Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

141–150 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#141

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

You mean to imply that a business would just lie to customers? Come on, the market wouldn't permit that to happen! They'd lose all their customers! /s Edit: on a less sarcastic note, I'd be less critical of Zoom if their software were open source.

What makes your comments even better is that Zoom's response from the get-go has basically been "Look at all these large companies that are using our service. Would they be using our service if we weren't secure?"

Meanwhile the companies in question universally refuse to acknowledge THEY NEVER ACTUALLY VERIFIED ANY of the claims around encryption. It would be hilarious if it weren't so terrifying. And oh, by the way, all of those companies refuse to admit they messed up so they ALSO haven't switched to another service, so Zoom is literally still selling on "If we weren't secure, these big guys wouldn't be paying for our service". It's insanity.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#142

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

Alex Stamos had a good thread on some of the costs and benefits of E2EE. There is a cost https://twitter.com/alexstamos/status/1268219067707453441

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#143
post #129

Earlier quoted context omitted.

It's encrypted all the way from one end to the other end, we just also happen to have a copy of the key and can dencrypt it in the middle. Technically, the exact packets of the data you send is E2E encrypted... but the copies they make for themselves aren't.

Is that consistent with the traditional definition of E2E? And if so then what's the term for encryption that a middle man cannot decrypt?

It’s definitely not adhering to the definition of E2E encryption. However given Zoom’s history of shadiness it’s a pretty good guess about how it will be implemented.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#144
post #76
post #57

with closed source, hosted software E2EE is as much about trust as it is about technology since you can't verify its implementation. arguably, if trust is there, E2EE doesn't get you much anyway other than for scenarios where the company itself is breached. in any case, if the trust isn't there, you can't validate the E2EE, so your risk profile with regards to using the software doesn't change much.

Apple FaceTime is also closed source, E2E and verifiable

What is the process for verifying that FaceTime isn't leaking the encryption keys to Apple's servers?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#145

Earlier quoted context omitted.

I think their concern is paedophile rings using large group E2EE for live child abuse with completely anonymous accounts.

Only 4 comments in and we hit one of the four boogymen of the civil rights apocalypse. How many comments until we get to domestic terrorism or illegal drugs?

> one of the four boogymen of the civil rights apocalypse

The public is willing trade away privacy in exchange for protection from certain categories of risk. Instead of denying that, one can lean into it by ensuring strict definitions and enforcement options within those categories while preserving full privacy for those without. Arguing pedophile rings and terrorism are a cost of a privacy policy is a good way to sink that policy.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#146

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

They're 6 months away from becoming a case study in squandering momentum.

The goodwill has already been squandered. There’s simply nowhere else to jump to (jitsi lol). As soon as a viable competitor launches, everyone will jump. Same thing happened from Skype to Discord with the gaming community.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#148

Earlier quoted context omitted.

I disagree it's "racism." It's how the CCP operates. We can say the same story for different super powers from previous times. People suspected German Ambassador to USA for being a bosch spy. Founder of a communications company isn't that far off. Huawei is a great example. Founders of a company control the companies direction.

Except Eric is not any sort of govt or party representative. He is a naturalized American of Chinese ancestry. In history, this kind of scapegoating was counterproductive.

The CCP can and will exert pressure on family members to get expats and former citizens to do what they want. They're not the only country to do so, not by a long shot, but they are particularly brazen about it.

Though I think the CEO is less relevant than the critical amount of developers Zoom relies on that are directly living under and subject to CCP malfeasance.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#149
post #129

Earlier quoted context omitted.

It wouldn't surprise me as recently the app tried to get me to trust an untrusted cert.

It's encrypted all the way from one end to the other end, we just also happen to have a copy of the key and can dencrypt it in the middle. Technically, the exact packets of the data you send is E2E encrypted... but the copies they make for themselves aren't.

[deleted]

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#150

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

Alex Stamos had a good thread on some of the costs and benefits of E2EE. There is a cost https://twitter.com/alexstamos/status/1268219067707453441

There is also a cost in not having your smart TV microphone record all conversations and upload them to the police.
Post reply on HN