23 ms·
I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts
by hypewatch 6y ago
I find this story arch with Zoom amusing:
1. Pre-COVID Zoom claims it has E2E encryption for everyone.
2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate.
3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers.
4. Zoom gets another wave of criticism for restricting its new E2E encryption service so it walks back to its original message that all accounts get E2E encryption.
Given their track record I’d expect this timeline to repeat itself so after they release this E2E encryption feature, security researchers will discover that it’s not true E2E encryption again.
- minusSeven 6y agoI guess this is a literal definition of fake it till you make.
- thevagrant 6y agoIt wouldn't surprise me as recently the app tried to get me to trust an untrusted cert.
- freedomben 6y agoyikes, if they ended up murdering Keybase and still ship crap, I will never forgive them.
- sfuller808 6y agowhats the post-keybase landscape?
- bisby 6y agoIt's encrypted all the way from one end to the other end, we just also happen to have a copy of the key and can dencrypt it in the middle. Technically, the exact packets of the data you send is E2E encrypted... but the copies they make for themselves aren't.
- paulryanrogers 6y agoIs that consistent with the traditional definition of E2E? And if so then what's the term for encryption that a middle man cannot decrypt?
- tcoff91 6y agoIt’s definitely not adhering to the definition of E2E encryption. However given Zoom’s history of shadiness it’s a pretty good guess about how it will be implemented.
- pwdisswordfish2 6y agoRegarding question #2, Peer-to-peer.
- g-b-r 6y agoIf that's the answer to "what's the term for encryption that a middle man cannot decrypt", NO: peer-to-peer simply means... well, pretty much it means sending IP packets directly to each other rather than through a central server (yes, not much of a thing, but it meant you could get free music more easily, so the term got a lot of traction)
- pwdisswordfish2 6y agoThat's right. It is certainly possible to use peer-to-peer to send unencrypted packets. Peer-to-peer does not imply encryption. It does imply avoiding a "middleman". Thus, to send encrypted packets without using a middleman, peer-to-peer is a viable method.
- g-b-r 6y ago> It does imply avoiding a "middleman" No, it only implies avoiding a central server (and not even for every aspect of the service), you still run through routers, ISPs, NSA etc. If you are certain that there's no middleman, you don't need encryption. N.B. Maybe someone defines it in another way today, but when the term became popular, with Napster, it really meant simply not having a central server for certain functions, or even more banally not downloading your mp3s from a web site or ftp server; it did have some significance also because the legal aspect of it was more uncertain; when people started getting 100k dollars fines, peer-to-peer stopped meaning much, sometimes it's better to send packets directly to each other, other times through a server, but you almost always encrypt and almost always ought to encrypt end-to-end
- coreypreston 6y agoThey're 6 months away from becoming a case study in squandering momentum.
- jimbob45 6y agoThe goodwill has already been squandered. There’s simply nowhere else to jump to (jitsi lol). As soon as a viable competitor launches, everyone will jump. Same thing happened from Skype to Discord with the gaming community.
- boogies 6y agoJitsi Meet's not a viable competitor? It's simpler to set up (accounts and password protection are optional), IMO easier to use (eg. the hand button is on the bottom bar with mute, etc. and not in a menu labeled "Participants") and higher quality according to the New York Times, who deemed it "reliable and easy to use": https://www.nytimes.com/wirecutter/reviews/best-video-conferencing-service/ https://www.nytimes.com/wirecutter/reviews/best-video-confer.... I've introduced it to extended family members who've used Zoom prolifically, with zero complaints. Can you name a single disadvantage?
- arthurcolle 6y agoWe tested it at my org, it doesn't scale past 15 users
- boogies 6y agoYeah, something like BigBlueButton might be better for big business meetings. (it's built for them and education, and claims to support 150+ participants). Participant limits in Jitsi Meet are a bit confusing. There's a lot of variables to consider. https://community.jitsi.org/t/jitsi-meet-performance-comparison-to-hangouts-teams-and-bigbluebutton/22676/43 https://community.jitsi.org/t/jitsi-meet-performance-compari... > 1. Room hard limit is 75 users, recommended 35 users. > 2. The limit with more than 15 users with camera is the user’s PC. > 3. Working test with a good bare metal servers, 115 mute users and 5 users with camera. > 4. Test in progress for 500 simultaneous users.
- inetknght 6y agoYou mean to imply that a business would just lie to customers? Come on, the market wouldn't permit that to happen! They'd lose all their customers! /s Edit: on a less sarcastic note, I'd be less critical of Zoom if their software were open source.
