SpaceX bans Zoom over privacy concerns
reuters.com
reuters.com
insert Hanlons razor quote here
Being incompetent has nothing to do with the size or prominence of the company. Big/prominent companies fuck up/are sloppy all the time.
Their intention was to deceive users that the communication was encrypted, when in reality it wasn't.
I'm in no way saying it's impossible that Zoom did say E2E encryption while knowing that's not true, but I could imagine a scenario where a security person says "Yeah, we're encrypting connections to our backend" and a marketing person researching E2E and then saying to themselves "Yeah, sounds like we're doing E2E, let's write that", because this stuff happens all the time in the industry.
> Their intention was to deceive users
You sound so sure about their intentions, do you have any actual proof of this that others are missing? Again, I'm not saying it's impossible that their intention was to deceive users, but as an engineer, I always favor proof over guessing.
But just because someone uses a word wrong doesn't give you any proof about their intentions. See https://news.ycombinator.com/item?id=22767447 for further elaboration on that point.
Again, it's harmful to use words incorrectly, _especially_ when it comes to E2E, so they should rightly get flak for getting it wrong. You all seem to be so sure that it was intentional though, while I've seen the same problem so many times before in the industry without it being intentional. If you do have proof it's intentional, please share it with the rest of us so we can be on the same page.
If I remember correctly, zoom used to have on the front page - use this it's encrypted, and 'even used by us govt something-something' - so I assumed it was completely secure.
I actually refused to use other conference services much to the bemoans of many clients who already had other 'goto' software installed, used and understood - and convinced them that in order to talk turkey we needed to use the real secure zoom system.
It passed the smell test at the time for me because they also had paid plans which meant to me a legitimate business that did not need to slay privacy with ads and such, as they had a clear path to make money.
Now they are tarnished, and my reputation with several clients and doctors and others may be as well - as this is getting mainstream press (I think that's a good thing actually) - I'm livid about this.
I agree with below it is also fraud - and another commentator mentioned they changed to "your client connection is encrypted" is still deception imho. Needs a big asterisk and real explanation of the lack of privacy.
1) I don't want to train them on it
2) I don't want to support them on it
3) It isn't good enough for them to use without 1-2
So I pick the shiny costly commercial version that comes with training and support.
I mean, I've done the recommend my parents and older coworkers use difficult OSS software thing in my past, and I honestly regret it. No one won.
where's the hassle? or the lack of shine? it works better than any other proprietary service
I know it's the kind of thing that can randomly keep a person up at night, but I think you can probably safely forget about this awkwardness and move on.
People in Tennessee watching regular news on free over the air antenna (non-cable news) -> https://www.wsmv.com/news/security-experts-warn-about-zoom-h...
any anyone who is within earshot of such 'non-tech news' is hearing how unsecure zoom is.
Sure most of my clients are unlikely to read HN at all, and most are unlikely to read tech crunch regularly if at all - but I bet some have TC or something similar in their fbook feed.
People watching TV news in Utah see: https://fox17.com/news/nation-world/zoom-call-with-utah-elem...
However people who don't even own computers are seeing this debacle.
So, anyone I've advised to use zoom for privacy and security, citing the encryption and use by US gov - is going to have to wonder - how do these things happen on a secure, private, encrypted system - must not be what it was purported to be by that guy Steve. Then they are going to wonder what kind of damage could be done with the info that was 'securely' shared with the service.
It's natural that there is a divide and marketing isn't expected to understand every engineering thing (nor the other way around.) If your job is to write words, though, you are responsible for the words you right.
Wait, did you do that on purpose? :)
On a more serious note, you would need to trust not one ISP if the video wasn't encrypted, but all the ISPs in the room simultaneously, and that is probably something even less trustworthy than Facebook.
"If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices."
Ultimately, it's false to equate iMessage's encryption scheme, which is end-to-end, to an encryption scheme that requires a server to relay decrypted data.
