Live data from Hacker News

Zoom’s encryption has links to China, researchers discover

theintercept.com

81–90 of 137 posts

Re: Zoom’s encryption has links to China, researchers discover

#81

Earlier quoted context omitted.

It is a US company and the founder is american too. https://www.bloomberg.com/profile/company/ZM:US

Aren’t most of their developers in China?

I'm not sure if/how that would even matter in the context.

Re: Zoom’s encryption has links to China, researchers discover

#82
post #3

The story here is that Zoom uses key distribution servers located in China (in addition to several servers in the USA) and that Chinese law might be compelling Zoom to disclose the encryption keys. I think it is a valid concern, but for me it also raises the question of whether this may also be required in the US. In addition to letting the Chinese (and possibly US) government in on the encryption keys, the encryptio…

Who the hell still uses ECB?

Wikipedia has a great visualization of this for those who are curious: https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation...

Re: Zoom’s encryption has links to China, researchers discover

#83
post #75

OK, this makes things clearer. Zoom does in fact encrypt their streams from client to client but they have easy access to the keys. In their recent post about this question they apologize for what they admit to be an incorrect use of the phrase "end to end encryption". They base this on the existence of things like the gateways used to the regular telephone network. It seems like an odd way to spin this. Why didn't t…

Apple does not have access to FaceTime keys or iMessage keys for that matter. They are truly end-to-end encrypted, and I don’t think there is any need to cheapen or muddy the term for the sake of marketers.

They can still write software to insert themselves into the key exchange flow and eavesdrop on a conversation. E.g. I don’t believe there is anything stopping Apple from pretending a participant bought a new device.

Re: Zoom’s encryption has links to China, researchers discover

#84
post #75

OK, this makes things clearer. Zoom does in fact encrypt their streams from client to client but they have easy access to the keys. In their recent post about this question they apologize for what they admit to be an incorrect use of the phrase "end to end encryption". They base this on the existence of things like the gateways used to the regular telephone network. It seems like an odd way to spin this. Why didn't t…

Apple does not have access to FaceTime keys or iMessage keys for that matter. They are truly end-to-end encrypted, and I don’t think there is any need to cheapen or muddy the term for the sake of marketers.

Perhaps as that was based on random internet comments. FaceTime still ends up at level 2 with Zoom and the rest because Apple can MITM the traffic without much trouble. There is no provision for the user to prevent/detect a MITM attack in FaceTime or iMessage.

Re: Zoom’s encryption has links to China, researchers discover

#85

OK, this makes things clearer. Zoom does in fact encrypt their streams from client to client but they have easy access to the keys. In their recent post about this question they apologize for what they admit to be an incorrect use of the phrase "end to end encryption". They base this on the existence of things like the gateways used to the regular telephone network. It seems like an odd way to spin this. Why didn't t…

Apple doesn’t have access to the keys used to encrypt FaceTime calls. They are in fact end to end. Zoom is not.

https://support.apple.com/en-us/HT209110

Re: Zoom’s encryption has links to China, researchers discover

#86

Earlier quoted context omitted.

I've really grown to dislike the "people who presumably consider themselves ethical defending a regime that represses free speech and expression, brutally crushes dissenters, disappears ethical doctors, is led by a 'president for life' dictator, and has literally hauled off 1M muslims to internment campus where their organs are being harvested and their culture is being erased, thing".

"has literally hauled off 1M muslims to internment campus where their organs are being harvested and their culture is being erased, thing" Citation needed on the '1M', 'organs...harvested', 'culture...erased'.

First Page Of Google.

Re: Zoom’s encryption has links to China, researchers discover

#87

Earlier quoted context omitted.

I've really grown to dislike the "people who presumably consider themselves ethical defending a regime that represses free speech and expression, brutally crushes dissenters, disappears ethical doctors, is led by a 'president for life' dictator, and has literally hauled off 1M muslims to internment campus where their organs are being harvested and their culture is being erased, thing".

"has literally hauled off 1M muslims to internment campus where their organs are being harvested and their culture is being erased, thing" Citation needed on the '1M', 'organs...harvested', 'culture...erased'.

Wikipedia references estimates of 1.5 million & 1-3 million. [0]

"Uighurs are allegedly pressured to renounce their culture" [1] More references is the Wikipedia article as well.

"China forcefully harvests organs from detainees" [2] Same article discusses the 1.5 million figure.

All of these are from basic Google searches. The information is out there if you look.

[0] https://en.wikipedia.org/wiki/Xinjiang_re-education_camps

[1] http://www.taipeitimes.com/News/front/archives/2019/11/14/20...

[2] https://www.nbcnews.com/news/world/china-forcefully-harvests...

Re: Zoom’s encryption has links to China, researchers discover

#88

I always knew that the "zoom.us" is a dodgy name for an installation file. As if someone was going an extra length to make sure you think its a US company.

It is a US company and the founder is american too. https://www.bloomberg.com/profile/company/ZM:US

Is Eric Yuan a US citizen? He wasn't born or educated here so I don't know he considers himself American, and a significant amount of his company's product development is not done in America.

Before this sounds anti-immigrant, I'm the product of immigrants like most Americans and I think the qualifier for being American is considering oneself American and having citizenship or on the path to get it.

Re: Zoom’s encryption has links to China, researchers discover

#89
post #75

Earlier quoted context omitted.

Apple does not have access to FaceTime keys or iMessage keys for that matter. They are truly end-to-end encrypted, and I don’t think there is any need to cheapen or muddy the term for the sake of marketers.

They can still write software to insert themselves into the key exchange flow and eavesdrop on a conversation. E.g. I don’t believe there is anything stopping Apple from pretending a participant bought a new device.

How would they spoof the 2FA from an existing device?

Re: Zoom’s encryption has links to China, researchers discover

#90
post #75

Earlier quoted context omitted.

Apple does not have access to FaceTime keys or iMessage keys for that matter. They are truly end-to-end encrypted, and I don’t think there is any need to cheapen or muddy the term for the sake of marketers.

Perhaps as that was based on random internet comments. FaceTime still ends up at level 2 with Zoom and the rest because Apple can MITM the traffic without much trouble. There is no provision for the user to prevent/detect a MITM attack in FaceTime or iMessage.

So you’re saying there should be a three-level consumer standard where the third level excludes any possible consumer product? Please don’t pretend that Apple and Zoom’s approaches are equivalent here. There is a substantial difference that deserves to be acknowledged. Anyone whose threat model includes Apple subverting their own security architecture shouldn’t be using any communication platforms.
Post reply on HN