Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

21–30 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#21
post #6

"To make this possible, Free/Basic users seeking access to E2EE will participate in a one-time process that will prompt the user for additional pieces of information, such as verifying a phone number via a text message. Many leading companies perform similar steps on account creation to reduce the mass creation of abusive accounts." Perfect instrument to collect more personal data.

Zoom is evil. Also, fun note - just noticed Eric Yuan posted that and also created Zoom. https://en.wikipedia.org/wiki/Eric_Yuan Eric S. Yuan (Chinese: 袁征; pinyin: Yuán Zhēng; born 1970) is a Chinese-American billionaire businessman, and the CEO and founder of Zoom Video Communications, of which he owns 22%. No wonder why they have to play party with CCP.

Unfortunately, I have to post this comment again, from just 3 days ago [1]. Also remember that Eric Yuan is an American citizen, not a Chinese citizen. He switched. Original comment:

When will this meme die?

Zoom is NOT a Chinese company. It is incorporated in and headquartered in the US. Like any American company ever, it follows US laws in the US, and local laws in other companies where it operates. End of story.

Yes their culture certainly has stronger cultural internal ties to China, due to the number of Chinese employees, but what has that got to do with anything? At the end of the day, they're a public, profit-driven corporation trying to make lots of money across the entire world.

It's not like they're secretly and nefariously doing the CCP's bidding, which seems to be the veiled suggestion people keep making.

Seriously, every time someone brings up that Zoom is "really" a Chinese company, it comes across as borderline racism or conspiracy-mongering or both. And while I'd usually never comment on someone using a throwaway account, in this case when you're pushing these kinds of shady "stronger than the more-commonly-discussed" insituations, I think using a throwaway here is representative of exactly the kind of astroturfing that spreads malicious rumors without evidence.

[1] https://news.ycombinator.com/item?id=23510886

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#22

Earlier quoted context omitted.

Yes. The whole point of end-to-end encryption is that your data is safe even when it goes through untrusted servers. (I know they might have a backdoor, or might screw it up somehow. But in principle, if they do it securely, then this holds.)

Is it possible for Zoom / the CCP to hold the encryption keys? That would make it insecure, right? (genuine question).

It would, and apparently they do, don't want to spread rumors though, so take this with a grain of salt: https://news.ycombinator.com/item?id=23553453

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#23
I commend Zoom for listening to the outcry over E2EE being limited to paid users. Between this move and their quick acknowledgement of mishandling the shutdown of accounts when asked by China, they're doing a better job than most of responding to criticism.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#24

Earlier quoted context omitted.

Yes. The whole point of end-to-end encryption is that your data is safe even when it goes through untrusted servers. (I know they might have a backdoor, or might screw it up somehow. But in principle, if they do it securely, then this holds.)

Is it possible for Zoom / the CCP to hold the encryption keys? That would make it insecure, right? (genuine question).

Yes, if the keys are held in servers that they have access to then they would be able to decrypt the traffic and see what is happening. The whole point of e2e encryption is that only the 2 parties have the keys, Zoom are abusing this term and making people believe they are doing e2e

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#25
Zoom is primarily an enterprise product. They have chosen to have some form off verification to lower the amount of abuse on their platform.

If you want privacy you simply have to choose another product or service.

You aren't entitled to use their service without paying for it.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#26

Earlier quoted context omitted.

Yes. The whole point of end-to-end encryption is that your data is safe even when it goes through untrusted servers. (I know they might have a backdoor, or might screw it up somehow. But in principle, if they do it securely, then this holds.)

Is it possible for Zoom / the CCP to hold the encryption keys? That would make it insecure, right? (genuine question).

Yes

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#27

Earlier quoted context omitted.

Zoom is evil. Also, fun note - just noticed Eric Yuan posted that and also created Zoom. https://en.wikipedia.org/wiki/Eric_Yuan Eric S. Yuan (Chinese: 袁征; pinyin: Yuán Zhēng; born 1970) is a Chinese-American billionaire businessman, and the CEO and founder of Zoom Video Communications, of which he owns 22%. No wonder why they have to play party with CCP.

Wait, your point is that Zoom is evil because the founder is Chinese?

Because of its inevitable ties and implicit subservience to the CCP.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#28
post #16

Has Zoom ever had their application(s) audited for security? Without an independent, external audit I don't know why they should be trusted that they've actually done e2e completely or correctly.

Any E2E implementation is worthless if the service provider controls the keys and doesn't allow the user to verify it (or alerts the user in the event of a key changing). Otherwise the service provider can simply swap the keys when they want to eavesdrop on someone and the users would be none the wiser. I don't believe that zoom has such measures, so any audit into whether E2E was implemented properly is pointless.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#29

Earlier quoted context omitted.

Zoom is evil. Also, fun note - just noticed Eric Yuan posted that and also created Zoom. https://en.wikipedia.org/wiki/Eric_Yuan Eric S. Yuan (Chinese: 袁征; pinyin: Yuán Zhēng; born 1970) is a Chinese-American billionaire businessman, and the CEO and founder of Zoom Video Communications, of which he owns 22%. No wonder why they have to play party with CCP.

Unfortunately, I have to post this comment again, from just 3 days ago [1]. Also remember that Eric Yuan is an American citizen, not a Chinese citizen. He switched. Original comment: When will this meme die? Zoom is NOT a Chinese company. It is incorporated in and headquartered in the US. Like any American company ever, it follows US laws in the US, and local laws in other companies where it operates. End of story. Y…

> Yes their culture certainly has stronger cultural internal ties to China, due to the number of Chinese employees, but what has that got to do with anything?

A lot.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#30
post #7

It’s still only opt-in. Users have to submit an application (including text message verification and other personal info) to gain access to E2E encryption. Zoom has shown that it does not care about privacy.

Well to be fair if it was enabled by default it would break dial in (with traditional telephone) support as E2E doesn’t allow for that. This is a reason why even some large paying organisations haven’t enabled E2E
Post reply on HN