Utterly false. Real end-to-end encryption would encrypt the backup with a key that is not available to the backup service (e.g. derived from a passphrase not sent to the server).
Of course this system has better usability, which is why Apple does it. But it's still a farce to call a system where Apple has the ability to decrypt the majority of messages "end-to-end" encrypted. The fact that it's through the backup servers instead of the iMessage servers makes no difference.
What's more, it's possible to do better without sacrificing usability. For several years Android has been end-to-end encrypting backups using the user's lock screen passcode, with protection against brute force attacks provided by hardware secure elements. https://security.googleblog.com/2018/10/google-and-android-h...
It makes a big difference. If I print out the texts I receive, it doesn't change whether the texting program is end-to-end encrypted. The same goes for backups. An unencrypted system-level backup doesn't mean that the program being backed up is failing at security.
It's bad that Apple doesn't let you encrypt your backups properly, but it's a separate issue.
> An unencrypted system-level backup doesn't mean that the program being backed up is failing at security.
iOS programs can choose how their data is backed up. iMessage isn't just getting its data stolen by iCloud accidentally. These backups are a feature of iMessage as much as iCloud. And besides, iCloud is made by the same company, it's not a separate entity.
> iOS programs choose how their data is backed up.
Well desktop apps don't. Would you say that no desktop app that saves its key can ever qualify as end-to-end encrypted?
> And besides, iCloud is made by the same company, it's not a separate entity.
I'm not convinced that's relevant to whether the encryption is end-to-end or not.
I would say that no app can qualify as end-to-end encrypted if a large fraction of users send their data to the maker of the app in a form that can be decrypted by the maker of the app, regardless of the reason.
Have you considered that some people trust Apple but don't trust Zoom? At some point you have to trust somebody, right?
> At some point you have to trust somebody, right?
It's possible to use an actual end to end encrypted app that doesn't have the keys to read your messages stored on their servers.
iMessage doesn't store your decryption keys on Apple's servers unless you opt into iCloud backup which is a whole different service and security concern.
> Apple does not have the ability to read your messages.
iCloud backup is an Apple service and it has the ability to read most of your messages even if you don't use it, which makes this statement categorically false.
That I may have given Apple my private key through a different message in no way affects that end-to-end encryption, because it is trivial to decide not to give Apple that key.
You can decide not to give your keys to Apple, but you can't decide for all your friends to not give their keys to Apple, and the result is the same: Apple can read your messages.
And the marketing is so misleading that hardly anyone knows that Apple can read most iMessages.
> > iCloud isn't some separate entity from iMessage. It's all Apple.
> Got any sources for that? Sounds a lot like FUD.
You don't use a password to encrypt your iCloud backups... They're specific to the hardware your backing up. If you have an itouch for example it's backups are separate from your phone.
So now you have these backups in the cloud and you lose your iPhone, you remote wipe it.
Now your new one arrives and you restore from backup... Your iMessage private keys are available to apple unencrypted .... Because you didn't need to provide a second factor of authentication for unlocking the backup you were just asked which one to use.
Apple and any reputable nation-state can read your iMessages with a subpoena ... If you use iCloud backups and not local backups with a password.
2) What about your iCloud account and password that are required to encrypt, store, access, and decrypt the backups there? Is that not a factor worth consideration?
I wish this meme of trying to sound fancy by misusing the term "nation-state" would die.
Here is another article from 2016, which shows that Apple patched iMessage to prevent attackers who don't have access to Apple's servers from reading the messages but still kept the ability to read the messages themselves. https://blog.cryptographyengineering.com/category/imessage/
Apple was aware that people knew it could decrypt iMessage messages this entire time, but Apple made no changes that would fix that. That should give you some idea of whether Apple intends to ever fix that.
E2E encryption simply means that messages are only decrypted at the endpoints. That certainly isn't true of iMessage in China, and it might not even be true for some users in the US — we have no way of knowing because the protocol makes no guarantee against it.
