Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

301–310 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#301
post #129

Earlier quoted context omitted.

It's encrypted all the way from one end to the other end, we just also happen to have a copy of the key and can dencrypt it in the middle. Technically, the exact packets of the data you send is E2E encrypted... but the copies they make for themselves aren't.

This could be the case for literally any E2EE service that controls key distribution (including WhatsApp, Signal, etc.), especially when there's no way to verify key fingerprints (here Signal differs because it does have a way, and it's open source so you can be more confident that it's not BSing you). It's shocking to me how often this is glossed over when discussing E2EE services: you still must trust the platform.

"E2EE" is kinda antonymous with "key distribution" (unless, maybe, if you mean authentication keys)

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#302

Earlier quoted context omitted.

Isn't it fair to say that this brings Zoom more-or-less exactly in line with the privacy vs law enforcement balance of a normal telephone call? Writing from the UK, I'm reasonably sure that (a) all my phone calls are not recorded and (b) the phone number and duration of every call absolutely is recorded (this has to be shown on your phone bill!) and is available to the police when needed. Speculating further, with th…

Why on Earth would you trust Zoom, a company which has repeatedly done extremely sketchy things, to implement their closed-source proprietary platform in this specific way? It would be easier to just lie about the encryption being end-to-end. Personally, I will never use Zoom for anything, a decision I came to when my OS vendor (Apple) pushed a security update for my OS to get rid of Zoom .

I wasn't really trying to comment on their overall trustworthiness - I just don't think you have to stretch very far to imagine how a conversation between ≥1 Zoom employee who genuinely does care about privacy ("our users are demanding E2EE") and law enforcement agencies ("we demand or are entitled to certain powers") might have resulted in the offering being announced today.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#303

Earlier quoted context omitted.

Is that consistent with the traditional definition of E2E? And if so then what's the term for encryption that a middle man cannot decrypt?

Regarding question #2, Peer-to-peer.

If that's the answer to "what's the term for encryption that a middle man cannot decrypt", NO: peer-to-peer simply means... well, pretty much it means sending IP packets directly to each other rather than through a central server (yes, not much of a thing, but it meant you could get free music more easily, so the term got a lot of traction)

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#304

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

You should also mention step 4b. Zoom admits it censors accounts for China, losing any and all hope of being trustworthy.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#305
post #138

Earlier quoted context omitted.

Same reason why Google censored itself for China in 2006. Did people think Google was a 'Chinese company'? Note that this was before Google set up a presence in China. http://news.bbc.co.uk/2/hi/technology/4645596.stm

I guess I don't consider that the same thing at all. They're censoring searches coming from china to google.cn (hosted in China). They didn't really have a choice, the servers are in China, the users are in China. What they aren't doing is actively blocking users from China getting to www.google.com, and they aren't censoring searches Chinese users do on www.google.com because those resources aren't hosted in China a…

they didn't have a choice not to use servers in China?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#306
post #44

Earlier quoted context omitted.

How is it racist to suggest that Zoom has Chinese influences (seemingly not farfetched based on the equity ownership mentioned above and not at all disputed based on the technicality of Zoom being a US company)?

It is not racist to suggest that the Chinese government influences companies. It is racist to suggest that Chinese people are automatically predispositioned to certain actions.

It's racist to suggest that Chinese people (NOT the similarly-colored Taiwanese) feel some weight from the dictatorship were they live/grew up/have parents in?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#307

How exactly does E2E encryption work for something bandwidth intensive like Zoom? It can't possibly be encrypting the stream with a different key for every participant, the bandwidth requirements would be impossible. Is a new key generated for each stream, which is then individually encrypted with every other participants public key, and then sent to the participants for them to decrypt?

Here's their whitepaper, linked in the post: https://github.com/zoom/zoom-e2e-whitepaper

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#308
post #141

Earlier quoted context omitted.

You mean to imply that a business would just lie to customers? Come on, the market wouldn't permit that to happen! They'd lose all their customers! /s Edit: on a less sarcastic note, I'd be less critical of Zoom if their software were open source.

What makes your comments even better is that Zoom's response from the get-go has basically been "Look at all these large companies that are using our service. Would they be using our service if we weren't secure?" Meanwhile the companies in question universally refuse to acknowledge THEY NEVER ACTUALLY VERIFIED ANY of the claims around encryption. It would be hilarious if it weren't so terrifying. And oh, by the way,…

Meanwhile the companies in question universally refuse to acknowledge THEY NEVER ACTUALLY VERIFIED ANY of the claims around encryption.

In most companies I've observed, the people deciding what products to buy are not capable of reviewing any of the products claims. If they happen to have an employee that is capable, and that employee points out a problem, they are usually ignored. Especially if it would make someone in management look bad for spending money on something they shouldn't have, or even worse if it would make them lose their free lunches and golf trips with their vendor buddy.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#309

Earlier quoted context omitted.

You mean to imply that a business would just lie to customers? Come on, the market wouldn't permit that to happen! They'd lose all their customers! /s Edit: on a less sarcastic note, I'd be less critical of Zoom if their software were open source.

> Come on, the market wouldn't permit that to happen! They'd lose all their customers! You scoff, but isn’t that exactly what we’re all doing to Zoom right now?

All? So Zoom has basically no customers now, because their initial false claims triggered a boycott?

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#310
post #141

Earlier quoted context omitted.

You mean to imply that a business would just lie to customers? Come on, the market wouldn't permit that to happen! They'd lose all their customers! /s Edit: on a less sarcastic note, I'd be less critical of Zoom if their software were open source.

What makes your comments even better is that Zoom's response from the get-go has basically been "Look at all these large companies that are using our service. Would they be using our service if we weren't secure?" Meanwhile the companies in question universally refuse to acknowledge THEY NEVER ACTUALLY VERIFIED ANY of the claims around encryption. It would be hilarious if it weren't so terrifying. And oh, by the way,…

I've been in the interview loop as of late, and there's been a crazy shift away from Zoom. Almost every video chat I had was using Zoom a couple months back, now everyone is using Google Chat or MS Team Meetings.

Now these are small to medium-ish size companies (20-500 people), so maybe it's not a big deal to Zoom's marketing bottom line. But it's definitely a thing.

Post reply on HN