Live data from Hacker News

The facts around Zoom and encryption for meetings/webinars

blog.zoom.us

1–10 of 145 posts

Re: The facts around Zoom and encryption for meetings/webinars

#2
> For those who want additional control of their keys, an on-premise solution exists today for the entire meeting infrastructure, and a solution will be available later this year to allow organizations to leverage Zoom’s cloud infrastructure but host the key management system within their environment. Additionally, enterprise customers have the option to run certain versions of our connectors within their own data centers if they would like to manage the decryption and translation process themselves.

So... privacy is a premium feature requiring you to self-host? Why not just run jitsi for free?

Re: The facts around Zoom and encryption for meetings/webinars

#3

> For those who want additional control of their keys, an on-premise solution exists today for the entire meeting infrastructure, and a solution will be available later this year to allow organizations to leverage Zoom’s cloud infrastructure but host the key management system within their environment. Additionally, enterprise customers have the option to run certain versions of our connectors within their own data ce…

Doesn't Jitsi have the same problem? The solution is the same: Run your own server. End to end encrypted videoconferencing does not scale easily without a server.

> Is Jitsi Meet end-to-end encrypted? #409

> ... "yes, https://meet.jit.si/ encrypts the communication, only the two clients and our server has access to them". ... [1]

[1]: https://github.com/jitsi/jitsi-meet/issues/409

Re: The facts around Zoom and encryption for meetings/webinars

#4
post #3

> For those who want additional control of their keys, an on-premise solution exists today for the entire meeting infrastructure, and a solution will be available later this year to allow organizations to leverage Zoom’s cloud infrastructure but host the key management system within their environment. Additionally, enterprise customers have the option to run certain versions of our connectors within their own data ce…

Doesn't Jitsi have the same problem? The solution is the same: Run your own server. End to end encrypted videoconferencing does not scale easily without a server. > Is Jitsi Meet end-to-end encrypted? #409 > ... "yes, https://meet.jit.si/ encrypts the communication, only the two clients and our server has access to them". ... [1] [1]: https://github.com/jitsi/jitsi-meet/issues/409

Yes... but in one case the software is entirely FOSS and readily deployable via a docker image. The Zoom server is not FOSS, or even accessible through their GitHub.

https://github.com/jitsi/docker-jitsi-meet

Re: The facts around Zoom and encryption for meetings/webinars

#5
post #3

> For those who want additional control of their keys, an on-premise solution exists today for the entire meeting infrastructure, and a solution will be available later this year to allow organizations to leverage Zoom’s cloud infrastructure but host the key management system within their environment. Additionally, enterprise customers have the option to run certain versions of our connectors within their own data ce…

Doesn't Jitsi have the same problem? The solution is the same: Run your own server. End to end encrypted videoconferencing does not scale easily without a server. > Is Jitsi Meet end-to-end encrypted? #409 > ... "yes, https://meet.jit.si/ encrypts the communication, only the two clients and our server has access to them". ... [1] [1]: https://github.com/jitsi/jitsi-meet/issues/409

Uh, I can't believe that their answer is "yes.....and our server has access to them."

Which is it Jitsi team? You can't have your users' cake and eat it, too.

Re: The facts around Zoom and encryption for meetings/webinars

#7
"Zoom has always strived to use encryption to protect content in as many scenarios as possible, and in that spirit, we used the term end-to-end encryption. While we never intended to deceive any of our customers, we recognize that there is a discrepancy between the commonly accepted definition of end-to-end encryption and how we were using it."

In other words, "We deceived our customers with false advertising but we're never going to admit that."

Re: The facts around Zoom and encryption for meetings/webinars

#9
post #6

I love that the address one issue and ignore all the other security holes. They have a structural problem with taking security seriously.

They had a separate post about privacy/security in general: https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u...
Post reply on HN