Live data from Hacker News

Zoom’s encryption has links to China, researchers discover

theintercept.com

111–120 of 137 posts

Re: Zoom’s encryption has links to China, researchers discover

#111

Earlier quoted context omitted.

They can still write software to insert themselves into the key exchange flow and eavesdrop on a conversation. E.g. I don’t believe there is anything stopping Apple from pretending a participant bought a new device.

That's a much less scary attack vector though, since they would also need to somehow impersonate the participants voice or image right?

Think of it as aiming a phone at another phone. Apple would decrypt everything and then reencrypt it.

Re: Zoom’s encryption has links to China, researchers discover

#112
post #85

OK, this makes things clearer. Zoom does in fact encrypt their streams from client to client but they have easy access to the keys. In their recent post about this question they apologize for what they admit to be an incorrect use of the phrase "end to end encryption". They base this on the existence of things like the gateways used to the regular telephone network. It seems like an odd way to spin this. Why didn't t…

Apple doesn’t have access to the keys used to encrypt FaceTime calls. They are in fact end to end. Zoom is not. https://support.apple.com/en-us/HT209110

That's just a bald statement by the entity that would have to be deceitful. It doesn't even specify how the key exchange is done.

Re: Zoom’s encryption has links to China, researchers discover

#113
post #90

Earlier quoted context omitted.

Perhaps as that was based on random internet comments. FaceTime still ends up at level 2 with Zoom and the rest because Apple can MITM the traffic without much trouble. There is no provision for the user to prevent/detect a MITM attack in FaceTime or iMessage.

So you’re saying there should be a three-level consumer standard where the third level excludes any possible consumer product? Please don’t pretend that Apple and Zoom’s approaches are equivalent here. There is a substantial difference that deserves to be acknowledged. Anyone whose threat model includes Apple subverting their own security architecture shouldn’t be using any communication platforms.

There is nothing wrong with allowing a consumer to verify that they are talking to who they think they are talking to. Is Signal a consumer product?

Zoom specifically states that they do not have access to session keys. Apple doesn't even make such a statement.

Re: Zoom’s encryption has links to China, researchers discover

#114
post #85

OK, this makes things clearer. Zoom does in fact encrypt their streams from client to client but they have easy access to the keys. In their recent post about this question they apologize for what they admit to be an incorrect use of the phrase "end to end encryption". They base this on the existence of things like the gateways used to the regular telephone network. It seems like an odd way to spin this. Why didn't t…

Apple doesn’t have access to the keys used to encrypt FaceTime calls. They are in fact end to end. Zoom is not. https://support.apple.com/en-us/HT209110

Yes, Apple literally doesn't have access to the keys if they do nothing. If they do something, they have very easy access to the keys.

Re: Zoom’s encryption has links to China, researchers discover

#115

Earlier quoted context omitted.

> Is ECB any worse than any other deterministic encryption? Yes, it's objectively worse than literally any other AES mode. You wouldn't need to depend on compression to protect your data.

Note that I was asking specifically about deterministic modes. Those include SIV mode [1] but not the more common CBC, CTR, etc. Any deterministic encryption relies on entropy of the plaintext for security [2]. This is not unique to ECB. My objection was to the hyperbolic phrase "trivially broken." SIV mode is deterministic, but nobody who understands what it does would call it "trivially broken." And I'm definitely…

[deleted]

Re: Zoom’s encryption has links to China, researchers discover

#116
post #81

Earlier quoted context omitted.

Aren’t most of their developers in China?

I'm not sure if/how that would even matter in the context.

You don’t remember the whole Australia debacle when their government passed a law allowing them to secretly compel software developers to compromise whatever they’re working on? This is basically the same thing, where we know the Chinese government is capable and willing to coerce anybody in their grasp to serve in their interests. Guess where software developers in China happen to live? China. Where can the CCP most easily wield their power and influence? Also China.

Re: Zoom’s encryption has links to China, researchers discover

#117
post #3

The story here is that Zoom uses key distribution servers located in China (in addition to several servers in the USA) and that Chinese law might be compelling Zoom to disclose the encryption keys. I think it is a valid concern, but for me it also raises the question of whether this may also be required in the US. In addition to letting the Chinese (and possibly US) government in on the encryption keys, the encryptio…

[flagged]

If you keep taking HN threads further into political, nationalistic, or ideological flamewar, we are going to have to ban you.

That's not because we agree or disagree. It's because such threads are predictable, therefore tedious, therefore boring, therefore off topic here.

https://news.ycombinator.com/newsguidelines.html

Re: Zoom’s encryption has links to China, researchers discover

#118

I'd recommend reading the original Citizen Lab article as well, which discusses the flaws more specifically. This Intercept article is good, but seems to be aimed at more of a general, less-technical audience. https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto... At the very least, they are validating TLS certificates. (Which I know is the true bare minimum requirement of TLS, but "goto fail" and all...) >W…

That article is now being discussed at https://news.ycombinator.com/item?id=22768494. Not sure whether to try to merge these threads.

Re: Zoom’s encryption has links to China, researchers discover

#119
post #3

The story here is that Zoom uses key distribution servers located in China (in addition to several servers in the USA) and that Chinese law might be compelling Zoom to disclose the encryption keys. I think it is a valid concern, but for me it also raises the question of whether this may also be required in the US. In addition to letting the Chinese (and possibly US) government in on the encryption keys, the encryptio…

Don’t forget the straight up lying about using 256bit keys when they are actually using 128bit keys

Re: Zoom’s encryption has links to China, researchers discover

#120
post #99

Earlier quoted context omitted.

Is Eric Yuan a US citizen? He wasn't born or educated here so I don't know he considers himself American, and a significant amount of his company's product development is not done in America. Before this sounds anti-immigrant, I'm the product of immigrants like most Americans and I think the qualifier for being American is considering oneself American and having citizenship or on the path to get it.

He received his visa on his ninth try in the 90s. Is there anything that prompts you to doubt his citizenship?

The numerous people I've worked with that have been here for decades and aren't citizens and don't consider themselves to be American?
Post reply on HN