3 ms·
> The difference is that there is no certificate authority vouching for each participant in a video call's identity, so you would need to do independent identit
by dpwm 7y ago
> The difference is that there is no certificate authority vouching for each participant in a video call's identity, so you would need to do independent identity verification if you want to ensure that the call is secure, which some people would do by reading the public keys of each participant aloud, and people verifying that everything matches what they see.
This is a good point I hadn't considered. It led to me questioning how signal did it "right," and realising that there is seemingly no way around educating users to check public keys.[0]
So if video chats were meaningfully E2E encrypted, we would need a way to verify the public keys, which afaik Zoom doesn't have.
[0] https://web.archive.org/web/20160828135326/https://www.internetsociety.org/sites/default/files/09%20when-signal-hits-the-fan-on-the-usability-and-security-of-state-of-the-art-secure-mobile-messaging.pdf https://web.archive.org/web/20160828135326/https://www.inter...