"If you have iCloud Backup turned on, your backup includes a copy of the key protecting your Messages. This ensures you can recover your Messages if you lose access to iCloud Keychain and your trusted devices."
What we know is that they can and do decrypt iMessages from iCloud backups in response to law enforcement requests[1]. This proves that they hold the keys, if their own support pages weren't enough evidence for you.
[1] https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
https://threatpost.com/apple-imessage-open-to-man-in-the-mid...
This is why WhatsApp for example notifies users when the key of the recipient changes, and they give you a way of verifying that the both keys at both ends are identical.
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
FaceTime chats, though, truly are end-to-end encrypted and the calls aren't backed up like iMessages are.
They merely mention that backups to iCloud happen automatically by default, and not that doing so means the default is that Apple can view and decrypt all your messages.
Two options impact it: "Messages in iCloud" re-encrypts and uploads messages to the user's iCloud account and stores the key in iCloud Keychain (also end-to-end encrypted).
Only when enabling iCloud backup will that key be revealed to Apple.
> To be clear, in a meeting where all of the participants are using Zoom clients, and the meeting is not being recorded, we encrypt all video, audio, screen sharing, and chat content at the sending client, and do not decrypt it at any point before it reaches the receiving clients.
The first problem is:
> Zoom currently maintains the key management system for these systems in the cloud.
Obviously, this compromises many of the benefits of e2e encryption. Having said that, it doesn't remove all of the benefits, and it's a (bad) precedent that has been set by other companies (eg. apple) where keys for end-to-end encrypted communication are backed up to the cloud.
The second problem is that Zoom has a second class of "client" called a "Connector" which runs in the cloud, and also has access to the keys for decrypting the stream. I definitely think that when one of these connectors is being used, it is false advertising to show the "e2e encrypted" status. However, there are clear technical reasons why these connectors are needed. Being able to dial into a meeting from an ordinary phone is important functionality that simply cannot support end-to-end encryption.
The interesting section to me is the later paragraph:
> For those who want additional control of their keys, an on-premise solution exists today for the entire meeting infrastructure, and a solution will be available later this year to allow organizations to leverage Zoom’s cloud infrastructure but host the key management system within their environment. Additionally, enterprise customers have the option to run certain versions of our connectors within their own data centers if they would like to manage the decryption and translation process themselves.
In particular, being able to use your own key management system would make this truly end-to-end encrypted by any definition, even if you are still using Zoom's cloud infrastructure.
Backed up for iCloud users who might not know any better, but not backed up for people who take the time to learn how to guarantee the full protection of E2E by keeping iCloud off. The fact that the full benefit is available with little effort, albeit not obvious, creates a contrast to how:
> Zoom has never built a mechanism to decrypt live meetings for lawful intercept purposes
...but they easily could. Users can't just search for how to harden the Zoom encryption to the point of lawful intercept becoming impossible and find a simple solution the way they can with Apple.
> an on-premise solution exists today for the entire meeting infrastructure
...is not practical for most.
So, eliminating the E2E badge was the right move. The fact that it was there until now is shady.
Which is the reason zoom gets used so much.
Last time I used meet it tended to turn my laptop into a fireball, even with just one or two other participants.
I tried Hangouts recently and the quality was terrible compared to Zoom. Discord was far better than Zoom though.
Very long story, but long story short, I needed the tool urgently (this was pre-Ghidra), like hours & days mattered. I am a small company, they were "skeptical" of me and my intentions, they demanded all sorts of paperwork and IDs, etc. It was seriously as though it was a dark comedy nightmare.
Everything you wrote is true. So many people fellate IDA given the chance; I don't know what they're smoking. The product is clunky and ugly (but it mostly works), but as you said, it's got very little competition. I and a few of my colleagues (and many here on HN) could probably do a better job, but I don't want to live in that world.
Man, I think I got pretty far afield there, but your comment resonated with me. Thank you.
The reason? "It just works."
It's clear their singular focus on making it "just work" for even the least tech-savvy users has led them to prioritise user experience over security/privacy. I imagine a rebalancing is coming.
