Earlier quoted context omitted.
In my opinion they seem better off from this blog post. For example yesterday I read this comment[1] and it seemed to say Zoom always decrypts the content on the servers, in which case it's very bad to say it's "end-to-end encrypted". But this blog post explains that if you don't have any external connector attached, it in fact is end-to-end encrypted, no false advertising. When you have an external connector attache…
> if you don't have any external connector attached, it in fact is end-to-end encrypted, It doesn't say that all.
The facts around Zoom and encryption for meetings/webinars
121–130 of 145 posts
Re: The facts around Zoom and encryption for meetings/webinars
#122Earlier quoted context omitted.
In my opinion they seem better off from this blog post. For example yesterday I read this comment[1] and it seemed to say Zoom always decrypts the content on the servers, in which case it's very bad to say it's "end-to-end encrypted". But this blog post explains that if you don't have any external connector attached, it in fact is end-to-end encrypted, no false advertising. When you have an external connector attache…
> if you don't have any external connector attached, it in fact is end-to-end encrypted, It doesn't say that all.
This seems to say it, but I guess as luckylion points out, e2e doesn't mean not decrypted in the middle, it means no one besides the ends has the key. So you're right, the design they say isn't really e2e encrypted.
Re: The facts around Zoom and encryption for meetings/webinars
#123Earlier quoted context omitted.
In my opinion they seem better off from this blog post. For example yesterday I read this comment[1] and it seemed to say Zoom always decrypts the content on the servers, in which case it's very bad to say it's "end-to-end encrypted". But this blog post explains that if you don't have any external connector attached, it in fact is end-to-end encrypted, no false advertising. When you have an external connector attache…
> But this blog post explains that if you don't have any external connector attached, it in fact is end-to-end encrypted, no false advertising. No, it says that they don't decrypt it until it reaches the other client, not that they can't decrypt it.
But I don't think "can't decrypt it" is necessarily a requirement for e2e encryption. Maybe can't decrypt it with a passive attack. With an active attack it's possible to decrypt even e2e encrypted stuff assuming there's no out of band key exchange. Most Zoom users won't bother with an out of band key exchange.
Re: The facts around Zoom and encryption for meetings/webinars
#124Earlier quoted context omitted.
Clients already do this yes, but to achieve the reliability that zoom is renowned for you also need to dynamically adjust what is sent _TO_ individual clients
Can the clients not advise the server what bandwidth and packet loss rate they are seeing, so the server can adjust their traffic rate? There is no reason not to allow a signalling channel separate to the E2E encrypted data channels.
Re: The facts around Zoom and encryption for meetings/webinars
#125Zoom! What are you doing?! > To be clear, in a meeting where all of the participants are using Zoom clients, and the meeting is not being recorded, we encrypt all video, audio, screen sharing, and chat content at the sending client, and do not decrypt it at any point before it reaches the receiving clients. That is still not what "end-to-end encryption" means. From wikipedia[1]: > End-to-end encryption (E2EE) is a sy…
Continuing to lie. Did you expect differently from this malware company?
Re: The facts around Zoom and encryption for meetings/webinars
#126Zoom marketed end-to-end encryption. They didn't have end-to-end encryption. Parroting the "we used the term differently" line is counterproductive. They need to acknowledge the problem, appoint the CEO as the spokesperson and over correct [1]. If Zoom's CEO publicly apologized for the lies, fixed their marketing copy and offered refunds to anyone who felt misled, this problem would go away. [1] https://www.youtube.c…
Hundreds of millions of people use Facebook Messenger for their everyday communications, which is not meaningfully encrypted at all other than by TLS. Similarly, Discord is also very popular, as is Skype. None of these offer privacy.
Most people have a very fatalistic view about their opportunities for privacy in their electronic communications.
Re: The facts around Zoom and encryption for meetings/webinars
#127Earlier quoted context omitted.
> I took issue with a specific definition that precludes both products. This isn’t the first time you’ve tried to compare Zoom and iMessage; it’s just that I chose this one to respond to.
Have I made a false comparison anywhere else, or was the comparison valid as in this case?
Re: The facts around Zoom and encryption for meetings/webinars
#128Earlier quoted context omitted.
No, Apple cannot decrypt iMessage or FaceTime traffic because they don't have the keys. Apple could silently add an extra recipient for whom they do have the keys, but that is out of scope for E2E (in other words, key distribution is out of scope).
> No, Apple cannot decrypt iMessage or FaceTime traffic because they don't have the keys. They can very easily decrypt iMessage traffic using the method outlined in the article. They simply provide the sender with an erroneous key. > key distribution is out of scope Not according to GGP's definition, which didn't require merely that messages stay encrypted between endpoints but that middlemen have no way of decryptin…
Re: The facts around Zoom and encryption for meetings/webinars
#129Re: The facts around Zoom and encryption for meetings/webinars
#130Zoom! What are you doing?! > To be clear, in a meeting where all of the participants are using Zoom clients, and the meeting is not being recorded, we encrypt all video, audio, screen sharing, and chat content at the sending client, and do not decrypt it at any point before it reaches the receiving clients. That is still not what "end-to-end encryption" means. From wikipedia[1]: > End-to-end encryption (E2EE) is a sy…
> The fact that it's possible to decrypt is what makes this not "end-to-end encryption". By that definition, iMessage is also not end-to-end encrypted because Apple can decrypt the messages due to controlling the key servers and the relay servers, but few people bat an eye when Apple claims iMessage is end-to-end encrypted on its privacy marketing page. https://blog.cryptographyengineering.com/2013/06/26/can-appl...…
True, if true (I've not checked the iMessage details), but unimportant.
Whether or not iMessage is end-to-end-encrypted by the actual definition of end-to-end-encryption, does not change the fact the Zoom's communication is not end-to-end-encrypted by the actual definition of end-to-end-encryption while they are persisting in claiming that it actually is.
If they held up a blue ball and said "our ball is bright green", that would be incorrect. If someone else held up a yellow ball and said "our ball is bright green" that would not make Zoom's statement any more correct.