Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

151–160 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#151
post #103
post #6

"To make this possible, Free/Basic users seeking access to E2EE will participate in a one-time process that will prompt the user for additional pieces of information, such as verifying a phone number via a text message. Many leading companies perform similar steps on account creation to reduce the mass creation of abusive accounts." Perfect instrument to collect more personal data.

Is there any E2EE app that doesn't require verification? Whatsapp does. Even Signal requires a phone number.

Riot/matrix

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#152

Earlier quoted context omitted.

Only 4 comments in and we hit one of the four boogymen of the civil rights apocalypse. How many comments until we get to domestic terrorism or illegal drugs?

> one of the four boogymen of the civil rights apocalypse The public is willing trade away privacy in exchange for protection from certain categories of risk. Instead of denying that, one can lean into it by ensuring strict definitions and enforcement options within those categories while preserving full privacy for those without. Arguing pedophile rings and terrorism are a cost of a privacy policy is a good way to s…

I would make a cogent argument to rebuff your straw man, but it's not worth my time if you don't share a priori assumptions with me about E2EE being uncrackable. It's just math. I don't see why the talk of trade-offs even is relevant to the discussion. People will use secure tools with E2EE or they will suffer the consequences of not doing so. Doing illegal things is already illegal. Banning or watering down E2EE so that it becomes no long E2EE is throwing the baby out with the bathwater.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#153

Earlier quoted context omitted.

Their argument doesn't make sense. The objective behind verifying accounts is to prevent spammers creating lots of spam accounts and using those to spam. However, spammers rarely care if their spam is encrypted, so putting E2E behind verification won't do anything as far as spammers are concerned - they'll happily keep spamming using the unencrypted accounts. There's some other reason behind this that isn't about red…

If I recall from their previous statement, it's not about spammers, it's about people sharing child abuse photos.

If I recall from their even more previous statement, it was already E2EE, but that turned out to be a lie...

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#154
post #19

Give us your mobile number so we can hand it over to the PLA so they're able to launch targeted attacks at dissidents?

Are you dissident ? Know any ?

“No one is free until we are all free.” -- Rev. Dr. Martin Luther King, Jr.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#155
post #129

Earlier quoted context omitted.

It wouldn't surprise me as recently the app tried to get me to trust an untrusted cert.

It's encrypted all the way from one end to the other end, we just also happen to have a copy of the key and can dencrypt it in the middle. Technically, the exact packets of the data you send is E2E encrypted... but the copies they make for themselves aren't.

[deleted]

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#156

Zoom seems to be a poster child for the surveillance state. Does anyone reasonably want their "encrypted" conversation to route through servers physically in China?

If they're actually encrypted, I don't care much security-wise, but I do performance-wise. Given that Zoom works reasonably well, I very much doubt that they're sending all my data to and from China. You don't run a service like this without servers in lots of places.

I'd hope that when I Zoom with my coworkers two miles south of me in Austin, we're using AWS/Azure/Google Cloud/whatever servers in Texas, or at least within a couple thousand miles.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#157

Earlier quoted context omitted.

Yeah - I'm pretty sure this is the real concern and verifying a phone number is reasonable trade-off. I know this argument is often quickly dismissed on HN since people see child abuse or 'going dark' as an easy excuse for the government to leverage to get more control (and it has been used for this), but that doesn't mean the problem isn't serious or doesn't exist. See this: https://www.nytimes.com/interactive/2019/…

> The people carrying out the abuse are sophisticated. In this case wouldn't they build their own solutions (potentially based on existing open-source solutions like Asterisk + Linphone or Jitsi Meet) or they might've built them already? Phone numbers are also very easy to obtain anonymously, so I am not sure SMS verification would help track down abusers when it'll lead to a prepaid SIM or some innocent user's phone…

Yes, some would - but not all.

I agree that these reasons are why it's not a good idea to break or outlaw encryption since bad actors can still use it and good people that need it are blocked, but this doesn't mean that making it the default doesn't enable more abusers to get away with it that might be caught otherwise.

There's a spectrum of sophistication, if it's harder more of them will make more mistakes that make them easier to catch.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#159

Earlier quoted context omitted.

They're 6 months away from becoming a case study in squandering momentum.

The goodwill has already been squandered. There’s simply nowhere else to jump to (jitsi lol). As soon as a viable competitor launches, everyone will jump. Same thing happened from Skype to Discord with the gaming community.

Jitsi Meet's not a viable competitor?

It's simpler to set up (accounts and password protection are optional), IMO easier to use (eg. the hand button is on the bottom bar with mute, etc. and not in a menu labeled "Participants") and higher quality according to the New York Times, who deemed it "reliable and easy to use": https://www.nytimes.com/wirecutter/reviews/best-video-confer.... I've introduced it to extended family members who've used Zoom prolifically, with zero complaints.

Can you name a single disadvantage?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#160
post #128

Earlier quoted context omitted.

I'm disgusted that in 2020, Americans continue to use the same racist, unfounded smears againts people based on their ethnicity just as they did when they were throwing Japanese-Americans into internment camps.

There are plenty of HN users who won't (or wouldn't, in an ideal world) use any US-based software because of NSA interference. The issue is national origin, not ethnicity. Japanese Americans were thrown into camps for the same reason, but we're not talking about jailing anyone here. We're talking about avoiding a specific product. Another difference is that Japanese Americans were put into camps regardless of how man…

> The issue is national origin, not ethnicity. Japanese Americans were thrown into camps for the same reason

``` Of 127,000 Japanese Americans living in the continental United States at the time of the Pearl Harbor attack, 112,000 resided on the West Coast.[9] About 80,000 were Nisei (literal translation: "second generation"; American-born Japanese with U.S. citizenship) and Sansei ("third generation"; the children of Nisei). The rest were Issei ("first generation") immigrants born in Japan who were ineligible for U.S. citizenship under U.S. law.[10] ```

From https://en.wikipedia.org/wiki/Internment_of_Japanese_America...

What do you suggest?

Should there be a upper limit on the generations to be considered not originated from a nation state? According to what happened to WWII Japanese ethnic Americans, that number seems have to be > 3?

And remember that what happened in WWII Japanese internment camp is an evidence that "national origin" as an association was plainly wrong, from the same wiki page:

``` In 1980, under mounting pressure from the Japanese American Citizens League and redress organizations,[30] President Jimmy Carter opened an investigation to determine whether the decision to put Japanese Americans into concentration camps had been justified by the government. He appointed the Commission on Wartime Relocation and Internment of Civilians (CWRIC) to investigate the camps. The Commission's report, titled Personal Justice Denied, found little evidence of Japanese disloyalty at the time and concluded that the incarceration had been the product of racism ```

Emphasis on the last statement: `the incarceration had been the product of racism`.

Post reply on HN