Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

51–60 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#51

This is the same company that said that it "won't encrypt free calls so it can work more with law enforcement"[1]. I'd stay away. [1]: https://news.ycombinator.com/item?id=23399924

This blog post specifically says that it's a walk-back of the policy announced in your link.

My read on this is that they found a way to backdoor all supposedly E2E-encrypted calls and legal compliance is no longer a problem for them. Perhaps I’m being too cynical.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#54

Earlier quoted context omitted.

Yes. The whole point of end-to-end encryption is that your data is safe even when it goes through untrusted servers. (I know they might have a backdoor, or might screw it up somehow. But in principle, if they do it securely, then this holds.)

Is it possible for Zoom / the CCP to hold the encryption keys? That would make it insecure, right? (genuine question).

If implemented correctly, the server doesn’t get the key. Look up Diffie–Hellman key exchange for more information on how this is possible. This can be verified by auditing the client so you don’t need to trust Zoom.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#55
As long as zoom is closed source from end to end, they could pretend to use quantum entanglement over IP, for all I care.

I still use it, don't get me wrong. My threat model for the use case that I make of zoom does not need strong encryption, only being script kiddies proof.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#56
post #27

Earlier quoted context omitted.

Because of its inevitable ties and implicit subservience to the CCP.

The only "relevant" information found in the quote in the GP comment is the nationality of the CEO. How does one jump from the CEO's nationality to inevitable ties and implicit subservience to CCP?

[deleted]

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#57
with closed source, hosted software E2EE is as much about trust as it is about technology since you can't verify its implementation. arguably, if trust is there, E2EE doesn't get you much anyway other than for scenarios where the company itself is breached.

in any case, if the trust isn't there, you can't validate the E2EE, so your risk profile with regards to using the software doesn't change much.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#58
Aside from whatever the Zoom news story of the day is, it's completely unsurprising that they're eating WebEx's lunch. I just tried scheduling a meeting and it was outrageously bad.

The bright green "Start" and "Schedule Meeting" buttons just pop up an error. The correct button to progress is the dark grey (as if disabled) "Next" button.

It prompts me to create a "personal conference number", whatever that is. This errors and tells that I need set a PIN in my preferences. I search for the preferences for a while and eventually find that I _do_ have a host PIN set...

At this point I gave up.

Gripes on the participant side: Why does it ask me to provide my name in the browser when joining a meeting before launching the app which already knows my name? Why do I have to manually press the refresh button to discover scheduled meetings?

Cisco pulled a Boeing with the development of one of their crown jewels, and Zoom swooped in, even with shady practices, and snatched up significant market share.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#59
post #7

It’s still only opt-in. Users have to submit an application (including text message verification and other personal info) to gain access to E2E encryption. Zoom has shown that it does not care about privacy.

Well to be fair if it was enabled by default it would break dial in (with traditional telephone) support as E2E doesn’t allow for that. This is a reason why even some large paying organisations haven’t enabled E2E

Why can't that be the opt-in part?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#60

Earlier quoted context omitted.

Wait, your point is that Zoom is evil because the founder is Chinese?

Yeah what the fuck, that was some weird casual racism you don't expect to see on HN.

Chinese is also a nationality and that does have relevance if the person has ties to Beijing and the CCP. If the founder were Russian and had ties to Moscow would we be complaining about “casual racism?” It’s racist to suggest racism when a Chinese is involved when similar accusations wouldn’t have been made if the situation were Russian.
Post reply on HN