Earlier quoted context omitted.
They can still write software to insert themselves into the key exchange flow and eavesdrop on a conversation. E.g. I don’t believe there is anything stopping Apple from pretending a participant bought a new device.
That's a much less scary attack vector though, since they would also need to somehow impersonate the participants voice or image right?
Zoom’s encryption has links to China, researchers discover
111–120 of 137 posts
Re: Zoom’s encryption has links to China, researchers discover
#112OK, this makes things clearer. Zoom does in fact encrypt their streams from client to client but they have easy access to the keys. In their recent post about this question they apologize for what they admit to be an incorrect use of the phrase "end to end encryption". They base this on the existence of things like the gateways used to the regular telephone network. It seems like an odd way to spin this. Why didn't t…
Apple doesn’t have access to the keys used to encrypt FaceTime calls. They are in fact end to end. Zoom is not. https://support.apple.com/en-us/HT209110
Re: Zoom’s encryption has links to China, researchers discover
#113Earlier quoted context omitted.
Perhaps as that was based on random internet comments. FaceTime still ends up at level 2 with Zoom and the rest because Apple can MITM the traffic without much trouble. There is no provision for the user to prevent/detect a MITM attack in FaceTime or iMessage.
So you’re saying there should be a three-level consumer standard where the third level excludes any possible consumer product? Please don’t pretend that Apple and Zoom’s approaches are equivalent here. There is a substantial difference that deserves to be acknowledged. Anyone whose threat model includes Apple subverting their own security architecture shouldn’t be using any communication platforms.
Zoom specifically states that they do not have access to session keys. Apple doesn't even make such a statement.
Re: Zoom’s encryption has links to China, researchers discover
#114OK, this makes things clearer. Zoom does in fact encrypt their streams from client to client but they have easy access to the keys. In their recent post about this question they apologize for what they admit to be an incorrect use of the phrase "end to end encryption". They base this on the existence of things like the gateways used to the regular telephone network. It seems like an odd way to spin this. Why didn't t…
Apple doesn’t have access to the keys used to encrypt FaceTime calls. They are in fact end to end. Zoom is not. https://support.apple.com/en-us/HT209110
Re: Zoom’s encryption has links to China, researchers discover
#115Earlier quoted context omitted.
> Is ECB any worse than any other deterministic encryption? Yes, it's objectively worse than literally any other AES mode. You wouldn't need to depend on compression to protect your data.
Note that I was asking specifically about deterministic modes. Those include SIV mode [1] but not the more common CBC, CTR, etc. Any deterministic encryption relies on entropy of the plaintext for security [2]. This is not unique to ECB. My objection was to the hyperbolic phrase "trivially broken." SIV mode is deterministic, but nobody who understands what it does would call it "trivially broken." And I'm definitely…
Re: Zoom’s encryption has links to China, researchers discover
#116Earlier quoted context omitted.
Aren’t most of their developers in China?
I'm not sure if/how that would even matter in the context.
Re: Zoom’s encryption has links to China, researchers discover
#117The story here is that Zoom uses key distribution servers located in China (in addition to several servers in the USA) and that Chinese law might be compelling Zoom to disclose the encryption keys. I think it is a valid concern, but for me it also raises the question of whether this may also be required in the US. In addition to letting the Chinese (and possibly US) government in on the encryption keys, the encryptio…
[flagged]
That's not because we agree or disagree. It's because such threads are predictable, therefore tedious, therefore boring, therefore off topic here.
Re: Zoom’s encryption has links to China, researchers discover
#118I'd recommend reading the original Citizen Lab article as well, which discusses the flaws more specifically. This Intercept article is good, but seems to be aimed at more of a general, less-technical audience. https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto... At the very least, they are validating TLS certificates. (Which I know is the true bare minimum requirement of TLS, but "goto fail" and all...) >W…
Re: Zoom’s encryption has links to China, researchers discover
#119The story here is that Zoom uses key distribution servers located in China (in addition to several servers in the USA) and that Chinese law might be compelling Zoom to disclose the encryption keys. I think it is a valid concern, but for me it also raises the question of whether this may also be required in the US. In addition to letting the Chinese (and possibly US) government in on the encryption keys, the encryptio…
Re: Zoom’s encryption has links to China, researchers discover
#120Earlier quoted context omitted.
Is Eric Yuan a US citizen? He wasn't born or educated here so I don't know he considers himself American, and a significant amount of his company's product development is not done in America. Before this sounds anti-immigrant, I'm the product of immigrants like most Americans and I think the qualifier for being American is considering oneself American and having citizenship or on the path to get it.
He received his visa on his ninth try in the 90s. Is there anything that prompts you to doubt his citizenship?