Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

381–390 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#381
post #6

"To make this possible, Free/Basic users seeking access to E2EE will participate in a one-time process that will prompt the user for additional pieces of information, such as verifying a phone number via a text message. Many leading companies perform similar steps on account creation to reduce the mass creation of abusive accounts." Perfect instrument to collect more personal data.

Discord recently demanded my cell phone number to be able to type messages. I declined, contacted customer service, who offered no other way to authenticate. I will not be using Discord anymore and will recommend to everyone I know to avoid it as well. There is no need to use my cell phone or any telephone number when you already have a means of communication via email or any other channel.

If you live in the US, burner SIMs are cheap and anonymous.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#382
post #44

Earlier quoted context omitted.

How is it racist to suggest that Zoom has Chinese influences (seemingly not farfetched based on the equity ownership mentioned above and not at all disputed based on the technicality of Zoom being a US company)?

It is not racist to suggest that the Chinese government influences companies. It is racist to suggest that Chinese people are automatically predispositioned to certain actions.

That was never suggested. Zoom is developed almost entirely in China, which means it is effectively a Chinese company under full influence of the CCP.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#383

Earlier quoted context omitted.

I absolutely hate the term virtue signalling. It's always reductive and dismissive. If I am willing to go a LITTLE out of my way to protect my privacy, but not a LOT out of my way, am I "just virtue signalling"? If I continue to use a privacy-less platform (e.g. zoom/instagram/facebook) but just exercise caution with what I say using that medium, is that also "just virtue signalling"? I agree, evidence shows most peo…

https://www.adamsmith.org/blog/stop-saying-virtue-signalling

100% agreed. It's almost exclusively used as an ad hominem by people who lack that particular virtue to dismiss people who espouse a caring viewpoint.

If you want to argue that your target does less to further that particular cause than you do, fine. If you want to argue the cause is misguided, fine.

But using the term is just lazy.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#384

Earlier quoted context omitted.

This blog post specifically says that it's a walk-back of the policy announced in your link.

My read on this is that they found a way to backdoor all supposedly E2E-encrypted calls and legal compliance is no longer a problem for them. Perhaps I’m being too cynical.

It's E2EE properly, but just ignore that "CCPBot" user in your server that isn't visible anywhere.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#385

> All Zoom users will continue to use AES 256 GCM transport encryption as the default encryption, one of the strongest encryption standards in use today. I’m glad that Zoom is finally implementing E2E encryption, but I hate that they have been (and still are) advertising “full encryption” and using jargon like “AES 256 GCM” to deceive users into thinking they’re using anything more than SSL.

They previously fraudulently advertised "end to end encryption" when it was not. I wouldn't be surprised that they continue to lie.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#386
post #182

Oh god... Let this die already, they had their chance -- it's gone. Nobody in their right mind would touch Zoom with an 10" pole.

I wish it was true. Every meeting at my job requires Zoom.

Then your job has security staff so careless that they don't care about IP exfiltration to China.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#387
post #67

Earlier quoted context omitted.

There was a time when outside traffic routed through china. I believe zoom said it was a mistake. I'm not convinced that a setting alone should provide much confidence in terms of traffic routing considering that it can always be changed independent of what setting in the application you make.

> I believe zoom said it was a mistake. Yes, zoom said it was unintentional. For me, that's hard to believe. They weren't routing the call itself through China, they were just sending the encryption keys to a server in china. That seems pretty intentional. Even if they weren't routing the call through China from a user's perspective, their US server could still be sending the call data to China or recording the call…

A product developed almost entirely within China is beholden to the whims of the CCP. Especially a billion dollar company. There is literally no escaping this reality.

If the CCP wants the keys, they'll get them.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#388

I am surprised at how unforgiving everyone is here. Zoom owned their mistakes publicly and trying to improve on that as soon as possible. How much more can you get ? Looking back you can see such incidents with all kinds of companies like faang. Don’t buy into surface level news and get outraged. This is a fantastic product and I think they deserve a chance to correct themselves.

The difference is that Zoom is developed almost entirely within China, making them beholden to CCP influence and laws.

Can you name a single company in China that offers true E2EE? All the messaging apps are utterly compromised and running real-time surveillance and censoring, for example.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#389
post #373

Earlier quoted context omitted.

The central server is the "middleman" as I am using that term. Routers are not middlemen under the meaning I am using. I am referring to peer-to-peer without any supernode forwarding traffic. No central server. There may be a "rendezvous server" involved in allowing two nodes to discover how to connect to one another, however that server does not route traffic. I never implied a need for encryption associated with pe…

I know that the term "peer-to-peer" could be interpreted in many ways, but to the best of my knowledge it is usually interpreted how I wrote above. Which I think it's pretty much how you defined it too in your (last) comment, so I'm not sure what we're debating. The important thing was that no one reading these comments get the impression that the multitude of systems that describe themselves as "peer-to-peer" are fo…

Just because the peer-to-peer software known to you may suck does not mean that the concept of peer-to-peer is obsolete. Nevermind Wireguard and other known examples of peer-to-peer software that does not suck, consider that there is software you do not know about. The idea that "peer-to-peer" is Napster plus some list of crappy, widely known software fiddling around with DHTs and dreaming about "the next big thing" is nonsense. Peer-to-peer is just a design principle The term the parent comment used was "middle man" not man-in-the-middle. As for "E2EE", I have never seen djb even use that term. I see many untrustworthy "tech" companies using it though.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#390

Earlier quoted context omitted.

One thing that has changed is that their userbase broadened. They were mostly focused on workplace meetings. If that's your focus, then most of your users are employees of some company whose contact information you have. Users with unverified identities are a corner case that you may not feel is worth trying to get right. Thanks to the pandemic, they have millions of new users who use Zoom for personal purposes (meet…

They have more users, but so what? They suddenly found (privacy) religion, so now they can be trusted? That certainly sounds like a leap of faith. A blind one. Stop looking at the empty words they say, and start looking at their very intentional and malignant actions over the last few months/years.

I guess "broadened" could be interpreted two ways. I don't mean the numbers grew. I mean that userbase came to incorporate new, different types of users.
Post reply on HN