always wondered why zoom.us url not zoom.com which they both own. it's basically to give the perception it's US company and assumed trustworthy.
Zoom rolled their own encryption scheme, transmit keys through servers in China
191–200 of 316 posts
Re: Zoom rolled their own encryption scheme, transmit keys through servers in China
#192Earlier quoted context omitted.
Doesn’t Germany have specific data privacy laws based on the massive surveillance state that operated in the East up through 1990 or so? And you’re not concerned with using services that go through a country that, by all accounts, is trying to outdo the old Stasi with modern technology?
Zoom claims to be GDPR compliant ( https://zoom.us/de-de/gdpr.html ). Frankly, ensuring a company claims compliance is as far as I can go. I'm still hoping that if a company intentionally lies about this they will get sued out of existence. If I'm wrong about this the GDPR is worthless anyway and there isn't really anything I can do.
Re: Zoom rolled their own encryption scheme, transmit keys through servers in China
#193"China" is a threat not a vulnerability is all I meant, and using it for hype-training seems dishonest.
I've had meetings with people in different companies using webex,goto meeting,skype , zoom,teams and hangouts. I found hangouts to be the most worrysome with regards to privacy (not security). A lot of the issues that keep popping up about zoom this week might also apply to the others (looking at you webex!).
Zoom became popular because you can see everyone's video all at once. They had a betterr product. Vulnerabilities don't make a product bad, how you handle them does! If anything, I would like someone to show me how the free security audit zoom received by the hype crowd this week does not make it a superior alternative (provided they continue patching it).
Re: Zoom rolled their own encryption scheme, transmit keys through servers in China
#194Earlier quoted context omitted.
But it does increase the entropy per byte, thus making patterns harder to spot.
....so your argument us to hope an adversary only sees part of your video and not all of it?
Re: Zoom rolled their own encryption scheme, transmit keys through servers in China
#195Earlier quoted context omitted.
The point is that any pattern in the plaintxt data shows up in encrypted data if you use AES-ECB. Compression does not introdoce entropy to a stream. So assuming that saying the stream is compressed and calling it good is a very bad idea. Please refer to Shannon's source coding theorem. If anything, compression reduces the entropy in the information.
> The point is that any pattern in the plaintxt data shows up in encrypted data if you use AES-ECB. No, that's false. ECB reveals repeating plaintext blocks. "F0123456789ABCDEF0123456789ABCDEF" contains a repeating block-length sequence, but would encrypt to three distinct blocks under ECB, because the sequence is not aligned to a block boundary.
That by definition is saying any pattern in plaintext shows up in cipher text
Re: Zoom rolled their own encryption scheme, transmit keys through servers in China
#196Earlier quoted context omitted.
The point is that any pattern in the plaintxt data shows up in encrypted data if you use AES-ECB. Compression does not introdoce entropy to a stream. So assuming that saying the stream is compressed and calling it good is a very bad idea. Please refer to Shannon's source coding theorem. If anything, compression reduces the entropy in the information.
I think you may want to look closer at Shannon’s source coding theorem; The Shannon entropy of the output of a compression algorithm will be higher than the entropy of the source as identifiable patterns are eliminated. Otherwise the theorem would trivially contradict itself.
Re: Zoom rolled their own encryption scheme, transmit keys through servers in China
#197Earlier quoted context omitted.
....so your argument us to hope an adversary only sees part of your video and not all of it?
No, their argument is that if you have a higher entropy per byte, there will be more variation in the aligned 16-byte chunks that are relevant for attacking AES-128-ECB. This reduces the probability of the attacker being able to find equal blocks.
If I am encrypting something, I only want to depend on the strength of the encryption. I don't want to hope that something else ensures that an adversary cannot figure out my ciohertext. That is a very bad idea.
Re: Zoom rolled their own encryption scheme, transmit keys through servers in China
#198Earlier quoted context omitted.
This is a great article, but as an educational provider it fails to answer one question: Why should I care? The only concerning thing for me is, why would they lie about using AES-256 when none of my users (and I assume most of their users) would care in any way about AES-256 vs. AES-128 in ECB mode. Why would they lie? Even after this, having my users conducting university lessons over something that might be decryp…
Lets say these lessons are a politics seminar discussing whatever PRC finds objectionable, then family of the student back in the old country get their social credit score deducted. Or even better use those recording in the future as compromat as needed.
Re: Zoom rolled their own encryption scheme, transmit keys through servers in China
#199Earlier quoted context omitted.
Lets say these lessons are a politics seminar discussing whatever PRC finds objectionable, then family of the student back in the old country get their social credit score deducted. Or even better use those recording in the future as compromat as needed.
I don't know how much free time they have over there, but snooping in on courses that a relative outside the country is taking and storing all of them... I mean, if you want to peg someone's social credit score, just stakeout their house and wait for them to spit outside or something. Hell, just make something up and dare them to come argue. Why go to all that effort?
Re: Zoom rolled their own encryption scheme, transmit keys through servers in China
#200Earlier quoted context omitted.
I mean, isn't this stuff they can fix? Like good that the market is stressing them on their security, at $30bn they should be able to engage with that feedback and then loop. On the other hand, tried to use Skype lately? Product has barely evolved since they were bought out by MSFT. Guess google does videoconferencing too, but they know enough about us all already....
It’ll take a new CEO before people will trust them again, kind of like what happened at Uber.
Such a strangely extreme viewpoint to suddenly jump to.