Live data from Hacker News

SpaceX bans Zoom over privacy concerns

reuters.com

101–110 of 301 posts

Re: SpaceX bans Zoom over privacy concerns

#101
post #81
post #4

The fact that they show end users (no pun intended) an "end-to-end encrypted" badge on the meeting window itself, and elsewhere explain how a Zoom server (not Zoom client) is what constitutes an "end" despite the whole rest of the electronic communication industry using "end-to-end" to refer exclusively to user agents, is bonkers.

Apple does the same thing, where they claim iMessage is ETE encrypted, but the keys (so capabilities to read) are stored on their servers.

This is not true. Don't spread FUD. Apple does not have the ability to read your messages. All messages stored on their servers are encrypted with keys that live only on the phone.

iMessage doesn't store your decryption keys on Apple's servers unless you opt into iCloud backup which is a whole different service and security concern.

Re: SpaceX bans Zoom over privacy concerns

#102
post #88

Earlier quoted context omitted.

No, it doesn't. https://support.apple.com/guide/security/how-imessage-sends-...

I think this article is a bit over my head, but if Apple never has possession of users' private keys, how are they able to recover iMessage conversations when a phone is lost/stolen (which I know they can do)?

They can only do that if you have backed up your phone. If you haven't they cannot recover your messages.

Re: SpaceX bans Zoom over privacy concerns

#103
post #95

That's the right thing to do. If SpaceX is important to national security, then Zoom security and privacy is so bad, that a bad actor could steal SpaceX technology. At my previous job, we used to dial in random zoom numbers and entered into random conversations of other companies. Once we landed into a Facebook call where they were talking about Libra (before it was a thing). If you turn of camera and video, the host…

Doesn’t it chime when someone enters?

Re: SpaceX bans Zoom over privacy concerns

#104
post #81

Earlier quoted context omitted.

Apple does the same thing, where they claim iMessage is ETE encrypted, but the keys (so capabilities to read) are stored on their servers.

This is not true. Don't spread FUD. Apple does not have the ability to read your messages. All messages stored on their servers are encrypted with keys that live only on the phone. iMessage doesn't store your decryption keys on Apple's servers unless you opt into iCloud backup which is a whole different service and security concern.

Most people use iCloud backup. Even if you don't, your messages are still sent to Apple by the recipient. And Apple prohibits third party backup services.

> Apple does not have the ability to read your messages.

iCloud backup is an Apple service and it has the ability to read most of your messages even if you don't use it, which makes this statement categorically false.

Re: SpaceX bans Zoom over privacy concerns

#105
post #88

Earlier quoted context omitted.

No, it doesn't. https://support.apple.com/guide/security/how-imessage-sends-...

Yes, it does. The messages are 'end to end' encrypted in the iMessage service, but then iMessage backs up its encryption key in the iCloud backup service, defeating the point. "If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices." https://support.apple.com/en-us/H…

That is true of any end-to-end solution. If you back up your private keys, anyone who has access to your backup would be able to access the encrypted messages. Remember, you can turn off iCloud backup if you're worried about Apple accessing your keys.

Ultimately, it's false to equate iMessage's encryption scheme, which is end-to-end, to an encryption scheme that requires a server to relay decrypted data.

Re: SpaceX bans Zoom over privacy concerns

#106
post #10
post #3

SpaceX is strategic national defense, so this makes sense. I expect many similar companies to follow suit.

Seems like any organization under ITAR should prefer in-house solutions in areas relating to dissemination of sensitive design notes.

"In house (software)" is usually synonyms with "not properly tested or secured"... I'd generally rather they relied on third party code audited by the nations security services.

Re: SpaceX bans Zoom over privacy concerns

#107
post #78

Earlier quoted context omitted.

Can't seem to find it right now :/ sorry.

Plausible though, considering Musk’s fundamentalist tone

And the amount of classified material they handle, and the fact that Jeff Bezos is a direct competitor so Amazon is very very closely affiliated with a direct competitor.

Re: SpaceX bans Zoom over privacy concerns

#108

Earlier quoted context omitted.

In my experience Google's Hangout Meetings have been at least as good or better quality and the interface is far superior in my opinion. For example it works in the browser without any plugins (even in Firefox.)

The quality send to suffer when there are a large number of participants. Which is the reason zoom gets used so much.

My company uses Google meets and it works flawlessly with more than 100 people in a call. Automatic integration with GSuite and Chrome box are an added bonus.

Re: SpaceX bans Zoom over privacy concerns

#109

Earlier quoted context omitted.

Yes, it does. The messages are 'end to end' encrypted in the iMessage service, but then iMessage backs up its encryption key in the iCloud backup service, defeating the point. "If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices." https://support.apple.com/en-us/H…

That is true of any end-to-end solution. If you back up your private keys, anyone who has access to your backup would be able to access the encrypted messages. Remember, you can turn off iCloud backup if you're worried about Apple accessing your keys. Ultimately, it's false to equate iMessage's encryption scheme, which is end-to-end, to an encryption scheme that requires a server to relay decrypted data.

> That is true of any end-to-end solution.

Utterly false. Real end-to-end encryption would encrypt the backup with a key that is not available to the backup service (e.g. derived from a passphrase not sent to the server).

Of course this system has better usability, which is why Apple does it. But it's still a farce to call a system where Apple has the ability to decrypt the majority of messages "end-to-end" encrypted. The fact that it's through the backup servers instead of the iMessage servers makes no difference.

What's more, it's possible to do better without sacrificing usability. For several years Android has been end-to-end encrypting backups using the user's lock screen passcode, with protection against brute force attacks provided by hardware secure elements. https://security.googleblog.com/2018/10/google-and-android-h...

Re: SpaceX bans Zoom over privacy concerns

#110
post #95

That's the right thing to do. If SpaceX is important to national security, then Zoom security and privacy is so bad, that a bad actor could steal SpaceX technology. At my previous job, we used to dial in random zoom numbers and entered into random conversations of other companies. Once we landed into a Facebook call where they were talking about Libra (before it was a thing). If you turn of camera and video, the host…

Doesn’t it chime when someone enters?

Sure, but with a large enough call, legitimate users may come and go during the call too.
Post reply on HN