Live data from Hacker News

The facts around Zoom and encryption for meetings/webinars

blog.zoom.us

51–60 of 145 posts

Re: The facts around Zoom and encryption for meetings/webinars

#51
post #30

How could they guarantee end-to-end if not all gadgets support encryption?! Let's demand end-to-end encryption for people connecting via FAX machines to read only the comments. Of course connecting via unreliable machines / protocols means Zoom must have some bridge on their side somewhere. In light of this post it looks like for the majority of users it is end-to-end encrypted. I don't even use Zoom, but really, the…

> How could they guarantee end-to-end if not all gadgets support encryption?! They can't. So they shouldn't. > In light of this post it looks like for the majority of users it is end-to-end encrypted. It absolutely is not. What they can say is for the vast majority of users, the streams are encrypted between all clients, and due to policy, Zoom won't view them as they pass through. The problem is Zoom could intercept…

> The problem is Zoom could intercept and decrypt streams, if they wanted to

And we have the spirit of encryption to guarantee they, or a third party who infiltrated/hacked them, won't.

>> and in that spirit, we used the term end-to-end encryption

Re: The facts around Zoom and encryption for meetings/webinars

#52
post #24
post #17

If this pisses you off, it's worth noting that Telegram group chats have the same property, and that Telegram argues forcefully (and falsely) that what they're doing does meet the definition of "end-to-end encryption".

Wait, I thought Telegram was worse than that - Zoom does (what appears to be) end-to-end encryption if you have four native Zoom clients in a meeting. Telegram doesn't do end-to-end if you have four Telegram clients in a group chat, right? (I might be missing something about either Zoom or Telegram)

[deleted]

Re: The facts around Zoom and encryption for meetings/webinars

#53
post #51
post #30

Earlier quoted context omitted.

> How could they guarantee end-to-end if not all gadgets support encryption?! They can't. So they shouldn't. > In light of this post it looks like for the majority of users it is end-to-end encrypted. It absolutely is not. What they can say is for the vast majority of users, the streams are encrypted between all clients, and due to policy, Zoom won't view them as they pass through. The problem is Zoom could intercept…

> The problem is Zoom could intercept and decrypt streams, if they wanted to And we have the spirit of encryption to guarantee they, or a third party who infiltrated/hacked them, won't. >> and in that spirit, we used the term end-to-end encryption

The spirit of encryption? What does that mean? End to end encrypted means from one client through all networks and servers to the other client, no one can decrypt the traffic. Anything besides that is not end to end.

Re: The facts around Zoom and encryption for meetings/webinars

#54
post #24
post #17

If this pisses you off, it's worth noting that Telegram group chats have the same property, and that Telegram argues forcefully (and falsely) that what they're doing does meet the definition of "end-to-end encryption".

Wait, I thought Telegram was worse than that - Zoom does (what appears to be) end-to-end encryption if you have four native Zoom clients in a meeting. Telegram doesn't do end-to-end if you have four Telegram clients in a group chat, right? (I might be missing something about either Zoom or Telegram)

> Zoom does (what appears to be) end-to-end encryption if you have four native Zoom clients in a meeting.

I don't understand their blog post that way. From the post: we encrypt all video, audio, screen sharing, and chat content at the sending client, and do not decrypt it at any point before it reaches the receiving clients. That sounds like "we could decrypt it, but we promise not to". That's not e2e.

They continue with When users join Zoom meetings using devices that do not inherently use Zoom’s communication protocol, such as a phone (connected via traditional telephone line, rather than the app) or SIP/H.323 room-based systems, Zoom’s encryption cannot be applied directly by that phone or device so if those users can join the meeting after it has been established between Zoom-clients, it's not e2e.

