Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

511–520 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#511
post #422
post #334

Earlier quoted context omitted.

I don’t know, but as a black box it’s been extensively looked at. But nothing is unhackable even E2E.

How would one know that this black box works the same for every user? What would stop Apple from distributing a compromised update to everyone or to selected users?

Yep any protocol and any app can have this problem.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#512
post #476

Earlier quoted context omitted.

Your mistake is bringing a technical argument to a political question. My personal political answer to "how to have end-to-end encryption and prevent its use for child rape" would be to tax the companies which profit from E2EE, and use that money to fund death squads, which livestream dragging child rapists out of their home, anywhere in the world, and beating them to death with truncheons. I'm joking, of course (or…

This is creeping a little close to populist rhetoric. The crimes you've described are obviously awful but angry politics will only lead to knee-jerk solutions. In which ways do you think it is underfunded?

It's clearly underfunded in relation to the difficulty in prosecuting these cases. Banning E2EE is a way of lowering the bar of difficulty in prosecuting these cases. The crime is reprehensible, and worthy of enforcement due to the heinous nature of abuse. Curtailing abuse via violating human right to encrypt is not the way to end abuse. Thus, more funding is likely justified, if it leads to an end to abuse. This social benefit of reduction and elimination of abuse should not come at the expense of human rights and E2EE.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#513
post #373

Earlier quoted context omitted.

I know that the term "peer-to-peer" could be interpreted in many ways, but to the best of my knowledge it is usually interpreted how I wrote above. Which I think it's pretty much how you defined it too in your (last) comment, so I'm not sure what we're debating. The important thing was that no one reading these comments get the impression that the multitude of systems that describe themselves as "peer-to-peer" are fo…

Just because the peer-to-peer software known to you may suck does not mean that the concept of peer-to-peer is obsolete. Nevermind Wireguard and other known examples of peer-to-peer software that does not suck, consider that there is software you do not know about. The idea that "peer-to-peer" is Napster plus some list of crappy, widely known software fiddling around with DHTs and dreaming about "the next big thing"…

I don't know what's going on here, I never said that any peer-to-peer software sucks or that the concept is obsolete, in fact I much prefer it if a system is distributed/peer-to-peer.

All I said and cared to stress, to avoid that someone reading this make mistaken assumptions about p2p software (although probably few of this site's users would run the risk), is that ^^^they don't, as you claimed in https://news.ycombinator.com/item?id=23554823 , automatically imply "encryption that a middle man cannot decrypt"^^^.

You admitted you don't even know what end-to-end encryption is, and apparently don't know much about encryption, what are you debating?

---

> The term the parent comment used was "middle man" not man-in-the-middle

It's the same thing (unless the post author meant "a man of middle age")

---

> As for "E2EE", I have never seen djb even use that term

You mean Daniel J. Bernstein with djb? Do you mean that you are actually knowledgeable about encryption? I don't mean to be insulting but it didn't seem so (and there wouldn't be anything bad in that), it's hard to believe that someone with basic familiarity with encryption wouldn't know what end-to-end encryption is.

If with "that term" you meant the E2EE acronym, I indeed wouldn't be surprised if Daniel J. Bernstein never used it, it's the first time I see it myself (but it obviously doesn't mean anything more than "end-to-end encryption").

---

I don't know why you took it so personally, maybe I sounded aggressive in saying NO in uppercase, if so I'm sorry, it was just to make it more visible

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#514
post #412

Earlier quoted context omitted.

The idea that you can't attack someone's behavior is ridiculous. If you want to consider what i'm doing virtue signaling then go right ahead I guess.

Yes. You calling other people for virtue signalling is a form of virtue signalling in itself. Don’t you realize how ridiculous and useless this argument is?

Don't you understand that I am arguing that virtue signaling is real. You saying I am virtue signaling is only agreeing with my point.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#515

Earlier quoted context omitted.

No other company right now can get the reliability and “just works” like Zoom. If they open source everything, why wouldn’t all the competitors including the biggest companies in the world not start seeing how Zoom is doing things. We already see open source “borrowed” frequently. Amazon’s AWS being a regular.

> No other company right now can get the reliability and “just works” like Zoom. I disagree. Plenty of video chat software has comparable reliability and "just works"-ity. Google Meet, Skype, Microsoft Teams, Discord... Hell, Apple has had "just works" and "reliability" in their walled garden since FaceTime was introduced -- if you're willing to look only in their walled garden.

I haven't tried discord, but all of the other tools that you mention are materially worse than Zoom, in my experience.

Zoom is almost as good on a laptop as dedicated Cisco gear.

I have been video conferencing mostly for work for almost a decade, and Zoom is the best solution for that that I've encountered.

I recently changed roles, and the use of Zoom was a small reason to go with the company I did.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#516
post #508
post #305

Earlier quoted context omitted.

they didn't have a choice not to use servers in China?

They actually didn't. Their options were filtered servers in China or no services in China at all. We can collectively be upset at their decision but they ARE beholden to their shareholders as a public company. Abandoning the Chinese market entirely is something they could've tried, but their major shareholders made it pretty clear there would be a change of leadership if they tried. Unless you've got a magic bullet…

Ok it was the fault of their major shareholders, but then it's ok to make them pay their decision, I think (hoping that they're still holding those shares).

By the way, in general my understanding is that the "beholden to their shareholders as a public company" (and thus forced to make the most remunerative decisions) belief is a myth, a public company is free to make ethical choices (if its major shareholders don't oppose them).

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#517
post #195

Earlier quoted context omitted.

BlueJeans and RingCentral might as well be clones of Zoom. Amazon Chime and Microsoft Teams are fine for me too, but I'm not picky.

After the disastrous experience I had with BlueJeans this morning, I wouldn't include it as a quality or reliability match for Zoom. The company my wife works for can't get a reliable Teams conference going with anyone in France.

Zoom is a really great product.

The company lied about their encryption.

Both of these statements can be true, it's just a question of trade offs.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#518

Earlier quoted context omitted.

If I had to decide the official comms app for my employer, I'd be wary of Google, due to their poor track record with comms apps.

Meet is a GSuite product, and the only video-conferencing app in GSuite. Google doesn't fuck with GSuite.

I have to remind this to myself when I see features available for free which are not ported to GSuite (parental control, google assistant for home users, reminders, inbox in the past (it took I think a year to port it)

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#519
post #511
post #422

Earlier quoted context omitted.

How would one know that this black box works the same for every user? What would stop Apple from distributing a compromised update to everyone or to selected users?

Yep any protocol and any app can have this problem.

The protection against this problem is to have the app (or the platform it's running on) check before installing an update that the hash of the binary it has downloaded has been recorded in a public transparency log.

With closed source software, though, this doesn't give as much confidence, since a company could create a version which they send to everyone but which contains an "if (userId == NSA_TARGET)" conditional branch.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#520
post #356

Earlier quoted context omitted.

i don't think it'd work particularly well. people pay for zoom not because of 'enterprise support', but because they want features that they need (eg. meetings not automatically ending after 40 minutes).

The two aren't mutually exclusive though

how successful do you think zoom would be if their only value was support? do you think they'd be incentivized to create as frictionless a product as possible?
Post reply on HN