Earlier quoted context omitted.
Anybody that trusts zoom with anything even slightly sensitive these days is completely nuts. Yes, we know its easy to use.
99% of people do not care about privacy. They won't switch programs because a nation state might spy on them.
Zoom to bring end-to-end encryption to all users, including non-paying
451–460 of 557 posts
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#452Re: Zoom to bring end-to-end encryption to all users, including non-paying
#453I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…
Alex Stamos had a good thread on some of the costs and benefits of E2EE. There is a cost https://twitter.com/alexstamos/status/1268219067707453441
Denying E2EE is a cost as you are punishing people for the crimes of another, this is depriving them of their hard-earned freedoms and liberties, for something someone else has done or may do.
Look at the activism going on today. BLM, dissidents in China, the rise of oppressive far-right governments in Europe like Hungary. I am sure if you dig far enough, you could find many people fighting in obscure causes, high profile causes, in a number of countries, who would fear the fist of an oppressive government.
What if the FBI / NSA decides to surveil BLM, as they already are? What if the CCP strikes down a dissident as they already have on Zoom? What if Orban decides you are a secret agent of George Soros plotting to undermine the government? Is it the case that everyone should roll over because a criminal might use the same means as them?
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#454Aside from whatever the Zoom news story of the day is, it's completely unsurprising that they're eating WebEx's lunch. I just tried scheduling a meeting and it was outrageously bad. The bright green "Start" and "Schedule Meeting" buttons just pop up an error. The correct button to progress is the dark grey (as if disabled) "Next" button. It prompts me to create a "personal conference number", whatever that is. This e…
Ugh. And Google Meet us even worse. My kids' schools use it, for supposed privacy reasons. Audio is absolutely terrible. Echoey as hell. UI is a disaster. You have to install a third party Chrome extension just to get grid view, which keeps breaking. My work uses Zoom, and it's night and day and smooth everything is.
Also IMO there's been some drastic improvements to audio quality lately. My very noisy fan that triggers my mic in Discord is totally inaudible in Google Meet, even when I'm talking.
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#455I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…
Zoom’s engineering team is based in the PRC. This opens them up to pressure from the dictatorship which has made large scale industrial espionage a public policy goal. Somebody is listening, and likely transcribing, every call at organizations of interest. The source code, public statements, etc are irrelevant; if the PLA wants a Chinese national in China to do something, they will. The penalties for noncompliance ar…
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#456Earlier quoted context omitted.
Just curious: Fake news was coined by Trump, so you're agreeing it was a meaningful usage?
Ironically, it was not coined by Trump. https://twitter.com/CraigSilverman/status/522179364767924224 and https://www.theverge.com/2014/10/22/7028983/fake-news-sites-... are good examples of its use pre-Trump. By the time Trump started applying it to actual news outlets, it was already in relatively common use.
https://www.cnn.com/2016/12/08/politics/hillary-clinton-fake...
December 2016 Hillary Clinton decides to use the term in reference to recent events like her losing the election. The media picks up on it and the term starts to lose its meaning. Then Donald Trump, always with a nose for catch phrase politics, picks up the term and runs with it, a turn of events that someone on HN called a huge "own goal" by the media, and I can't say I disagree with that assessment.
For more analysis of this cultural specimen:
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#457Earlier quoted context omitted.
Enterprise support is the usual answer, and it'd probably work pretty well for Zoom given how many enterprises are already willing to pay Zoom for said support.
i don't think it'd work particularly well. people pay for zoom not because of 'enterprise support', but because they want features that they need (eg. meetings not automatically ending after 40 minutes).
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#458Earlier quoted context omitted.
I'm actually more alarmed than I was before the announcement, because it indicates that there wasn't sufficient pressure for them not to do this. Watch them put the key in a predictable memory location, then have a subtle vulnerability elsewhere that lets them exfiltrate the client-generated key at any time. Anyone with views that might be dangerous to reveal to state actors should be very, very wary.
Anybody that trusts zoom with anything even slightly sensitive these days is completely nuts. Yes, we know its easy to use.
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#459Earlier quoted context omitted.
Only 4 comments in and we hit one of the four boogymen of the civil rights apocalypse. How many comments until we get to domestic terrorism or illegal drugs?
> one of the four boogymen of the civil rights apocalypse The public is willing trade away privacy in exchange for protection from certain categories of risk. Instead of denying that, one can lean into it by ensuring strict definitions and enforcement options within those categories while preserving full privacy for those without. Arguing pedophile rings and terrorism are a cost of a privacy policy is a good way to s…
Now, I'm not saying there is nothing that can be done to reduce it. I very much hope there can be, especially if counsellors can find warning signs and we can better figure out how to spot the danger signs, both online and off.
Facebook took a good step forward by putting warnings up to minors when someone outside of their social circles has contacted many others, although there are other things which could be done.
Should they be allowed to contact them through onion routing during such situations? Where do you draw the line of when such technologies can be used? Is it better not to open this can of worms and risk a slippery descent? What are the chances of false positives, will it unfairly impact relatives? Will it give a black mark to privacy technologies and civil liberties to be associated with automatic blocks? What if minors want to engage in activism, should this be limited? At what point does pushing and pushing start the lie about your age shenanigans again?
This is about Facebook here but it ties back to arguments about doing this or that for the greater good.
Is a more grounded approach better? Ensure minors are well-educated of the risks and dangers online? Invest in mental health services to avoid minors falling into depressive slumps where they might be susceptible to such criminals? In the rare event they drag anyone back home, whether they think they're of a similar age or not, they bring them before the parents first?
Re: Zoom to bring end-to-end encryption to all users, including non-paying
#460Earlier quoted context omitted.
E2EE and open source: the two things people assume automatically makes things super-crazy-secure. The implementation of E2EE must be robust and there must be somebody who is actually checking the source code (plus verifiable builds)
If you go down that road, you can make this argument infinitely. Even if you verify your builds, you cannot know if the software you are using to check the build isn't compromised. Or if you check the software you use to check the build, you have to check the software doing that check and so on. Nothing makes software automatically super-crazy-secure. Absolute security doesn't exist.