Live data from Hacker News

Zoom rolled their own encryption scheme, transmit keys through servers in China

citizenlab.ca

191–200 of 316 posts

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#192
post #160

Earlier quoted context omitted.

Doesn’t Germany have specific data privacy laws based on the massive surveillance state that operated in the East up through 1990 or so? And you’re not concerned with using services that go through a country that, by all accounts, is trying to outdo the old Stasi with modern technology?

Zoom claims to be GDPR compliant ( https://zoom.us/de-de/gdpr.html ). Frankly, ensuring a company claims compliance is as far as I can go. I'm still hoping that if a company intentionally lies about this they will get sued out of existence. If I'm wrong about this the GDPR is worthless anyway and there isn't really anything I can do.

If you’re not especially worried about having a communist police state intercept your private conversations, that’s your personal business. All I can ask is that you don’t go out of your way trying to legitimize that for everyone else as you have here.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#193
Just a pet-peeve here: I am well aware if the CCP and how they run things in China as well as their hostilities against the west. But sending traffic or anything to or through China in itself is not a security risk. If the data goes through the US and you are european, whatever protocol weakness exists should also worry you because of possible network and server-side adversaries in the US.

"China" is a threat not a vulnerability is all I meant, and using it for hype-training seems dishonest.

I've had meetings with people in different companies using webex,goto meeting,skype , zoom,teams and hangouts. I found hangouts to be the most worrysome with regards to privacy (not security). A lot of the issues that keep popping up about zoom this week might also apply to the others (looking at you webex!).

Zoom became popular because you can see everyone's video all at once. They had a betterr product. Vulnerabilities don't make a product bad, how you handle them does! If anything, I would like someone to show me how the free security audit zoom received by the hype crowd this week does not make it a superior alternative (provided they continue patching it).

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#194
post #108

Earlier quoted context omitted.

But it does increase the entropy per byte, thus making patterns harder to spot.

....so your argument us to hope an adversary only sees part of your video and not all of it?

No, their argument is that if you have a higher entropy per byte, there will be more variation in the aligned 16-byte chunks that are relevant for attacking AES-128-ECB. This reduces the probability of the attacker being able to find equal blocks.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#195
post #86

Earlier quoted context omitted.

The point is that any pattern in the plaintxt data shows up in encrypted data if you use AES-ECB. Compression does not introdoce entropy to a stream. So assuming that saying the stream is compressed and calling it good is a very bad idea. Please refer to Shannon's source coding theorem. If anything, compression reduces the entropy in the information.

> The point is that any pattern in the plaintxt data shows up in encrypted data if you use AES-ECB. No, that's false. ECB reveals repeating plaintext blocks. "F0123456789ABCDEF0123456789ABCDEF" contains a repeating block-length sequence, but would encrypt to three distinct blocks under ECB, because the sequence is not aligned to a block boundary.

> ECB reveals repeating plaintext blocks.

That by definition is saying any pattern in plaintext shows up in cipher text

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#196
post #86

Earlier quoted context omitted.

The point is that any pattern in the plaintxt data shows up in encrypted data if you use AES-ECB. Compression does not introdoce entropy to a stream. So assuming that saying the stream is compressed and calling it good is a very bad idea. Please refer to Shannon's source coding theorem. If anything, compression reduces the entropy in the information.

I think you may want to look closer at Shannon’s source coding theorem; The Shannon entropy of the output of a compression algorithm will be higher than the entropy of the source as identifiable patterns are eliminated. Otherwise the theorem would trivially contradict itself.

Shannon's source coding theorn says that the entropy in a compressed information is at most the entropy of the uncompressed information. If you add entropy to a compressed algorithm, you are by definition adding noise to the SNR of a signal.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#197
post #108

Earlier quoted context omitted.

....so your argument us to hope an adversary only sees part of your video and not all of it?

No, their argument is that if you have a higher entropy per byte, there will be more variation in the aligned 16-byte chunks that are relevant for attacking AES-128-ECB. This reduces the probability of the attacker being able to find equal blocks.

And my argument is if I know the video encoding and compression sequence, I wouldn't depend on AES-ECB. I know the patterns that show up.

If I am encrypting something, I only want to depend on the strength of the encryption. I don't want to hope that something else ensures that an adversary cannot figure out my ciohertext. That is a very bad idea.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#198
post #190
post #63

Earlier quoted context omitted.

This is a great article, but as an educational provider it fails to answer one question: Why should I care? The only concerning thing for me is, why would they lie about using AES-256 when none of my users (and I assume most of their users) would care in any way about AES-256 vs. AES-128 in ECB mode. Why would they lie? Even after this, having my users conducting university lessons over something that might be decryp…

Lets say these lessons are a politics seminar discussing whatever PRC finds objectionable, then family of the student back in the old country get their social credit score deducted. Or even better use those recording in the future as compromat as needed.

I don't know how much free time they have over there, but snooping in on courses that a relative outside the country is taking and storing all of them... I mean, if you want to peg someone's social credit score, just stakeout their house and wait for them to spit outside or something. Hell, just make something up and dare them to come argue. Why go to all that effort?

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#199
post #198
post #190

Earlier quoted context omitted.

Lets say these lessons are a politics seminar discussing whatever PRC finds objectionable, then family of the student back in the old country get their social credit score deducted. Or even better use those recording in the future as compromat as needed.

I don't know how much free time they have over there, but snooping in on courses that a relative outside the country is taking and storing all of them... I mean, if you want to peg someone's social credit score, just stakeout their house and wait for them to spit outside or something. Hell, just make something up and dare them to come argue. Why go to all that effort?

Doesnt go exactly like that. More like: CCTV captures someone going to an area where known rebels or political activists live. (Look up videos on chinas face recognition, its insane.) Police decide to look through the person's zoom meeting transcripts, making a search on certain keywords. They find evidence of rebellious activities, and order further surveillance on the individual or arrest them.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#200

Earlier quoted context omitted.

I mean, isn't this stuff they can fix? Like good that the market is stressing them on their security, at $30bn they should be able to engage with that feedback and then loop. On the other hand, tried to use Skype lately? Product has barely evolved since they were bought out by MSFT. Guess google does videoconferencing too, but they know enough about us all already....

It’ll take a new CEO before people will trust them again, kind of like what happened at Uber.

Who are you hoping picks up this little unit of opinion? Are you hoping to see it quoted, or just vaguely referred to as "growing discontent" and know that you were in there?

Such a strangely extreme viewpoint to suddenly jump to.

Post reply on HN