Live data from Hacker News

Zoom rolled their own encryption scheme, transmit keys through servers in China

citizenlab.ca

231–240 of 316 posts

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#231
post #211

Earlier quoted context omitted.

At first, the site attracted about sixteen hundred daily visitors, and Graham moderated and maintained it himself. Today, around five million people read Hacker News each month, and it’s grown more difficult to moderate. The technical discussions remain varied and can be insightful. But social, cultural, and political conversations, which, despite the guidelines, have proliferated, tend to devolve. A recent comment t…

I find that the opposite is true. Most comments are emotional, and I have to search for controversial comments to find anything objective/worth reading. Like Reddit, this site is biased to the political left (USA). I wish we could just avoid all politics in tech.

I don't think it's possible to avoid politics in any profession. Teachers care about education reform, which is a political subject. Doctors care about the healthcare system, which is a political subject. Civil engineers care about building codes and safety regulations, which are political subjects. Accountants care about tax laws, which are an incredibly political subject. Social workers care about welfare programs, which is also a very political subject. You might not talk about it in the realm of politics while at work, but it has an impact on your work as well as the lives of the public.

You could even argue that being "apolitical" actually means that your political opinion is that the status quo is acceptable, which other people may disagree with. For instance, some people believe that selling water is unethical because it's a basic human need which you should always have free access to -- saying that the status quo is acceptable means that you don't think that for-sale water is unethical. There's nothing wrong with that opinion, but it is an opinion (and a political one at that).

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#232

Earlier quoted context omitted.

There's more in the stream than just compressed data. There'll be metadata info that you can make reasonable guesses about. ECB mode lets you take that information and apply it to other blocks in the ciphertext.

I’m not arguing that. I’m saying that for compressed data , underlying patterns in data aren’t trivially exposed by ECB. Ergo, the “tux” attack on bitmap image files doesn’t really apply here. I meant nothing more and nothing less than that.

And I'm saying that they aren't just sending compressed data, nor would hardly any practical communication application, which makes the "well maybe they have enough entropy that it doesn't matter?" argument moot.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#233

The serverside key handling stuff is bad, but generally known (Zoom has features whose natural implementation require them to keep keys serverside). People are dunking on Zoom for rolling their own crypto and coming up with AES-128-ECB. This is also bad, but people should be aware that it's a lot more complicated than "you can see penguins through it". You can see penguins through an ECB-encrypted bitmap because disc…

> the real danger of ECB is in interactive settings, where we as attackers get to induce plaintext patterns, and use chosen boundaries to isolate targeted ciphertext

Is it conceivable that actual Zoom use cases might allow attackers to do some of these things? I don't have an example in mind, but I'm thinking that the Zoom protocol supports many more actions than just audio and video transmission, so perhaps some of the other protocol features could be exploited for plaintext injection.

For example, Zoom supports text chats, and some kind of metadata information about participants and call setup. Perhaps those are all directly encrypted under the same key with the same block cipher mode?

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#234

Earlier quoted context omitted.

There's a reason airlines don't put a freshly minted, cheap pilot in command of a 747.

I know market cap isn't everything, but just thought I would look it up. Zoom (ZM) has a market cap of $40.77B (with a forward PE of 327.31...). Delta (DAL) has a market cap of $18.19B, with a forward PE of 3.91. Like I said, market cap isn't everything, but I find that astonishing.

Well, the airlines are being destroyed at the moment.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#235
post #103

Earlier quoted context omitted.

As I alluded to in another post I am from Germany and certain people I work with actually went through the "... they came for me" phase. Your point does not stand on its own.

Your point does not stand on its own. No, but it will when the next generation of Nazi, Stalinist, and Maoist regimes arise and gain access to the data in question because we weren't fanatical enough about E2E privacy today. And just as Niemoeller's verse warns, by then it will be too late.

