Earlier quoted context omitted.
You mean to imply that a business would just lie to customers? Come on, the market wouldn't permit that to happen! They'd lose all their customers! /s Edit: on a less sarcastic note, I'd be less critical of Zoom if their software were open source.
From a business model perspective, if Zoom embraced open-source, what would be their moat/value-add, compared to users downloading/forking from GitHub? Not being snarky: I'm genuinely curious what the "good citizen" (but still profitable) OS/FOSS model would look like, whether at equivalent revenue or reduced revenue.
Zoom to bring end-to-end encryption to all users, including non-paying
341–350 of 557 posts
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#342Earlier quoted context omitted.
If that's the answer to " what's the term for encryption that a middle man cannot decrypt ", NO : peer-to-peer simply means... well, pretty much it means sending IP packets directly to each other rather than through a central server (yes, not much of a thing, but it meant you could get free music more easily, so the term got a lot of traction)
That's right. It is certainly possible to use peer-to-peer to send unencrypted packets. Peer-to-peer does not imply encryption. It does imply avoiding a "middleman". Thus, to send encrypted packets without using a middleman, peer-to-peer is a viable method.
No, it only implies avoiding a central server (and not even for every aspect of the service), you still run through routers, ISPs, NSA etc.
If you are certain that there's no middleman, you don't need encryption.
N.B. Maybe someone defines it in another way today, but when the term became popular, with Napster, it really meant simply not having a central server for certain functions, or even more banally not downloading your mp3s from a web site or ftp server; it did have some significance also because the legal aspect of it was more uncertain; when people started getting 100k dollars fines, peer-to-peer stopped meaning much, sometimes it's better to send packets directly to each other, other times through a server, but you almost always encrypt and almost always ought to encrypt end-to-end
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#343Earlier quoted context omitted.
There is also a cost in not having your smart TV microphone record all conversations and upload them to the police.
That's a false equivalence. At any point in this, there is little we can do to verify E2EE, but trust a 3rd party. We can trust that they enable it, or as previously proposed we can trust that they are visibly in the meetings and observing. Either way, we have no way to ensure this is true when dealing with 3rd party providers. Your smart tv recording has nothing to do with this, but one does still need to trust that…
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#344Earlier quoted context omitted.
This could be the case for literally any E2EE service that controls key distribution (including WhatsApp, Signal, etc.), especially when there's no way to verify key fingerprints (here Signal differs because it does have a way, and it's open source so you can be more confident that it's not BSing you). It's shocking to me how often this is glossed over when discussing E2EE services: you still must trust the platform.
E2EE and open source: the two things people assume automatically makes things super-crazy-secure. The implementation of E2EE must be robust and there must be somebody who is actually checking the source code (plus verifiable builds)
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#345Earlier quoted context omitted.
You mean to imply that a business would just lie to customers? Come on, the market wouldn't permit that to happen! They'd lose all their customers! /s Edit: on a less sarcastic note, I'd be less critical of Zoom if their software were open source.
What makes your comments even better is that Zoom's response from the get-go has basically been "Look at all these large companies that are using our service. Would they be using our service if we weren't secure?" Meanwhile the companies in question universally refuse to acknowledge THEY NEVER ACTUALLY VERIFIED ANY of the claims around encryption. It would be hilarious if it weren't so terrifying. And oh, by the way,…
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#346Earlier quoted context omitted.
It's encrypted all the way from one end to the other end, we just also happen to have a copy of the key and can dencrypt it in the middle. Technically, the exact packets of the data you send is E2E encrypted... but the copies they make for themselves aren't.
Is that consistent with the traditional definition of E2E? And if so then what's the term for encryption that a middle man cannot decrypt?
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#347So what are they actually announcing then?
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#348Re: Zoom to bring end-to-end encryption to all users, including non-paying
#349I am surprised at how unforgiving everyone is here. Zoom owned their mistakes publicly and trying to improve on that as soon as possible. How much more can you get ? Looking back you can see such incidents with all kinds of companies like faang. Don’t buy into surface level news and get outraged. This is a fantastic product and I think they deserve a chance to correct themselves.
1) Adding a missing feature, which is a form of technical correction.
2) Fixing the corporate culture and their attitude to their customers. This is a form of non-technical correction.
Zoom has done a half-arsed job of (1), and one could legitimately argue that it's too little, too late. But the real issue is that nothing indicates that (2) has improved in any way. Fundamentally, the Zoom corporate default is "lie to the customers and when caught, double-down".
They're taking a page from Trump's book. I'm sure you don't need me to explain why that particular management style is unpopular here.
For a recent example, see how PostgreSQL fixed a technical issue discovered by Jepsen. They were advertising on their website that they had a certain technical guarantee related to serializability of transactions. Turns out there was an error -- an honest mistake. They immediately corrected the issue. People trusted them more because of this management attitude. [1]
Now compare with nearly the exact same technical issue with MongoDB discovered by Jepsen. Mongo's website repeatedly lied about their data integrity features, even referencing the Jepsen test as proof! Tests they failed! It's like the snake oil salesman saying "scientifically tested" as if it's a good thing that every scientific test proved that it's just oil and does nothing. Mongo was rightly derided and mocked.[2]
[1] https://news.ycombinator.com/item?id=23499667
> Personally, this kind of thing actually gives me _more_ confidence in Postgres rather than less. The core team's responsiveness to this bug report was incredibly impressive.
[2] https://news.ycombinator.com/item?id=23285768
> In the circles I run in, MongoDB is regarded as a joke and the company behind it as basically duplicitous.
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#350Earlier quoted context omitted.
I'll ignore for a second the fact they refused to even acknowledge Tiananmen Square in that post, despite the fact that as was pointed out they're a US company that isn't beholden to China and they're posting in English on their US-based website. They are actually admitting that they're going to prevent people IN CHINA from connecting to a meeting that is presumably hosted IN THE US . That doesn't make it better, it…
I'm sure that if the US had as strict control over our/their internet as China does over theirs, non-US sites would be forced to operate differently for peers in the US too.