- tw04 6y agoWhat makes your comments even better is that Zoom's response from the get-go has basically been "Look at all these large companies that are using our service. Would they be using our service if we weren't secure?" Meanwhile the companies in question universally refuse to acknowledge THEY NEVER ACTUALLY VERIFIED ANY of the claims around encryption. It would be hilarious if it weren't so terrifying. And oh, by the way, all of those companies refuse to admit they messed up so they ALSO haven't switched to another service, so Zoom is literally still selling on "If we weren't secure, these big guys wouldn't be paying for our service". It's insanity.
- DelTaco 6y agoFeels like Theranos except the only difference is that Zoom has working software
- skinnymuch 6y agoI don’t understand. That means it’s fine. Theranos big issue was not having anything. Otherwise they lied a ton. Not unlike many, many companies.
- zentiggr 6y agoNope, this is human nature at it's most basic and obvious. Saving face by not admitting egregious mistakes and even lying about making or not making them even after the evidence is public and irrefutable is just the human ego defending itself. I'm starting to get past taht sort of childishness in my own life but having lived it for a long time I see it easily in others.
- 6y ago
- dheera 6y agoE2E encryption is meaningless unless there is a way to prove that it is E2E, e.g. by showing us the source code of the client side and allowing us to compile it ourselves, which Signal does. It would be super interesting if there was a way to abstract out encryption on the camera itself, where the video call software gets an encrypted video stream and its only job is to convey that stream to the other side, which decrypts it. The hard part is sending an encrypted stream that can be programatically degraded based on available bandwidth, and still be cryptographically secure.
- gliese1337 6y agoSounds like a use-case for efficient homomorphic encryption.
- anticensor 6y agoWe really need a fully homomorphic fast public key encryption. That would enable digital signing schemes that can encrypt the entire document using public key scheme (double-barrelled signing: first encrypt using private key that would be decrypted using public key, then encrypt that form using public key that would be decrypted using private key; the first (and only that one!) encryption would be homomorphic).
- jorblumesea 6y agoIt's confusing too because implementing E2E crypto seems far easier than the above events. Any ideas why they might be so resistant to it?
- beached_whale 6y agoAlex Stamos had a good thread on some of the costs and benefits of E2EE. There is a cost https://twitter.com/alexstamos/status/1268219067707453441 https://twitter.com/alexstamos/status/1268219067707453441
- What_wonder 6y agoThere is also a cost in not having your smart TV microphone record all conversations and upload them to the police.
- beached_whale 6y agoThat's a false equivalence. At any point in this, there is little we can do to verify E2EE, but trust a 3rd party. We can trust that they enable it, or as previously proposed we can trust that they are visibly in the meetings and observing. Either way, we have no way to ensure this is true when dealing with 3rd party providers. Your smart tv recording has nothing to do with this, but one does still need to trust that it isn't happening. In the case of the smart tv we can attempt to look for microphones or other components that are able to be used as microphones. Software offers a more difficult path in verification.
- What_wonder 6y agoI have no idea why verification, or other technical details, would affect the ethical calculus of having our conversations spied upon.
- vonquant 6y agoPeople who wish to mask their crimes have a greater incentive to use E2EE so will probably gravitate towards platforms that offer it. I would therefore suggest those not committing crimes are disproportionately affected by E2EE not being made the default where possible. Once one service in a particular category offers E2EE, the benefits of the other services in that category not offering it is significantly reduced.
- SamWhited 6y agoYou forgot "5. Zoom gets praised for developing features in response to criticism that already existed in other products that work better." Jokes aside, with Zoom's track record, it's not worth using anymore regardless of what features they implement. Not having E2E encryption is no where near as much of a red flag as lying about it is to me.
- DelTaco 6y agoJust curious - what other product that works better do you recommend? Webex, Skype, Hangouts/Meet, Teams all pale in comparison when it comes to quality and ease-of-use.
- jszymborski 6y agojitsi works wonderfully. I've also have been using Discord for voice almost daily for a little over a year and it just works 99% of the time. Unfortunately, it suffers from "gamer" branding that makes it awkward suggesting for work. They should try offering a "business skin" that interops with discord.
- CarbyAu 6y agoI second Jitsi. For me, the value is in hosting your own Jitsi server. Really not that hard to do. Mind you, I only host it at home on a VM for personal use. Have had sessions with 6 people with one of them a Europe-Australia connection. All fine on default 720p. If I were looking for 20+ meeting software though I'd consider something else. I would consider it a case for streaming to faceless attendees. I have never had a meeting with useful input from more than 10 people.
