Does Zoom use end-to-end encryption?
blog.cryptographyengineering.com
blog.cryptographyengineering.com
The Intercept article on it has a discussion here: https://news.ycombinator.com/item?id=22767807
Its key findings:
-Zoom documentation claims that the app uses “AES-256” encryption for meetings where possible. However, we find that in each Zoom meeting, a single AES-128 key is used in ECB mode by all participants to encrypt and decrypt audio and video. The use of ECB mode is not recommended because patterns present in the plaintext are preserved during encryption.
-The AES-128 keys, which we verified are sufficient to decrypt Zoom packets intercepted in Internet traffic, appear to be generated by Zoom servers, and in some cases, are delivered to participants in a Zoom meeting through servers in China, even when all meeting participants, and the Zoom subscriber’s company, are outside of China.
-Zoom, a Silicon Valley-based company, appears to own three companies in China through which at least 700 employees are paid to develop Zoom’s software. This arrangement is ostensibly an effort at labor arbitrage: Zoom can avoid paying US wages while selling to US customers, thus increasing their profit margin. However, this arrangement may make Zoom responsive to pressure from Chinese authorities.
It's not clear to me whether the threads should be merged, or—if we're to have only one on the front page—which thread should be the one.
But I think some people are still missing the general point that E2EE is fundamentally incompatible with general-purpose business/educational videoconferencing.
It works for Facetime which is designed for small groups exclusively using a Facetime app.
But the second you allow phone dial-in (virtually always a hard requirement), the second you allow cloud recording (which the article acknowledges), E2EE becomes meaningless, because the server itself necessarily becomes another endpoint.
For >99.9% of people this is fine.
For the <0.1% who might be the hand-selected targets of government spying, industrial espionage, or crime enforcement, then no, you shouldn't be using Zoom. But if that's a top priority for you, you weren't already using Zoom anyways -- I assume you'd be using auditable open-source encryption. You wouldn't have trusted Zoom marketing terms in the first place.
Not sure I agree with this one. Assuming a design where the server is just jockeying around encrypted streams because it doesn't have the keys, it could store the encrypted stream upon instructions from the client. The client would need to keep the key so it can retrieve and decrypt the recording later.
I'm really curious about this one — I've noticed that indeed in the US people tend to expect to be able to dial-in using the PSTN. Why would people do that? I haven't seen this happening much in Europe, and the Whereby (https://whereby.com/) conferencing tool doesn't even offer dial-in, which isn't a problem.
Why is dialing in using the PSTN a thing?
I've participated in Zoom meetings while sitting in a conference room with a speakerphone of considerably higher quality than any laptop mic.
The first case is probably unsafe. The second was very common back when we had offices with high-quality speakerphones.
I had the same problem but found a way to fix it. The Waves Maxx Audio tool which is apparently responsible for managing the hardware is useless junk.
For whatever technological reason, cell phone calls tend to be far more reliable than internet calls. Especially if you're in a taxi or on a train, you may get so many dropped packets it's literally unusable. While an actual phone calls works perfectly fine.
Not sure if it's how carriers prioritize traffic, or different technologies, or what. I'd be curious if anyone has the answer.
I'm also not sure why this would be any different in Europe.
(It's also, of course, the option of last resort when you can't get the damned app/microphone to work for whichever of a million reasons.)
Zoom does seem to be more reliable than skype for business.
It's perfectly possible to have end to end encrypted email, text, payments etc, but: 1. You will always loose features. 2. The "endpoint" (you) becomes responsible for a much bigger part of the protocol.
Most modern applied crypto is just shuffling trust and responsibility around.
The US government engages in bulk spying; this comment is a red herring. Without end to end cryptography, even normal, everyday people are at risk.
This trivializes a very important issue.
Encryption is directly linked to freedom in a society, because the lack of encryption acts as a power multiplier for those who are already in power, because it makes manipulating the masses easier even if single individuals are not at all hurt by it.
[1]: https://www.reuters.com/article/us-spacex-zoom-video-commn/e...
Being from Romania, in all the companies I worked on, we had the need to communicate online by voice and video (mostly with Americans and among ourselves), plus I tended to work in companies with a remote culture. The last time somebody needed to dial into a call I was in was ... 10 years ago. Given we have nearly unlimited 4G data plans for cheap and smartphones, being on the go isn't a problem either.
Since when is this ability to dial-in such a hard requirement?
> "For >99.9% of people this is fine."
99.9% of people don't understand what end-to-end encryption is and why it is needed, because they think their calls are secure, when in fact they aren't. It is actually our responsibility to make end-to-end encryption mainstream and to educate people.
