Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

321–330 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#321
post #66
post #6

"To make this possible, Free/Basic users seeking access to E2EE will participate in a one-time process that will prompt the user for additional pieces of information, such as verifying a phone number via a text message. Many leading companies perform similar steps on account creation to reduce the mass creation of abusive accounts." Perfect instrument to collect more personal data.

You also signed up an account for banks, they collect a ton of data on all your payments, got a problem with that? You gonna say yeah Zoom is not a bank, but your prose is the data collection part

> You also signed up an account for banks, they collect a ton of data on all your payments, got a problem with that?

Yes.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#322
post #9

I'm quite frustrated they are calling this end to end. I can't find it now but a tweet earlier indicated that they have the keys and can help law enforcement with investigations which means it's can't be end to end.

Any centralized E2EE service has the (public) keys; that's the only way to distribute them to users. You have to trust (or verify, in the case of Signal) them to deliver authentic keys rather than MitM'ing you.

It wouldn't be a problem if anybody at all had the _public_ keys, I think he meant the private ones.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#324

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

I guess this is a literal definition of fake it till you make.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#325
I am surprised at how unforgiving everyone is here. Zoom owned their mistakes publicly and trying to improve on that as soon as possible. How much more can you get ? Looking back you can see such incidents with all kinds of companies like faang. Don’t buy into surface level news and get outraged. This is a fantastic product and I think they deserve a chance to correct themselves.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#326

Earlier quoted context omitted.

Alex Stamos had a good thread on some of the costs and benefits of E2EE. There is a cost https://twitter.com/alexstamos/status/1268219067707453441

There is also a cost in not having your smart TV microphone record all conversations and upload them to the police.

That's a false equivalence. At any point in this, there is little we can do to verify E2EE, but trust a 3rd party. We can trust that they enable it, or as previously proposed we can trust that they are visibly in the meetings and observing. Either way, we have no way to ensure this is true when dealing with 3rd party providers.

Your smart tv recording has nothing to do with this, but one does still need to trust that it isn't happening. In the case of the smart tv we can attempt to look for microphones or other components that are able to be used as microphones. Software offers a more difficult path in verification.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#327

Earlier quoted context omitted.

Honestly, Meet has had huge updates in the past month or so that make it much better than Zoom. The image quality no longer looks like crap with more than 2 people in the room.

If I had to decide the official comms app for my employer, I'd be wary of Google, due to their poor track record with comms apps.

Meet is a GSuite product, and the only video-conferencing app in GSuite. Google doesn't fuck with GSuite.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#328
post #314

Earlier quoted context omitted.

> The CCP can and will exert pressure on family members to get expats and former citizens to do what they want. Could you give a few such cases?

Here's a bunch. https://www.hrw.org/news/2018/01/31/china-families-interpol-...

Summary: Chinese government harass the relatives of the fugitive corruption suspects to force these suspects to return voluntarily.

That's definitely one area the Chinese system is vastly behind the international standard. But this has not been conscious to me.

When I was a child, we had horror stories of people sentenced to death penalty and were executed on superficial charges that sexual misconduct. And my parents have witnessed detained thief were beaten like wild animals by policeman, and the thief's scream was heart far in the then poor village.

These measures can even escalate during "Yanda", a nationally-coordinated clampdown on criminal activities. In [1], it was noted: "China's execution rate increases dramatically during Yanda campaigns."

Such brutal national campaigns are dying down, the most recent one [2] has much less cruelty. And historically such campaigns enjoyed universal domestic support.

As of today, the Chinese government has a high degree of popular endorsement to use whatever not-too-out-of-line measures to bring back the corrupted businessman or former government officials, who are prosecuted by the public attorneys. Thanks a grain of national pride, i.e., "those corrupted bastard not only embezzled our money, and they escape to the country that is unfriendly and can be benefited from those fortune".

[1] https://www.jstor.org/stable/23639486?seq=1 [2] https://www.economist.com/china/2019/02/28/china-is-waging-a...

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#329

Earlier quoted context omitted.

This could be the case for literally any E2EE service that controls key distribution (including WhatsApp, Signal, etc.), especially when there's no way to verify key fingerprints (here Signal differs because it does have a way, and it's open source so you can be more confident that it's not BSing you). It's shocking to me how often this is glossed over when discussing E2EE services: you still must trust the platform.

E2EE and open source: the two things people assume automatically makes things super-crazy-secure. The implementation of E2EE must be robust and there must be somebody who is actually checking the source code (plus verifiable builds)

If you go down that road, you can make this argument infinitely. Even if you verify your builds, you cannot know if the software you are using to check the build isn't compromised. Or if you check the software you use to check the build, you have to check the software doing that check and so on.

Nothing makes software automatically super-crazy-secure. Absolute security doesn't exist.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#330
post #303

Earlier quoted context omitted.

Regarding question #2, Peer-to-peer.

If that's the answer to " what's the term for encryption that a middle man cannot decrypt ", NO : peer-to-peer simply means... well, pretty much it means sending IP packets directly to each other rather than through a central server (yes, not much of a thing, but it meant you could get free music more easily, so the term got a lot of traction)

That's right. It is certainly possible to use peer-to-peer to send unencrypted packets. Peer-to-peer does not imply encryption. It does imply avoiding a "middleman". Thus, to send encrypted packets without using a middleman, peer-to-peer is a viable method.
Post reply on HN