Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

291–300 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#291
post #229

Earlier quoted context omitted.

Lying about a feature isn’t just a “mistake”.

Lying about a feature is exactly what Silicon Valley's "fake it till you make it" culture encourages. Crucifying Zoom over this while letting virtually every other company in the space (inc. Hangout/Meet and MS Teams/Skype) go free seems quite hypocritical from an HN community that's comprised of many startupers and startup wannabees who spend their professional lives working for entities with similar practices.

And perhaps instead of being lenient with Zoom because "well everyone else lies about features", we should instead be consistent about holding companies accountable for dishonest business practices.

(I think I'm preaching to the choir here; just clarifying for anyone else reading your comment)

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#292

Earlier quoted context omitted.

You mean to imply that a business would just lie to customers? Come on, the market wouldn't permit that to happen! They'd lose all their customers! /s Edit: on a less sarcastic note, I'd be less critical of Zoom if their software were open source.

From a business model perspective, if Zoom embraced open-source, what would be their moat/value-add, compared to users downloading/forking from GitHub? Not being snarky: I'm genuinely curious what the "good citizen" (but still profitable) OS/FOSS model would look like, whether at equivalent revenue or reduced revenue.

Enterprise support is the usual answer, and it'd probably work pretty well for Zoom given how many enterprises are already willing to pay Zoom for said support.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#293
post #284

Earlier quoted context omitted.

That’s not what the expression means. If you are a tiny company and a big customer comes to you and says “can you scale to support us”, you answer yes even if you are not 100% sure you are ready. If however you claim to have feature X and you don’t, that’s just a lie.

I think I agree with you, but this argument seems like a pretty arbitrary line. How is saying "yes we can scale" when you're not sure if you can, aren't you essentially implying that you have the infrastructure to deliver on that promise? And if you don't actually have that infrastructure yet/built/proven, then you're essentially selling a feature that doesn't exist. It's shades of grey from lying about E2EE, but see…

/like a pretty arbitrary line/

Really? Do you think they would/could lie on the features of a product that they deliver to a client. If they did, do you think they should get away with that?

'We have that capability' claim is totally not the same.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#294
post #141

Earlier quoted context omitted.

What makes your comments even better is that Zoom's response from the get-go has basically been "Look at all these large companies that are using our service. Would they be using our service if we weren't secure?" Meanwhile the companies in question universally refuse to acknowledge THEY NEVER ACTUALLY VERIFIED ANY of the claims around encryption. It would be hilarious if it weren't so terrifying. And oh, by the way,…

Nope, this is human nature at it's most basic and obvious. Saving face by not admitting egregious mistakes and even lying about making or not making them even after the evidence is public and irrefutable is just the human ego defending itself. I'm starting to get past taht sort of childishness in my own life but having lived it for a long time I see it easily in others.

People don't mind lies though. General public will forget about it after a week if you keep silent or show them lies. Admitting your mistake isn't always a good choice in the corporate environment.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#295
post #246

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

The key information is in this sentences: "We are also pleased to share that we have identified a path forward that balances the legitimate right of all users to privacy and the safety of users on our platform ... while maintaining the ability to prevent and fight abuse on our platform." So they found a balance between privacy and ability to prevent abuse. In other words: this E2E encryption will have some backdoor w…

I agree. That's why I'm asking Zoom: "Define end-to-end encryption." Most likely, it will be backdoored form where they can intercept the call if they want to. And they'll promise us they won't unless there's a "lawful request."

What use is E2EE if it's backdoored? Nada, zero, zilch.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#296

Earlier quoted context omitted.

We tested it at my org, it doesn't scale past 15 users

Yeah, something like BigBlueButton might be better for big business meetings. (it's built for them and education, and claims to support 150+ participants). Participant limits in Jitsi Meet are a bit confusing. There's a lot of variables to consider. https://community.jitsi.org/t/jitsi-meet-performance-compari... > 1. Room hard limit is 75 users, recommended 35 users. > 2. The limit with more than 15 users with camera…

Heh. I like that this thread reveals Zoom's true advantage: it scales like hell.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#297
post #246

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

The key information is in this sentences: "We are also pleased to share that we have identified a path forward that balances the legitimate right of all users to privacy and the safety of users on our platform ... while maintaining the ability to prevent and fight abuse on our platform." So they found a balance between privacy and ability to prevent abuse. In other words: this E2E encryption will have some backdoor w…

It's easy to say "it balances" if it's you who decide how much the stuff on the plates weigh

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#298

Earlier quoted context omitted.

Their argument doesn't make sense. The objective behind verifying accounts is to prevent spammers creating lots of spam accounts and using those to spam. However, spammers rarely care if their spam is encrypted, so putting E2E behind verification won't do anything as far as spammers are concerned - they'll happily keep spamming using the unencrypted accounts. There's some other reason behind this that isn't about red…

If I recall from their previous statement, it's not about spammers, it's about people sharing child abuse photos.

It's really more about being able to trace accounts to people period, as allowed through the Patriot Act: https://en.wikipedia.org/wiki/Patriot_Act#Title_II:_Enhanced...

Child pornography gets held up to the public a lot because it's a crime nobody can defend and walk away the same they were, no matter what you say. If you publicly contest this move for privacy reasons, you're automatically defending the worst child molester someone's mind can come up with.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#299

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

You mean to imply that a business would just lie to customers? Come on, the market wouldn't permit that to happen! They'd lose all their customers! /s Edit: on a less sarcastic note, I'd be less critical of Zoom if their software were open source.

> Come on, the market wouldn't permit that to happen! They'd lose all their customers!

You scoff, but isn’t that exactly what we’re all doing to Zoom right now?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#300

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

Another way of looking at it is that Zoom is learning from its mistakes and making improvements that the market demands. I'm no Zoom fan (I'd even use BlueJeans first), but people on HN are always so eager to crucify a company for its past. If it made mistakes, get out the tar and feathers! If it doesn't fix those mistakes, get out more tar and feathers! If it fixes the mistakes, even more tar and feathers!

I'd be tempted to agree if their "mistakes" ended with the E2E debacle and Zoom was quick to admit wrongdoing and take responsability.

Unfortunately, it didn't end there. Rather than earning back their reputation, they have continued to burn through it with blunder after blunder.

The company has proven itself ethically corrupt and that's not something that can be made up for with apologies and product improvements. It will take time, demonstrations of humility, and a healthy dose of transparency to restore their reputation with me.

Post reply on HN