Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

331–340 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#331
post #57

with closed source, hosted software E2EE is as much about trust as it is about technology since you can't verify its implementation. arguably, if trust is there, E2EE doesn't get you much anyway other than for scenarios where the company itself is breached. in any case, if the trust isn't there, you can't validate the E2EE, so your risk profile with regards to using the software doesn't change much.

You can verify closed source E2EE as long as you can inspect the traffic going client-server. The problem is that most E2EE apps allow auto-updating, so baking in something that transmits info to a third party is easy (but detectable with enough eyes on the code).

I imagine you mean inspecting everything that gets transmitted besides the -2E part, but even if you could there are a thousand ways for not-really-safely-encrypting a communication without you being able to notice

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#332
post #276

Earlier quoted context omitted.

If you think this strengthens the case against encryption laws, I suggest you rethink. There’s plenty of valid arguments against banning strong encryption and this isn’t one. You can’t simultaneously argue that E2EE keeps people’s conversations private to eavesdropping and then suggest that it doesn’t prevent eavesdropping for law enforcement purposes- at face value it does , and image hash databases to prevent the s…

> There’s plenty of valid arguments against banning strong encryption There are no valid arguments against encryption > And yes, law enforcement eavesdrops for law enforcement purposes Lawful eavesdropping is an oxymoron

Do you think there is no situation where it can be lawful for a law enforcement agency to perform a wiretap?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#333

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

> Given their track record I’d expect this timeline to repeat itself so after they release this E2E encryption feature, security researchers will discover that it’s not true E2E encryption again.

I mean, you can already look at the design if you wish, it was disclosed by Alex Stamos: https://twitter.com/alexstamos/status/1268061790954385408

TBH I'm sort of surprised they gave in to the new wave of criticism, their arguments for not giving E2E to free accounts were pretty decent.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#334
post #76

Earlier quoted context omitted.

Apple FaceTime is also closed source, E2E and verifiable

What is the process for verifying that FaceTime isn't leaking the encryption keys to Apple's servers?

I don’t know, but as a black box it’s been extensively looked at. But nothing is unhackable even E2E.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#335
post #109

Earlier quoted context omitted.

Zoom claimed they had to remove Chinese participants from the US-hosted meeting but didn't have the functionality to do that so (wrongly) banned the US hosts. They said it was wrong to do, reinstated those accounts, and are building the functionality to enforce those Chinese laws without ever impacting users outside China. That's from their blog. https://blog.zoom.us/wordpress/2020/06/11/improving-our-poli...

I'll ignore for a second the fact they refused to even acknowledge Tiananmen Square in that post, despite the fact that as was pointed out they're a US company that isn't beholden to China and they're posting in English on their US-based website. They are actually admitting that they're going to prevent people IN CHINA from connecting to a meeting that is presumably hosted IN THE US . That doesn't make it better, it…

I'm sure that if the US had as strict control over our/their internet as China does over theirs, non-US sites would be forced to operate differently for peers in the US too.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#336

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

You forgot "5. Zoom gets praised for developing features in response to criticism that already existed in other products that work better." Jokes aside, with Zoom's track record, it's not worth using anymore regardless of what features they implement. Not having E2E encryption is no where near as much of a red flag as lying about it is to me.

> it's not worth using anymore regardless of what features they implement.

Not to me. I would just assume they don't have E2E encryption and wouldn't base my calls around the idea of needing that. The claim is never worth it without an independent review and then thinking about the attack surface you actually want to shield against.

I mean, in another market, if you have ever investigated VPN providers you would see 100% conflicts of interest with affiliate marketing everywhere and the articles never acknowledge that the business of reselling internet access has inherent trust and unverifiable claims involved. A government can always tap the source with a legal order and there will always be information available to them.

For a video chat service, them merely saying E2E doesn't mean anything without a way to verify it, or host the whole stack myself and this is incompatible with being a company.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#337
post #141

Earlier quoted context omitted.

What makes your comments even better is that Zoom's response from the get-go has basically been "Look at all these large companies that are using our service. Would they be using our service if we weren't secure?" Meanwhile the companies in question universally refuse to acknowledge THEY NEVER ACTUALLY VERIFIED ANY of the claims around encryption. It would be hilarious if it weren't so terrifying. And oh, by the way,…

I've been in the interview loop as of late, and there's been a crazy shift away from Zoom. Almost every video chat I had was using Zoom a couple months back, now everyone is using Google Chat or MS Team Meetings. Now these are small to medium-ish size companies (20-500 people), so maybe it's not a big deal to Zoom's marketing bottom line. But it's definitely a thing.

It’s the business model. Scaling up Zoom or Webex is costly because it’s based on meeting hosts.

Teams or Meet works fine (unlike the train wreck of Skype), have improved recently and are already paid for.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#338

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

I'm actually more alarmed than I was before the announcement, because it indicates that there wasn't sufficient pressure for them not to do this. Watch them put the key in a predictable memory location, then have a subtle vulnerability elsewhere that lets them exfiltrate the client-generated key at any time. Anyone with views that might be dangerous to reveal to state actors should be very, very wary.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#339
post #129

Earlier quoted context omitted.

It's encrypted all the way from one end to the other end, we just also happen to have a copy of the key and can dencrypt it in the middle. Technically, the exact packets of the data you send is E2E encrypted... but the copies they make for themselves aren't.

This could be the case for literally any E2EE service that controls key distribution (including WhatsApp, Signal, etc.), especially when there's no way to verify key fingerprints (here Signal differs because it does have a way, and it's open source so you can be more confident that it's not BSing you). It's shocking to me how often this is glossed over when discussing E2EE services: you still must trust the platform.

You can check the finger print on WhatsApp

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#340
post #338

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

I'm actually more alarmed than I was before the announcement, because it indicates that there wasn't sufficient pressure for them not to do this. Watch them put the key in a predictable memory location, then have a subtle vulnerability elsewhere that lets them exfiltrate the client-generated key at any time. Anyone with views that might be dangerous to reveal to state actors should be very, very wary.

Anybody that trusts zoom with anything even slightly sensitive these days is completely nuts.

Yes, we know its easy to use.

Post reply on HN