Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

231–240 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#231
post #199

Earlier quoted context omitted.

Just curious - what other product that works better do you recommend? Webex, Skype, Hangouts/Meet, Teams all pale in comparison when it comes to quality and ease-of-use.

More to the point: which of those has true e2e encryption?

Can't speak for others but Microsoft Teams & Skype do not have E2E, and neither does Google Hangout/Meet.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#232

Earlier quoted context omitted.

End to Eavesdropper to End?

End to End to End :) AB/BC link encryption is the correct way to refer to such a scheme.

If we're being serious, then then another term used is "hop-to-hop encryption", as in [0]:

"Unlike PGP and S/MIME, STARTTLS provides hop-to-hop encryption (TLS for email), not end-to-end."

[0] https://www.eff.org/deeplinks/2018/06/technical-deep-dive-st...

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#234

Earlier quoted context omitted.

Why trust any company that put out the initial policy in the first place? Have they had a fundamental turnover in management, indicating a new pro-privacy culture? Did they move their development out from under the thumb of the CCP? No and no? So what’s changed? If they weren’t trustworthy before, they certainly aren’t now.

One thing that has changed is that their userbase broadened. They were mostly focused on workplace meetings. If that's your focus, then most of your users are employees of some company whose contact information you have. Users with unverified identities are a corner case that you may not feel is worth trying to get right. Thanks to the pandemic, they have millions of new users who use Zoom for personal purposes (meet…

> One thing that has changed is that their userbase broadened.

Their userbase changed in the two weeks since they announced their policy?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#235

Earlier quoted context omitted.

From a business model perspective, if Zoom embraced open-source, what would be their moat/value-add, compared to users downloading/forking from GitHub? Not being snarky: I'm genuinely curious what the "good citizen" (but still profitable) OS/FOSS model would look like, whether at equivalent revenue or reduced revenue.

> From a business model perspective, if Zoom embraced open-source, what would be their moat/value-add, compared to users downloading/forking from GitHub? Not being snarky: I'm genuinely curious what the "good citizen" (but still profitable) OS/FOSS model would look like, whether at equivalent revenue or reduced revenue. The idea that a business needs a moat to be profitable is a problem endemic to business. The value…

> The idea that a business needs a moat to be profitable is a problem endemic to business.

I'm pretty econ-left philosophically (socdem short-term, mutualist/ancom long-term), so you can't get much argument from me here. :)

But I want to steelman the other perspective: so long as we live in a pre-post-scarcity market economy, having some kind of moat is part of how one gains bargaining leverage in a price negotiation. (Think of "moat" in this context as influencing cost/benefit incentives, rather than an absolute barrier: the customer could build a boat to cross it, or they could pay the toll to cross the bridge, with the latter being usually cheaper.)

One answer is as you describe: hosting services and support contracts, in a market ecosystem of interoperable commodity services. Sign me up! But: such an ecosystem has a free-rider problem when it comes to the non-trivial expense of creating and maintaining the client software (including the risk of front-loading the 0-to-1 effort of building it before you know it will be adopted). In a FOSS model, other players in that ecosystem can obviously contribute to that effort, but those who don't contribute will have a competitive advantage, since commodity markets tend to viciously compete until margins are as near-zero as possible.

There are "moats" / competitive advantages that have nothing at all to do with the software itself: superior support experience, brand reputation, efficient hosting services through economy of scale. So I don't at all claim your model is unworkable, and there are many successful companies who do just that.

I don't disagree that the world would be a better place (and the overall economy perhaps more efficient), if most/all software was FOSS, and business models required less centralized control. (Note that nothing has stopped us from a building a pure FOSS E2EE VC client with a comparable feature-set; we still could.) But say I'm a board member or an investor in Zoom, whether pre- or post-success: how would you pitch me on the business value of open-sourcing the expensive-to-produce client software?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#236

Personally, I'm not feeling comfortable using Zoom on my PC. Just the other day, when opening the app, I was given a warning that the security certificate was untrusted and I would need to trust the certificate to proceed. I tried updating the app and the same error occurred. Perhaps their cert had expired or it was some oversight but I'm done. I've removed Zoom.

> Personally, I'm not feeling comfortable using Zoom on my PC. Just the other day, when opening the app, I was given a warning that the security certificate was untrusted and I would need to trust the certificate to proceed.

I mean, Zoom's atrocious security record aside, mistakes do happen. Microsoft recently forgot to renew some certs for Teams that caused a lot of trouble.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#237
post #141

Earlier quoted context omitted.

You mean to imply that a business would just lie to customers? Come on, the market wouldn't permit that to happen! They'd lose all their customers! /s Edit: on a less sarcastic note, I'd be less critical of Zoom if their software were open source.

What makes your comments even better is that Zoom's response from the get-go has basically been "Look at all these large companies that are using our service. Would they be using our service if we weren't secure?" Meanwhile the companies in question universally refuse to acknowledge THEY NEVER ACTUALLY VERIFIED ANY of the claims around encryption. It would be hilarious if it weren't so terrifying. And oh, by the way,…

Nope, this is human nature at it's most basic and obvious.

Saving face by not admitting egregious mistakes and even lying about making or not making them even after the evidence is public and irrefutable is just the human ego defending itself.

I'm starting to get past taht sort of childishness in my own life but having lived it for a long time I see it easily in others.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#239
post #199

Earlier quoted context omitted.

Just curious - what other product that works better do you recommend? Webex, Skype, Hangouts/Meet, Teams all pale in comparison when it comes to quality and ease-of-use.

More to the point: which of those has true e2e encryption?

I don't think any of them do, but more relevant to security none of them has auditable source code. Jitsi Meet (the easiest to use out of the services I've tried, namely Zoom and Google Meet) has experimental E2EE. But if you want real security you probably want something more like GNU Jami, which is not grandma-friendly easy to use and is a native application only.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#240

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

Another way of looking at it is that Zoom is learning from its mistakes and making improvements that the market demands. I'm no Zoom fan (I'd even use BlueJeans first), but people on HN are always so eager to crucify a company for its past. If it made mistakes, get out the tar and feathers! If it doesn't fix those mistakes, get out more tar and feathers! If it fixes the mistakes, even more tar and feathers!

This is overly charitable.

Zoom isn't learning from mistakes and making improvements that the market demands. It's providing a feature it said it already had.

Zoom knew E2EE was something the market demanded, so it lied about having E2EE. This was a blatant lie to get more people to use its platform. Then Zoom got caught. Now it's actually trying to provide what it said it provided in the first place.

Post reply on HN