- hunter2_ 6y agoIt bothers me a bit that such branding/skin influences the situations in which people use good products. I tried to get my friends to switch from Facebook Messenger to Slack, and plenty of them use Slack at work (as do I), and a large amount of pushback was along the lines of "I don't want to feel like I'm working." It's just a means of communicating, people. Maybe a few Discord features aren't useful outside of gaming and a few Slack features aren't useful outside of the workplace. I find that to be a stupid reason not to generalize the use of these products. Skinning (and filtering away those specific features) just might be the ticket.
- feanaro 6y agoDidn't they also announce they wouldn't implement E2EE so they could cooperate with the police better?
- TallGuyShort 6y agoMy immediate thought was that they'll introduce encryption that happens on the client, and decryption that happens on the other client, but will have a way to know what the key is on the server, too. Honestly any near-ubiquitous communication medium is going to have enormous pressure to be insecure by design, if not from the Chinese government then from the US.
- reaperducer 6y agoAnother way of looking at it is that Zoom is learning from its mistakes and making improvements that the market demands. I'm no Zoom fan (I'd even use BlueJeans first), but people on HN are always so eager to crucify a company for its past. If it made mistakes, get out the tar and feathers! If it doesn't fix those mistakes, get out more tar and feathers! If it fixes the mistakes, even more tar and feathers!
- jdsully 6y agoLying about a feature isn’t just a “mistake”.
- vntok 6y agoLying about a feature is exactly what Silicon Valley's "fake it till you make it" culture encourages. Crucifying Zoom over this while letting virtually every other company in the space (inc. Hangout/Meet and MS Teams/Skype) go free seems quite hypocritical from an HN community that's comprised of many startupers and startup wannabees who spend their professional lives working for entities with similar practices.
- deleted 6y ago[deleted]
- markkanof 6y agoThat’s not what the expression means. If you are a tiny company and a big customer comes to you and says “can you scale to support us”, you answer yes even if you are not 100% sure you are ready. If however you claim to have feature X and you don’t, that’s just a lie.
- velp 6y agoI think I agree with you, but this argument seems like a pretty arbitrary line. How is saying "yes we can scale" when you're not sure if you can, aren't you essentially implying that you have the infrastructure to deliver on that promise? And if you don't actually have that infrastructure yet/built/proven, then you're essentially selling a feature that doesn't exist. It's shades of grey from lying about E2EE, but seems pretty similar imo
- pulse7 6y agoThe key information is in this sentences: "We are also pleased to share that we have identified a path forward that balances the legitimate right of all users to privacy and the safety of users on our platform ... while maintaining the ability to prevent and fight abuse on our platform." So they found a balance between privacy and ability to prevent abuse. In other words: this E2E encryption will have some backdoor which will be used only for legal reasons (to prevent abuse, etc.). Just like in the 80's when the US government asked Atari if they can provide encryption for their systems... In was encrypted for everybody, except... the government...
- thePunisher 6y agoI agree. That's why I'm asking Zoom: "Define end-to-end encryption." Most likely, it will be backdoored form where they can intercept the call if they want to. And they'll promise us they won't unless there's a "lawful request." What use is E2EE if it's backdoored? Nada, zero, zilch.
- g-b-r 6y agoIt's easy to say "it balances" if it's you who decide how much the stuff on the plates weigh
- deathgrips 6y agoThis is one of the downsides of the casual acceptance of corporate invasion of our privacy. Corporations can do whatever they want! Including letting China listen to your doctor appointments.
- fludlight 6y agoZoom’s engineering team is based in the PRC. This opens them up to pressure from the dictatorship which has made large scale industrial espionage a public policy goal. Somebody is listening, and likely transcribing, every call at organizations of interest. The source code, public statements, etc are irrelevant; if the PLA wants a Chinese national in China to do something, they will. The penalties for noncompliance are terrifying.
- BelleOfTheBall 6y agoYou should also mention step 4b. Zoom admits it censors accounts for China, losing any and all hope of being trustworthy.
- virgilp 6y ago> Given their track record I’d expect this timeline to repeat itself so after they release this E2E encryption feature, security researchers will discover that it’s not true E2E encryption again. I mean, you can already look at the design if you wish, it was disclosed by Alex Stamos: https://twitter.com/alexstamos/status/1268061790954385408 https://twitter.com/alexstamos/status/1268061790954385408 TBH I'm sort of surprised they gave in to the new wave of criticism, their arguments for not giving E2E to free accounts were pretty decent.
