Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

281–290 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#281

Earlier quoted context omitted.

> Yeah - I'm pretty sure this is the real concern and verifying a phone number is reasonable trade-off. It's not a reasonable trade off in countries where you get you legs broken, skin flayed alive, and head cut off: https://www.telegraph.co.uk/news/2019/11/18/russian-mercenar... A likelier explanation, is they want an easy way to wash their hands off when being pressed.

If you read the rest of my comment beyond the first line (particularly my blog link), you'd see that I agree with you when it comes to companies taking an ethical stand against authoritarian governments. What you're arguing is a strawman, we agree more than we disagree.

> If you read the rest of my comment beyond the first line (particularly my blog link),

I read, and I think your argument is hollow, and, assuming your goodwill, you are not understanding the matter at all, and if not, I see an ill intent.

I do not appreciate all what you say at all. Any argument against encryption must be quashed without exceptions, and second thoughts.

It is only since the start of 21st century, the experience akin to "legs broken, skin flayed alive, and head cut off" has been a grim reality for far more than a million people by now, mostly for, really, nothing. What are talking about this! And what you talk about?

Attack this argument, not something not even having a passing genuine relation to the matter.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#282
post #276

Earlier quoted context omitted.

> Indeed, E2EE will enable criminals to go undetected. And this is a real problem. This is not the problem. The argument is hollow. People need to take child protection laws out of political discourse, as it's now approaching silly.

If you think this strengthens the case against encryption laws, I suggest you rethink. There’s plenty of valid arguments against banning strong encryption and this isn’t one. You can’t simultaneously argue that E2EE keeps people’s conversations private to eavesdropping and then suggest that it doesn’t prevent eavesdropping for law enforcement purposes- at face value it does , and image hash databases to prevent the s…

> There’s plenty of valid arguments against banning strong encryption

There are no valid arguments against encryption

> And yes, law enforcement eavesdrops for law enforcement purposes

Lawful eavesdropping is an oxymoron

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#283
post #229

Earlier quoted context omitted.

Lying about a feature is exactly what Silicon Valley's "fake it till you make it" culture encourages. Crucifying Zoom over this while letting virtually every other company in the space (inc. Hangout/Meet and MS Teams/Skype) go free seems quite hypocritical from an HN community that's comprised of many startupers and startup wannabees who spend their professional lives working for entities with similar practices.

Did Meet/Teams/Skype claim E2E encryption? The only alternative I ever looked into was Jitsi (because it was the first alternative I started doing research on, and by the time I'd finished researching it there was no doubt that it was more than good enough -- and super easy to build our own cloud instance so that, even though it wasn't E2E, we had total control of the server that managed the encryption), but I don't…

[deleted]

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#284
post #229

Earlier quoted context omitted.

Lying about a feature is exactly what Silicon Valley's "fake it till you make it" culture encourages. Crucifying Zoom over this while letting virtually every other company in the space (inc. Hangout/Meet and MS Teams/Skype) go free seems quite hypocritical from an HN community that's comprised of many startupers and startup wannabees who spend their professional lives working for entities with similar practices.

That’s not what the expression means. If you are a tiny company and a big customer comes to you and says “can you scale to support us”, you answer yes even if you are not 100% sure you are ready. If however you claim to have feature X and you don’t, that’s just a lie.

I think I agree with you, but this argument seems like a pretty arbitrary line.

How is saying "yes we can scale" when you're not sure if you can, aren't you essentially implying that you have the infrastructure to deliver on that promise? And if you don't actually have that infrastructure yet/built/proven, then you're essentially selling a feature that doesn't exist.

It's shades of grey from lying about E2EE, but seems pretty similar imo

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#285

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

Zoom’s engineering team is based in the PRC. This opens them up to pressure from the dictatorship which has made large scale industrial espionage a public policy goal. Somebody is listening, and likely transcribing, every call at organizations of interest. The source code, public statements, etc are irrelevant; if the PLA wants a Chinese national in China to do something, they will. The penalties for noncompliance are terrifying.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#287

Earlier quoted context omitted.

I don't think any of them do, but more relevant to security none of them has auditable source code. Jitsi Meet (the easiest to use out of the services I've tried, namely Zoom and Google Meet) has experimental E2EE. But if you want real security you probably want something more like GNU Jami, which is not grandma-friendly easy to use and is a native application only.

The beauty of Jitsi is that you can run the software yourself (especially with the free Google Cloud credit) and then the E2E is hardly relevant because it's still server-to-client encrypted and you own the server...

My understanding is that Jitsi does actually have E2E at this point, at least in an experimental form.

It's in here somewhere: https://jitsi.org/security/

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#288
post #182

Oh god... Let this die already, they had their chance -- it's gone. Nobody in their right mind would touch Zoom with an 10" pole.

I wish it was true. Every meeting at my job requires Zoom.

What are feature-complete (remote control, whiteboard) alternatives?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#289
post #284

Earlier quoted context omitted.

That’s not what the expression means. If you are a tiny company and a big customer comes to you and says “can you scale to support us”, you answer yes even if you are not 100% sure you are ready. If however you claim to have feature X and you don’t, that’s just a lie.

I think I agree with you, but this argument seems like a pretty arbitrary line. How is saying "yes we can scale" when you're not sure if you can, aren't you essentially implying that you have the infrastructure to deliver on that promise? And if you don't actually have that infrastructure yet/built/proven, then you're essentially selling a feature that doesn't exist. It's shades of grey from lying about E2EE, but see…

Because with presumably feasible level of efforts and resources, you can make a claim that's not yet true, but has a reasonable probability of becoming true by the time you need to deliver your product/service. So you can make that claim in good faith, even if you're not 100% certain it will hold true.

That's very different than making a specific claim that you already have a feature right now, that you in fact don't. That claim cannot possibly be made in good faith, as it's currently outright false, and you can never retroactively apply end to end encryption on conversations that have already happened.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#290
post #220

Correct me if I'm wrong, but calling this E2E encryption is a marketing stunt. If I model Zoom as a malicious entity (or them being compromised by a third party), confidentiality is still compromised. This is different to what we normally understand under E2E, where I only have to trust the people I communicate with.

This is covered in the whitepaper: https://github.com/zoom/zoom-e2e-whitepaper
Post reply on HN