Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

221–230 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#221
post #137

Earlier quoted context omitted.

E2E encryption is meaningless unless there is a way to prove that it is E2E, e.g. by showing us the source code of the client side and allowing us to compile it ourselves, which Signal does. It would be super interesting if there was a way to abstract out encryption on the camera itself, where the video call software gets an encrypted video stream and its only job is to convey that stream to the other side, which dec…

Sounds like a use-case for efficient homomorphic encryption.

We really need a fully homomorphic fast public key encryption. That would enable digital signing schemes that can encrypt the entire document using public key scheme (double-barrelled signing: first encrypt using private key that would be decrypted using public key, then encrypt that form using public key that would be decrypted using private key; the first (and only that one!) encryption would be homomorphic).

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#222

Earlier quoted context omitted.

You forgot "5. Zoom gets praised for developing features in response to criticism that already existed in other products that work better." Jokes aside, with Zoom's track record, it's not worth using anymore regardless of what features they implement. Not having E2E encryption is no where near as much of a red flag as lying about it is to me.

Just curious - what other product that works better do you recommend? Webex, Skype, Hangouts/Meet, Teams all pale in comparison when it comes to quality and ease-of-use.

For ease of use I recommend Whereby.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#223

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

Another way of looking at it is that Zoom is learning from its mistakes and making improvements that the market demands. I'm no Zoom fan (I'd even use BlueJeans first), but people on HN are always so eager to crucify a company for its past. If it made mistakes, get out the tar and feathers! If it doesn't fix those mistakes, get out more tar and feathers! If it fixes the mistakes, even more tar and feathers!

A generalization like “people on HN are always...” coming from a 3yr old HN user with 20k+ karma points looks like a case of the pot calling the kettle black.

Criticisms of large corporations is a healthy part of the HN community IMO. In fact, if we didn’t criticize Zoom they might still be lying about their E2EE capabilities.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#224

Earlier quoted context omitted.

> The people carrying out the abuse are sophisticated. In this case wouldn't they build their own solutions (potentially based on existing open-source solutions like Asterisk + Linphone or Jitsi Meet) or they might've built them already? Phone numbers are also very easy to obtain anonymously, so I am not sure SMS verification would help track down abusers when it'll lead to a prepaid SIM or some innocent user's phone…

Yes, some would - but not all. I agree that these reasons are why it's not a good idea to break or outlaw encryption since bad actors can still use it and good people that need it are blocked, but this doesn't mean that making it the default doesn't enable more abusers to get away with it that might be caught otherwise. There's a spectrum of sophistication, if it's harder more of them will make more mistakes that mak…

So how do you define that giving away phone numbers is the right trade-off in the "spectrum of sophistication"? It effectively means lack of anonymous communications for everyone, i.e. global surveillance (personally identifiable metadata is in the hands of Zoom).

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#225

Earlier quoted context omitted.

Wait, your point is that Zoom is evil because the founder is Chinese?

While I understand that on the surface seems "bad", you have to understand the CCP taps into people worldwide, and while I don't know his position per se, or finances -- or connection with China today. It doesn't paint a great picture, especially with espionage and CCP tactics. Look at previous German and USA interference w/ GE, Bosch, -- it's the same story. Except now it's highlight as "bad" to point out that conne…

I don't see how this isn't just discriminating based on national origin.

It'd be one thing if there are actually some nefarious ties between Eric and CCP, but all we are going by is he's originally from China and there could be influence by CCP on people from China. It's not bad to point out a connection, it's bad to point out a possible connection based on nothing more than where the guy is from.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#226

Earlier quoted context omitted.

I think their concern is paedophile rings using large group E2EE for live child abuse with completely anonymous accounts.

Only 4 comments in and we hit one of the four boogymen of the civil rights apocalypse. How many comments until we get to domestic terrorism or illegal drugs?

Next thing you know, people will be using E2EE to stream gasp copyrighted material!

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#227
post #220

Correct me if I'm wrong, but calling this E2E encryption is a marketing stunt. If I model Zoom as a malicious entity (or them being compromised by a third party), confidentiality is still compromised. This is different to what we normally understand under E2E, where I only have to trust the people I communicate with.

Very true. If Zoom handles the encryption and decryption on their servers, rather than fully on the client's machine, then they can still "listen in". The only way I would trust their E2E is if they can't see or hear what's happening too. It's wild to me that companies I've worked for that have insane privacy and on-prem server requirements, will use Zoom no questions asked.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#228

Earlier quoted context omitted.

This could be the case for literally any E2EE service that controls key distribution (including WhatsApp, Signal, etc.), especially when there's no way to verify key fingerprints (here Signal differs because it does have a way, and it's open source so you can be more confident that it's not BSing you). It's shocking to me how often this is glossed over when discussing E2EE services: you still must trust the platform.

E2EE and open source: the two things people assume automatically makes things super-crazy-secure. The implementation of E2EE must be robust and there must be somebody who is actually checking the source code (plus verifiable builds)

Don't forget the human element: users still have actually do the verifying (e.g. checking public key fingerprints of recipients) that the source code enables!

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#229

Earlier quoted context omitted.

Another way of looking at it is that Zoom is learning from its mistakes and making improvements that the market demands. I'm no Zoom fan (I'd even use BlueJeans first), but people on HN are always so eager to crucify a company for its past. If it made mistakes, get out the tar and feathers! If it doesn't fix those mistakes, get out more tar and feathers! If it fixes the mistakes, even more tar and feathers!

Lying about a feature isn’t just a “mistake”.

Lying about a feature is exactly what Silicon Valley's "fake it till you make it" culture encourages.

Crucifying Zoom over this while letting virtually every other company in the space (inc. Hangout/Meet and MS Teams/Skype) go free seems quite hypocritical from an HN community that's comprised of many startupers and startup wannabees who spend their professional lives working for entities with similar practices.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#230

Earlier quoted context omitted.

Yes, some would - but not all. I agree that these reasons are why it's not a good idea to break or outlaw encryption since bad actors can still use it and good people that need it are blocked, but this doesn't mean that making it the default doesn't enable more abusers to get away with it that might be caught otherwise. There's a spectrum of sophistication, if it's harder more of them will make more mistakes that mak…

So how do you define that giving away phone numbers is the right trade-off in the "spectrum of sophistication"? It effectively means lack of anonymous communications for everyone, i.e. global surveillance (personally identifiable metadata is in the hands of Zoom).

I didn't say it was 'right', I said it was 'reasonable' - and there aren't easy answers to this.

Also to clarify, specifically a reasonable trade-off for Zoom (I don't think there should be a general law that requires IDs for video software use or something).

Zoom is not a company I would use at all if you're looking for secure communications (https://zalberico.com/essay/2020/06/13/zoom-in-china.html).

If you care about secure communication you should be using something else.

Post reply on HN