Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

171–180 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#172

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

You mean to imply that a business would just lie to customers? Come on, the market wouldn't permit that to happen! They'd lose all their customers! /s Edit: on a less sarcastic note, I'd be less critical of Zoom if their software were open source.

From a business model perspective, if Zoom embraced open-source, what would be their moat/value-add, compared to users downloading/forking from GitHub? Not being snarky: I'm genuinely curious what the "good citizen" (but still profitable) OS/FOSS model would look like, whether at equivalent revenue or reduced revenue.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#173

Earlier quoted context omitted.

> one of the four boogymen of the civil rights apocalypse The public is willing trade away privacy in exchange for protection from certain categories of risk. Instead of denying that, one can lean into it by ensuring strict definitions and enforcement options within those categories while preserving full privacy for those without. Arguing pedophile rings and terrorism are a cost of a privacy policy is a good way to s…

I would make a cogent argument to rebuff your straw man, but it's not worth my time if you don't share a priori assumptions with me about E2EE being uncrackable. It's just math. I don't see why the talk of trade-offs even is relevant to the discussion. People will use secure tools with E2EE or they will suffer the consequences of not doing so. Doing illegal things is already illegal. Banning or watering down E2EE so…

Your mistake is bringing a technical argument to a political question.

My personal political answer to "how to have end-to-end encryption and prevent its use for child rape" would be to tax the companies which profit from E2EE, and use that money to fund death squads, which livestream dragging child rapists out of their home, anywhere in the world, and beating them to death with truncheons.

I'm joking, of course (or am I?) but I do consider this the general shape of a viable solution. E2EE is essential for a modern life which isn't a hellish surveillance dystopia, and the detection and prosecution of child rape is criminally underfunded.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#174

Earlier quoted context omitted.

Is it possible for Zoom / the CCP to hold the encryption keys? That would make it insecure, right? (genuine question).

If implemented correctly, the server doesn’t get the key. Look up Diffie–Hellman key exchange for more information on how this is possible. This can be verified by auditing the client so you don’t need to trust Zoom.

> The Diffie–Hellman exchange by itself does not provide authentication of the communicating parties and is thus vulnerable to a man-in-the-middle attack.[1]

Whoever controls key distribution can control the encryption channel; without a way to verify public keys, all bets are always off. You're right that auditing the client is one (if not the only?) way to do this.

[1]: https://en.wikipedia.org/wiki/Diffie%E2%80%93Hellman_key_exc...

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#175
post #129

Earlier quoted context omitted.

It's encrypted all the way from one end to the other end, we just also happen to have a copy of the key and can dencrypt it in the middle. Technically, the exact packets of the data you send is E2E encrypted... but the copies they make for themselves aren't.

Is that consistent with the traditional definition of E2E? And if so then what's the term for encryption that a middle man cannot decrypt?

Regarding question #2, Peer-to-peer.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#176

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

Alex Stamos had a good thread on some of the costs and benefits of E2EE. There is a cost https://twitter.com/alexstamos/status/1268219067707453441

People who wish to mask their crimes have a greater incentive to use E2EE so will probably gravitate towards platforms that offer it. I would therefore suggest those not committing crimes are disproportionately affected by E2EE not being made the default where possible. Once one service in a particular category offers E2EE, the benefits of the other services in that category not offering it is significantly reduced.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#177
post #141

Earlier quoted context omitted.

You mean to imply that a business would just lie to customers? Come on, the market wouldn't permit that to happen! They'd lose all their customers! /s Edit: on a less sarcastic note, I'd be less critical of Zoom if their software were open source.

What makes your comments even better is that Zoom's response from the get-go has basically been "Look at all these large companies that are using our service. Would they be using our service if we weren't secure?" Meanwhile the companies in question universally refuse to acknowledge THEY NEVER ACTUALLY VERIFIED ANY of the claims around encryption. It would be hilarious if it weren't so terrifying. And oh, by the way,…

Feels like Theranos except the only difference is that Zoom has working software

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#178
That's actually very common, most online conferencing systems will say they are end-to-end encrypted when they actually aren't/they consider end-to-end to be from your client to the server. This was a big issue when we were selecting a supplier for such a solution and actually wanted to use a cloud solution but none of them had proper end-to-end encryption.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#180
post #103
post #6

"To make this possible, Free/Basic users seeking access to E2EE will participate in a one-time process that will prompt the user for additional pieces of information, such as verifying a phone number via a text message. Many leading companies perform similar steps on account creation to reduce the mass creation of abusive accounts." Perfect instrument to collect more personal data.

Is there any E2EE app that doesn't require verification? Whatsapp does. Even Signal requires a phone number.

Threema.
Post reply on HN