Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

371–380 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#371

This is the same company that said that it "won't encrypt free calls so it can work more with law enforcement"[1]. I'd stay away. [1]: https://news.ycombinator.com/item?id=23399924

This blog post specifically says that it's a walk-back of the policy announced in your link.

This wasn't the only problem with Zoom, and it was an egregious problem. Zoom has lost all presumption of good faith, and in fact earned the presumption of bad faith as far as I'm concerned.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#372

> All Zoom users will continue to use AES 256 GCM transport encryption as the default encryption, one of the strongest encryption standards in use today. I’m glad that Zoom is finally implementing E2E encryption, but I hate that they have been (and still are) advertising “full encryption” and using jargon like “AES 256 GCM” to deceive users into thinking they’re using anything more than SSL.

Worse than that. Saying AESGCM doesn’t even mean they are using SSL or DH key exchange or etc. it just means they’re using symmetric for the data, that’s all. Nothing about how the key is securely transferred to each side and how the user can have any confidence they aren’t passing the key back to themselves anyhow.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#373
post #342

Earlier quoted context omitted.

> It does imply avoiding a "middleman" No, it only implies avoiding a central server (and not even for every aspect of the service), you still run through routers, ISPs, NSA etc. If you are certain that there's no middleman, you don't need encryption. N.B. Maybe someone defines it in another way today, but when the term became popular, with Napster, it really meant simply not having a central server for certain funct…

The central server is the "middleman" as I am using that term. Routers are not middlemen under the meaning I am using. I am referring to peer-to-peer without any supernode forwarding traffic. No central server. There may be a "rendezvous server" involved in allowing two nodes to discover how to connect to one another, however that server does not route traffic. I never implied a need for encryption associated with pe…

I know that the term "peer-to-peer" could be interpreted in many ways, but to the best of my knowledge it is usually interpreted how I wrote above.

Which I think it's pretty much how you defined it too in your (last) comment, so I'm not sure what we're debating.

The important thing was that no one reading these comments get the impression that the multitude of systems that describe themselves as "peer-to-peer" are for sure using "encryption that a middle man cannot decrypt".

---

> The parent comment asked about avoiding a middleman

Middle man in cryptography is anyone intercepting a message

---

> I have no idea what "end-to-end encryption" means, nor do I seek to know

Well, I don't mean to be rude, but then there's not much you can say in a discussion about encryption...

---

Look, the important thing was to underscore that the https://news.ycombinator.com/item?id=23554823 comment was (apparently) wrong, I don't have any interest in winning a battle, I appreciate your enthusiasm, you probably currently don't know everything about cryptography or networking and there's nothing wrong with that, no one is born expert and no one knows everything there is to know. I have to go to sleep, bye

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#374
post #351
post #203

Earlier quoted context omitted.

There is a difference between US based software (e.g. servers located in the US), vs a CEO that's from the US (or China in this case). If the argument is that Zoom the company has routes traffic to China etc then fine I can get behind that. But if the argument is the CEO is from China I find that problematic. I mean it's not like internment of Japanese Americans is ok if it's limited to only first gen. EDIT: Also sou…

> Also sounds like you're saying that it's ok to avoid doing business with someone based on national origin, which I also find problematic. Sure, it can be problematic. I've seen articles about how Russian people in the software industry are having a very hard time because of what Putin's regime does. It's not fair for the people who have nothing to do with Putin and no exposure to him. But what is the alternative? P…

The alternative is to not discriminate based on national origin? Which is a protected class by the way. Nationality is also very different from national origin. Eric is an American citizen as far as I aware. You can point to the requirement to be bore in the US to run for presidency, but 1) that’s an edge case and 2) where is the line? Is it ok to discriminate again foreign born Americans but not against native born? What about native born Americans with relatives in China / Russian / North Korea.

I mean overall you really don’t find it an issue to blankedly judge an entire class of people based on what some people within that population does or could do?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#375

Earlier quoted context omitted.

Yes they will. You need to be thinking about LGBTQ people in many non-Western countries.

They are the 1%. 99% of people consider "privacy" a good value in abstract but will not lift a finger to protect their own privacy. It's virtue signalling.

Every single day I see more and more 100K liked tweets about this or that creepy person. I don't think people don't care about privacy, they just don't see the through line because it's abstract.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#376

Earlier quoted context omitted.

They are the 1%. 99% of people consider "privacy" a good value in abstract but will not lift a finger to protect their own privacy. It's virtue signalling.

I absolutely hate the term virtue signalling. It's always reductive and dismissive. If I am willing to go a LITTLE out of my way to protect my privacy, but not a LOT out of my way, am I "just virtue signalling"? If I continue to use a privacy-less platform (e.g. zoom/instagram/facebook) but just exercise caution with what I say using that medium, is that also "just virtue signalling"? I agree, evidence shows most peo…

https://www.adamsmith.org/blog/stop-saying-virtue-signalling

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#377

Earlier quoted context omitted.

Anybody that trusts zoom with anything even slightly sensitive these days is completely nuts. Yes, we know its easy to use.

99% of people do not care about privacy. They won't switch programs because a nation state might spy on them.

Zoom is being used by at least one court system for remote hearings. Their barebones IT people are completely incapable of independently verifying Zoom's encryption claims.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#378
Weibo approach; give your personal info and grow from there. Lots of info to pay with x00m ... World can’t trust they hold my record and share it with Gov (including and in particular chinese gov). The balance is not transparent. And you are not sure ... for the one I have no choice like studying my 2nd master degree. But the one I have ... a big NO. Already have google and Facebook that know a lot about me than myself. Do not want #ccp as well.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#379

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

It's crazy that zoom seems to have no real competitors who take this stuff seriously.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#380

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

You mean to imply that a business would just lie to customers? Come on, the market wouldn't permit that to happen! They'd lose all their customers! /s Edit: on a less sarcastic note, I'd be less critical of Zoom if their software were open source.

With your personal info kind of closed sourced. The program is not the ultimate issue.

And they can be changed without you knowing it. Do you have a Fingerprint that what you get is what they share?

Post reply on HN