Live data from Hacker News

Zoom’s encryption has links to China, researchers discover

theintercept.com

101–110 of 137 posts

Re: Zoom’s encryption has links to China, researchers discover

#101
post #59

Earlier quoted context omitted.

Software by an American Company[0] founded by a man who's been here since the 90s[1] is now "Chinese Tech"? Is everything from Paul Graham "British Tech"? Are Apple Products now "Chinese Tech" because of their keyservers in China[2]? [0] https://en.m.wikipedia.org/wiki/Zoom_Video_Communications [1] https://en.m.wikipedia.org/wiki/Eric_Yuan [2] https://www.reuters.com/article/us-china-apple-icloud-insigh...

I find it shocking that your comment is being downvoted. If Zoom is “Chinese tech” because of the CEO’s ethnicity, then I suppose NVIDIA and AMD are now “Chinese tech.”

I never said anything about ethnicity. Maybe "tech with critical security related software components developed and hosted in China, by Chinese nationals, thus clearly subject to draconian Chinese laws and potentially exposed to Chinese government and military influence" would be more precise. That's as close to "Chinese tech" though, as makes no difference.

I would expect a more stringent approach to something used by a government to actually conduct "governing", and in the time of crisis at that!

Re: Zoom’s encryption has links to China, researchers discover

#102

Earlier quoted context omitted.

Is ECB any worse than any other deterministic encryption? Deterministic encryption can be ok if the data that you’re encrypting is already really random (high min-entropy). Compressed audio and video streams have a decent amount of entropy. Probably not enough to satisfy a cryptographer, but it’s probably enough to make it very difficult to learn much from 128-bit AES ECB blocks. Note that everyone’s favorite ECB exa…

> Is ECB any worse than any other deterministic encryption? Yes, it's objectively worse than literally any other AES mode. You wouldn't need to depend on compression to protect your data.

Note that I was asking specifically about deterministic modes. Those include SIV mode [1] but not the more common CBC, CTR, etc.

Any deterministic encryption relies on entropy of the plaintext for security [2]. This is not unique to ECB.

My objection was to the hyperbolic phrase "trivially broken." SIV mode is deterministic, but nobody who understands what it does would call it "trivially broken."

And I'm definitely not saying that anyone should use ECB. Just that in this case, the vulnerability may not live up to the hype.

By all means, go ahead bashing on Zoom. It's the cool thing to do these days, and clearly they've done enough to deserve most of it.

[1] https://web.cs.ucdavis.edu/~rogaway/papers/siv.pdf

[2] https://eprint.iacr.org/2006/186

Re: Zoom’s encryption has links to China, researchers discover

#103
post #43

Earlier quoted context omitted.

The CL article seems to be underplaying the vulnerability of ECB, with the "not recommended" description. Any cryptographer will tell you it's downright trivially broken, with textbook practical attacks taught to undergrads.

Is ECB any worse than any other deterministic encryption? Deterministic encryption can be ok if the data that you’re encrypting is already really random (high min-entropy). Compressed audio and video streams have a decent amount of entropy. Probably not enough to satisfy a cryptographer, but it’s probably enough to make it very difficult to learn much from 128-bit AES ECB blocks. Note that everyone’s favorite ECB exa…

All this is technically true. As long as you believe that you will never ever under any circumstance send the same video chunk twice under the same key, you get all the security guarantees of a real CPA-secure (=> non-deterministic) symmetric cipher. But 1. I don't think this is a reasonable belief, and 2. even if it is, why chance it when you can use CTR mode and a random nonce, with practically zero overhead?

Re: Zoom’s encryption has links to China, researchers discover

#104

Earlier quoted context omitted.

Is ECB any worse than any other deterministic encryption? Deterministic encryption can be ok if the data that you’re encrypting is already really random (high min-entropy). Compressed audio and video streams have a decent amount of entropy. Probably not enough to satisfy a cryptographer, but it’s probably enough to make it very difficult to learn much from 128-bit AES ECB blocks. Note that everyone’s favorite ECB exa…

All this is technically true. As long as you believe that you will never ever under any circumstance send the same video chunk twice under the same key, you get all the security guarantees of a real CPA-secure (=> non-deterministic) symmetric cipher. But 1. I don't think this is a reasonable belief, and 2. even if it is, why chance it when you can use CTR mode and a random nonce, with practically zero overhead?

