Live data from Hacker News

The facts around Zoom and encryption for meetings/webinars

blog.zoom.us

41–50 of 145 posts

Re: The facts around Zoom and encryption for meetings/webinars

#41

How could they guarantee end-to-end if not all gadgets support encryption?! Let's demand end-to-end encryption for people connecting via FAX machines to read only the comments. Of course connecting via unreliable machines / protocols means Zoom must have some bridge on their side somewhere. In light of this post it looks like for the majority of users it is end-to-end encrypted. I don't even use Zoom, but really, the…

So don't claim you do end-to-end encryption? And don't put a green lock signifying end-to-end encryption in the client when you aren't actually doing end-to-end encryption?

You act as if they're the innocent victim here. They literally made indicators and showcase them in the client to signify encryption when they aren't doing it. If you send your kids to school and the teacher says they're being fed everyday, but then you find out a year later that kids with allergies just don't get lunch, you're OK with that? Or would you expect them to tell you UP FRONT about the caveats?

Re: The facts around Zoom and encryption for meetings/webinars

#42
post #35

Earlier quoted context omitted.

> Zoom marketed end-to-end encryption. They didn't have end-to-end encryption. My understanding is that they do in fact have end-to-end-encryption between Zoom clients, it's just that when you join via a dial-in phone number, the connection is (of course) not encrypted between your phone and the system you're dialing into. People who wanted end-to-end encryption could just choose to not dial in by phone, and they'd g…

I understood they never had it for video. Which was included in their claim. So there's that.

OK, that would be serious flaw, and also the current blog post states clearly that they do, so if that's a lie, then we have a much bigger problem on our hands than whether they should be using the term "end-to-end encryption."

> To be clear, in a meeting where all of the participants are using Zoom clients, and the meeting is not being recorded, we encrypt all video, audio, screen sharing, and chat content at the sending client, and do not decrypt it at any point before it reaches the receiving clients.

Re: The facts around Zoom and encryption for meetings/webinars

#43
>The Facts Around Zoom and Encryption for Meetings/Webinars

Is everyone doing alternative facts now ? This was a relatively simple thing to clear up, if they wanted to clear it up. They can decrypt whatever they want. So it's not end to end. Claiming otherwise was disingenuous, but putting out some PR spin on top of that is doubly so.

Re: The facts around Zoom and encryption for meetings/webinars

#44

Does anyone know how this could technically be possible? For a meeting with all Zoom clients they say they use E2E. When a new participant joins, they are immediately added to the meeting. Is a new pubkey key generated and passed to existing participants? Is there one shared symmetric key that is sent to the new participant? What stops zoom from "adding a participant" and allowing themselves to decrypt the meeting? I…

[deleted]

Re: The facts around Zoom and encryption for meetings/webinars

#45

Is there any evidence that other teleconferencing solutions meet or exceed what's described in this blog article? I just find the Zoom hate weird. We have no reason to think Teams, Hangouts, or anything else does anything close to or better than this. Lots of reason to suspect they probably don't. Don't get me wrong, I think the scrutiny is good, and will lead to positive outcomes. But we probably need to scrutinize…

> Is there any evidence that other teleconferencing solutions meet or exceed what's described in this blog article? Did they market themselves as end-to-end encrypted? Zoom has security problems. This isn't one of them. This is a marketing, and more fundamentally, potential culture/honesty problem. (Best case, it's one of attention to detail. Marketing didn't understand a term, used it and nobody looked back.)

Or is it that Zoom is so ubiquitous, that they get the scrutiny? But every other vendor doesn't get this level of scrutiny?

Re: The facts around Zoom and encryption for meetings/webinars

#46

Earlier quoted context omitted.

> Is there any evidence that other teleconferencing solutions meet or exceed what's described in this blog article? Did they market themselves as end-to-end encrypted? Zoom has security problems. This isn't one of them. This is a marketing, and more fundamentally, potential culture/honesty problem. (Best case, it's one of attention to detail. Marketing didn't understand a term, used it and nobody looked back.)

Or is it that Zoom is so ubiquitous, that they get the scrutiny? But every other vendor doesn't get this level of scrutiny?

> every other vendor doesn't get this level of scrutiny?

One, that doesn’t excuse false advertising. Two, yes, it makes more sense to scrutinise things everyone uses than things nobody does.

Growing pains are nothing new. How a culture reacts to such pains is informative.

Re: The facts around Zoom and encryption for meetings/webinars

#48
> While we never intended to deceive any of our customers, we recognize that there is a discrepancy between the commonly accepted definition of end-to-end encryption and how we were using it.

So you knew that your users would misinterpret the term "end-to-end encryption" but chose to use it anyways. And you somehow expect us to believe you "never intended to deceive any of [your] customers"?

> The goal of our encryption design is to provide the maximum amount of privacy possible while supporting the diverse needs of our client base.

This statement is at odds with the statement that immediately follows.

> To be clear, in a meeting where all of the participants are using Zoom clients, and the meeting is not being recorded, we encrypt all video, audio, screen sharing, and chat content at the sending client, and do not decrypt it at any point before it reaches the receiving clients.

If you do not decrypt it at any point, then you are admitting you have no legitimate need to decrypt it. If you have no legitimate need to decrypt it, but are retaining the ability to decrypt it anyways, then you are not providing the "maximum amount of privacy possible". If you are communicating between two Zoom clients, then there does not seem to be a reason not to use true end-to-end encryption.

I'm 100% fine with Zoom offering solutions without true end-to-end encryption. The way they have described their "Zoom Connector" solution, I think they've already gone above and beyond most of their competitors. However, that absolutely does not excuse how they have deliberately mislead their users.

Re: The facts around Zoom and encryption for meetings/webinars

#49

How could they guarantee end-to-end if not all gadgets support encryption?! Let's demand end-to-end encryption for people connecting via FAX machines to read only the comments. Of course connecting via unreliable machines / protocols means Zoom must have some bridge on their side somewhere. In light of this post it looks like for the majority of users it is end-to-end encrypted. I don't even use Zoom, but really, the…

If you need more encryption you can sign up for their HIPPA service.

Note that it disables certain endpoint options and other features - so only worth doing if you really need it.

Post reply on HN