- suizi 6y agoTheir arguments for not giving it to free accounts was awful and the same trite which has been regurgitated for twenty years. The real reason is they want to be able to hand data over to China / NSA / marketers.
- virgilp 6y ago> The other safety issue is related to hosts creating meetings that are meant to facilitate really horrible abuse. These hosts mostly come in from VPNs, using throwaway email addresses, create self-service orgs and host a handful of meetings before creating a new identity. It's honestly the first time I heard this justification - where else did you hear it in the last twenty years? Also do you have some concrete reasons to believe Zoom hands over data to marketers? That's the first time I personally heard this claim - can you link me some evidence?
- suizi 6y agoTwitter has been caught using phone numbers for security purposes / tackling fake accounts in the past for marketing purposes. Zoom has a very dubious history, involving China, lies and a complete lack of security. As for the same old same old? It hasn't been precisely in that form but criminals have used Facebook, Tor, Email, Discord, YouTube, Usenet, Skype, MySpace, and other technologies / sites to facilitate abuse. This is merely the newest iteration.
- 6y ago
- btown 6y agoI'm actually more alarmed than I was before the announcement, because it indicates that there wasn't sufficient pressure for them not to do this. Watch them put the key in a predictable memory location, then have a subtle vulnerability elsewhere that lets them exfiltrate the client-generated key at any time. Anyone with views that might be dangerous to reveal to state actors should be very, very wary.
- throwaway2048 6y agoAnybody that trusts zoom with anything even slightly sensitive these days is completely nuts. Yes, we know its easy to use.
- deathgrips 6y ago99% of people do not care about privacy. They won't switch programs because a nation state might spy on them.
- mindfulhack 6y agoYes they will. You need to be thinking about LGBTQ people in many non-Western countries.
- deathgrips 6y agoThey are the 1%. 99% of people consider "privacy" a good value in abstract but will not lift a finger to protect their own privacy. It's virtue signalling.
- kennywinker 6y agoI absolutely hate the term virtue signalling. It's always reductive and dismissive. If I am willing to go a LITTLE out of my way to protect my privacy, but not a LOT out of my way, am I "just virtue signalling"? If I continue to use a privacy-less platform (e.g. zoom/instagram/facebook) but just exercise caution with what I say using that medium, is that also "just virtue signalling"? I agree, evidence shows most people are not willing to go very far out of their way to defend their privacy. But I also think privacy is a genuine virtue, and a desire for it is present and often untapped. Why else would Apple have run privacy-centric ad campaigns? Attempting to tap into the weak but widespread desire for privacy, I think Also, side note, lgbtq people make up somewhere in the range of 2-7% of the population, not 1%.
- soulofmischief 6y agoThey hired the Keybase team. I feel like if the team was directed to develop countermeasures to the E2E or design the E2E to be vulnerable, someone would have blown the whistle. E2E was Keybase's thing and it would be a huge slap in the face.
- bamboozled 6y agoIt's crazy that zoom seems to have no real competitors who take this stuff seriously.
- jmull3n 6y agoYou missed the part where they acquired Keybase to help them build e2e encryption. https://techcrunch.com/2020/05/07/zoom-acquires-keybase-to-get-end-to-end-encryption-expertise/ https://techcrunch.com/2020/05/07/zoom-acquires-keybase-to-g...
- ragona 6y agoI think that’s a little lacking in nuance. The team they have putting this together say to me they’re putting their money where their mouth is, at least. That paper has a fucking legit list of contributors.
- m463 6y agoI've always suspected they didn't want E2E encryption themselves, not because of any "work with the authorities" strategy. end to end encryption would prevent lots of monetization strategies, such as indentifying people via facial recognition and voice printing and then using this data (along with transcripts for example) to "add value". Now the "we have identified a path forward" bit makes me wonder if they can still pull it off. Maybe it's client-side identification with out-of-band notification. Google makes an enormous amount of money identifying people.
- vijucat 6y agoAside: Zoom stock has risen 252% during this time ($67 on Dec 18th 2019 to $236 on Jun 18th 2020).
- glennpratt 6y agoIn "enterprise" software, E2E hasn't meant what it means in modern chat programs. In my world, it just meant encrypted over the wire and at rest, nothing more. We aren't there technologically to have many zero knowledge SaaS products. I don't know they aren't liars, but that difference might be a reason.
- quotemstr 6y agoWithout identity management, E2E is worthless because you don't know that today's E is the same as yesterday's. Zoom is probably still sucking up to various state security agencies but doing it via MITM instead of just tapping the server.