When you are using the tool for business, that is a deal breaker.
When you are using the tool for business, that is a deal breaker.
What makes people trust the advertised E2E encryption is really happening when they most need? Faith in these companies?
It's pretty depressing, actually. A determined adversary with intelligence-service level resources can get a lot done. Your main hope is to be such an insignificant target that they don't want to waste resources, e.g. expose 0-day vulnerabilities etc to get just you.
Still the best thing available if it works for your case.
Also appear.in works on Linux.
Skype through Office 365 is also Skype for Business/Lync.
First time I saw it I couldn't help to notice the similarities. Even the emoticons were the same!
There was an integration you could get (purchase, I think?) which allowed Lync to connect to the MSN network and chat to users of MSN.
It provides end to end encryption with customer owned keys.
High level data on the security model: https://www.ciscospark.com/content/dam/ciscospark/eopi/count...
Draft of the KMS technology behind it: https://tools.ietf.org/html/draft-abiggs-saag-key-management...
There are many open source for teleconference these days, e.g. https://jitsi.org/ - I recall a few appearing on HN as well.
I mean, whatsapp claims it has E2E encryption, but I've never checked...
I'm not sure what parts you can verify, but I'm willing to trust the word of those at Whisper. Perhaps I'm naive but they seem to genuinely care about improving privacy for others.
If you are a high-profile target, no matter what vendor or software you use, Five Eyes will do whatever is needed to infiltrate your network. Cisco is a large target just due to their volumes compared to most other solutions (you are more likely to see news of Cisco attacked due to volume of sales). But with that, Cisco will also dedicate resources to trying to defeat this type of attack.
[0] http://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa-...
If you read the "Exploitation and Public Announcements" section of the Cisco publication, it meantions the source was another CVE from a month ago[1].
StarLeaf (https://www.starleaf.com/) is a great alternative for businesses.
The cloud is at the end someone else's computer. No, I'm sure Microsoft CEO isn't interested in sabotaging my business just like I'm sure the POTUS doesn't actively decide to kill innocent civilians. However, they make compromises (something we all do in engineering) and some of those compromises could end up with us as collateral damage.
What I'm getting at is even if all government agencies have purest of pure hearts, someone somewhere will eventually leave a door unlocked. Nobody can tell me with 100% certainty that this won't happen in the US and I trust their competence more than some outside contractor working for the Qatari emir.
This is my point of view on why we shouldn't have a dragnet. I don't have to argue that my government is evil. I don't even have to say my government is incompetent. But who in my government will testify for the other 200+ governments and their agents?
You just don't know whose tapped the line, whose listening, and what systems your text is being indexed into. So reliable E2E is key.
[1] https://theintercept.com/2014/12/13/belgacom-hack-gchq-insid...
Unless you're using physical couriers and airgapped networks with TEMPEST protection. I say this unironically; these are facts people tend to brush away.