Where I work nobody calls in and everyone uses webcams for VTC (software company, skews younger), but at my girlfriend's company a lot of people call in and nobody uses webcams.
Then it’s cool when it works and allows niche uses, but you can’t expect the feature to be there forever and can’t keep optimizing a service for these use cases.
The main reason I see people use dial-in, is when their audio or meeting client is not working, for whatever reason. The phone is a nice backup in those cases, and it (almost) always works.
Any time you have groups at two companies calling each other it's going to be a decently common requirement. Each company has X people in a conference room. Those X people need to all be able to talk and hear. Thus you use the room's audio equipment which is basically an expensive telephone to dial in.
Also, cell audio is much more reliable than cell data.
I call into meetings with my phone all the time. Especially when the meeting is an emergency, and I'm not home (obviously not applicable now).
It's a lot easier to pull out a phone and dial a number than to find my laptop, set up the hotspot, fire up the videoconference software, and then worry about running out of hotspot data in the middle of the call.
I'm an academic and a long-time Hacker News reader. It seems that the tech community has collectively decided that all internet communication -- of whatever sort -- should be secure, all the time.
My first thought, is an outsider, is that this is unnecessarily anal-retentive. But upon reflection, I'm very grateful for this. The more anal-retentive that developers have to be, the less I have to be. If HN is so up in arms about this, it's a very good sign for Internet security overall.
What is it that you'd educate me about? That someone could have snooped in on my departmental meeting? Before Covid-19, these meetings were held in in an open room, in an unlocked building where people walk in and out all day. Anyone with the desire to snoop would have had no difficulty.
From what I understand, enough pressure is being placed on Zoom that they are cleaning up their act. From where I sit as an outsider, the system seems to mostly be working. I'm not angry at Zoom, but I'm very happy that others are.
I think the argument would be that you could secure those meetings if your management felt it was necessary. Many large companies have badge readers, cameras, and the like at various places in their buildings. If they need to hold a secure meeting, they can hold it in a secure area.
With Zoom, there's no such thing as a secure area. Your company is basically forced to hold meetings in a wiretapped room.
It's like having a car company and saying, "I don't know why anybody would want seatbelts in their car, our cars explode when hit at over 5mph."
This is my point, in reverse.
I work in a university. Thousands of students come each day, to attend class, to show up to professors' office hours, to attend special events. Having physical security in the building would be a huge pain, extremely impractical. I have never heard anyone call for it.
Are there problems? Yes, but they are either minor or very rare. For example, sales reps for publishers will walk in and go to professors' offices door to door. A nuisance to be sure, but not that common.
Occasionally there are more serious problems. For example, in 1978, a Stanford professor was murdered by a disgruntled former grad student [1]. If this sort of thing was even remotely common, I expect you'd see some building security. But it's not.
In the analog world, on average people are just not all that concerned about security. I'm not terribly convinced that they should be.
Most of the vitriol about this issue is from a subset of security and IT people for whom E2EE is a term of art. In most any commercial service setting, E2EE is always going to be a bullshit term for someone.
With a conference, the server could generate a private/public key pair for each dialed-in phone number. That way you could retain hope that they were giving you non-MITM-ed keys for participants when no phones are involved.
Generally though, Apple's "end-to-end encryption" is a false promise and SHOULD NOT be trusted. If they wanted to provide privacy and weren't bound by the government (like they were when they tried to encrypt backups), they'd follow whatsapp and allow offline comparison of keys via QR codes and notify of changes. But they didn't.
Apple won the marketing battle on privacy, but please don't trust them. They have access to all backups, all your pictures, and they can MITM your iMessage/FaceTime when the government requests it (or whenever they want to, really).
This isn't true if one of the involved parties hosts their own video server. With jitsi I found it tremendously easy to set up a server.
https://blog.zoom.us/wordpress/2020/04/01/facts-around-zoom-...
"In light of recent interest in our encryption practices, we want to start by apologizing for the confusion we have caused by incorrectly suggesting that Zoom meetings were capable of using end-to-end encryption."
And
"To be clear, in a meeting where all of the participants are using Zoom clients, and the meeting is not being recorded, we encrypt all video, audio, screen sharing, and chat content at the sending client, and do not decrypt it at any point before it reaches the receiving clients."
As others have said, the moment you have to interact with the public phone system, decryption has to happen before the "end".
>Am I misunderstanding the product, or are the streams not being merged on the server into a single feed?
Are they not recompressing streams depending on the receiving device? I find that somewhat unbelievable?
