8 ms·
This is a great article, but as an educational provider it fails to answer one question: Why should I care? The only concerning thing for me is, why would they
by consonaut 7y ago
This is a great article, but as an educational provider it fails to answer one question: Why should I care?
The only concerning thing for me is, why would they lie about using AES-256 when none of my users (and I assume most of their users) would care in any way about AES-256 vs. AES-128 in ECB mode. Why would they lie?
Even after this, having my users conducting university lessons over something that might be decrypted in China is honestly not that big of an issue. I would of course prefer it if these meetings would be private from the PRCs scrutiny but at least in my situation (and I think most educational contexts) this is not really that important.
- basch 7y agoBecause a company doing an RFP with a checklist of features is going to rank them against their competitors, and it would look bad in the spreadsheet.
- consonaut 7y agoI assume this is your answer to "why would they lie?". It does not answer the question to why should an educational provider care though. And assuming I'll consider switching to webex the response to encryption in webex is this: https://www.webex.com/content/dam/Webex/eopi/Americas/USA/en_us/documents/pdf/security_Webex.pdf https://www.webex.com/content/dam/Webex/eopi/Americas/USA/en... Which 404's and basically represents my experience with Cisco: "We don't give a shit about you, you already payed us.". Frankly Webex could host the next coming of Jesus and I would not give them any more money.
- google234123 7y agolol, nice job finding a link that 404s and basing your entire argument on it. Here is another one for your next post: https://www.webex.com/sdvfebdwq3433t8hjaxcxqadxe https://www.webex.com/sdvfebdwq3433t8hjaxcxqadxe
- consonaut 7y agoFrankly, Cisco can post whatever they like I will not give them any more money. You are certainly right that I was disingenuous and I do not care what they do with Webex. My link was cherry picked from their press release for encryption in Webex that I though it was funny that that link would 404. Good job discrediting my post though. It's not like Cisco basically told everybody in a KB that if you want to use the same features Zoom provides (or a Linux client, or desktop sharing or breakout rooms or audio transcription or waiting rooms or...) you would have to give up every encryption feature Webex provides. But I assume you are a seasoned Webex admin and can provide us some insight into why you are using webex in contrast any other solution. Or you are trolling, whatever.
- philwelch 7y agoIn the general case, it’s bad practice to do business with liars. That’s one reason why an educational institution would care.
- consonaut 7y agoCorrect, and if a Zoom representative would have lied to me that would factor into my decision. Frankly though, for student lectures and faculty meetings I don't care about their encryption (as long as they do TLS for client->server to protect my users in a public wifi situation) and a certain encryption level was never a basis for my decision. As long as they provide transport security I don't really care.
- fulafel 7y agoWebex is so bad that nobody would consider using it based on technical merits, security track record or being backed by a competent organisation, so it's kind of immune from the kind of critique that is being leveled against Zoom. I have a feeling computer accessible Webex is just there because of the dedicated videoconf HW that Cisco makes. The software is to provide a feature checkmark and make its victims miserable enough to buy the HW.
- gerdesj 7y ago"... and then they came for me". Obviously that poem was written about something rather more serious than your privacy but the point stands.
- consonaut 7y agoAs I alluded to in another post I am from Germany and certain people I work with actually went through the "... they came for me" phase. Your point does not stand on its own.
- gerdesj 7y agoI (en_GB) lived in that weird place called West Germany for about 10 years on and off back in the 70s and 80s. We have many friends (Hi Wurms, int al) who also have family, friends and acquaintances that lived through those days directly, shall we say, and of course my own family members who did from another side and perspective. You may want to take another look at my username and make of that what you will. My point really does stand. You might gradually allow erosion of your rights until you find that none are left. It is so easy to say "I have nothing to hide" until you find that actually you do have something to hide for reasons that are not immediately obvious. I am not saying that using Zoom will have nasty consequences but I am saying that the attitude that abrogates responsibility for your own privacy might have unintended consequences. If it becomes common place to simply say "meh" we might not like the world we get instead of the world we might wish for. My Old Saxon friends have a rather more robust attitude to privacy concerns than you mate!
- consonaut 7y agoI'm not going to play "guess what my username means" with you, sorry. I'm also not going to play "who knows more people that lived through the 3rd reich" with you. Me administering a Zoom account for my fellow employees and my students does not erode anybodies right. For me it is a choice between a GDPR compliant vendor and a vendor that does not care about the GDPR. Personally I have had good experiences with the GDPR (Facebook finally having to delete my account even though I would not verify it with a personal ID and cell phone number after I went through the irish data protection authority) and Zoom claims to be GDPR compliant. So, frankly I'm not sure what you are talking about. It seems like you are going for a slippery slope argument I don't agree with.
