4 ms·
Is E2E encryption desirable for video chats with >2 participants? Let's say I'm talking with two other people: is there a way to do E2E encryption without havi
by dpwm 7y ago
Is E2E encryption desirable for video chats with >2 participants?
Let's say I'm talking with two other people: is there a way to do E2E encryption without having to send out the same stream twice?
edit: Just realised a common key would allow this. But I am still interested in schemes for deriving a key amongst multiple parties using a middleman without the middleman knowing the key. It seems like a rather hard problem.
- endorphone 7y agoYou can send a single stream with E2E, just as your can send a PGP message to multiple recipients. Each packet/bundle/whatever has the decrypt key encrypted against each of the recipient keys.
- dpwm 7y agoThanks, I hadn't realised that. Looking into it, it seems PGP creates a shared symmetric key and then shares that key using public-key, which does seem like the most obvious way to do it. [0] https://superuser.com/questions/554513/pgp-encrypt-single-message-for-multiple-recipients https://superuser.com/questions/554513/pgp-encrypt-single-me...
- coder543 7y ago> But I am still interested in schemes for deriving a key amongst multiple parties using a middleman without the middleman knowing the key. It seems like a rather hard problem. This is exactly what happens when your browser establishes an HTTPS connection. There are many middlemen between you and the web server, but it still manages to negotiate a shared symmetric key (the session key) that can be used for the bulk of the encryption. The difference is that there is no certificate authority vouching for each participant in a video call's identity, so you would need to do independent identity verification if you want to ensure that the call is secure, which some people would do by reading the public keys of each participant aloud, and people verifying that everything matches what they see.
- dpwm 7y ago> The difference is that there is no certificate authority vouching for each participant in a video call's identity, so you would need to do independent identity verification if you want to ensure that the call is secure, which some people would do by reading the public keys of each participant aloud, and people verifying that everything matches what they see. This is a good point I hadn't considered. It led to me questioning how signal did it "right," and realising that there is seemingly no way around educating users to check public keys.[0] So if video chats were meaningfully E2E encrypted, we would need a way to verify the public keys, which afaik Zoom doesn't have. [0] https://web.archive.org/web/20160828135326/https://www.internetsociety.org/sites/default/files/09%20when-signal-hits-the-fan-on-the-usability-and-security-of-state-of-the-art-secure-mobile-messaging.pdf https://web.archive.org/web/20160828135326/https://www.inter...
- jonny_eh 7y agoGoogle Duo and FaceTime are able to do E2E with group chats.
- dpwm 7y agoIs there a way we can verify that they're doing that?
- fulafel 7y agoFrequently yes. We often make computers/network do more work when it's a good tradeoff. You could say that's what computers are for.