Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

451–460 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#451

Earlier quoted context omitted.

Anybody that trusts zoom with anything even slightly sensitive these days is completely nuts. Yes, we know its easy to use.

99% of people do not care about privacy. They won't switch programs because a nation state might spy on them.

It's far too black-and-white to hold the belief you wrote. Pessimism is an indulgence.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#453

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

Alex Stamos had a good thread on some of the costs and benefits of E2EE. There is a cost https://twitter.com/alexstamos/status/1268219067707453441

I don't really like Mr. Stamos because he has been saying everything he can to discredit Facebook since he got ejected after a row with management. This could just be my perception of him but I don't find his arguments to be entirely in good faith.

Denying E2EE is a cost as you are punishing people for the crimes of another, this is depriving them of their hard-earned freedoms and liberties, for something someone else has done or may do.

Look at the activism going on today. BLM, dissidents in China, the rise of oppressive far-right governments in Europe like Hungary. I am sure if you dig far enough, you could find many people fighting in obscure causes, high profile causes, in a number of countries, who would fear the fist of an oppressive government.

What if the FBI / NSA decides to surveil BLM, as they already are? What if the CCP strikes down a dissident as they already have on Zoom? What if Orban decides you are a secret agent of George Soros plotting to undermine the government? Is it the case that everyone should roll over because a criminal might use the same means as them?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#454
post #435

Aside from whatever the Zoom news story of the day is, it's completely unsurprising that they're eating WebEx's lunch. I just tried scheduling a meeting and it was outrageously bad. The bright green "Start" and "Schedule Meeting" buttons just pop up an error. The correct button to progress is the dark grey (as if disabled) "Next" button. It prompts me to create a "personal conference number", whatever that is. This e…

Ugh. And Google Meet us even worse. My kids' schools use it, for supposed privacy reasons. Audio is absolutely terrible. Echoey as hell. UI is a disaster. You have to install a third party Chrome extension just to get grid view, which keeps breaking. My work uses Zoom, and it's night and day and smooth everything is.

As a big ol' disclaimer, I work at Google. However, it's no longer necessary to install a 3rd party extension for grid view, it was added natively a few months ago.

Also IMO there's been some drastic improvements to audio quality lately. My very noisy fan that triggers my mic in Discord is totally inaudible in Google Meet, even when I'm talking.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#455

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

Zoom’s engineering team is based in the PRC. This opens them up to pressure from the dictatorship which has made large scale industrial espionage a public policy goal. Somebody is listening, and likely transcribing, every call at organizations of interest. The source code, public statements, etc are irrelevant; if the PLA wants a Chinese national in China to do something, they will. The penalties for noncompliance ar…

And at the same time they are probably pressured by the nsa. They should just upload every call to YouTube so any intelligence service can access them

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#456

Earlier quoted context omitted.

Just curious: Fake news was coined by Trump, so you're agreeing it was a meaningful usage?

Ironically, it was not coined by Trump. https://twitter.com/CraigSilverman/status/522179364767924224 and https://www.theverge.com/2014/10/22/7028983/fake-news-sites-... are good examples of its use pre-Trump. By the time Trump started applying it to actual news outlets, it was already in relatively common use.

The irony runs deep in this case. The examples you point out are good ones for the term in common use through the end of 2016. Then this happened:

https://www.cnn.com/2016/12/08/politics/hillary-clinton-fake...

December 2016 Hillary Clinton decides to use the term in reference to recent events like her losing the election. The media picks up on it and the term starts to lose its meaning. Then Donald Trump, always with a nose for catch phrase politics, picks up the term and runs with it, a turn of events that someone on HN called a huge "own goal" by the media, and I can't say I disagree with that assessment.

For more analysis of this cultural specimen:

https://www.bbc.com/news/blogs-trending-42724320

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#457
post #356

Earlier quoted context omitted.

Enterprise support is the usual answer, and it'd probably work pretty well for Zoom given how many enterprises are already willing to pay Zoom for said support.

i don't think it'd work particularly well. people pay for zoom not because of 'enterprise support', but because they want features that they need (eg. meetings not automatically ending after 40 minutes).

The two aren't mutually exclusive though

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#458
post #338

Earlier quoted context omitted.

I'm actually more alarmed than I was before the announcement, because it indicates that there wasn't sufficient pressure for them not to do this. Watch them put the key in a predictable memory location, then have a subtle vulnerability elsewhere that lets them exfiltrate the client-generated key at any time. Anyone with views that might be dangerous to reveal to state actors should be very, very wary.

Anybody that trusts zoom with anything even slightly sensitive these days is completely nuts. Yes, we know its easy to use.

I gave Jitsi a spin last week and was surprised at how easy it is to use. If you have a browser you sont even need to install anything if you’re not on mobile.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#459

Earlier quoted context omitted.

Only 4 comments in and we hit one of the four boogymen of the civil rights apocalypse. How many comments until we get to domestic terrorism or illegal drugs?

> one of the four boogymen of the civil rights apocalypse The public is willing trade away privacy in exchange for protection from certain categories of risk. Instead of denying that, one can lean into it by ensuring strict definitions and enforcement options within those categories while preserving full privacy for those without. Arguing pedophile rings and terrorism are a cost of a privacy policy is a good way to s…

What if the only practical way to 100% stop all crime is to shutdown the internet?

Now, I'm not saying there is nothing that can be done to reduce it. I very much hope there can be, especially if counsellors can find warning signs and we can better figure out how to spot the danger signs, both online and off.

Facebook took a good step forward by putting warnings up to minors when someone outside of their social circles has contacted many others, although there are other things which could be done.

Should they be allowed to contact them through onion routing during such situations? Where do you draw the line of when such technologies can be used? Is it better not to open this can of worms and risk a slippery descent? What are the chances of false positives, will it unfairly impact relatives? Will it give a black mark to privacy technologies and civil liberties to be associated with automatic blocks? What if minors want to engage in activism, should this be limited? At what point does pushing and pushing start the lie about your age shenanigans again?

This is about Facebook here but it ties back to arguments about doing this or that for the greater good.

Is a more grounded approach better? Ensure minors are well-educated of the risks and dangers online? Invest in mental health services to avoid minors falling into depressive slumps where they might be susceptible to such criminals? In the rare event they drag anyone back home, whether they think they're of a similar age or not, they bring them before the parents first?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#460
post #329

Earlier quoted context omitted.

E2EE and open source: the two things people assume automatically makes things super-crazy-secure. The implementation of E2EE must be robust and there must be somebody who is actually checking the source code (plus verifiable builds)

If you go down that road, you can make this argument infinitely. Even if you verify your builds, you cannot know if the software you are using to check the build isn't compromised. Or if you check the software you use to check the build, you have to check the software doing that check and so on. Nothing makes software automatically super-crazy-secure. Absolute security doesn't exist.

You'd get close by doing all you mentioned, but also compiling and hosting the code and infrastructure yourself. Not often this is feasible.
Post reply on HN