Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

81–90 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#81
post #6

"To make this possible, Free/Basic users seeking access to E2EE will participate in a one-time process that will prompt the user for additional pieces of information, such as verifying a phone number via a text message. Many leading companies perform similar steps on account creation to reduce the mass creation of abusive accounts." Perfect instrument to collect more personal data.

Their argument doesn't make sense. The objective behind verifying accounts is to prevent spammers creating lots of spam accounts and using those to spam. However, spammers rarely care if their spam is encrypted, so putting E2E behind verification won't do anything as far as spammers are concerned - they'll happily keep spamming using the unencrypted accounts. There's some other reason behind this that isn't about red…

If I recall from their previous statement, it's not about spammers, it's about people sharing child abuse photos.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#82
post #27

Earlier quoted context omitted.

Because of its inevitable ties and implicit subservience to the CCP.

The only "relevant" information found in the quote in the GP comment is the nationality of the CEO. How does one jump from the CEO's nationality to inevitable ties and implicit subservience to CCP?

ignoring the quote for a second we know a few things about this CEO and zoom.

1. zoom's application is sending data to Chinese servers separate from the application functionality servers.

2. the CEO is from china, I'm going to assume he has relatives in china.

3. we know CCP is a completely fucked up government with an absolutely horrible history of civil rights violations, genocide, etc.

I wouldn't put it past CCP to be pressuring the CEO by threatening relatives who live in china. this wouldn't be unheard of for CCP.

add the the unnecessary data transfer to chinese servers makes it look really bad.

its a fairly reasonable conclusion to draw that the CEO is compromised if all the above holds true.

more extreme conclusions could just as easily be drawn from that same data that he is literally a foreign agent for china.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#83
post #67

Earlier quoted context omitted.

That's factually untrue, it's not "known". To the contrary, you can pick the region for your servers, which presumably for 99% of people is precisely to avoid China: https://blog.zoom.us/wordpress/2020/04/13/coming-april-18-co...

There was a time when outside traffic routed through china. I believe zoom said it was a mistake. I'm not convinced that a setting alone should provide much confidence in terms of traffic routing considering that it can always be changed independent of what setting in the application you make.

> I believe zoom said it was a mistake.

Yes, zoom said it was unintentional.

For me, that's hard to believe. They weren't routing the call itself through China, they were just sending the encryption keys to a server in china. That seems pretty intentional. Even if they weren't routing the call through China from a user's perspective, their US server could still be sending the call data to China or recording the call for playback (from China) later. Their track record around security is so bad that I would stay as far away as possible.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#84
post #6

"To make this possible, Free/Basic users seeking access to E2EE will participate in a one-time process that will prompt the user for additional pieces of information, such as verifying a phone number via a text message. Many leading companies perform similar steps on account creation to reduce the mass creation of abusive accounts." Perfect instrument to collect more personal data.

First rule of HN commenting: Assume bad faith.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#85
post #35

Earlier quoted context omitted.

Unfortunately, I have to post this comment again, from just 3 days ago [1]. Also remember that Eric Yuan is an American citizen, not a Chinese citizen. He switched. Original comment: When will this meme die? Zoom is NOT a Chinese company. It is incorporated in and headquartered in the US. Like any American company ever, it follows US laws in the US, and local laws in other companies where it operates. End of story. Y…

Really? And which part of "local law" required Zoom to close accounts of US citizens in the US who weren't breaking any US Laws? https://news.sky.com/story/zoom-disables-accounts-of-chinese... >The suspension targeted Humanitarian China, an organisation based in the US, after it held a call with roughly 250 people, including a number who dialled in from China.

Zoom claimed they had to remove Chinese participants from the US-hosted meeting but didn't have the functionality to do that so (wrongly) banned the US hosts.

They said it was wrong to do, reinstated those accounts, and are building the functionality to enforce those Chinese laws without ever impacting users outside China.

That's from their blog. https://blog.zoom.us/wordpress/2020/06/11/improving-our-poli...

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#86
post #57

with closed source, hosted software E2EE is as much about trust as it is about technology since you can't verify its implementation. arguably, if trust is there, E2EE doesn't get you much anyway other than for scenarios where the company itself is breached. in any case, if the trust isn't there, you can't validate the E2EE, so your risk profile with regards to using the software doesn't change much.

You can verify closed source E2EE as long as you can inspect the traffic going client-server. The problem is that most E2EE apps allow auto-updating, so baking in something that transmits info to a third party is easy (but detectable with enough eyes on the code).

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#87

I commend Zoom for listening to the outcry over E2EE being limited to paid users. Between this move and their quick acknowledgement of mishandling the shutdown of accounts when asked by China, they're doing a better job than most of responding to criticism.

Agreed. I am always confused about the smackdown following a reversal from an arguably bad decision. We should be welcoming in hopes other companies note that being responsive is a good thing. Otherwise, it is just being stuck between rock and a hard place with no place to move.

What good are the apologies when they keep making new "mistakes"?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#89
Personally, I'm not feeling comfortable using Zoom on my PC. Just the other day, when opening the app, I was given a warning that the security certificate was untrusted and I would need to trust the certificate to proceed.

I tried updating the app and the same error occurred. Perhaps their cert had expired or it was some oversight but I'm done. I've removed Zoom.

Post reply on HN