Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

461–470 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#461

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

I've always suspected they didn't want E2E encryption themselves, not because of any "work with the authorities" strategy.

end to end encryption would prevent lots of monetization strategies, such as indentifying people via facial recognition and voice printing and then using this data (along with transcripts for example) to "add value".

Now the "we have identified a path forward" bit makes me wonder if they can still pull it off. Maybe it's client-side identification with out-of-band notification.

Google makes an enormous amount of money identifying people.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#463
post #421

Earlier quoted context omitted.

Summary: Chinese government harass the relatives of the fugitive corruption suspects to force these suspects to return voluntarily. That's definitely one area the Chinese system is vastly behind the international standard. But this has not been conscious to me. When I was a child, we had horror stories of people sentenced to death penalty and were executed on superficial charges that sexual misconduct. And my parents…

I'll be honest, I'm not sure what your point is. Your response reads a bit like a defence of the practice, but I'm going to give you the benefit of the doubt (since there's an obvious language issue). I will say... it's curious to me that you seem to be well aware of such practices but still challenged the parent to provide examples (the implication being, that they were misinformed). Why did you ask the parent to pr…

#1 I was aware of the flaw in legal system. But the flaws I know was that the Chinese legal system was ineffective, inefficient, and quite a bit corrupted.

#2 I was not aware of the details of harassing on corruption suspects' relatives.

#3 I think it was reasonable to not able to link these 2 facts automatically together as self-evident.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#464

Earlier quoted context omitted.

Another way of looking at it is that Zoom is learning from its mistakes and making improvements that the market demands. I'm no Zoom fan (I'd even use BlueJeans first), but people on HN are always so eager to crucify a company for its past. If it made mistakes, get out the tar and feathers! If it doesn't fix those mistakes, get out more tar and feathers! If it fixes the mistakes, even more tar and feathers!

A generalization like “people on HN are always...” coming from a 3yr old HN user with 20k+ karma points looks like a case of the pot calling the kettle black. Criticisms of large corporations is a healthy part of the HN community IMO. In fact, if we didn’t criticize Zoom they might still be lying about their E2EE capabilities.

That's a fairly new account.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#465
I'm still skeptical about everything they propose as "secure" and "safe" after all the previous security issues and censoring meetings for the memorial of the 1989 Tiananmen massacre. Also, the one-time verification thing with phone number verification?...

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#466
post #446

Earlier quoted context omitted.

> Given their track record I’d expect this timeline to repeat itself so after they release this E2E encryption feature, security researchers will discover that it’s not true E2E encryption again. I mean, you can already look at the design if you wish, it was disclosed by Alex Stamos: https://twitter.com/alexstamos/status/1268061790954385408 TBH I'm sort of surprised they gave in to the new wave of criticism, their ar…

Their arguments for not giving it to free accounts was awful and the same trite which has been regurgitated for twenty years. The real reason is they want to be able to hand data over to China / NSA / marketers.

> The other safety issue is related to hosts creating meetings that are meant to facilitate really horrible abuse. These hosts mostly come in from VPNs, using throwaway email addresses, create self-service orgs and host a handful of meetings before creating a new identity.

It's honestly the first time I heard this justification - where else did you hear it in the last twenty years?

Also do you have some concrete reasons to believe Zoom hands over data to marketers? That's the first time I personally heard this claim - can you link me some evidence?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#468
post #121

Earlier quoted context omitted.

What makes you think they're abusing the term? Did you read their whitepaper? https://github.com/zoom/zoom-e2e-whitepaper

The whitepaper is fine, it's the comments from Alex Stemos that make me think they are abusing the term. https://twitter.com/alexstamos/status/1268061792527241216 He did not say they can't monitor calls. https://twitter.com/alexstamos/status/1268061795572314113 If they can enter the meeting, either they have to get confirmation from the host who would send the keys to the person entering the meeting or they already h…

Is this before or after their new E2EE plans?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#469
post #194

Earlier quoted context omitted.

Yeah - I'm pretty sure this is the real concern and verifying a phone number is reasonable trade-off. I know this argument is often quickly dismissed on HN since people see child abuse or 'going dark' as an easy excuse for the government to leverage to get more control (and it has been used for this), but that doesn't mean the problem isn't serious or doesn't exist. See this: https://www.nytimes.com/interactive/2019/…

Indeed, E2EE will enable criminals to go undetected. And this is a real problem. However, it’s an arms race that will end with criminals having proper, strong E2EE anyways. Trying to reverse this is like trying to reverse entropy, the toothpaste does not go back into the tube. It may seem like it is still doable now , but I’d be willing to place bets that feeling will evaporate shortly. Of course, criminals are ordin…

> Indeed, E2EE will enable criminals to go undetected. And this is a real problem. However, it’s an arms race that will end with criminals having proper, strong E2EE anyways.

Individual child abusers aren’t part of a monolithic organization with training on how to secure their comms and practice OpSec.

The number of criminals who still create evidence against themselves on unencrypted platforms (SMS, phone, etc) is significant, despite E2EE options already being available. People are even being arrested for rioting after admitting on public TikTok videos to participating.

I think the only way criminals will standardize on E2EE is if every platform and communication mechanism is E2EE by default. Otherwise they will continue to make mistakes or think they can slip under the radar.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#470

Earlier quoted context omitted.

Yes they will. You need to be thinking about LGBTQ people in many non-Western countries.

They are the 1%. 99% of people consider "privacy" a good value in abstract but will not lift a finger to protect their own privacy. It's virtue signalling.

To be pedantic LGBTQ are ~5% of the population in the US. With higher or lower numbers in the other countries. Source for the US: https://en.m.wikipedia.org/wiki/LGBT_demographics_of_the_Uni...
Post reply on HN