Re: The facts around Zoom and encryption for meetings/webinars

#55
post #7

"Zoom has always strived to use encryption to protect content in as many scenarios as possible, and in that spirit, we used the term end-to-end encryption. While we never intended to deceive any of our customers, we recognize that there is a discrepancy between the commonly accepted definition of end-to-end encryption and how we were using it." In other words, "We deceived our customers with false advertising but we'…

"We never intended to deceive any customers when we invented a new definition of e2e encryption"

Re: The facts around Zoom and encryption for meetings/webinars

#56
post #35

Zoom marketed end-to-end encryption. They didn't have end-to-end encryption. Parroting the "we used the term differently" line is counterproductive. They need to acknowledge the problem, appoint the CEO as the spokesperson and over correct [1]. If Zoom's CEO publicly apologized for the lies, fixed their marketing copy and offered refunds to anyone who felt misled, this problem would go away. [1] https://www.youtube.c…

> Zoom marketed end-to-end encryption. They didn't have end-to-end encryption. My understanding is that they do in fact have end-to-end-encryption between Zoom clients, it's just that when you join via a dial-in phone number, the connection is (of course) not encrypted between your phone and the system you're dialing into. People who wanted end-to-end encryption could just choose to not dial in by phone, and they'd g…

> My understanding is that they do in fact have end-to-end-encryption between Zoom clients, it's just that when you join via a dial-in phone number, the connection is (of course) not encrypted between your phone and the system you're dialing into.

Which means, there is no end-to-end-encryption. Zoom knows the key but does not decrypt the data unless they need to to let a member join via phone. You need to trust Zoom that they keep their promise not to decrypt your communication, there is no technical hurdle.

Re: The facts around Zoom and encryption for meetings/webinars

#57
post #15

wow!! zoom you were better off not having written that blog. you guys are some shady assholes. Everything from the text to the graphics are intended to mislead and obscure. I don’t think i’ve seen a company act in such bad faith since theranos was a thing.

In my opinion they seem better off from this blog post. For example yesterday I read this comment[1] and it seemed to say Zoom always decrypts the content on the servers, in which case it's very bad to say it's "end-to-end encrypted". But this blog post explains that if you don't have any external connector attached, it in fact is end-to-end encrypted, no false advertising. When you have an external connector attache…

> But this blog post explains that if you don't have any external connector attached, it in fact is end-to-end encrypted, no false advertising.

No, it says that they don't decrypt it until it reaches the other client, not that they can't decrypt it.

Re: The facts around Zoom and encryption for meetings/webinars

#58
post #40

Earlier quoted context omitted.

When a product specifies "end to end encryption" my expectation is that the only function of the server is to pass the public keys from two clients around so they can Diffie-Hellman kx to achieve a mutually shared private key to encrypt their communications to each other, so that information flow is: client client (no server knowledge of communications aside from the encrypted packets being passed back end forth) Not…

I'm not sure what to do with systems like iMessage/FaceTime under this definition, where the server doesn't hold the private keys but also the client provides no means to check fingerprints out-of-band. In these systems, the server could MITM the clients to each other and thereby snoop on client communications with the same effective result as Zoom/Jitsi. (These systems also generally support changing the peer's fing…

How do iMessage and FaceTime provide end-to-end encryption? Is there a public key associated with Apple account? How does my private key get on different Apple devices without my help?

Re: The facts around Zoom and encryption for meetings/webinars

#59
post #53
post #51

Earlier quoted context omitted.

> The problem is Zoom could intercept and decrypt streams, if they wanted to And we have the spirit of encryption to guarantee they, or a third party who infiltrated/hacked them, won't. >> and in that spirit, we used the term end-to-end encryption

The spirit of encryption? What does that mean? End to end encrypted means from one client through all networks and servers to the other client, no one can decrypt the traffic. Anything besides that is not end to end.

It means nothing but this is what Zoom tells us we have. Encryption given "in the spirit" of their intentions.

> Zoom has always strived to use encryption to protect content in as many scenarios as possible, and in that spirit, we used the term end-to-end encryption.

Re: The facts around Zoom and encryption for meetings/webinars

#60
post #13

In fairness, it sounds like it’s end to end encrypted until a legacy device connects. Am I misunderstanding something? This doesn’t seem like it should be controversial.

Is the end to end encryption removed for all clients when a legacy device connects?

I don't understand how some devices could be end to end encrypted in a meeting while some legacy devices in the same meeting are not. How could the legacy devices send and receive to the encrypted clients?

Post reply on HN