Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

211–220 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#211

Earlier quoted context omitted.

I think their concern is paedophile rings using large group E2EE for live child abuse with completely anonymous accounts.

Yeah - I'm pretty sure this is the real concern and verifying a phone number is reasonable trade-off. I know this argument is often quickly dismissed on HN since people see child abuse or 'going dark' as an easy excuse for the government to leverage to get more control (and it has been used for this), but that doesn't mean the problem isn't serious or doesn't exist. See this: https://www.nytimes.com/interactive/2019/…

>verifying a phone number is reasonable trade-off

Lower privacy "because security" is not a reasonable trade-off. It should not be. See also: https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp...

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#212

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

Another way of looking at it is that Zoom is learning from its mistakes and making improvements that the market demands. I'm no Zoom fan (I'd even use BlueJeans first), but people on HN are always so eager to crucify a company for its past. If it made mistakes, get out the tar and feathers! If it doesn't fix those mistakes, get out more tar and feathers! If it fixes the mistakes, even more tar and feathers!

I feel like the mistakes you are referring to were actually lies and there is a sort of a pattern emerging with a company that is not merely making innocuous mistakes

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#213
post #103
post #6

"To make this possible, Free/Basic users seeking access to E2EE will participate in a one-time process that will prompt the user for additional pieces of information, such as verifying a phone number via a text message. Many leading companies perform similar steps on account creation to reduce the mass creation of abusive accounts." Perfect instrument to collect more personal data.

Is there any E2EE app that doesn't require verification? Whatsapp does. Even Signal requires a phone number.

https://matrix.org

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#214

Earlier quoted context omitted.

Alex Stamos had a good thread on some of the costs and benefits of E2EE. There is a cost https://twitter.com/alexstamos/status/1268219067707453441

People who wish to mask their crimes have a greater incentive to use E2EE so will probably gravitate towards platforms that offer it. I would therefore suggest those not committing crimes are disproportionately affected by E2EE not being made the default where possible. Once one service in a particular category offers E2EE, the benefits of the other services in that category not offering it is significantly reduced.

This is only true if you assume that the world is populated with an equal number of criminals and non-criminals.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#215

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

Another way of looking at it is that Zoom is learning from its mistakes and making improvements that the market demands. I'm no Zoom fan (I'd even use BlueJeans first), but people on HN are always so eager to crucify a company for its past. If it made mistakes, get out the tar and feathers! If it doesn't fix those mistakes, get out more tar and feathers! If it fixes the mistakes, even more tar and feathers!

What is weing with Zoom that you’d use blue jeans before?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#217

Earlier quoted context omitted.

This blog post specifically says that it's a walk-back of the policy announced in your link.

Why trust any company that put out the initial policy in the first place? Have they had a fundamental turnover in management, indicating a new pro-privacy culture? Did they move their development out from under the thumb of the CCP? No and no? So what’s changed? If they weren’t trustworthy before, they certainly aren’t now.

Maybe they listened to feedback and updated their priors?

Why do you believe their real intention was revealed a week ago, and not today?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#218

Earlier quoted context omitted.

Just curious - what other product that works better do you recommend? Webex, Skype, Hangouts/Meet, Teams all pale in comparison when it comes to quality and ease-of-use.

Honestly, Meet has had huge updates in the past month or so that make it much better than Zoom. The image quality no longer looks like crap with more than 2 people in the room.

If I had to decide the official comms app for my employer, I'd be wary of Google, due to their poor track record with comms apps.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#219

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

Another way of looking at it is that Zoom is learning from its mistakes and making improvements that the market demands. I'm no Zoom fan (I'd even use BlueJeans first), but people on HN are always so eager to crucify a company for its past. If it made mistakes, get out the tar and feathers! If it doesn't fix those mistakes, get out more tar and feathers! If it fixes the mistakes, even more tar and feathers!

There's a difference between a couple of honest mistakes and a history of shadiness (MacOS hidden server to prevent uninstallation), outright lies (E2EE), and attacking the pillars of democracy (censoring Chinese Americans discussing Tienanmen Square).

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#220
Correct me if I'm wrong, but calling this E2E encryption is a marketing stunt. If I model Zoom as a malicious entity (or them being compromised by a third party), confidentiality is still compromised. This is different to what we normally understand under E2E, where I only have to trust the people I communicate with.
Post reply on HN