Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

101–110 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#101

Earlier quoted context omitted.

Agreed. I am always confused about the smackdown following a reversal from an arguably bad decision. We should be welcoming in hopes other companies note that being responsive is a good thing. Otherwise, it is just being stuck between rock and a hard place with no place to move.

What good are the apologies when they keep making new "mistakes"?

I would argue that it is harder on us as it requires engagement and being a conscious customer.

Sadly, it is not really new. Companies will typically attempt to extract maximum amount of milk with minimum amount of moo. If they keep making mistakes, we need to keep making noise.

Not fun, but someone has to do it.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#102
post #7

It’s still only opt-in. Users have to submit an application (including text message verification and other personal info) to gain access to E2E encryption. Zoom has shown that it does not care about privacy.

Isn't it fair to say that this brings Zoom more-or-less exactly in line with the privacy vs law enforcement balance of a normal telephone call?

Writing from the UK, I'm reasonably sure that (a) all my phone calls are not recorded and (b) the phone number and duration of every call absolutely is recorded (this has to be shown on your phone bill!) and is available to the police when needed.

Speculating further, with the right court orders / warrants the normal E2E encryption algorithm for a particular user could be replaced with a "law enforcement decryptable" one and, hey presto, it's a Zoom equivalent of a proportionate wiretap that only covers future calls. Certainly a lot better than encrypting the calls of all users with such an algorithm "just in case".

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#103
post #6

"To make this possible, Free/Basic users seeking access to E2EE will participate in a one-time process that will prompt the user for additional pieces of information, such as verifying a phone number via a text message. Many leading companies perform similar steps on account creation to reduce the mass creation of abusive accounts." Perfect instrument to collect more personal data.

Is there any E2EE app that doesn't require verification? Whatsapp does. Even Signal requires a phone number.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#104
post #57

with closed source, hosted software E2EE is as much about trust as it is about technology since you can't verify its implementation. arguably, if trust is there, E2EE doesn't get you much anyway other than for scenarios where the company itself is breached. in any case, if the trust isn't there, you can't validate the E2EE, so your risk profile with regards to using the software doesn't change much.

You can verify closed source E2EE as long as you can inspect the traffic going client-server. The problem is that most E2EE apps allow auto-updating, so baking in something that transmits info to a third party is easy (but detectable with enough eyes on the code).

But what's stopping the software from, say, having a backdoor that is only exposed under certain conditions? For example, if you are under an FBI investigation. I suppose you could automate the verification on a per-call basis. Unfortunately, every bit over the wire would need to be seen by a fool-proof algorithm to ensure your safety. Seems not tractable.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#105

Aside from whatever the Zoom news story of the day is, it's completely unsurprising that they're eating WebEx's lunch. I just tried scheduling a meeting and it was outrageously bad. The bright green "Start" and "Schedule Meeting" buttons just pop up an error. The correct button to progress is the dark grey (as if disabled) "Next" button. It prompts me to create a "personal conference number", whatever that is. This e…

I think Cisco bought webex largely because Cisco's big expensive conferencing hardware / software were under threat and they wanted in on what would replace it.

Cisco itself has time and again bought its way into things that aren't their core competency and they fumble around with them.

They bought Flip video for 590 million years ago, despite the fact that every person in Cisco's office had a smart phone in their pocket that would render it relatively useless...

I think video conferencing applications are often doomed to turn into behemoth messes for some reason that I can't figure out.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#106

This is the same company that said that it "won't encrypt free calls so it can work more with law enforcement"[1]. I'd stay away. [1]: https://news.ycombinator.com/item?id=23399924

This blog post specifically says that it's a walk-back of the policy announced in your link.

Why trust any company that put out the initial policy in the first place?

Have they had a fundamental turnover in management, indicating a new pro-privacy culture? Did they move their development out from under the thumb of the CCP?

No and no?

So what’s changed?

If they weren’t trustworthy before, they certainly aren’t now.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#108

I've got to wonder who wants their e-to-e connection to root through servers physically in China. Zoom seems to be a poster child for the surveillance state.

What does this even mean? E2e is specifically designed to address this problem.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#109
post #35

Earlier quoted context omitted.

Really? And which part of "local law" required Zoom to close accounts of US citizens in the US who weren't breaking any US Laws? https://news.sky.com/story/zoom-disables-accounts-of-chinese... >The suspension targeted Humanitarian China, an organisation based in the US, after it held a call with roughly 250 people, including a number who dialled in from China.

Zoom claimed they had to remove Chinese participants from the US-hosted meeting but didn't have the functionality to do that so (wrongly) banned the US hosts. They said it was wrong to do, reinstated those accounts, and are building the functionality to enforce those Chinese laws without ever impacting users outside China. That's from their blog. https://blog.zoom.us/wordpress/2020/06/11/improving-our-poli...

I'll ignore for a second the fact they refused to even acknowledge Tiananmen Square in that post, despite the fact that as was pointed out they're a US company that isn't beholden to China and they're posting in English on their US-based website.

They are actually admitting that they're going to prevent people IN CHINA from connecting to a meeting that is presumably hosted IN THE US. That doesn't make it better, it makes it WORSE. You're basically telling the world that China will dictate how you operate WOLRDWIDE not just in China.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#110
post #24

Earlier quoted context omitted.

Yes, if the keys are held in servers that they have access to then they would be able to decrypt the traffic and see what is happening. The whole point of e2e encryption is that only the 2 parties have the keys, Zoom are abusing this term and making people believe they are doing e2e

What makes you think they're abusing the term? Did you read their whitepaper? https://github.com/zoom/zoom-e2e-whitepaper

They apparently 'define it differently' to every other company, organization, and infosec professional. This sort of thing used to be called lying, but it's essentially an 'alternative fact' now:

https://www.theverge.com/2020/3/31/21201234/zoom-end-to-end-...

Zoom, however, denies that it’s misleading users. The company told The Intercept, “When we use the phrase ‘End to End’ in our other literature, it is in reference to the connection being encrypted from Zoom end point to Zoom end point,” and that “content is not decrypted as it transfers across the Zoom cloud.

Whether the paper is any different is sort of irrelevant if they're starting off from a place of bad faith. One time after another this company has 'accidents' like this, while removing CCP distinguished nonpersons from the platform. A sense of skepticism is certainly justified.

Post reply on HN