Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

271–280 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#271

Earlier quoted context omitted.

Yeah - I'm pretty sure this is the real concern and verifying a phone number is reasonable trade-off. I know this argument is often quickly dismissed on HN since people see child abuse or 'going dark' as an easy excuse for the government to leverage to get more control (and it has been used for this), but that doesn't mean the problem isn't serious or doesn't exist. See this: https://www.nytimes.com/interactive/2019/…

> Yeah - I'm pretty sure this is the real concern and verifying a phone number is reasonable trade-off. It's not a reasonable trade off in countries where you get you legs broken, skin flayed alive, and head cut off: https://www.telegraph.co.uk/news/2019/11/18/russian-mercenar... A likelier explanation, is they want an easy way to wash their hands off when being pressed.

It's not Zoom's job to solve every use case for every person in every situation.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#272
post #195

Earlier quoted context omitted.

BlueJeans and RingCentral might as well be clones of Zoom. Amazon Chime and Microsoft Teams are fine for me too, but I'm not picky.

Ring Central uses Zoom for the backend. I know they just announced their own "Ring central video" But im weary of that for the time being.

*wary

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#273

Earlier quoted context omitted.

Yeah - I'm pretty sure this is the real concern and verifying a phone number is reasonable trade-off. I know this argument is often quickly dismissed on HN since people see child abuse or 'going dark' as an easy excuse for the government to leverage to get more control (and it has been used for this), but that doesn't mean the problem isn't serious or doesn't exist. See this: https://www.nytimes.com/interactive/2019/…

> Yeah - I'm pretty sure this is the real concern and verifying a phone number is reasonable trade-off. It's not a reasonable trade off in countries where you get you legs broken, skin flayed alive, and head cut off: https://www.telegraph.co.uk/news/2019/11/18/russian-mercenar... A likelier explanation, is they want an easy way to wash their hands off when being pressed.

If you read the rest of my comment beyond the first line (particularly my blog link), you'd see that I agree with you when it comes to companies taking an ethical stand against authoritarian governments.

What you're arguing is a strawman, we agree more than we disagree.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#274

Earlier quoted context omitted.

You forgot "5. Zoom gets praised for developing features in response to criticism that already existed in other products that work better." Jokes aside, with Zoom's track record, it's not worth using anymore regardless of what features they implement. Not having E2E encryption is no where near as much of a red flag as lying about it is to me.

Just curious - what other product that works better do you recommend? Webex, Skype, Hangouts/Meet, Teams all pale in comparison when it comes to quality and ease-of-use.

jitsi works wonderfully.

I've also have been using Discord for voice almost daily for a little over a year and it just works 99% of the time. Unfortunately, it suffers from "gamer" branding that makes it awkward suggesting for work. They should try offering a "business skin" that interops with discord.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#275
post #82

Earlier quoted context omitted.

The only "relevant" information found in the quote in the GP comment is the nationality of the CEO. How does one jump from the CEO's nationality to inevitable ties and implicit subservience to CCP?

ignoring the quote for a second we know a few things about this CEO and zoom. 1. zoom's application is sending data to Chinese servers separate from the application functionality servers. 2. the CEO is from china, I'm going to assume he has relatives in china. 3. we know CCP is a completely fucked up government with an absolutely horrible history of civil rights violations, genocide, etc. I wouldn't put it past CCP t…

I find myself agreeing with most of your points. I mainly took issue with taking a shortcut from "being born and raised in China" to being a hostile Chinese agent (and we don't even know if the CEO has relatives in China that can be leveraged anyway).

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#276
post #194

Earlier quoted context omitted.

Indeed, E2EE will enable criminals to go undetected. And this is a real problem. However, it’s an arms race that will end with criminals having proper, strong E2EE anyways. Trying to reverse this is like trying to reverse entropy, the toothpaste does not go back into the tube. It may seem like it is still doable now , but I’d be willing to place bets that feeling will evaporate shortly. Of course, criminals are ordin…

> Indeed, E2EE will enable criminals to go undetected. And this is a real problem. This is not the problem. The argument is hollow. People need to take child protection laws out of political discourse, as it's now approaching silly.

If you think this strengthens the case against encryption laws, I suggest you rethink. There’s plenty of valid arguments against banning strong encryption and this isn’t one. You can’t simultaneously argue that E2EE keeps people’s conversations private to eavesdropping and then suggest that it doesn’t prevent eavesdropping for law enforcement purposes- at face value it does, and image hash databases to prevent the spread of known CSAM exist today; see, for example, Project Arachnid. And yes, law enforcement eavesdrops for law enforcement purposes. That’s why wiretap warrants exist. Whether its a good thing is another argument entirely, but it is indeed the status quo.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#277

Earlier quoted context omitted.

Why trust any company that put out the initial policy in the first place? Have they had a fundamental turnover in management, indicating a new pro-privacy culture? Did they move their development out from under the thumb of the CCP? No and no? So what’s changed? If they weren’t trustworthy before, they certainly aren’t now.

Maybe they listened to feedback and updated their priors? Why do you believe their real intention was revealed a week ago, and not today?

Updated their priors? Review their history. Their "real intentions" have been "revealed" multiple times over the past several months (or years). It's a litany of privacy-related blunders. This is pure PR; words to distract you from their many misdeeds.

Trust, but verify, yes? Well, they're verifiably full of crapola.

So why would you trust?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#278

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

Another way of looking at it is that Zoom is learning from its mistakes and making improvements that the market demands. I'm no Zoom fan (I'd even use BlueJeans first), but people on HN are always so eager to crucify a company for its past. If it made mistakes, get out the tar and feathers! If it doesn't fix those mistakes, get out more tar and feathers! If it fixes the mistakes, even more tar and feathers!

I'm fine with companies making mistakes and working to fix them, but Zoom has been bad not just because of E2E encryption, but because of their questionable ties to the CCP.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#279

Earlier quoted context omitted.

Why trust any company that put out the initial policy in the first place? Have they had a fundamental turnover in management, indicating a new pro-privacy culture? Did they move their development out from under the thumb of the CCP? No and no? So what’s changed? If they weren’t trustworthy before, they certainly aren’t now.

One thing that has changed is that their userbase broadened. They were mostly focused on workplace meetings. If that's your focus, then most of your users are employees of some company whose contact information you have. Users with unverified identities are a corner case that you may not feel is worth trying to get right. Thanks to the pandemic, they have millions of new users who use Zoom for personal purposes (meet…

They have more users, but so what? They suddenly found (privacy) religion, so now they can be trusted? That certainly sounds like a leap of faith. A blind one.

Stop looking at the empty words they say, and start looking at their very intentional and malignant actions over the last few months/years.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#280

Earlier quoted context omitted.

It wouldn't surprise me as recently the app tried to get me to trust an untrusted cert.

yikes, if they ended up murdering Keybase and still ship crap, I will never forgive them.

whats the post-keybase landscape?
Post reply on HN