Live data from Hacker News

The facts around Zoom and encryption for meetings/webinars

blog.zoom.us

121–130 of 145 posts

Re: The facts around Zoom and encryption for meetings/webinars

#121
post #15

Earlier quoted context omitted.

In my opinion they seem better off from this blog post. For example yesterday I read this comment[1] and it seemed to say Zoom always decrypts the content on the servers, in which case it's very bad to say it's "end-to-end encrypted". But this blog post explains that if you don't have any external connector attached, it in fact is end-to-end encrypted, no false advertising. When you have an external connector attache…

> if you don't have any external connector attached, it in fact is end-to-end encrypted, It doesn't say that all.

[deleted]

Re: The facts around Zoom and encryption for meetings/webinars

#122
post #15

Earlier quoted context omitted.

In my opinion they seem better off from this blog post. For example yesterday I read this comment[1] and it seemed to say Zoom always decrypts the content on the servers, in which case it's very bad to say it's "end-to-end encrypted". But this blog post explains that if you don't have any external connector attached, it in fact is end-to-end encrypted, no false advertising. When you have an external connector attache…

> if you don't have any external connector attached, it in fact is end-to-end encrypted, It doesn't say that all.

> we encrypt all video, audio, screen sharing, and chat content at the sending client, and do not decrypt it at any point before it reaches the receiving clients.

This seems to say it, but I guess as luckylion points out, e2e doesn't mean not decrypted in the middle, it means no one besides the ends has the key. So you're right, the design they say isn't really e2e encrypted.

Re: The facts around Zoom and encryption for meetings/webinars

#123
post #15

Earlier quoted context omitted.

In my opinion they seem better off from this blog post. For example yesterday I read this comment[1] and it seemed to say Zoom always decrypts the content on the servers, in which case it's very bad to say it's "end-to-end encrypted". But this blog post explains that if you don't have any external connector attached, it in fact is end-to-end encrypted, no false advertising. When you have an external connector attache…

> But this blog post explains that if you don't have any external connector attached, it in fact is end-to-end encrypted, no false advertising. No, it says that they don't decrypt it until it reaches the other client, not that they can't decrypt it.

I now agree with your point that it's not really e2e encrypted, because they never claim they don't have the key.

But I don't think "can't decrypt it" is necessarily a requirement for e2e encryption. Maybe can't decrypt it with a passive attack. With an active attack it's possible to decrypt even e2e encrypted stuff assuming there's no out of band key exchange. Most Zoom users won't bother with an out of band key exchange.

Re: The facts around Zoom and encryption for meetings/webinars

#124

Earlier quoted context omitted.

Clients already do this yes, but to achieve the reliability that zoom is renowned for you also need to dynamically adjust what is sent _TO_ individual clients

Can the clients not advise the server what bandwidth and packet loss rate they are seeing, so the server can adjust their traffic rate? There is no reason not to allow a signalling channel separate to the E2E encrypted data channels.

The server would then have to tell the streamer / talker to reduce their quality for that one client while degrading all other clients that have a fine connection right?

Re: The facts around Zoom and encryption for meetings/webinars

#125
post #29

Zoom! What are you doing?! > To be clear, in a meeting where all of the participants are using Zoom clients, and the meeting is not being recorded, we encrypt all video, audio, screen sharing, and chat content at the sending client, and do not decrypt it at any point before it reaches the receiving clients. That is still not what "end-to-end encryption" means. From wikipedia[1]: > End-to-end encryption (E2EE) is a sy…

> Zoom! What are you doing?!

Continuing to lie. Did you expect differently from this malware company?

Re: The facts around Zoom and encryption for meetings/webinars

#126

Zoom marketed end-to-end encryption. They didn't have end-to-end encryption. Parroting the "we used the term differently" line is counterproductive. They need to acknowledge the problem, appoint the CEO as the spokesperson and over correct [1]. If Zoom's CEO publicly apologized for the lies, fixed their marketing copy and offered refunds to anyone who felt misled, this problem would go away. [1] https://www.youtube.c…

This problem will probably go away anyway.

Hundreds of millions of people use Facebook Messenger for their everyday communications, which is not meaningfully encrypted at all other than by TLS. Similarly, Discord is also very popular, as is Skype. None of these offer privacy.

Most people have a very fatalistic view about their opportunities for privacy in their electronic communications.

Re: The facts around Zoom and encryption for meetings/webinars

#127

Earlier quoted context omitted.

> I took issue with a specific definition that precludes both products. This isn’t the first time you’ve tried to compare Zoom and iMessage; it’s just that I chose this one to respond to.

Have I made a false comparison anywhere else, or was the comparison valid as in this case?

You keep drawing parallels between Zoom's end-to-end encryption and iMessage's, when there really is little to compare. iMessage is end-to-end encrypted because intermediaries do not have access to decryption keys; your "attack" relies on a malicious actor tampering with key distribution using a technique that requires even more setup than is described in the old article you've linked. On the other hand, Zoom has been actually decrypting traffic as a key part of their service and yet called it end-to-end.

Re: The facts around Zoom and encryption for meetings/webinars

#128

Earlier quoted context omitted.

No, Apple cannot decrypt iMessage or FaceTime traffic because they don't have the keys. Apple could silently add an extra recipient for whom they do have the keys, but that is out of scope for E2E (in other words, key distribution is out of scope).

> No, Apple cannot decrypt iMessage or FaceTime traffic because they don't have the keys. They can very easily decrypt iMessage traffic using the method outlined in the article. They simply provide the sender with an erroneous key. > key distribution is out of scope Not according to GGP's definition, which didn't require merely that messages stay encrypted between endpoints but that middlemen have no way of decryptin…

Middlemen don't have a way of decrypting the data, because they don't have the keys to decrypt it. If they're malicious they can try to send you new keys to use, and only if you accept them will they then have the keys to decrypt your messages.

Re: The facts around Zoom and encryption for meetings/webinars

#129

Earlier quoted context omitted.

It's not outdated; Apple still controls the key distribution and the users cannot verify how many recipient key sets there are.

For one, iMessage (and FaceTime) will now tell you if a new device is added.

If you believe them.

Re: The facts around Zoom and encryption for meetings/webinars

#130
post #29

Zoom! What are you doing?! > To be clear, in a meeting where all of the participants are using Zoom clients, and the meeting is not being recorded, we encrypt all video, audio, screen sharing, and chat content at the sending client, and do not decrypt it at any point before it reaches the receiving clients. That is still not what "end-to-end encryption" means. From wikipedia[1]: > End-to-end encryption (E2EE) is a sy…

> The fact that it's possible to decrypt is what makes this not "end-to-end encryption". By that definition, iMessage is also not end-to-end encrypted because Apple can decrypt the messages due to controlling the key servers and the relay servers, but few people bat an eye when Apple claims iMessage is end-to-end encrypted on its privacy marketing page. https://blog.cryptographyengineering.com/2013/06/26/can-appl...…

> By that definition, iMessage is also not end-to-end encrypted because

True, if true (I've not checked the iMessage details), but unimportant.

Whether or not iMessage is end-to-end-encrypted by the actual definition of end-to-end-encryption, does not change the fact the Zoom's communication is not end-to-end-encrypted by the actual definition of end-to-end-encryption while they are persisting in claiming that it actually is.

If they held up a blue ball and said "our ball is bright green", that would be incorrect. If someone else held up a yellow ball and said "our ball is bright green" that would not make Zoom's statement any more correct.

Post reply on HN