Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

201–210 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#202
post #195

Earlier quoted context omitted.

Just curious - what other product that works better do you recommend? Webex, Skype, Hangouts/Meet, Teams all pale in comparison when it comes to quality and ease-of-use.

BlueJeans and RingCentral might as well be clones of Zoom. Amazon Chime and Microsoft Teams are fine for me too, but I'm not picky.

After the disastrous experience I had with BlueJeans this morning, I wouldn't include it as a quality or reliability match for Zoom.

The company my wife works for can't get a reliable Teams conference going with anyone in France.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#203
post #128

Earlier quoted context omitted.

I'm disgusted that in 2020, Americans continue to use the same racist, unfounded smears againts people based on their ethnicity just as they did when they were throwing Japanese-Americans into internment camps.

There are plenty of HN users who won't (or wouldn't, in an ideal world) use any US-based software because of NSA interference. The issue is national origin, not ethnicity. Japanese Americans were thrown into camps for the same reason, but we're not talking about jailing anyone here. We're talking about avoiding a specific product. Another difference is that Japanese Americans were put into camps regardless of how man…

There is a difference between US based software (e.g. servers located in the US), vs a CEO that's from the US (or China in this case). If the argument is that Zoom the company has routes traffic to China etc then fine I can get behind that. But if the argument is the CEO is from China I find that problematic. I mean it's not like internment of Japanese Americans is ok if it's limited to only first gen.

EDIT: Also sounds like you're saying that it's ok to avoid doing business with someone based on national origin, which I also find problematic.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#204
How exactly does E2E encryption work for something bandwidth intensive like Zoom? It can't possibly be encrypting the stream with a different key for every participant, the bandwidth requirements would be impossible.

Is a new key generated for each stream, which is then individually encrypted with every other participants public key, and then sent to the participants for them to decrypt?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#205

Earlier quoted context omitted.

You mean to imply that a business would just lie to customers? Come on, the market wouldn't permit that to happen! They'd lose all their customers! /s Edit: on a less sarcastic note, I'd be less critical of Zoom if their software were open source.

From a business model perspective, if Zoom embraced open-source, what would be their moat/value-add, compared to users downloading/forking from GitHub? Not being snarky: I'm genuinely curious what the "good citizen" (but still profitable) OS/FOSS model would look like, whether at equivalent revenue or reduced revenue.

> From a business model perspective, if Zoom embraced open-source, what would be their moat/value-add, compared to users downloading/forking from GitHub? Not being snarky: I'm genuinely curious what the "good citizen" (but still profitable) OS/FOSS model would look like, whether at equivalent revenue or reduced revenue.

The idea that a business needs a moat to be profitable is a problem endemic to business.

The value add would be in hosting services and support contracts. Video chat is needed by a lot of non-technical people. Furthering, plenty of people don't have sufficient bandwidth to host their own video chat even with just their own friends or teams. Even technical people often don't understand how to write secure software.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#206

Earlier quoted context omitted.

Jitsi Meet's not a viable competitor? It's simpler to set up (accounts and password protection are optional), IMO easier to use (eg. the hand button is on the bottom bar with mute, etc. and not in a menu labeled "Participants") and higher quality according to the New York Times, who deemed it "reliable and easy to use": https://www.nytimes.com/wirecutter/reviews/best-video-confer... . I've introduced it to extended f…

We tested it at my org, it doesn't scale past 15 users

Yeah, something like BigBlueButton might be better for big business meetings. (it's built for them and education, and claims to support 150+ participants).

Participant limits in Jitsi Meet are a bit confusing. There's a lot of variables to consider. https://community.jitsi.org/t/jitsi-meet-performance-compari...

> 1. Room hard limit is 75 users, recommended 35 users. > 2. The limit with more than 15 users with camera is the user’s PC. > 3. Working test with a good bare metal servers, 115 mute users and 5 users with camera. > 4. Test in progress for 500 simultaneous users.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#207

I commend Zoom for listening to the outcry over E2EE being limited to paid users. Between this move and their quick acknowledgement of mishandling the shutdown of accounts when asked by China, they're doing a better job than most of responding to criticism.

Agreed. I am always confused about the smackdown following a reversal from an arguably bad decision. We should be welcoming in hopes other companies note that being responsive is a good thing. Otherwise, it is just being stuck between rock and a hard place with no place to move.

Honestly, "reward good behavior" is the best approach, to be combined with "condemn bad behavior".

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#208

Personally, I'm not feeling comfortable using Zoom on my PC. Just the other day, when opening the app, I was given a warning that the security certificate was untrusted and I would need to trust the certificate to proceed. I tried updating the app and the same error occurred. Perhaps their cert had expired or it was some oversight but I'm done. I've removed Zoom.

I only have it installed on a spare laptop that I leave off unless I'm doing a meeting. 100% do not trust.

I only use it on my iPad. It's not getting anywhere near a non-locked down system.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#209

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

Another way of looking at it is that Zoom is learning from its mistakes and making improvements that the market demands. I'm no Zoom fan (I'd even use BlueJeans first), but people on HN are always so eager to crucify a company for its past. If it made mistakes, get out the tar and feathers! If it doesn't fix those mistakes, get out more tar and feathers! If it fixes the mistakes, even more tar and feathers!

Lying about a feature isn’t just a “mistake”.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#210

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

Another way of looking at it is that Zoom is learning from its mistakes and making improvements that the market demands. I'm no Zoom fan (I'd even use BlueJeans first), but people on HN are always so eager to crucify a company for its past. If it made mistakes, get out the tar and feathers! If it doesn't fix those mistakes, get out more tar and feathers! If it fixes the mistakes, even more tar and feathers!

> people on HN are always so eager to crucify a company for its past

Perhaps. In my case it's less crucifying a company despite intentions to fix and more crucifying a company because I'm tired of hearing the same PR nonsense and not seeing real improvement to the industry as a whole.

What you're seeing is the flip side of the whole "it's easier to ask forgiveness than permission" nonsense.

Post reply on HN