- eanzenberg 7y agoYou should care because Zoom is a company run by and within China. What's troubling for the west is having so much IP and information flowing through a bad state actor without knowing about it.
- eyegor 7y ago> Why would they lie? I kind of doubt it was intentional. Developers are not marketing, typically, and it seems reasonable to assume that a technical person said "aes" when a marketing person asked "do we have encryption?". And then the marketing person searched for "aes" and assumed that meant "aes-256".
- ngcc_hk 7y agoBecause you do not want china great again. Human should. Not communist shipping virus out killing its own people.
- tlear 7y agoLets say these lessons are a politics seminar discussing whatever PRC finds objectionable, then family of the student back in the old country get their social credit score deducted. Or even better use those recording in the future as compromat as needed.
- Igelau 7y agoI don't know how much free time they have over there, but snooping in on courses that a relative outside the country is taking and storing all of them... I mean, if you want to peg someone's social credit score, just stakeout their house and wait for them to spit outside or something. Hell, just make something up and dare them to come argue. Why go to all that effort?
- kart23 7y agoDoesnt go exactly like that. More like: CCTV captures someone going to an area where known rebels or political activists live. (Look up videos on chinas face recognition, its insane.) Police decide to look through the person's zoom meeting transcripts, making a search on certain keywords. They find evidence of rebellious activities, and order further surveillance on the individual or arrest them.
- Igelau 7y agoIn a surveillance state of the scope you've described, triangulating the zoom transcripts of an international relative's course work back to someone you spotted on CCTV is still hardly worth the extra trouble. At that level of erosion of civil liberties, they can already send the jackboots to break down the door when they make the CCTV match. Don't find anything? You plant something or coerce them into ratting on someone else. Why would you go mining terabytes of data that's mostly boring meetings and calls from grandma?
- killjoywashere 7y agoIt's all take data collection and they mine it later. 10 years from now they go looking for video from you. And yes, if you don't think people have weird incentives and time on their hands, have a look at the shitshow of US Presidential politics.
- notechback 7y agoBecause big orgs check for a minimum list of features and that list will nowadays always include some element of encryption/data protection. Many companies use zoom, or e.g. I've seen the OECD host seminars there. Have they done due diligence and an independent audit of the software? No, Robert and Lucy from procurement had a week to read through 8 different bids describing software features and support modalities, assured they fit the checklist and then calculated which one is the lowest bid (or "best value for money" which is checklist points/price) as they are obliged to choose that. Then zoom can go around and claim OECD and IBM and the UN (all made up) use them, which lends credence, even if it's just that one training team in Nairobi that trialed the software once.
- xenonite 7y agoThe students log in via email and from home, they both count as personal identifiers. Now, China knows who is attending which lesson. And how much activity each individual shows. And also, what happens on the side like environment sounds, environment at the camera (e.g., how generous the student's apartment is). Also, the client can analyze the mouse cursor movement, see what other apps are running and how (on native clients), and on mobile clients there is for example the gravitational sensor. Moreover, a voice (and the face, of course) is like a fingerprint of a person. Hence you now have a reverse lookup table from voice/face to person.
- consonaut 6y agoJust as an FYI 2 weeks later... We decided on not enforcing Zoom accounts for our students for various reasons. So the PRC might have IP address access to a SIP/Zoom server but this is not something we, as a small university, can solve. Even without Zoom the PRC could trace access to our bigbluebutton server or a jitsi videobridge and I don't presume that using Webex or Vidyo or what have you would solve this issue (and honestly all other solutions would have ended up being more expensive). We still do not have any evidence that the PRC has access to unencrypted Zoom server logs and frankly I assume we would have the same (or worse) issues I had with my tests from Iran that either SIP/WebRTC doesn't work or appears to be intercepted. So, at least for me and my users, Zoom is the most accessible and "least worst" solution.
- xenonite 6y agoThank you for the follow-up. No, we don't have evidence that they have access to the server logs, or even more, the streams. I guess that an intelligence would compromise one of Zoom's employees, then gaining access without any further evidence. This gives them to possibility to sneak on any Zoom call that is routed to the respective servers. And indeed, an intelligence could possibly hack your bigbluebutton server. This involves, however, a targeted attack instead. I think this is a different scenario, though.