> As long as you believe that you will never ever under any circumstance send the same video chunk twice under the same key

Yes, that is the question here, and it's a really fascinating one. How often do you send two identical 128-bit chunks in practice? How much does it depend on the quality of your webcam and your lighting? If the video is grainy and splotchy in the background, you're getting a lot of randomness in your data. How much does that help? Any at all? Or are you still totally screwed?

> even if it is, why chance it when you can use CTR mode and a random nonce, with practically zero overhead?

1000 times this. Crypto code should be like the safety components in a car or an airplane. You wouldn't buy a car with seatbelts or brakes that work 90% or even 95% of the time. In the same way, you shouldn't write network code that probably doesn't let an adversary figure out everything you're sending.

Re: Zoom’s encryption has links to China, researchers discover

#105

I've really grown to dislike the "China == bad" thing, yes, they're domestically authoritarian, without excusing any of it, I like to act on hard evidence, not hear say, I am stunned that after the Bloomberg fiasco these kind of stories didn't take a hit. P.S. Personally, I don't consider the NSA having my data as being any better, thank you. EDIT: Just to be clear, I don't think Zoom's encryption claims should be tr…

I've really grown to dislike the "people who presumably consider themselves ethical defending a regime that represses free speech and expression, brutally crushes dissenters, disappears ethical doctors, is led by a 'president for life' dictator, and has literally hauled off 1M muslims to internment campus where their organs are being harvested and their culture is being erased, thing".

Maybe am just cynical, but the West has done all of the same things. Worse, every time someone in the developing world was trying to help their people, the U.S./UK swept in to overthrow them. So spare me.

I do not like China's domestic policies, but I've came to see them as just another cynical player in "the game", trying to survive. Just another (yes, often evil), empire.

The only way to progress is to stop building empires. But that goes for all the players, not just China.

Re: Zoom’s encryption has links to China, researchers discover

#106
post #5

And another case of lying in marketing: "A security white paper from the company claims that Zoom meetings are protected using 256-bit AES keys, but the Citizen Lab researchers confirmed the keys in use are actually only 128-bit." How do they keep doing this? Do they just put whatever sells best in the documents and implement something else? First the end2end thing, now 128 instead of 256 bits. How many more are we g…

> Do they just put whatever sells best in the documents and implement something else?

I've worked 10+ years in Silicon Valley and the motto "it is better to beg forgiveness than ask for permission" really does ring true. This manifests at all levels from ICs and up the chain of leadership. People do what gets them their bonus/promotion and everything else be damned. "Acquire the customer and fix the security problem later" was the mindset here.

Re: Zoom’s encryption has links to China, researchers discover

#107
post #80
post #78

Earlier quoted context omitted.

So does Apple.

At Apple Stores. Not developing their software.

https://jobs.apple.com/en-us/search?location=china-CHNC&team...

Look for yourself how many postings they have for software and hardware positions in China.

Re: Zoom’s encryption has links to China, researchers discover

#108

Earlier quoted context omitted.

I find it shocking that your comment is being downvoted. If Zoom is “Chinese tech” because of the CEO’s ethnicity, then I suppose NVIDIA and AMD are now “Chinese tech.”

I never said anything about ethnicity. Maybe "tech with critical security related software components developed and hosted in China, by Chinese nationals, thus clearly subject to draconian Chinese laws and potentially exposed to Chinese government and military influence" would be more precise. That's as close to "Chinese tech" though, as makes no difference. I would expect a more stringent approach to something used…

https://nvidia.wd5.myworkdayjobs.com/NVIDIAExternalCareerSit...

https://jobs.amd.com/search/?createNewAlert=false&q=&locatio...

The Nvidia WeWork link might not work but you can look for job postings and filter for China yourself.

Re: Zoom’s encryption has links to China, researchers discover

#109
post #75

Earlier quoted context omitted.

Apple does not have access to FaceTime keys or iMessage keys for that matter. They are truly end-to-end encrypted, and I don’t think there is any need to cheapen or muddy the term for the sake of marketers.

They can still write software to insert themselves into the key exchange flow and eavesdrop on a conversation. E.g. I don’t believe there is anything stopping Apple from pretending a participant bought a new device.

That's a much less scary attack vector though, since they would also need to somehow impersonate the participants voice or image right?

Re: Zoom’s encryption has links to China, researchers discover

#110

Earlier quoted context omitted.

That is truly amazing. I know precious little about encryption, but I assumed everyone knows that ECB is bad and that CBC is the only sensible way to do AES. [edited for typo]

Your first point is correct, second is definitely not.

See how precious little I know about encryption? And yet even I know that ECB is a terrible choice!

(In minor defense of self, I should have said CBC or "later").

Post reply on HN