The problem is, that the actions of Zoom doesn't make them look like a trustworthy provider. They lied about the end-to-end encryption. What they should have done instead is to be transparent on how unencrypted data is used on their servers and what their protocols are to prevent unauthorized access to that data. Which is especially important in a business context, because the business users themselves have confidentiality agreements, they need to guarantee and using an external provider for confidential data required that provider passing the neccessary scrutiny.
And of course, the huge pile of security issues coming up with their client, the web server, the mac installer, the script host, give any reason to believe that they either don't know what they are doing or completely reckless at least. And the term "reckless" doesn't fit in a conversation about security :).
Your internet service provider can deduce the same about your HTTPS connections.
Not really because Zoom makes fairly extensive use of the decrypted video streams on their servers, e.g. to detect who is talking, pause video for people with slow connections, etc. You could maybe do it for meetings with a few people in, but good luck doing it for meetings with 100 people.
Hell the cryptography of group end-to-end encryption hasn't really been worked out yet. WhatsApp doesn't do it and that's just for text. I'm pretty sure Signal doesn't either.
There's really nothing bad with not having end-to-end encryption for group video conferencing apps. The shitty thing is that they pretended that they did.
You encrypt audio and video streams separately. If your connection is slow you stop grabbing the video stream. Detecting who is talking is a local function because you are receiving audio packets from them. Encryption doesn't have to change the amount of data sent.
> Hell the cryptography of group end-to-end encryption hasn't really been worked out yet. WhatsApp doesn't do it and that's just for text. I'm pretty sure Signal doesn't either.
Two ways: 1. Your password does not need to be shared with Zoom for entry into the meeting room. That password and the meeting room number are converted into a symmetric encryption key, so everyone who is able to join the meeting successfully has the same group shared secret for both sending and receiving video and audio.
2. You have an invitation system where the host of the meeting approves people. This approval causes the symmetric key of the meeting to be shared with the person seeking approval, encrypted to their public key. People who can supply a proof of possession of the password or whose public keys were associated with the meeting get invited without requiring confirmation by the host, although the participants in the room becomes a log of who was able to view the meeting.
These get harder if you want to say have a periodic key rotation while a meeting is going, for sure. They also get harder if you try to encrypt routing metadata or disguise that the traffic is audio/video in general.
The real thing that kills E2E for a corporate product like Zoom are the phone dial-ins. Hardly a point for all that security if you have one person calling in having the now unencrypted voice traffic bounced all over the place.
> There's really nothing bad with not having end-to-end encryption for group video conferencing apps. The shitty thing is that they pretended that they did.
100% agreed within Zoom's market because of integration of external services like dial-in/dial-out voice.
Wow this is news to me. Glad I'm not using whatsapp since forever.
Signal definitely encrypts group chats since forever: https://signal.org/blog/the-new-textsecure/
That doesn't seem to be accurate: https://faq.whatsapp.com/en/android/28030015/
Maybe you're thinking of this issue?: https://medium.com/@haniahshafi/are-whatsapp-group-chats-vul...
There may be advantages to processing video at the server, but it's definitely not a hard requirement.
If you want to support thumbnail/fullscreen versions of streams, the clients could just send along two streams or use a codec that supports this kind, like h.264 SVC.
There is no problem doing key exchanges between all the participants as long as the number of participants isn't too huge. Everyone just needs to kex with everyone else, so from the POV of a single participant the effort scales linearly with number of participants, even though the work collectively done by everyone is squared.
At my previous job, we used to dial in random zoom numbers and entered into random conversations of other companies. Once we landed into a Facebook call where they were talking about Libra (before it was a thing).
If you turn of camera and video, the host doesn't even know you're there unless they check guest list.
That's a hard no. Turned me off the service entirely.
Annoyingly it's a bit too convenient, so going out of band is a pain.
Seems like they need to get their CPU use under control.
