I'm quite frustrated they are calling this end to end. I can't find it now but a tweet earlier indicated that they have the keys and can help law enforcement with investigations which means it's can't be end to end.
It’s the new corporate offering of e2emitm
Zoom to bring end-to-end encryption to all users, including non-paying
91–100 of 557 posts
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#92"To make this possible, Free/Basic users seeking access to E2EE will participate in a one-time process that will prompt the user for additional pieces of information, such as verifying a phone number via a text message. Many leading companies perform similar steps on account creation to reduce the mass creation of abusive accounts." Perfect instrument to collect more personal data.
You also signed up an account for banks, they collect a ton of data on all your payments, got a problem with that? You gonna say yeah Zoom is not a bank, but your prose is the data collection part
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#931. Pre-COVID Zoom claims it has E2E encryption for everyone.
2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate.
3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers.
4. Zoom gets another wave of criticism for restricting its new E2E encryption service so it walks back to its original message that all accounts get E2E encryption.
Given their track record I’d expect this timeline to repeat itself so after they release this E2E encryption feature, security researchers will discover that it’s not true E2E encryption again.
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#94"To make this possible, Free/Basic users seeking access to E2EE will participate in a one-time process that will prompt the user for additional pieces of information, such as verifying a phone number via a text message. Many leading companies perform similar steps on account creation to reduce the mass creation of abusive accounts." Perfect instrument to collect more personal data.
First rule of HN commenting: Assume bad faith.
I believe Zoomed has earned the privilege of folks being highly skeptical of their actions / motivations.
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#95Earlier quoted context omitted.
Yeah what the fuck, that was some weird casual racism you don't expect to see on HN.
I disagree it's "racism." It's how the CCP operates. We can say the same story for different super powers from previous times. People suspected German Ambassador to USA for being a bosch spy. Founder of a communications company isn't that far off. Huawei is a great example. Founders of a company control the companies direction.
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#96Earlier quoted context omitted.
Their argument doesn't make sense. The objective behind verifying accounts is to prevent spammers creating lots of spam accounts and using those to spam. However, spammers rarely care if their spam is encrypted, so putting E2E behind verification won't do anything as far as spammers are concerned - they'll happily keep spamming using the unencrypted accounts. There's some other reason behind this that isn't about red…
I think their concern is paedophile rings using large group E2EE for live child abuse with completely anonymous accounts.
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#97Earlier quoted context omitted.
Unfortunately, I have to post this comment again, from just 3 days ago [1]. Also remember that Eric Yuan is an American citizen, not a Chinese citizen. He switched. Original comment: When will this meme die? Zoom is NOT a Chinese company. It is incorporated in and headquartered in the US. Like any American company ever, it follows US laws in the US, and local laws in other companies where it operates. End of story. Y…
Really? And which part of "local law" required Zoom to close accounts of US citizens in the US who weren't breaking any US Laws? https://news.sky.com/story/zoom-disables-accounts-of-chinese... >The suspension targeted Humanitarian China, an organisation based in the US, after it held a call with roughly 250 people, including a number who dialled in from China.
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#98I may need to install one of those open source substitute wannabes. It didn't have to be that way....
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#99Re: Zoom to bring end-to-end encryption to all users, including non-paying
#100Earlier quoted context omitted.
Their argument doesn't make sense. The objective behind verifying accounts is to prevent spammers creating lots of spam accounts and using those to spam. However, spammers rarely care if their spam is encrypted, so putting E2E behind verification won't do anything as far as spammers are concerned - they'll happily keep spamming using the unencrypted accounts. There's some other reason behind this that isn't about red…
I think their concern is paedophile rings using large group E2EE for live child abuse with completely anonymous accounts.
I know this argument is often quickly dismissed on HN since people see child abuse or 'going dark' as an easy excuse for the government to leverage to get more control (and it has been used for this), but that doesn't mean the problem isn't serious or doesn't exist.
See this: https://www.nytimes.com/interactive/2019/09/28/us/child-sex-...
The resources fighting this are relatively small in comparison the scale of the problem: https://www.freethink.com/videos/child-exploitation
The people carrying out the abuse are sophisticated.
I have a friend that works at WhatsApp and their entire team is focused on trying to remove groups that exist to share child abuse imagery (via metadata since content is encrypted).
I fall on the side that secure encryption is critical for all of the reasons that technical people normally argue that it's critical and breaking it doesn't work/is a bad idea, but I also understand and empathize with the difficulty encryption by default causes for the organizations fighting this abuse.
That said, I have serious disagreements with Zoom unrelated to this particular e2ee issue (https://zalberico.com/essay/2020/06/13/zoom-in-china.html), I think they don't actually care about protecting the speech of their users or securing content from authoritarian governments. It's still good to avoid them for that reason alone.