Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

41–50 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#41

I commend Zoom for listening to the outcry over E2EE being limited to paid users. Between this move and their quick acknowledgement of mishandling the shutdown of accounts when asked by China, they're doing a better job than most of responding to criticism.

Agreed. I am always confused about the smackdown following a reversal from an arguably bad decision. We should be welcoming in hopes other companies note that being responsive is a good thing.

Otherwise, it is just being stuck between rock and a hard place with no place to move.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#42

Earlier quoted context omitted.

Wait, your point is that Zoom is evil because the founder is Chinese?

Yeah what the fuck, that was some weird casual racism you don't expect to see on HN.

I disagree it's "racism." It's how the CCP operates. We can say the same story for different super powers from previous times.

People suspected German Ambassador to USA for being a bosch spy.

Founder of a communications company isn't that far off. Huawei is a great example.

Founders of a company control the companies direction.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#44

Earlier quoted context omitted.

Unfortunately, I have to post this comment again, from just 3 days ago [1]. Also remember that Eric Yuan is an American citizen, not a Chinese citizen. He switched. Original comment: When will this meme die? Zoom is NOT a Chinese company. It is incorporated in and headquartered in the US. Like any American company ever, it follows US laws in the US, and local laws in other companies where it operates. End of story. Y…

How is it racist to suggest that Zoom has Chinese influences (seemingly not farfetched based on the equity ownership mentioned above and not at all disputed based on the technicality of Zoom being a US company)?

It is not racist to suggest that the Chinese government influences companies. It is racist to suggest that Chinese people are automatically predispositioned to certain actions.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#45

Earlier quoted context omitted.

Wait, your point is that Zoom is evil because the founder is Chinese?

While I understand that on the surface seems "bad", you have to understand the CCP taps into people worldwide, and while I don't know his position per se, or finances -- or connection with China today. It doesn't paint a great picture, especially with espionage and CCP tactics. Look at previous German and USA interference w/ GE, Bosch, -- it's the same story. Except now it's highlight as "bad" to point out that conne…

I'm disgusted that in 2020, Americans continue to use the same racist, unfounded smears againts people based on their ethnicity just as they did when they were throwing Japanese-Americans into internment camps.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#46
post #9

I'm quite frustrated they are calling this end to end. I can't find it now but a tweet earlier indicated that they have the keys and can help law enforcement with investigations which means it's can't be end to end.

It’s the new corporate offering of e2emitm

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#47
post #4

Super. Would be interesting to see how good it scales. 200 people in a town-hall meeting will be an interesting engineering challenge I would think.

Diffie–Hellman[0] is pretty cheap, you do it every time you visit a site with SSL enabled. Having the meeting leader do it 200 times to pass around a shared key generated on the client would be e2e and have minimal if any performance impact. There is probably a cleverer way to do it that I'm not aware of as well.

Edit: One issue is the client can run out of entropy but I think that would only happen on modern operating systems if you had hundreds of thousands of clients to negotiate with.

[0]https://en.m.wikipedia.org/wiki/Diffie%E2%80%93Hellman_key_e...

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#48
post #35

Earlier quoted context omitted.

Unfortunately, I have to post this comment again, from just 3 days ago [1]. Also remember that Eric Yuan is an American citizen, not a Chinese citizen. He switched. Original comment: When will this meme die? Zoom is NOT a Chinese company. It is incorporated in and headquartered in the US. Like any American company ever, it follows US laws in the US, and local laws in other companies where it operates. End of story. Y…

Really? And which part of "local law" required Zoom to close accounts of US citizens in the US who weren't breaking any US Laws? https://news.sky.com/story/zoom-disables-accounts-of-chinese... >The suspension targeted Humanitarian China, an organisation based in the US, after it held a call with roughly 250 people, including a number who dialled in from China.

Same reason why Google censored itself for China in 2006. Did people think Google was a 'Chinese company'? Note that this was before Google set up a presence in China.

http://news.bbc.co.uk/2/hi/technology/4645596.stm

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#50
post #6

"To make this possible, Free/Basic users seeking access to E2EE will participate in a one-time process that will prompt the user for additional pieces of information, such as verifying a phone number via a text message. Many leading companies perform similar steps on account creation to reduce the mass creation of abusive accounts." Perfect instrument to collect more personal data.

Their argument doesn't make sense.

The objective behind verifying accounts is to prevent spammers creating lots of spam accounts and using those to spam.

However, spammers rarely care if their spam is encrypted, so putting E2E behind verification won't do anything as far as spammers are concerned - they'll happily keep spamming using the unencrypted accounts.

There's some other reason behind this that isn't about reducing spam.

Post reply on HN