As a headset user myself, no one ever asks me to repeat myself, notices when I type, or hears anything not within an inch of my mouth. Plus, I've got a physical mute switch for instant, unambiguous mute, as-needed.
Oh, and yes,I "almost forgot" ! How to they even physically manage to get multiple seconds latency at times, when everyone in the call is in the same city, and where the worst connection on the call is at about 20Mbit? Are they just buffering for the heck of it, why not simply drop some frames if you get behind?
This may improve soon. Slack is starting to force apps to request granular permissions (vs a big-tent "bot" scope like before) and when you submit to their store, they vet each permission and verify what you're using it for. They don't let you request permissions "just because" in my experience.
* View some URLs in messages
* View messages and other content in public channels, private channels, direct messages, and group direct messages that Zoom has been added to
* View basic information about direct and group direct messages that Zoom has been added to
* View basic information about public channels in your workspace
* View basic information about private channels that Zoom has been added to
* View files shared in channels and conversations that Zoom has been added to
* View pinned content in channels and conversations that Zoom has been added to
* View messages and files that Zoom has starred
* View emoji reactions and their associated content in channels and conversations that Zoom has been added to
But I agree the way they suggest it is end to end encrypted is misleading. I don't think it really can be end to end to get the performance and features. People just need to see each other at the moment. You can do anything sensitive with more secure communication. But it clearly doesn't belong in any place discussing technology with military applications.
I still think it is solid for my kids to keep up with their lessons or for a weekly meeting about some web development. There are genuine criticisms of Zoom at the moment that need to be taken seriously but there is likely also some negative media being generated from their competition that are missing out.
[1] https://en.wikipedia.org/wiki/Comparison_of_VoIP_software
The time to pull out might be after their next quarterly report.
Also, I have been enjoying this: https://github.com/arkadiyt/zoom-redirector which highlights how optional the use of the native client is.
There's also MS Government Cloud: https://azure.microsoft.com/en-us/global-infrastructure/gove...
Take Confluence for example, if I use the cloud version I can't store any files there or have any information about certain projects. But I can run the same Confluence in-house and then we can share project details. As you point out, its not always that easy.
Zoom is looking like it’s closer to Discord than Slack.
https://marketplace.fedramp.gov/#/product/zoom-for-governmen... https://marketplace.fedramp.gov/#/product/slack
Mattermost is self-hostable, so as long as you tightly control access, a lot of the SaaS prohibitions don't apply.
* laughs in Heartbleed
Your user name doesn't give me confidence...
Of course there's been other services working just as well or better for at least 10 years now. Interesting things converged suddenly on Zoom. I guess full cross-platform support was the key? Also interesting is the deluge of anti-zoom articles that are blanketing the cybersphere :-) just as they are getting traction. Jealous rivals? Disgruntled lovers?
MS Teams is better but you have to pay for it (and maybe it's complex to implement too).
Zoom is free (and supports large numbers of participants which other free alternatives don't). Also meetings can be setup with about 4 mouse clicks by the user himself with no other kit than a browser in Zoom. Getting your art department home workers to correctly
It has been weird watching people insist we use zoom because it supports so many users, when there are only three of us actually in a meeting. So the cynic in my suspects it's being used by (say) schools and universities (as the Skype limit was 32 people, now 50). And other people have assumed it's better since Harvard\Cambridge use it, so now they use it for 4 people...
I have 4 different accounts that have access to different Teams instances. They all have my full name, and therefore the same initials. There is no way to tell which account you are logged in as, in the UI.
A couple of months ago, they finally fixed the "log out and log in as a different user" flow so it actually did something for me. Before that, it would log out, and then just automatically log back in as the same user.
You can't (as far as I can tell) run two instances as different users at the same time.
I join most Teams meetings as "guest" on my phone. That works OK, but it doesn't really say much good about the Windows app.
There is a good overview of the options in an article recently posted here - see under "Videoconferencing":
My only 2 grievances with it are:
1. Teams steals focus to make the next message on a group, rather than in the threat ALL THE TIME. Ive been there for a dozen comments because Teams stole cursor focus.