Its interesting if what they say is true. Each device encodes their feed exactly once, and then when you are on a call with 50 people, you are receiving 50 separate encrypted feeds, which your client all decrypts separately? With one common key for the whole meeting, and the server has the ability to decrypt for ptsn and recordings, it just chooses not to when those features are not used?
What the TFA is saying is that the decryption key is generated by their servers and even passed through China, even if none of the people in the conversation are in China.
That's NOT end-to-end encryption, Zoom never does end-to-end encryption because they have the decryption keys.
And with that clarification they keep deceiving their users.
"Are we being unfair to Zoom?
I want to close by saying that many people are doing the best they can during a very hard time. This includes Zoom’s engineers, who are dealing with an unprecedented surge of users, and somehow managing to keep their service from falling over. They deserve a lot of credit for this. It seems almost unfair to criticize the company over some hypothetical security concerns right now.
But at the end of the day, this stuff is important. The goal here isn’t to score points against Zoom, it’s to make the service more secure. And in the end, that will benefit Zoom as much as it will benefit all of the rest of us."
[1] https://www.npr.org/2020/04/03/826129520/a-must-for-millions...
But this is the sort of lack of foresight that bothers me about Zoom. Let's be clear -
- It isn't that they're being attacked, that happens to any service where there's a payoff.
- Is is not that they have vulnerabilities, bugs happen.
Is is that they actively tried to deceive about E2E. It is that they never anticipated having 1M simultaneous connections, or the problem that would result before that. It is that they do insecure things to people's machines.
They act like undisciplined malware authors who happen to work on what is supposed to be a business product. What will the next "bug" be?
Actively looking for something that will work for us that isn't so untrustworthy.
I'm not knocking the need for trust, but trusting an closed source code served up by a central server is a bit of stretch for me. The temptation to monetise it is huge, and failing the governments around the world are give themselves permission to order the centralised server to decrypt it and send them a copy, and keep quiet about it. Finally there is absolutely no visibility to keep the vendor honest. They can silently update their code at any point without telling you, include switches that turn any feature off and on without you being aware of it and with little risk of researchers seeing it.
In circumstances like that any "trust" seems to me to be a huge stretch. About the best you can hope for competition is going to keep respecting the customers needs rather than their own need for money. It better to assume it's sent in the clear - which is what I assume with zoom.
I know it's easy for me to sit here and arm-chair quarter back and I don't have a solution for them. If I did I'd be working for them instead of my current day job! But lacking the ability to assist I still think it's fair to publicly criticize them so they pay attention and fix this ASAP. The more people that do the more emphasis they will put on getting past this, if nothing else to stop the negative PR.
When the FBI steps in and tells people to think twice about using an online service I hope even the most uniformed user will pay attention.
It was submitted to HN, but got less attention (ironically maybe because it's more technical?)
I just thought it was a high quality article going over some of the actual technical detail (rather than high-level anti-zoom articles about nothing, like the Facebook SDK).
Two things can be true, Zoom can still be comically better than the alternatives like Cisco/Webex which are universally terrible, but they can also have serious security concerns.
Hopefully this attention will cause them to fix it (though it may be hard to fix the Chinese development shop concerns).
I have some hope that Zoom can improve their security posture, but I have no hope that Cisco can make a good product.
If anything there wasn't nearly enough scrutiny of the adware domains in the CORS headers.
Also a "security posture" is corporate speak and has little to do with actual security - quite often the opposite, posturing security is what they have been doing all along.
As the article is saying, they always have the decryption key on the server side, so they always have the capability to decrypt the stream.
Given the current state of affairs I wouldn't have minded Zoom not being end-to-end encrypted, but by lying about it, my trust in Zoom plummeted.
Whole purpose of E2EE is to assume server is untrusted, but build a secure system anyway.
Zoom can watch & read your content whenever they want to. Full stop.
Contrast with Gotomeeting's claims[0] that data transmitted between their servers and their users are encrypted using TLS. This is a weaker claim.
[0]https://www.gotomeeting.com/meeting/resources/hipaa-complian... (third table)
I'll have all the sympathy for Zoom's employees who are probably having mandatory overtime in order to keep things running smoothly and to patch things up in response to all the (very legitimate) concerns being brought up, but at the end of the day, Zoom is a for-profit company, not a charity. A for-profit company with links to China [0] that's in a very unusual situation right now and potentially coming in contact with a lot of sensitive information as a great deal of people have come to rely on them. I don't think they deserve to be cut any slack and honestly, the more people find and use other alternatives, preferably open source ones (Jitsi Meet [1], BigBlueButton [2], Jami [3], among others) the better.
