4 ms·
> Zoom documentation claims that the app uses “AES-256” encryption for meetings where possible. However, we find that in each Zoom meeting, a single AES-128 key
by tlbsofware 6y ago
> Zoom documentation claims that the app uses “AES-256” encryption for meetings where possible. However, we find that in each Zoom meeting, a single AES-128 key is used in ECB mode by all participants to encrypt and decrypt audio and video. The use of ECB mode is not recommended because patterns present in the plaintext are preserved during encryption.
https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto-a-quick-look-at-the-confidentiality-of-zoom-meetings/ https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto...
- toomuchtodo 6y agoYou know, I had never considered being a shareholder and using said standing to sue a company into security best practices when they lie about it, considering regulation has failed to create the appropriate incentives.
- tlbsofware 6y agoNeither have I, but figured I’d link this since it is more than likely why they are suing
- shanemhansen 6y agoOh wow. ECB mode? That's horrifying.
- fnord123 6y agoFor those that don't know much about encryption, here is an example image for why ECB mode is trash: https://i.stack.imgur.com/bXAUL.png https://i.stack.imgur.com/bXAUL.png
- UncleMeat 6y agoImages are uniquely bad for ECB mode since they almost definitionally will have repeated material. ECB mode is bad and shouldn't be used. But it isn't like somebody listening to your zoom traffic can transparently see penguins.
- pedrocr 6y agoIsn't an h264 stream even worse given that unlike a random image it has a very well defined repeating structure? The risk isn't that someone will look at zoom traffic directly and see the content Matrix-style. The risk is that it should become possible to just completely decode the encryption given what you know about the plaintext. In that context the penguin image is a great illustration.
- shanemhansen 6y agoI would say that anyone who ever tries to encrypt some data and does the bare minimum google/stackoverflow search for how to do it would see extremely vigorous warnings not to touch ECB with a 10 foot pole. Unfortunately, crypto libraries have a history of having a terrible UI and defaulting to ECB. Years ago I ran into this with pycrypto. I worked on a team that joked about how important it was not to do ECB and it turns out they had done ECB. https://www.dlitz.net/software/pycrypto/api/current/Crypto.Cipher.AES-module.html https://www.dlitz.net/software/pycrypto/api/current/Crypto.C...