2. Its easy to make an invite to a one-shot room, rather than use an existing room. Doing so loses all history and provenance and discussion. And there's no "merge this room with the real place" when that happens.
But all in all, Ive been on 130+ person calls with no issue. Works very well, aside those issues above.
The fact that I lived with the bug described in https://news.ycombinator.com/item?id=22741348 for a long time with no idea how to fix it didn't help.
Another question, why ppl who so care about security keep relying marketing stuff rather than using open-source solution?
slenk@Enterprise:~$ host spacex.com
spacex.com has address 50.112.120.214
[output truncated]SpaceX.com at least uses an IP address owned by Amazon: https://www.abuseipdb.com/whois/50.112.120.214
slenk@Enterprise:~$ host spacex.com
spacex.com has address 50.112.120.214
[output truncated]Meanwhile, it's 2020. Didn't think video conferencing was such a big deal.
This is a matter of national issue. This rush to remote is not something that will go away completely.
I think many security minded people are not comfortable with zoom, but have to use it.
Please Apple, build something that can replace zoom.
The supposed root exploit found in Zoom also requires physical, logged-in access to the machine, at which point a Zoom exploit is the least of your problems [2].
Zoom is a solid piece of software, and the developers are responsive and seem to care. I'm disappointed to see it getting dumped on during the past few days. A cynic might even suspect a co-ordinated campaign by Cisco, considering Zoom was started by frustrated ex-Cisco employees and has had runaway growth during the viral crisis, while the same cannot be said for Cisco's competitor product WebEx.
[1] https://blog.zoom.us/wordpress/2020/03/27/zoom-use-of-facebo...
[2] https://9to5mac.com/2020/04/01/new-zoom-bugs-takeover-macs-c...
When you make weapons technology (as SpaceX does; rockets are weapons technology) and are involved in launching military satellites (as SpaceX is), you kinda have to take security issues seriously.
Large part of, if not entire, Zoom engineering is based in China, so just based on that singular fact IMHO this is not at all a knee-jerk reaction.
Add to that numerous security found in Zoom just over the last few days, and I'm surprised why more companies are not doing the same.
The senior people are all in the US though.
The dodgy things they've been doing suggest otherwise.
* Hijacking package preflight script rather than standard package installation mechanism, so their software is installed before the user clicks Install.
* Installing a hidden web server without user consent.
> The FBI’s Boston office on Monday issued a warning about Zoom, telling users not to make meetings on the site public or share links widely after it received two reports of unidentified individuals invading school sessions, a phenomenon known as “zoombombing.”
I get the exact opposite impression. Not just due to these bugs, but also the hidden webserver thing [1] a while back.
Recurring theme in this (the webserver and the installer issue) seems to be an unhealthy obsession with reducing the number of clicks the user needs to perform. They deliberately chose dubious, hacky solutions over doing things the right way due to this. It makes you wonder what other bad decisions they made in the client or server code.
[1] https://www.theverge.com/2019/7/10/20689644/apple-zoom-web-s...
Zoom has a pattern of abusing users' trust. Ok, maybe its not intentional, but increasingly, that doesn't matter in security discussions. The fact that it was unintentional is a concern itself. Maybe they lack discipline, or leadership, or something; I'm not asserting to know. But, its no longer good enough to simply say "we're sorry, it was an accident".
They have what is commonly referred to as form.
Consider the past year's highest voted stories whose title includes the word 'zoom'
https://hn.algolia.com/?dateRange=pastYear&page=0&prefix=fal...
This is certainly not a 'knee-jerk reaction' to the use of the Facebook SDK, but presumably extrapolates from the history of false uninstallation, insecurity by obscurity, false advertising, etc.
Each of those things has been, as you intimate, patched or resolved -- but does that give you increasing or decreasing confidence in their product and priorities?
No, it does not; 9to5Mac is just playing a game of telephone from the original blog post and the actual issue only requires code execution on the machine.