> While we never intended to deceive any of our customers, we recognize that there is a discrepancy between the commonly accepted definition of end-to-end encryption and how we were using it. So you knew that your users would misinterpret the term "end-to-end encryption" but chose to use it anyways. And you somehow expect us to believe you "never intended to deceive any of [your] customers"? > The goal of our encrypt…
I don't agree there is a common definition of end-to-end encryption. Ask a random, non-technical co-worker what they think it means and you might get an answer that matches Zoom's marketing claims.
The facts around Zoom and encryption for meetings/webinars
141–145 of 145 posts
Re: The facts around Zoom and encryption for meetings/webinars
#142Earlier quoted context omitted.
This statement is simply false, Telegram has never claimed group chats are "end-to-end encrypted". Only secret chats are claimed to be and proven to be. https://telegram.org/faq#q-so-how-do-you-encrypt-data As early as 2017, they broadly and publicly advertised that they are NOT end-to-end encrypted 'by default'. https://telegra.ph/Why-Isnt-Telegram-End-to-End-Encrypted-by...
Your refutation of my claim is an article that claims Telegram's use of TLS encryption makes it more secure than its competitors, and links to another article going into even more detail about that ridiculous claim. I feel comfortable with where it leaves my argument standing.
I don't see how the TLS claim is relevant, your comment is still wrong. It also misrepresents their argument, that competitors using cloud backup is less secure than not doing so because it introduces a very untrusted third party (Google Drive is not E2EE).
Their claim that E2EE + Google Drive backup is not secure seems pretty valid to me, not that it's related to the inaccuracy of your comment (it's still a false statement, and pretty egregious considering it's never been claimed).
Why are you putting words in their mouth?
Re: The facts around Zoom and encryption for meetings/webinars
#143If this pisses you off, it's worth noting that Telegram group chats have the same property, and that Telegram argues forcefully (and falsely) that what they're doing does meet the definition of "end-to-end encryption".
Wait, I thought Telegram was worse than that - Zoom does (what appears to be) end-to-end encryption if you have four native Zoom clients in a meeting. Telegram doesn't do end-to-end if you have four Telegram clients in a group chat, right? (I might be missing something about either Zoom or Telegram)
At any point, someone could go into Zoom's systems, get the keys to your chat, and monitor you, and you would have no way of knowing.
Re: The facts around Zoom and encryption for meetings/webinars
#144Earlier quoted context omitted.
I don't agree there is a common definition of end-to-end encryption. Ask a random, non-technical co-worker what they think it means and you might get an answer that matches Zoom's marketing claims.
I feel like "end-to-end encryption" is a mostly self-explanatory term. All data passed from one end to the other is encrypted. The point of encryption is to ensure that third parties cannot read your data. If a third party has the power to decrypt and read the data, then it's already misleading to advertise it as "encrypted". That would be like advertising a pair of boots as "waterproof" when they only actually preve…
* I generate a key * I give it to you and another party * You and the other party then chat through my service * I pass the messages between you but don't bother to decrypt them
Does that count as end-to-end encryption? At any time, I could decide to decrypt the message (even months later if it is logged).
Re: The facts around Zoom and encryption for meetings/webinars
#145Earlier quoted context omitted.
The connectors appear in the participant list - this is a pretty common architecture for all kinds of communications bridging solutions. When someone joins a meeting by phone, Zoom spins up a service that 'assumes the identity' of that phone user to join the meeting (incl. negotiating keys). So, the Zoom service is now a participant in the meeting, but you do know that since a user appears in the participant list. I…
Thanks, that makes sense. I am not familiar with Zoom the product to know the connectors show up in participant list. I think even if proper e2e channel established, without authentication (Zoom just allows you to join any meeting with a token, like every other Hangout product), the key exchanges with other participants will be very automated. There seems to be very limited security guarantee if anyone can send you a…
I would point out that this is in no way unique to Zoom, though. In fact, after the changes Zoom made in response to all of these issues, Zoom probably has the highest by-default level of meeting security of just about any product out there.