger co-students agree. Sadly most people don't even know about the problematic status of Zoom. And if one tells them, most do not u…

The students are all forced to agree to these abusive third party TOS simply to receive the education to which they are entitled/for which they have already paid. That’s a bait and switch on the part of the university. “You’ve already paid, but now you have to give up your civil rights against this third party you’ve never heard of to get the service.” There should be liability for the schools for doing this. A class…

There's a pandemic, schools and professors try what they can to keep the courses running and not ruin their students' year, and your reaction is "sue them"?

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#160
post #103

Earlier quoted context omitted.

As I alluded to in another post I am from Germany and certain people I work with actually went through the "... they came for me" phase. Your point does not stand on its own.

Doesn’t Germany have specific data privacy laws based on the massive surveillance state that operated in the East up through 1990 or so? And you’re not concerned with using services that go through a country that, by all accounts, is trying to outdo the old Stasi with modern technology?

Zoom claims to be GDPR compliant (https://zoom.us/de-de/gdpr.html). Frankly, ensuring a company claims compliance is as far as I can go. I'm still hoping that if a company intentionally lies about this they will get sued out of existence. If I'm wrong about this the GDPR is worthless anyway and there isn't really anything I can do.
Post reply on HN