Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

481–490 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#481
post #225

Earlier quoted context omitted.

While I understand that on the surface seems "bad", you have to understand the CCP taps into people worldwide, and while I don't know his position per se, or finances -- or connection with China today. It doesn't paint a great picture, especially with espionage and CCP tactics. Look at previous German and USA interference w/ GE, Bosch, -- it's the same story. Except now it's highlight as "bad" to point out that conne…

I don't see how this isn't just discriminating based on national origin. It'd be one thing if there are actually some nefarious ties between Eric and CCP, but all we are going by is he's originally from China and there could be influence by CCP on people from China. It's not bad to point out a connection, it's bad to point out a possible connection based on nothing more than where the guy is from.

There is plenty of evidence suggesting that Zoom collaborates with the CCP without it, there was undue pressure to terminate activists without users from China.

It is best to focus on these sorts of links rather than someone merely being from China.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#482
post #472

Earlier quoted context omitted.

Twitter has been caught using phone numbers for security purposes / tackling fake accounts in the past for marketing purposes. Zoom has a very dubious history, involving China, lies and a complete lack of security. As for the same old same old? It hasn't been precisely in that form but criminals have used Facebook, Tor, Email, Discord, YouTube, Usenet, Skype, MySpace, and other technologies / sites to facilitate abus…

"twitter sells phone numbers so Zoom must do the same" - really? Maybe not, because you know, they have actual legitimate revenue that doesn't rely on advertising. So it's not like they have the same incentives... Also, you seem to acknowledge that there are legitimate concerns/ reasons to NOT offer E2E encryption for free users. Unlike all the other services you mention - Zoom users that care about illegitimate inte…

https://twitter.com/SenBlumenthal/status/1247510907992846337 You mean the features they lied about and may have the FTC chasing them for?

Yes, it is a problem, it's been a problem for a very long time. Criminals gravitate to the most convenient platform like anyone else but otherwise don't stop being criminals. It only serves to punish other people.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#484

Earlier quoted context omitted.

Anybody that trusts zoom with anything even slightly sensitive these days is completely nuts. Yes, we know its easy to use.

I gave Jitsi a spin last week and was surprised at how easy it is to use. If you have a browser you sont even need to install anything if you’re not on mobile.

Jitsi is the way to go as far as I know. It passed the grandma test.

https://meet.jit.si/

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#485
post #194

Earlier quoted context omitted.

Indeed, E2EE will enable criminals to go undetected. And this is a real problem. However, it’s an arms race that will end with criminals having proper, strong E2EE anyways. Trying to reverse this is like trying to reverse entropy, the toothpaste does not go back into the tube. It may seem like it is still doable now , but I’d be willing to place bets that feeling will evaporate shortly. Of course, criminals are ordin…

> Indeed, E2EE will enable criminals to go undetected. And this is a real problem. However, it’s an arms race that will end with criminals having proper, strong E2EE anyways. Individual child abusers aren’t part of a monolithic organization with training on how to secure their comms and practice OpSec. The number of criminals who still create evidence against themselves on unencrypted platforms (SMS, phone, etc) is s…

> I think the only way criminals will standardize on E2EE is if every platform and communication mechanism is E2EE by default. Otherwise they will continue to make mistakes or think they can slip under the radar.

FWIW, I believe this is the future if lawmakers don’t prevent it. A look at some E2EE software today:

- WhatsApp

- Matrix

- Signal

- iMessage

- Firefox Send

- MEGA

- ...

The list will grow.

In my opinion, E2EE today is like TLS 10 years ago. TLS was once a nice-to-have when it came to communication that was not strictly necessary to encrypt. Today, TLS is more sophisticated, stronger, and easier to implement than ever, and damn near a necessity for anything, even toys.

Granted... E2EE is necessarily harder, since it requires application-level implementation of crypto primitives, things definitely get complicated. Still, I believe the state of the art will continue to improve and tooling with it. Eventually there will probably be defacto libraries and maybe even OS frameworks to deal with E2EE key management, trust, etc.

