I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…
You forgot "5. Zoom gets praised for developing features in response to criticism that already existed in other products that work better." Jokes aside, with Zoom's track record, it's not worth using anymore regardless of what features they implement. Not having E2E encryption is no where near as much of a red flag as lying about it is to me.
Zoom to bring end-to-end encryption to all users, including non-paying
181–190 of 557 posts
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#182Re: Zoom to bring end-to-end encryption to all users, including non-paying
#183"To make this possible, Free/Basic users seeking access to E2EE will participate in a one-time process that will prompt the user for additional pieces of information, such as verifying a phone number via a text message. Many leading companies perform similar steps on account creation to reduce the mass creation of abusive accounts." Perfect instrument to collect more personal data.
There is no need to use my cell phone or any telephone number when you already have a means of communication via email or any other channel.
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#184Earlier quoted context omitted.
It's encrypted all the way from one end to the other end, we just also happen to have a copy of the key and can dencrypt it in the middle. Technically, the exact packets of the data you send is E2E encrypted... but the copies they make for themselves aren't.
This could be the case for literally any E2EE service that controls key distribution (including WhatsApp, Signal, etc.), especially when there's no way to verify key fingerprints (here Signal differs because it does have a way, and it's open source so you can be more confident that it's not BSing you). It's shocking to me how often this is glossed over when discussing E2EE services: you still must trust the platform.
The implementation of E2EE must be robust and there must be somebody who is actually checking the source code (plus verifiable builds)
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#185Earlier quoted context omitted.
The goodwill has already been squandered. There’s simply nowhere else to jump to (jitsi lol). As soon as a viable competitor launches, everyone will jump. Same thing happened from Skype to Discord with the gaming community.
Skype was never a real player in the gaming community, it was really just Teamspeak, Ventrilo, and Mumble
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#186I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…
You mean to imply that a business would just lie to customers? Come on, the market wouldn't permit that to happen! They'd lose all their customers! /s Edit: on a less sarcastic note, I'd be less critical of Zoom if their software were open source.
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#187It’s still only opt-in. Users have to submit an application (including text message verification and other personal info) to gain access to E2E encryption. Zoom has shown that it does not care about privacy.
Isn't it fair to say that this brings Zoom more-or-less exactly in line with the privacy vs law enforcement balance of a normal telephone call? Writing from the UK, I'm reasonably sure that (a) all my phone calls are not recorded and (b) the phone number and duration of every call absolutely is recorded (this has to be shown on your phone bill!) and is available to the police when needed. Speculating further, with th…
It would be easier to just lie about the encryption being end-to-end.
Personally, I will never use Zoom for anything, a decision I came to when my OS vendor (Apple) pushed a security update for my OS to get rid of Zoom.
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#188Earlier quoted context omitted.
This blog post specifically says that it's a walk-back of the policy announced in your link.
Why trust any company that put out the initial policy in the first place? Have they had a fundamental turnover in management, indicating a new pro-privacy culture? Did they move their development out from under the thumb of the CCP? No and no? So what’s changed? If they weren’t trustworthy before, they certainly aren’t now.
They were mostly focused on workplace meetings. If that's your focus, then most of your users are employees of some company whose contact information you have. Users with unverified identities are a corner case that you may not feel is worth trying to get right.
Thanks to the pandemic, they have millions of new users who use Zoom for personal purposes (meeting with friends and family, etc.). What once was a corner case isn't anymore. It might even be their most common type of user.
I'm not arguing that Zoom can necessarily be trusted, but I can see a plausible reason how they could have gotten to where they are on this issue.
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#189Earlier quoted context omitted.
You mean to imply that a business would just lie to customers? Come on, the market wouldn't permit that to happen! They'd lose all their customers! /s Edit: on a less sarcastic note, I'd be less critical of Zoom if their software were open source.
From a business model perspective, if Zoom embraced open-source, what would be their moat/value-add, compared to users downloading/forking from GitHub? Not being snarky: I'm genuinely curious what the "good citizen" (but still profitable) OS/FOSS model would look like, whether at equivalent revenue or reduced revenue.
For the business model, it is the same as other OS, there are companies that want a tech insurance policy.
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#190Earlier quoted context omitted.
You forgot "5. Zoom gets praised for developing features in response to criticism that already existed in other products that work better." Jokes aside, with Zoom's track record, it's not worth using anymore regardless of what features they implement. Not having E2E encryption is no where near as much of a red flag as lying about it is to me.
Just curious - what other product that works better do you recommend? Webex, Skype, Hangouts/Meet, Teams all pale in comparison when it comes to quality and ease-of-use.