Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

361–370 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#361

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

Zoom’s engineering team is based in the PRC. This opens them up to pressure from the dictatorship which has made large scale industrial espionage a public policy goal. Somebody is listening, and likely transcribing, every call at organizations of interest. The source code, public statements, etc are irrelevant; if the PLA wants a Chinese national in China to do something, they will. The penalties for noncompliance ar…

Is there any better way to bring down China than them latching onto quarterly reporting and shareholder pressure?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#362

Earlier quoted context omitted.

Just curious - what other product that works better do you recommend? Webex, Skype, Hangouts/Meet, Teams all pale in comparison when it comes to quality and ease-of-use.

jitsi works wonderfully. I've also have been using Discord for voice almost daily for a little over a year and it just works 99% of the time. Unfortunately, it suffers from "gamer" branding that makes it awkward suggesting for work. They should try offering a "business skin" that interops with discord.

I second Jitsi. For me, the value is in hosting your own Jitsi server. Really not that hard to do.

Mind you, I only host it at home on a VM for personal use. Have had sessions with 6 people with one of them a Europe-Australia connection. All fine on default 720p.

If I were looking for 20+ meeting software though I'd consider something else. I would consider it a case for streaming to faceless attendees. I have never had a meeting with useful input from more than 10 people.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#363

Earlier quoted context omitted.

Anybody that trusts zoom with anything even slightly sensitive these days is completely nuts. Yes, we know its easy to use.

99% of people do not care about privacy. They won't switch programs because a nation state might spy on them.

Yes they will. You need to be thinking about LGBTQ people in many non-Western countries.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#364

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

They hired the Keybase team. I feel like if the team was directed to develop countermeasures to the E2E or design the E2E to be vulnerable, someone would have blown the whistle. E2E was Keybase's thing and it would be a huge slap in the face.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#365
post #246

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

The key information is in this sentences: "We are also pleased to share that we have identified a path forward that balances the legitimate right of all users to privacy and the safety of users on our platform ... while maintaining the ability to prevent and fight abuse on our platform." So they found a balance between privacy and ability to prevent abuse. In other words: this E2E encryption will have some backdoor w…

This is one of the downsides of the casual acceptance of corporate invasion of our privacy. Corporations can do whatever they want! Including letting China listen to your doctor appointments.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#366

Earlier quoted context omitted.

99% of people do not care about privacy. They won't switch programs because a nation state might spy on them.

Yes they will. You need to be thinking about LGBTQ people in many non-Western countries.

They are the 1%. 99% of people consider "privacy" a good value in abstract but will not lift a finger to protect their own privacy. It's virtue signalling.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#367

Earlier quoted context omitted.

> From a business model perspective, if Zoom embraced open-source, what would be their moat/value-add, compared to users downloading/forking from GitHub? Not being snarky: I'm genuinely curious what the "good citizen" (but still profitable) OS/FOSS model would look like, whether at equivalent revenue or reduced revenue. The idea that a business needs a moat to be profitable is a problem endemic to business. The value…

> The idea that a business needs a moat to be profitable is a problem endemic to business. I'm pretty econ-left philosophically (socdem short-term, mutualist/ancom long-term), so you can't get much argument from me here. :) But I want to steelman the other perspective: so long as we live in a pre-post-scarcity market economy, having some kind of moat is part of how one gains bargaining leverage in a price negotiation…

> But say I'm a board member or an investor in Zoom, whether pre- or post-success: how would you pitch me on the business value of open-sourcing the expensive-to-product client software?

Okay. Consider the following fantastical talk from technical me to you, oh dear fantastical board member:

Let's face a fact: yeah open source software is "free (as in free speech)" and it can also be "free (as in free beer)". Anyone can inspect it. Anyone can "steal" it so-to-speak and set up a competitor. That will always be the case. Just look at how many stolen software products end up in your favorite app store. Games are ripped off right down to their copyrightable artwork, malvertisements added, and reuploaded with a new name. But I think worrying about that is like worrying about the people brewing their own beer. I think that's preventing us from building a brewery.

Let's face another fact: what's expensive isn't software. That's pretty cheap. That's just man-hours. A kid in a garage can build video chat over a weekend or two. What's expensive is experience. Experience is basically an impossible-to-estimate number of man-hours. We'll never be able to pay one person or one team to understand all of the pieces and platforms and make it work for everyone.

