Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

61–70 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#61

This is the same company that said that it "won't encrypt free calls so it can work more with law enforcement"[1]. I'd stay away. [1]: https://news.ycombinator.com/item?id=23399924

This blog post specifically says that it's a walk-back of the policy announced in your link.

If working with law enforcement was to important to them why did they backtrack so quickly. Seems suspicious at best.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#62

Earlier quoted context omitted.

Yeah what the fuck, that was some weird casual racism you don't expect to see on HN.

I disagree it's "racism." It's how the CCP operates. We can say the same story for different super powers from previous times. People suspected German Ambassador to USA for being a bosch spy. Founder of a communications company isn't that far off. Huawei is a great example. Founders of a company control the companies direction.

Except Eric is not any sort of govt or party representative.

He is a naturalized American of Chinese ancestry.

In history, this kind of scapegoating was counterproductive.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#63
Good to see they're listening and customers are able to bring some accountability here. But it still seems like their heart isn't really in this move.

At work we have been looking at two fantastic "indie" alternatives:

https://whereby.com

https://team.video

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#64
post #44

Earlier quoted context omitted.

How is it racist to suggest that Zoom has Chinese influences (seemingly not farfetched based on the equity ownership mentioned above and not at all disputed based on the technicality of Zoom being a US company)?

It is not racist to suggest that the Chinese government influences companies. It is racist to suggest that Chinese people are automatically predispositioned to certain actions.

Fair enough and I don't think anyone here will find that statement controversial. I think what bothers me in some of the dialogue here is what I perceive as an attempt to play "hide the ball" by pretending that CCP interests don't run counter to the interests of liberal democracies by labeling raised concerns as racist. No one framed anything in racial terms to begin with so I don't see why it needs to be placed in that context.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#65
post #27

Earlier quoted context omitted.

Because of its inevitable ties and implicit subservience to the CCP.

The only "relevant" information found in the quote in the GP comment is the nationality of the CEO. How does one jump from the CEO's nationality to inevitable ties and implicit subservience to CCP?

Nationality is not a race. Nationality implies a connection with a specific country. And when that specific country is a vast wasteland for human rights and privacy and civil liberties, then yes, it’s relevant.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#66
post #6

"To make this possible, Free/Basic users seeking access to E2EE will participate in a one-time process that will prompt the user for additional pieces of information, such as verifying a phone number via a text message. Many leading companies perform similar steps on account creation to reduce the mass creation of abusive accounts." Perfect instrument to collect more personal data.

You also signed up an account for banks, they collect a ton of data on all your payments, got a problem with that? You gonna say yeah Zoom is not a bank, but your prose is the data collection part

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#67

Does end to end encryption help when it's known that much of the traffic is routed through China? Genuine question.

That's factually untrue, it's not "known". To the contrary, you can pick the region for your servers, which presumably for 99% of people is precisely to avoid China: https://blog.zoom.us/wordpress/2020/04/13/coming-april-18-co...

There was a time when outside traffic routed through china. I believe zoom said it was a mistake.

I'm not convinced that a setting alone should provide much confidence in terms of traffic routing considering that it can always be changed independent of what setting in the application you make.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#68

Earlier quoted context omitted.

Yeah what the fuck, that was some weird casual racism you don't expect to see on HN.

I disagree it's "racism." It's how the CCP operates. We can say the same story for different super powers from previous times. People suspected German Ambassador to USA for being a bosch spy. Founder of a communications company isn't that far off. Huawei is a great example. Founders of a company control the companies direction.

Which German ambassador are you talking about?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#69
To anyone who likes to argue Zoom is a US company, I'm sorry but that argument holds no water for me after this [1]:

> The statement raises questions about Zoom bowing to Chinese pressure. Unlike many Western social media platforms, it is not blocked in China. The company did not explain under what law the meetings – which were hosted outside mainland China – were deemed to be illegal.

For meetings outside of China where the Chinese government should have no jurisdiction, Zoom choose to cooperate.

Some obvious follow-up questions:

1. Where will the keys be stored? On servers in China or elsewhere? Will it depend on where the account holders are? Or are the private keys truly local?

2. What safeguards are in place to prevent further "cooperation" with Beijing in relation to supposedly encrypted traffic?

3. Zoom is not blocked in China, which is pretty rare for a supposedly US-based company. What concessions did they make to get this exemption?

4. Under what circumstances will any of your data be stored in, routed through or otherwise be accessible in mainland China?

Given China's philosophy that Chinese companies are nothing more than extensions of the state, these are entirely reasonable questions to ask. Were I the decision maker for any large company or government organization, I personally would consider use of Zoom to be too much of a security risk. And I don't think that's the slightest bit alarmist.

[1]: https://www.theguardian.com/world/2020/jun/12/zoom-admits-cu...

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#70
post #24

Earlier quoted context omitted.

Is it possible for Zoom / the CCP to hold the encryption keys? That would make it insecure, right? (genuine question).

Yes, if the keys are held in servers that they have access to then they would be able to decrypt the traffic and see what is happening. The whole point of e2e encryption is that only the 2 parties have the keys, Zoom are abusing this term and making people believe they are doing e2e

What makes you think they're abusing the term? Did you read their whitepaper?

https://github.com/zoom/zoom-e2e-whitepaper

Post reply on HN