Live data from Hacker News

SpaceX bans Zoom over privacy concerns

reuters.com

121–130 of 301 posts

Re: SpaceX bans Zoom over privacy concerns

#121
post #4

The fact that they show end users (no pun intended) an "end-to-end encrypted" badge on the meeting window itself, and elsewhere explain how a Zoom server (not Zoom client) is what constitutes an "end" despite the whole rest of the electronic communication industry using "end-to-end" to refer exclusively to user agents, is bonkers.

Using their definition, one would wonder what non-end-to-end encryption would look like.

Encryption at rest but not in transit.

Re: SpaceX bans Zoom over privacy concerns

#122
post #4

The fact that they show end users (no pun intended) an "end-to-end encrypted" badge on the meeting window itself, and elsewhere explain how a Zoom server (not Zoom client) is what constitutes an "end" despite the whole rest of the electronic communication industry using "end-to-end" to refer exclusively to user agents, is bonkers.

E2E changed meaning since, for example, HIPAA.

Re: SpaceX bans Zoom over privacy concerns

#123
post #121

Earlier quoted context omitted.

Using their definition, one would wonder what non-end-to-end encryption would look like.

Encryption at rest but not in transit.

What can that even mean for a videoconferencing platform?

Re: SpaceX bans Zoom over privacy concerns

#124
post #70

Earlier quoted context omitted.

Zoom and Slack are both FedRamp authorized for government use. Zoom is even authorized Moderate, while Slack is still being audited for that rating. https://marketplace.fedramp.gov/#/product/zoom-for-governmen... https://marketplace.fedramp.gov/#/product/slack

You don't get zoom's government platform by default, you have to ask for it and I'll bet it has different pricing. I suspect you also lose some features, like recording (at least at the server). I haven't checked Zoom but other FedRamp products I've seen are 3x the price of the standard offering.

FedRAMP moderate doesn't require an isolated, US citizen-only-staffed, environment. Only FedrAMP High requires that, so they can still be on shared infra for moderate.

Re: SpaceX bans Zoom over privacy concerns

#125
post #88

Earlier quoted context omitted.

No, it doesn't. https://support.apple.com/guide/security/how-imessage-sends-...

Yes, it does. The messages are 'end to end' encrypted in the iMessage service, but then iMessage backs up its encryption key in the iCloud backup service, defeating the point. "If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices." https://support.apple.com/en-us/H…

This would be less upsetting to me if my Macbook didn't bug me about iCloud every time I start up several years after I bought it.

Re: SpaceX bans Zoom over privacy concerns

#126
post #4

The fact that they show end users (no pun intended) an "end-to-end encrypted" badge on the meeting window itself, and elsewhere explain how a Zoom server (not Zoom client) is what constitutes an "end" despite the whole rest of the electronic communication industry using "end-to-end" to refer exclusively to user agents, is bonkers.

They are using the same language as Apple talking about iMessage and FaceTime. Apple talks about end to end encryption, but one end is iCloud which is why you can get your messages simultaneously on all devices.

There is a big difference there though. In transit, iMessage and FaceTime backups are end-to-end encrypted, it's just the iMessage backups on iCloud that also store the key.

FaceTime chats, though, truly are end-to-end encrypted and the calls aren't backed up like iMessages are.

Re: SpaceX bans Zoom over privacy concerns

#127
I've never heard of the Zoom app until about three weeks ago and now I'm reading something about it here on HN almost every day. Why is this company and their app suddenly so popular and so critiqued? I thought the world was Skype, FaceTime, WebEx, that whole cluster of technologies and related applications. Why are the Zoom folks suddenly on the front page everywher?

Re: SpaceX bans Zoom over privacy concerns

#128
post #122
post #4

The fact that they show end users (no pun intended) an "end-to-end encrypted" badge on the meeting window itself, and elsewhere explain how a Zoom server (not Zoom client) is what constitutes an "end" despite the whole rest of the electronic communication industry using "end-to-end" to refer exclusively to user agents, is bonkers.

E2E changed meaning since, for example, HIPAA.

Can you elaborate slightly? This is interesting.

Re: SpaceX bans Zoom over privacy concerns

#129

Earlier quoted context omitted.

The quality send to suffer when there are a large number of participants. Which is the reason zoom gets used so much.

My company uses Google meets and it works flawlessly with more than 100 people in a call. Automatic integration with GSuite and Chrome box are an added bonus.

Does it have the advanced features present in Zoom? At my $WORKPLACE we use the Spotlight feature so to ensure everyone is watching the right person (fairly important as we have lots of Deaf people and they all need to be watching the person signing) and Breakouts to set up discussion groups. While we don't have 100+ participants, we do have up to 25 active participants with lots of turn-taking (and not e.g. 100 watching 1 stream). Other platforms we tried didn't have these and made it difficult for participants especially those who aren't great with tech. Also helps Zoom seems to work well with video—other platforms we tried were great for audio so fine if you just need to listen to people but woeful with video making it a no go for meetings involving people who use sign language.

Re: SpaceX bans Zoom over privacy concerns

#130
post #2

I looked into adding Zoom to our Slack workspace this morning, and was beside myself with the set of permissions they requested — reading the contents of every channel and private chat they're included in? For a slash command? That's a hard no. Turned me off the service entirely.

We have Zoom on our Slack workspace and we'd remove it immediately if this were the case, but it appears to be false. The full list of permissions required by the official Zoom Slack integration is at www.slack.com/apps/A5GE9BMQC-zoom, and doesn't have read access to any channels, private or public, except for "some URLs in messages".
Post reply on HN