There is an actual Maoist regime operating today that has access to Zoom's data. This is not a hypothetical.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#236

The serverside key handling stuff is bad, but generally known (Zoom has features whose natural implementation require them to keep keys serverside). People are dunking on Zoom for rolling their own crypto and coming up with AES-128-ECB. This is also bad, but people should be aware that it's a lot more complicated than "you can see penguins through it". You can see penguins through an ECB-encrypted bitmap because disc…

I was a bit suspicious about that ECB leaking when they didn’t use an example from a Zoom call to demonstrate a leak, your explanation about it probably not having the same issue here makes a lot of sense.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#237
post #141

Earlier quoted context omitted.

I (en_GB) lived in that weird place called West Germany for about 10 years on and off back in the 70s and 80s. We have many friends (Hi Wurms, int al) who also have family, friends and acquaintances that lived through those days directly, shall we say, and of course my own family members who did from another side and perspective. You may want to take another look at my username and make of that what you will. My poin…

I'm not going to play "guess what my username means" with you, sorry. I'm also not going to play "who knows more people that lived through the 3rd reich" with you. Me administering a Zoom account for my fellow employees and my students does not erode anybodies right. For me it is a choice between a GDPR compliant vendor and a vendor that does not care about the GDPR. Personally I have had good experiences with the GD…

Nitpick: he's not talking about the Drittes Reich, he clearly must be talking about the experience people had in eastern German DDR / "German people's republic".

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#238
post #63
post #2

This is honestly the best “Zoom is bad” summery I’ve seen so far. While I certainly believe some of the Zoom hate is blown out of proportion, this article does a good job explaining to someone who isn't a security expert what the issues are. I've been getting questions about the company from family and friends, and will be forwarding this to them. Well done.

This is a great article, but as an educational provider it fails to answer one question: Why should I care? The only concerning thing for me is, why would they lie about using AES-256 when none of my users (and I assume most of their users) would care in any way about AES-256 vs. AES-128 in ECB mode. Why would they lie? Even after this, having my users conducting university lessons over something that might be decryp…

Because big orgs check for a minimum list of features and that list will nowadays always include some element of encryption/data protection. Many companies use zoom, or e.g. I've seen the OECD host seminars there. Have they done due diligence and an independent audit of the software? No, Robert and Lucy from procurement had a week to read through 8 different bids describing software features and support modalities, assured they fit the checklist and then calculated which one is the lowest bid (or "best value for money" which is checklist points/price) as they are obliged to choose that.

Then zoom can go around and claim OECD and IBM and the UN (all made up) use them, which lends credence, even if it's just that one training team in Nairobi that trialed the software once.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#239
post #96
post #65

Earlier quoted context omitted.

Because a company doing an RFP with a checklist of features is going to rank them against their competitors, and it would look bad in the spreadsheet.

I assume this is your answer to "why would they lie?". It does not answer the question to why should an educational provider care though. And assuming I'll consider switching to webex the response to encryption in webex is this: https://www.webex.com/content/dam/Webex/eopi/Americas/USA/en... Which 404's and basically represents my experience with Cisco: "We don't give a shit about you, you already payed us.". Frankly…

Webex is so bad that nobody would consider using it based on technical merits, security track record or being backed by a competent organisation, so it's kind of immune from the kind of critique that is being leveled against Zoom.

I have a feeling computer accessible Webex is just there because of the dedicated videoconf HW that Cisco makes. The software is to provide a feature checkmark and make its victims miserable enough to buy the HW.

Re: Zoom rolled their own encryption scheme, transmit keys through servers in China

#240
post #100

Earlier quoted context omitted.

The students are all forced to agree to these abusive third party TOS simply to receive the education to which they are entitled/for which they have already paid. That’s a bait and switch on the part of the university. “You’ve already paid, but now you have to give up your civil rights against this third party you’ve never heard of to get the service.” There should be liability for the schools for doing this. A class…

There's a pandemic, schools and professors try what they can to keep the courses running and not ruin their students' year, and your reaction is "sue them"?

Pandemic really shouldn't be an excuse to just sell out students to any party that used more marketing money.

There's a reason why (at least in this part of the world) the educational products receive additional scrutiny and need to comply to additional privacy and security directives.

Post reply on HN