Live data from Hacker News

The facts around Zoom and encryption for meetings/webinars

blog.zoom.us

11–20 of 145 posts

Re: The facts around Zoom and encryption for meetings/webinars

#11
wow!! zoom you were better off not having written that blog. you guys are some shady assholes.

Everything from the text to the graphics are intended to mislead and obscure. I don’t think i’ve seen a company act in such bad faith since theranos was a thing.

Re: The facts around Zoom and encryption for meetings/webinars

#12
post #3

> For those who want additional control of their keys, an on-premise solution exists today for the entire meeting infrastructure, and a solution will be available later this year to allow organizations to leverage Zoom’s cloud infrastructure but host the key management system within their environment. Additionally, enterprise customers have the option to run certain versions of our connectors within their own data ce…

Doesn't Jitsi have the same problem? The solution is the same: Run your own server. End to end encrypted videoconferencing does not scale easily without a server. > Is Jitsi Meet end-to-end encrypted? #409 > ... "yes, https://meet.jit.si/ encrypts the communication, only the two clients and our server has access to them". ... [1] [1]: https://github.com/jitsi/jitsi-meet/issues/409

To me, this quote gave the impression that Jitsi developers similarly (and falsely) claim that it is end-to-end encrypted:

> Is Jitsi Meet end-to-end encrypted? #409

> ... "yes, https://meet.jit.si/ encrypts the communication, only the two clients and our server has access to them". ... [1]

In fact, "yes, .. " is an answer to the question "is it reasonable to use Jitsi Meet from an untrusted wifi network?". It was written by a user of Jitsi and not one of the developers.

A developer answers "when talking on meet.jit.si your stream is encrypted on the network but decrypted on the machine that hosts the bridge."

Re: The facts around Zoom and encryption for meetings/webinars

#14

Don’t all these products need to do this if one of the participants is using a regular phone? It’s just impossible to support phone dial in otherwise. They claim to do end to end encryption if there are no phones on the call.

it is unclear how key exchanges can be handled securely in these cases. The post seems to suggest Zoom cannot insert itself as middleman ("without showing on the participant list"). But that contradicts directly to how these "connectors" work.

Re: The facts around Zoom and encryption for meetings/webinars

#15

wow!! zoom you were better off not having written that blog. you guys are some shady assholes. Everything from the text to the graphics are intended to mislead and obscure. I don’t think i’ve seen a company act in such bad faith since theranos was a thing.

In my opinion they seem better off from this blog post. For example yesterday I read this comment[1] and it seemed to say Zoom always decrypts the content on the servers, in which case it's very bad to say it's "end-to-end encrypted". But this blog post explains that if you don't have any external connector attached, it in fact is end-to-end encrypted, no false advertising. When you have an external connector attached it seems to me very difficult if not impossible to make it end-to-end encrypted, so it's reasonable that it's not. The problem is that they continued to say it was end-to-end encrypted even in that case when it's not and not possible to do so.

[1] https://news.ycombinator.com/item?id=22754699

Re: The facts around Zoom and encryption for meetings/webinars

#16
post #3

Earlier quoted context omitted.

Doesn't Jitsi have the same problem? The solution is the same: Run your own server. End to end encrypted videoconferencing does not scale easily without a server. > Is Jitsi Meet end-to-end encrypted? #409 > ... "yes, https://meet.jit.si/ encrypts the communication, only the two clients and our server has access to them". ... [1] [1]: https://github.com/jitsi/jitsi-meet/issues/409

Yes... but in one case the software is entirely FOSS and readily deployable via a docker image. The Zoom server is not FOSS, or even accessible through their GitHub. https://github.com/jitsi/docker-jitsi-meet

Right. Let's assume I refuse to take on the responsibility of a videoconferencing server. What are my options to get Jitsi Meet? Can I pay a company to set up and maintain it? Or do I have to hunt for a videoconferencing engineer?

Re: The facts around Zoom and encryption for meetings/webinars

#18
How could they guarantee end-to-end if not all gadgets support encryption?!

Let's demand end-to-end encryption for people connecting via FAX machines to read only the comments.

Of course connecting via unreliable machines / protocols means Zoom must have some bridge on their side somewhere.

In light of this post it looks like for the majority of users it is end-to-end encrypted.

I don't even use Zoom, but really, these attacks are starting to be annoying. From what I've seen all Zoom's reply is bang-on and they will come out of this even stronger.

Re: The facts around Zoom and encryption for meetings/webinars

#19
post #13

In fairness, it sounds like it’s end to end encrypted until a legacy device connects. Am I misunderstanding something? This doesn’t seem like it should be controversial.

It wouldn't be controversial if they explicitly stated that, and took "End-to-end encryption for all meetings" off of their features page.

Re: The facts around Zoom and encryption for meetings/webinars

#20
Is there any evidence that other teleconferencing solutions meet or exceed what's described in this blog article?

I just find the Zoom hate weird. We have no reason to think Teams, Hangouts, or anything else does anything close to or better than this. Lots of reason to suspect they probably don't.

Don't get me wrong, I think the scrutiny is good, and will lead to positive outcomes. But we probably need to scrutinize all these vendors

Post reply on HN