[0] https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto...
And the worst part is that all of this scaling work will be for only a temporary increase. Once everyone gets called back to the office and people can see their friends in person, their traffic will go back down.
Usually if you have an explosion of popularity like this you at least know that your work will be going towards continued growth and revenue.
Having been on the other side of explosive growth, I can empathize with the engineers at Zoom who have to deal with this.
To their credit, they seem to have built a system that can scale pretty well given how well the product has just kept working.
Maybe they should allow small groups to establish on-the-fly OTR-style conversations when they can.
Maybe I’m bad at English, but I had exactly the opposite interpretation. When someone says they “don’t” do something, that implies to me that they are able to, but choose not to. Otherwise, they’d just say they “can’t”.
Zoom is under scrutiny largely because it's a suddenly a highly popular choice. All the hoopla incented skeptics to take a closer look.
For that, I don't blame organizations for doing what they had to do - it's perfectly reasonable. But the discussion that results from this is mostly healthy. Zoom will suffer from the PR but I think that will give us better options as a result going forward.
vpn: https://www.cohesive.net/workforce-service-edge network edge plugins: https://docs.cohesive.net/docs/network-edge-plugins
edit: And we're offering expanded free licenses during the pandemic, https://www.cohesive.net/blog/helping-business-teams-stay-co...
Let's say I'm talking with two other people: is there a way to do E2E encryption without having to send out the same stream twice?
edit: Just realised a common key would allow this. But I am still interested in schemes for deriving a key amongst multiple parties using a middleman without the middleman knowing the key. It seems like a rather hard problem.
[0] https://superuser.com/questions/554513/pgp-encrypt-single-me...
This is exactly what happens when your browser establishes an HTTPS connection. There are many middlemen between you and the web server, but it still manages to negotiate a shared symmetric key (the session key) that can be used for the bulk of the encryption.
The difference is that there is no certificate authority vouching for each participant in a video call's identity, so you would need to do independent identity verification if you want to ensure that the call is secure, which some people would do by reading the public keys of each participant aloud, and people verifying that everything matches what they see.
This is a good point I hadn't considered. It led to me questioning how signal did it "right," and realising that there is seemingly no way around educating users to check public keys.[0]
So if video chats were meaningfully E2E encrypted, we would need a way to verify the public keys, which afaik Zoom doesn't have.
[0] https://web.archive.org/web/20160828135326/https://www.inter...
should they have marketed it is e2e when sometimes its not? of course not, theyre wrong.
do you fucking care? do you need more than one hand to count the number of products that are e2e encrypted? if you use the definition of e2e in the article, nothing apple does is e2e either. does anyone else that's not in tech even understand what encryption is at all, much less e2e?
they use a shitty encryption scheme when they do e2e? theyre wrong and should do better.
do you care? your threat model is that someone knows your meeting, is in place beforehand, intercepts the encryption, decodes it, and then spys on your conference?
this couldn't be more of a penny-wise, pound-foolish scenario. why are we still talking about this. please stop
My rule-of-thumb (NOT A LITMUS TEST) for e2e is as follows: If you have exchanged the public or pre-shared key(s) with the partner(s) out-of-band OR you had your public key signed by a NEUTRAL (key word) third party who is mutually trusted, then yes - you are likely using e2e.
If Zoom generated the keypairs, signed them, and transported the public keys themselves without an external independent library - I don't consider that e2e because they are the middle man every step along the way.
Should we treat other companies the same way if they claim they use e2e but don't? Yes, absolutely. This situation is bittersweet, it's (a bit) unfair to Zoom, but hopefully this will spark healthy discussions around what e2e is and more importantly, what it is not.
Millions are still using Zoom. Its shares are still trading at an enormous premium.
The technical discussion is something altogether different, and people are allowed to have that, regardless of your consternation. And hopefully a better product comes out of it.
"if you use the definition of e2e in the article, nothing apple does is e2e either"
This bit of sad whataboutism is technical nonsense, though. No, Apple, and a number of other vendors, actually do this right.
I honestly think Zoom's engineers, who have made a number of rudimentary serious technical blunders, thought "end-to-end encryption" meant "it's encrypted during every stage of transport". I've seen a number of companies make this mistake.
This means they're incompetent, full stop.
I don't think that at all. I think the marketing team is just full of shit.
In this time of crisis, where every hour of every day brings a new horror, it's like this is the one thing we can all be mad at.
Classic painting of the bike shed discussion.