Customers want to run Windows, Mac, Linux, iOS, Android... and all of that is hard to keep up with. Customers have a plethora of network and hardware configurations. Customers have crazy different bandwidth and latency profiles. It's really hard for us to make our software work in all of that. But some of our customers are experienced and they're curious and they are looking at our software with a fine toothed comb. We simply can't stop them from doing so. That's how we got into these repeated PR messes after all. So let's embrace that. I think there's a good chance that some of those customers would solve our problems for us if only there was a way they could contribute fixes.

Like I said, experience is expensive. With experience comes ideas. Ideas are gold. That's why we're worried about our competitors after all. We don't really have any solid ideas. Neither do they. Even if we did have a solid idea, they'd create a competing idea or even just outright steal ours. And we'll still be left holding the bag, we'll still have these PR details for not getting things right in the first place. So let's turn that on its head.

If we open source our software, we give these technical people the opportunity to help us fix problems before they become problems. There's a ton of home brewers out there and some of them would love to be able to help our big brewery. We're not going to stop home brewers. So we shouldn't even try. But home brewers do need tools. Let them come up with their own recipes.

So, we provide the tools for free. But we can sell the recipe. Or, technically: provide a cheap service for the people who need something they know is secure but don't have the technical know-how and/or time to set it up themselves. Lawyers have a legal requirement to keep their conversations private. Schools have a legal requirement to keep their children safe from stalkers. Even citizens have a right to privacy. We'll make all of the tools available for anyone to audit and validate. The recipe to use those tools is where we make profit.

The recipe is the environment. We'll provide, for a fixed cost, the ingress bandwidth and compute needed. We'll provide secure storage of recorded conversations and an audit history of who's accessed it. We'll provide the experienced technical support to directly either fix problems or point at misconfigured devices outside of our control (and why it's the source of a problem); we'll be able to understand the debug logs that the software provides. Of course, any other technical person could too. But that's already the case so we're not really losing anything here. Indeed, we're gaining here. We're gaining the trust of law firms and governments; the trust that they're getting the value that they want for the services they need and that they can go directly to us if they need troubleshooting.

I'm not arguing against centralization. Centralization is good for us and for our customers. It's an anchor point for experience to grow from. I'm saying that open source software can help us avoid further technical problems from our lack of security experience. And who knows? Maybe some of those home brewers are interested in a paying job at our brewery -- if only they could prove they knew a little bit about beer, if it was free. We could definitely use the experience.

/pitch

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#368

This is the same company that said that it "won't encrypt free calls so it can work more with law enforcement"[1]. I'd stay away. [1]: https://news.ycombinator.com/item?id=23399924

This blog post specifically says that it's a walk-back of the policy announced in your link.

Is it though? End to end encryption doesn’t mean they don’t pass the key back to themselves.

It’s a bit of weaseling here. They say they’re offering E2E and that might be true, and it could also be true they are sticking with their original vision of cooperation with law enforcement because they “are aware criminals use the service”.

There is no required mutual exclusion.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#369
post #7

It’s still only opt-in. Users have to submit an application (including text message verification and other personal info) to gain access to E2E encryption. Zoom has shown that it does not care about privacy.

Isn't it fair to say that this brings Zoom more-or-less exactly in line with the privacy vs law enforcement balance of a normal telephone call? Writing from the UK, I'm reasonably sure that (a) all my phone calls are not recorded and (b) the phone number and duration of every call absolutely is recorded (this has to be shown on your phone bill!) and is available to the police when needed. Speculating further, with th…

> Writing from the UK, I'm reasonably sure that (a) all my phone calls are not recorded

With 5 / 14 eyes and no specific privacy doctrine in the UK, I have no idea why you would have that assumption at all.

Maybe not recorded indefinitely, but it seems very possible to voice to text and store that forever.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#370

Earlier quoted context omitted.

Yes they will. You need to be thinking about LGBTQ people in many non-Western countries.

They are the 1%. 99% of people consider "privacy" a good value in abstract but will not lift a finger to protect their own privacy. It's virtue signalling.

I absolutely hate the term virtue signalling. It's always reductive and dismissive. If I am willing to go a LITTLE out of my way to protect my privacy, but not a LOT out of my way, am I "just virtue signalling"? If I continue to use a privacy-less platform (e.g. zoom/instagram/facebook) but just exercise caution with what I say using that medium, is that also "just virtue signalling"?

I agree, evidence shows most people are not willing to go very far out of their way to defend their privacy. But I also think privacy is a genuine virtue, and a desire for it is present and often untapped. Why else would Apple have run privacy-centric ad campaigns? Attempting to tap into the weak but widespread desire for privacy, I think

Also, side note, lgbtq people make up somewhere in the range of 2-7% of the population, not 1%.

Post reply on HN