4 ms·
I see lots of comments about the meaning of end-to-end encryption but less about what actually happens here. Zoom, like Meet, Teams, WebEx, and many others to
by barathr 3y ago
I see lots of comments about the meaning of end-to-end encryption but less about what actually happens here.
Zoom, like Meet, Teams, WebEx, and many others to my knowledge is "encrypted" but not by default "end-to-end encrypted" in the normal meaning of the term. (Some of these have options for E2EE but it's buried in the service configs and not easy to enable.) So they can and do see audio and video on their servers (as can anyone who breaches their infrastructure) by design. The encryption in this default mode only prevents your ISP from seeing the content of the call.
As a distinction, Signal calls are E2EE -- Signal doesn't see unencrypted video/audio for calls, even ones that are relayed through Signal servers. And even in that case, Signal still knows the participants of the call, just not what is being said.
(As a side note, this is why we built Booth.video -- to demo that this isn't a fundamental tradeoff and it's possible to have E2EE, metadata-secure video conferencing in the browser.)
- greiskul 3y agoYup, Signal is the industry standard into getting actual privacy. But one player that deserves a shoutout when it comes to privacy, is Whatsapp. Even after becoming a Facebook company, it has kept E2EE, for messagings, group chats, and calls. And they do so by using the library that the greak folks from Signal put out.
- facu17y 3y agoExcept Signal's founder probably has/had a connection with the NSA. All security is for making it hard for the common attacker, and hostile countries. The NSA, most likely, has social engineered its way into every stack and every important org.
- reciprocity 3y agoWhat? Where did you get that from?
- sundarurfriend 3y ago> Even after becoming a Facebook company, it has kept E2EE, for messagings, group chats, and calls. According to their own claims, right? There's no way for anyone to verify that they're actually E2EE, just Meta's word that it is so.
- greiskul 3y agoThe use the Signal library. A security researcher could analyze the binary, and check that it always calls the signal library correctly. Prove that they don't, and congratulations, you will become a very famous security researcher.
- mercora 3y ago>As a side note, this is why we built Booth.video -- to demo that this isn't a fundamental tradeoff and it's possible to have E2EE, metadata-secure video conferencing in the browser. now i wonder how you did that. Is the key exchange of participants happening out of band?
- barathr 3y agohttps://invisv.com/articles/booth https://invisv.com/articles/booth
- deleted 3y ago[deleted]
- mercora 3y agoi think it cleared a thing up or two. However, would you mind sharing why insertable streams are apparently required for this to work? As WebRTC traffic is encrypted already E2E it seems to me that constructing the SDP with the key, currently used here with insertable streams, would be good enough.
- barathr 3y agoSure. So WebRTC is encrypted between peers when 100% of the communication is going peer to peer. But in most WebRTC services, your peer is actually the SFU, which is the server. So you're encrypting to the server, not to the other participants. (Most "pure" WebRTC platforms switch over to SFU-based communications at 4 or more participants, but many of the bigger platforms always send video/audio through the SFU regardless of how many participants there are.)
- deleted 3y ago[deleted]