To be clear, I view this as strictly a good thing and an inevitability. I don’t think transport encryption and encryption-at-rest are good enough anymore for private communication. Of course for public sites like Twitter or Tiktok it’s all you would logically get, but for any group or direct communication I now believe E2EE is slowly becoming the new baseline, and it’s mostly the complexity of it that hampers adoption.

Now that iMessage and WhatsApp are E2EE though, there is a lot of messages flowing that, exploits notwithstanding, are “truly” private, today, and I think the number will only go up. The only real question in my mind is, who’s next?

As far as criminals making slip-ups, this is guaranteed; even the best make mistakes obviously. But assuming all criminals are foolish and stupid is a mistake; I believe there’s a lot of selection bias in there, since we don’t get to find out those who truly never get caught. Time will tell if any of this really matters, or, if, as usual, it’s just another panic that has no tangible effects. I vote on the latter, but I still do believe proliferation of E2EE will change the game in ways we can’t really anticipate 100%.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#486
post #332

Earlier quoted context omitted.

Do you think there is no situation where it can be lawful for a law enforcement agency to perform a wiretap?

Yes

Well this is probably not the case if you are an American. See US code title 18 section 2516 paragraph 1.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#487

Earlier quoted context omitted.

Yes they will. You need to be thinking about LGBTQ people in many non-Western countries.

They are the 1%. 99% of people consider "privacy" a good value in abstract but will not lift a finger to protect their own privacy. It's virtue signalling.

Most yes, but I don't think it is only 1%. Virtue signaling is for increasing your standing towards a social group through a feigned declaration of values. You can be sloppy with your privacy and still think it to be of utmost importance. Nobody pats you on the back for being privacy aware in the mainstream. On the contrary, it is looked down upon becuase it is associated with tin foil hats right now.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#488

Earlier quoted context omitted.

I absolutely hate the term virtue signalling. It's always reductive and dismissive. If I am willing to go a LITTLE out of my way to protect my privacy, but not a LOT out of my way, am I "just virtue signalling"? If I continue to use a privacy-less platform (e.g. zoom/instagram/facebook) but just exercise caution with what I say using that medium, is that also "just virtue signalling"? I agree, evidence shows most peo…

Man you really hit the nail on the head with this. I’ve never been able to articulate why the term bothers me so much and you just absolutely nailed it. It’s like the derogatory “social justice warrior.” What? It’s bad to give a damn about people and advocate on their behalf? If having empathy means I’m “an SJW” then I’ll gladly wear that moniker.

The social justice and warrior part once hinted at the oxymoron of enforcing solidarity with violence. It was never meant to be criticism of social justice. The dialogue that degraded just beyond nuance. The term is probably 10 years old at least. Today it probably means just left-leaning person for most people.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#489

Earlier quoted context omitted.

https://www.adamsmith.org/blog/stop-saying-virtue-signalling

That article gives such a bad argument that I feel I have now become more pro using the term than before. All of the arguments have huge exceptions or contradict each other. Signaling being a term used by some niche fields. We have that happen all the time. It’s how language evolves. The article says to use show off instead of virtue signaling. Right after the next argument is assuming the person is disingenuous. Whi…

"To an asshole, all virtue looks like virtue signaling." -- https://twitter.com/drvox/status/1273472663621529604

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#490
post #103
post #6

"To make this possible, Free/Basic users seeking access to E2EE will participate in a one-time process that will prompt the user for additional pieces of information, such as verifying a phone number via a text message. Many leading companies perform similar steps on account creation to reduce the mass creation of abusive accounts." Perfect instrument to collect more personal data.

Is there any E2EE app that doesn't require verification? Whatsapp does. Even Signal requires a phone number.

Tox.chat

with added bonus of no central server

Post reply on HN