Live data from Hacker News

Zoom’s encryption has links to China, researchers discover

theintercept.com

91–100 of 137 posts

Re: Zoom’s encryption has links to China, researchers discover

#91
post #20
post #5

And another case of lying in marketing: "A security white paper from the company claims that Zoom meetings are protected using 256-bit AES keys, but the Citizen Lab researchers confirmed the keys in use are actually only 128-bit." How do they keep doing this? Do they just put whatever sells best in the documents and implement something else? First the end2end thing, now 128 instead of 256 bits. How many more are we g…

"We never meant to mislead people but we realise we don't use the terminology in the way it is normally understood. We added up the keys on both sides of the conversation to reach 256 bits." Is probably what they'll say

"128 bits, each bit can be 0 or 1, there you go, 256 bits!"

Re: Zoom’s encryption has links to China, researchers discover

#92
post #59
post #56

Earlier quoted context omitted.

There's a history[0] of UK gov pushing through Chinese tech, despite security concerns. Why stop now... [0] https://www.bbc.com/news/uk-politics-51806704

Software by an American Company[0] founded by a man who's been here since the 90s[1] is now "Chinese Tech"? Is everything from Paul Graham "British Tech"? Are Apple Products now "Chinese Tech" because of their keyservers in China[2]? [0] https://en.m.wikipedia.org/wiki/Zoom_Video_Communications [1] https://en.m.wikipedia.org/wiki/Eric_Yuan [2] https://www.reuters.com/article/us-china-apple-icloud-insigh...

I find it shocking that your comment is being downvoted.

If Zoom is “Chinese tech” because of the CEO’s ethnicity, then I suppose NVIDIA and AMD are now “Chinese tech.”

Re: Zoom’s encryption has links to China, researchers discover

#93
post #3

The story here is that Zoom uses key distribution servers located in China (in addition to several servers in the USA) and that Chinese law might be compelling Zoom to disclose the encryption keys. I think it is a valid concern, but for me it also raises the question of whether this may also be required in the US. In addition to letting the Chinese (and possibly US) government in on the encryption keys, the encryptio…

They are using EBC mode? I don't know of a single crypto library that would pick that as a default, so someone actually made this decision (like actively lowered encryption capability). I thought of some of the previous issues of not being too bad, but this leaves me wondering...

Re: Zoom’s encryption has links to China, researchers discover

#95

I always knew that the "zoom.us" is a dodgy name for an installation file. As if someone was going an extra length to make sure you think its a US company.

I thought the “us” was like the word “Us”.

So “Zoom Us” like “Call Us.”

Re: Zoom’s encryption has links to China, researchers discover

#96

Maybe I've been sensitised by all the security flaws, privacy leaks and outright lies on Zoom's part, but I'm starting to really notice how much a lot of public figures are pushing Zoom. Does anyone else find it really weird? Late-night TV hosts, I can understand - maybe they just get paid for it, or have Zoom shares. But for example UK government leaders repeatedly mentioning it by name, e.g. Matt Hancock saying tha…

Zoom is now ‘Kleenex’ or ‘Coke’ for video conferencing. Skype was the same when it came out... but they had far less competition at the time. This is a huge win for Zoom on a marketing front.

Yep, showing up to uninvited random meetings by guessing IDs is now called Zoombombing apparently

Re: Zoom’s encryption has links to China, researchers discover

#98

Maybe I've been sensitised by all the security flaws, privacy leaks and outright lies on Zoom's part, but I'm starting to really notice how much a lot of public figures are pushing Zoom. Does anyone else find it really weird? Late-night TV hosts, I can understand - maybe they just get paid for it, or have Zoom shares. But for example UK government leaders repeatedly mentioning it by name, e.g. Matt Hancock saying tha…

Maybe they tried Skype first, which works horrible (tried twice, never managed connect all the participants at the same time), and finally relief over something that actually works. I have used Zoom successfully with 70 participants, and then breakout groups. The only alternative I can see that recently came to my attention is Jitsi Meet ( https://jitsi.org/ ), which I will try next time I have the opportunity. But s…

You can also try BigBlueButton (https://bigbluebutton.org). Open source, and a lot of nice things done better than the usual online meeting standards (e.g. included whiteboard and slides are real slides and watchers have a lot of flexibility in watching them).

Re: Zoom’s encryption has links to China, researchers discover

#99

Earlier quoted context omitted.

It is a US company and the founder is american too. https://www.bloomberg.com/profile/company/ZM:US

Is Eric Yuan a US citizen? He wasn't born or educated here so I don't know he considers himself American, and a significant amount of his company's product development is not done in America. Before this sounds anti-immigrant, I'm the product of immigrants like most Americans and I think the qualifier for being American is considering oneself American and having citizenship or on the path to get it.

He received his visa on his ninth try in the 90s. Is there anything that prompts you to doubt his citizenship?

Re: Zoom’s encryption has links to China, researchers discover

#100
post #3

The story here is that Zoom uses key distribution servers located in China (in addition to several servers in the USA) and that Chinese law might be compelling Zoom to disclose the encryption keys. I think it is a valid concern, but for me it also raises the question of whether this may also be required in the US. In addition to letting the Chinese (and possibly US) government in on the encryption keys, the encryptio…

[flagged]
Post reply on HN