Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

71–80 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#72
post #9

I'm quite frustrated they are calling this end to end. I can't find it now but a tweet earlier indicated that they have the keys and can help law enforcement with investigations which means it's can't be end to end.

It’s the new corporate offering of e2emitm

or rather, e2e2e

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#73
post #35

Earlier quoted context omitted.

Really? And which part of "local law" required Zoom to close accounts of US citizens in the US who weren't breaking any US Laws? https://news.sky.com/story/zoom-disables-accounts-of-chinese... >The suspension targeted Humanitarian China, an organisation based in the US, after it held a call with roughly 250 people, including a number who dialled in from China.

Same reason why Google censored itself for China in 2006. Did people think Google was a 'Chinese company'? Note that this was before Google set up a presence in China. http://news.bbc.co.uk/2/hi/technology/4645596.stm

I don't see how it's the same. In Zoom's case organization was in US and call organization was in US and company works by US laws. Why would they censor these accounts? Google on the other hand had to do it to operate in China, had to submit to Chinese regulations.

The same would be if they blocked Gmail of US citizens because of discussions related to China.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#74
post #7

It’s still only opt-in. Users have to submit an application (including text message verification and other personal info) to gain access to E2E encryption. Zoom has shown that it does not care about privacy.

Well to be fair if it was enabled by default it would break dial in (with traditional telephone) support as E2E doesn’t allow for that. This is a reason why even some large paying organisations haven’t enabled E2E

Agreed, to rephrase my concern: By default accounts don’t even have the option to enable E2E encryption in a meeting. There’s no button to press that will turn on encryption if nobody’s dialing in. Your user account has to go through a separate review process to get the “privilege” of encrypting your meeting.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#75

Earlier quoted context omitted.

Is it possible for Zoom / the CCP to hold the encryption keys? That would make it insecure, right? (genuine question).

If implemented correctly, the server doesn’t get the key. Look up Diffie–Hellman key exchange for more information on how this is possible. This can be verified by auditing the client so you don’t need to trust Zoom.

What do you mean by auditing the client... Like audit the source code or something that we could do independent of the source code? (serious question)

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#76
post #57

with closed source, hosted software E2EE is as much about trust as it is about technology since you can't verify its implementation. arguably, if trust is there, E2EE doesn't get you much anyway other than for scenarios where the company itself is breached. in any case, if the trust isn't there, you can't validate the E2EE, so your risk profile with regards to using the software doesn't change much.

Apple FaceTime is also closed source, E2E and verifiable

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#77
post #35

Earlier quoted context omitted.

Really? And which part of "local law" required Zoom to close accounts of US citizens in the US who weren't breaking any US Laws? https://news.sky.com/story/zoom-disables-accounts-of-chinese... >The suspension targeted Humanitarian China, an organisation based in the US, after it held a call with roughly 250 people, including a number who dialled in from China.

Same reason why Google censored itself for China in 2006. Did people think Google was a 'Chinese company'? Note that this was before Google set up a presence in China. http://news.bbc.co.uk/2/hi/technology/4645596.stm

I think you're missing the point. Google censored itself in china based on Chinese requests. Zoom censored itself in the US based on Chinese requests.

There's a pretty big difference IMO.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#78
post #66
post #6

"To make this possible, Free/Basic users seeking access to E2EE will participate in a one-time process that will prompt the user for additional pieces of information, such as verifying a phone number via a text message. Many leading companies perform similar steps on account creation to reduce the mass creation of abusive accounts." Perfect instrument to collect more personal data.

You also signed up an account for banks, they collect a ton of data on all your payments, got a problem with that? You gonna say yeah Zoom is not a bank, but your prose is the data collection part

> Why care about privacy in one area when this completely unrelated area does it worse?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#79
post #6

"To make this possible, Free/Basic users seeking access to E2EE will participate in a one-time process that will prompt the user for additional pieces of information, such as verifying a phone number via a text message. Many leading companies perform similar steps on account creation to reduce the mass creation of abusive accounts." Perfect instrument to collect more personal data.

Their argument doesn't make sense. The objective behind verifying accounts is to prevent spammers creating lots of spam accounts and using those to spam. However, spammers rarely care if their spam is encrypted, so putting E2E behind verification won't do anything as far as spammers are concerned - they'll happily keep spamming using the unencrypted accounts. There's some other reason behind this that isn't about red…

I think their concern is paedophile rings using large group E2EE for live child abuse with completely anonymous accounts.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#80

Earlier quoted context omitted.

Is it possible for Zoom / the CCP to hold the encryption keys? That would make it insecure, right? (genuine question).

If implemented correctly, the server doesn’t get the key. Look up Diffie–Hellman key exchange for more information on how this is possible. This can be verified by auditing the client so you don’t need to trust Zoom.

This is true, but they are going to help law enforcement with calls that have bad content in them, the only way this can happen is if they have the ability to decrypt the streams or enter calls silently and get the keys.

Edit: Sorry for coming across a little brash, I'm quite a strong advocate of real encryption and this kind dilution of terms makes my blood boil because terms are being diluted and people have trust in something that betrays them.

Post reply on HN