6 ms·
Do I have any way to verify this as a user?
by bobbydroptables 6y ago
Do I have any way to verify this as a user?
- virtue3 6y agoas the colloquialism goes: Talk is cheap...
- dijksterhuis 6y agoSure. Study a PhD in cryptanalysis and reverse engineering. If you want to look at something now, the white paper for the E2E protocol design is public and open right now: https://github.com/zoom/zoom-e2e-whitepaper https://github.com/zoom/zoom-e2e-whitepaper On a more serious note, until there is a protocol and implementation available then we can't say anything for sure. Us Security folks aren't magicians.
- TheSpiceIsLife 6y agoI like your tone, and it lead me to think: Any sufficiently advanced cryptography is indistinguishable from magic. Which isn’t entirely untrue from a layperson’s perspective. Edit: fixed a word. I’d accidentally written “is” rather than “isn’t”.
- randomsearch 6y agoCryptography is a religion
- manquer 6y agoThat was uncalled for . Yes it is hard or impossible to do in zoom . If these tools use open standards and well documented protocols this will not be a problem. I can verify without a phd in cryptoanalyis and reverse engineering my browser is running a secure connection to a website and certificate is signed by the source(for sites enabled with FS and HSTS ).
- kwanbix 6y agoWell, even if all of your software was open source, do you have the time to validate all of it, from the app to the OS? what about the CPU?
- manquer 6y agoThis is well known issue since Ken Thompson’s trusting trust paper and not what am I getting at it It is degrees of trust . Trust is not absolute , neither is security . Depending on your threat models you have to secure yourself. More transparency improves security does not solve all the problems just makes it costlier for an attacker . If cost outweighs the benefit they will not attempt to do it. Https does not magically make your communication 100% secure ,however the number of people who can issue a certificate from a comprised root CA or control one is considerably less than the number of people who can monitor your plain text traffic .
- dijksterhuis 6y agoDon't get me started on browser certificates. That's a whole week of my life I'll never get back. The short versiom of it is, your browser trusts CAs to say whether a certificate is valid. But CAs often trust other CAs who may not actually be that trustworthy. Those CAs then trust other CAs who definitely are not as trustworthy... Etc. So that certificate/padlock picture in your browser may not be as trustworthy as you think. It's an active problem.
- SXX 6y agoMandatory Ceryificate Transparency is solve problem of trust to CAs quite well though.
- dijksterhuis 6y agoIn terms of an actually relevant reply that's not bemoaning browser certs... Yes I was a bit harsh. But I was trying to demonstrate a point - no one knows for sure until we can look at this stuff in detail. Until the researchers get to pull it apart then no one can verify anything. The little green tick on a zoom call is practically worthless until some external work is done. The protocol is documented and open. I linked to it in my comment.
- mrmonkeyman 6y agoGo open source.