Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

261–270 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#261

Earlier quoted context omitted.

Zoom is evil. Also, fun note - just noticed Eric Yuan posted that and also created Zoom. https://en.wikipedia.org/wiki/Eric_Yuan Eric S. Yuan (Chinese: 袁征; pinyin: Yuán Zhēng; born 1970) is a Chinese-American billionaire businessman, and the CEO and founder of Zoom Video Communications, of which he owns 22%. No wonder why they have to play party with CCP.

Unfortunately, I have to post this comment again, from just 3 days ago [1]. Also remember that Eric Yuan is an American citizen, not a Chinese citizen. He switched. Original comment: When will this meme die? Zoom is NOT a Chinese company. It is incorporated in and headquartered in the US. Like any American company ever, it follows US laws in the US, and local laws in other companies where it operates. End of story. Y…

Dude, you need to think first. Handing over data to CCP ? thats genocide.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#262

Earlier quoted context omitted.

Their argument doesn't make sense. The objective behind verifying accounts is to prevent spammers creating lots of spam accounts and using those to spam. However, spammers rarely care if their spam is encrypted, so putting E2E behind verification won't do anything as far as spammers are concerned - they'll happily keep spamming using the unencrypted accounts. There's some other reason behind this that isn't about red…

I think their concern is paedophile rings using large group E2EE for live child abuse with completely anonymous accounts.

Please, don't derail the discussion with something as silly as this.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#264

Earlier quoted context omitted.

The goodwill has already been squandered. There’s simply nowhere else to jump to (jitsi lol). As soon as a viable competitor launches, everyone will jump. Same thing happened from Skype to Discord with the gaming community.

Jitsi Meet's not a viable competitor? It's simpler to set up (accounts and password protection are optional), IMO easier to use (eg. the hand button is on the bottom bar with mute, etc. and not in a menu labeled "Participants") and higher quality according to the New York Times, who deemed it "reliable and easy to use": https://www.nytimes.com/wirecutter/reviews/best-video-confer... . I've introduced it to extended f…

Jitsi has audio problems for several people in my peer group. I think from other audio work that it may be that they're using too small frame sizes, although it's possible that something else in their audio pipeline is busted.

Audio capture APIs often suggest it may be possible to use very small frame sizes, which naturally promise much improved latency. Going from 100ms of audio latency to 20ms is great so surely going from 20ms to 5ms is even better right? Well, the hardware underneath that API may not be able to deliver, at least it may not be able to deliver consistently. If your 5ms buffer isn't filled on time, what do you send? A partially filled buffer? Silence? The last 5ms of filled buffer again? All bad answers.

Tool A with 40ms of latency may feel imperceptibly worse than Tool B with 30ms of latency. But Tool C with 10ms of latency but frequent "drain piping" as audio frames are garbled or undelivered is clearly much worse than either.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#265

Earlier quoted context omitted.

I think their concern is paedophile rings using large group E2EE for live child abuse with completely anonymous accounts.

Yeah - I'm pretty sure this is the real concern and verifying a phone number is reasonable trade-off. I know this argument is often quickly dismissed on HN since people see child abuse or 'going dark' as an easy excuse for the government to leverage to get more control (and it has been used for this), but that doesn't mean the problem isn't serious or doesn't exist. See this: https://www.nytimes.com/interactive/2019/…

> Yeah - I'm pretty sure this is the real concern and verifying a phone number is reasonable trade-off.

It's not a reasonable trade off in countries where you get you legs broken, skin flayed alive, and head cut off: https://www.telegraph.co.uk/news/2019/11/18/russian-mercenar...

A likelier explanation, is they want an easy way to wash their hands off when being pressed.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#266

Earlier quoted context omitted.

Yeah - I'm pretty sure this is the real concern and verifying a phone number is reasonable trade-off. I know this argument is often quickly dismissed on HN since people see child abuse or 'going dark' as an easy excuse for the government to leverage to get more control (and it has been used for this), but that doesn't mean the problem isn't serious or doesn't exist. See this: https://www.nytimes.com/interactive/2019/…

> The people carrying out the abuse are sophisticated. In this case wouldn't they build their own solutions (potentially based on existing open-source solutions like Asterisk + Linphone or Jitsi Meet) or they might've built them already? Phone numbers are also very easy to obtain anonymously, so I am not sure SMS verification would help track down abusers when it'll lead to a prepaid SIM or some innocent user's phone…

> Phone numbers are also very easy to obtain anonymously, so I am not sure SMS verification would help track down abusers when it'll lead to a prepaid SIM or some innocent user's phone that happened to be compromised by malware.

It depends on which country really. In some places in Europe it became almost impossible to do that (sadly).

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#267
post #195

Earlier quoted context omitted.

Just curious - what other product that works better do you recommend? Webex, Skype, Hangouts/Meet, Teams all pale in comparison when it comes to quality and ease-of-use.

BlueJeans and RingCentral might as well be clones of Zoom. Amazon Chime and Microsoft Teams are fine for me too, but I'm not picky.

Ring Central uses Zoom for the backend.

I know they just announced their own "Ring central video" But im weary of that for the time being.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#268

Earlier quoted context omitted.

This could be the case for literally any E2EE service that controls key distribution (including WhatsApp, Signal, etc.), especially when there's no way to verify key fingerprints (here Signal differs because it does have a way, and it's open source so you can be more confident that it's not BSing you). It's shocking to me how often this is glossed over when discussing E2EE services: you still must trust the platform.

E2EE and open source: the two things people assume automatically makes things super-crazy-secure. The implementation of E2EE must be robust and there must be somebody who is actually checking the source code (plus verifiable builds)

It doesn’t automatically make everything secure, but it’s still a prerequisite for a trusted secure thing.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#269

Earlier quoted context omitted.

I would make a cogent argument to rebuff your straw man, but it's not worth my time if you don't share a priori assumptions with me about E2EE being uncrackable. It's just math. I don't see why the talk of trade-offs even is relevant to the discussion. People will use secure tools with E2EE or they will suffer the consequences of not doing so. Doing illegal things is already illegal. Banning or watering down E2EE so…

Your mistake is bringing a technical argument to a political question. My personal political answer to "how to have end-to-end encryption and prevent its use for child rape" would be to tax the companies which profit from E2EE, and use that money to fund death squads, which livestream dragging child rapists out of their home, anywhere in the world, and beating them to death with truncheons. I'm joking, of course (or…

> E2EE is essential for a modern life which isn't a hellish surveillance dystopia, and the detection and prosecution of child rape is criminally underfunded.

Yup. This.

Post reply on HN