I don't have much respect for zoom's security practices, while I do have much respect for the keybase team.
Perhaps this is Zoom's way of admitting that there is no way they can just solve the problem internally by keeping doing what they're doing and they need to get some fresh blood and build upon good practices designed outside their current culture.
Because no one ever buys or hires a conscience. If you thought a conscience was worth having one, that implies you would already have one and thus wouldn't need to outsource it in the first place.
Ethics always rolls downhill. If Al Capone goes out and hires Mr. Rogers, the power imbalance between them means Mr. Rogers is going to get dirtier than Capone will get clean.
On April 1 the CEO basically said they messed up and would pause all feature development and focus exclusively on security & privacy for 90 days.[1] They've also done weekly video AMAs that are summarised on their blog under the 90-Day Security Plan posts.[2]
They've made a lot of progress.
The Keybase acquisition is absolutely about helping to build a security team that can help them implement end-to-end encryption across 1000 person meetings. You can see that from this Twitter post[3] from Alex Stamos and this interview[4] with him.
[1] https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u... [2] https://blog.zoom.us/wordpress/category/announcements/ [3] https://twitter.com/alexstamos/status/1258405729720918016 [4] https://cheddar.com/media/zoom-acquires-keybase-beefs-up-sec...
Besides upvotes, HN should have a hall of fame for comments this good.
It reminds me of 1 Corinthians 15:33 quoting the Greek poet Menander:
Do not be misled: “Bad company corrupts good character.”Essentially, on some level we never stop the role-model based adaptation we did as children, when we modeled our behavior on what our parent(s) did.
If having a conscience means prioritizing security above all else, then Keybase is doomed.
But security isn’t the only thing that matters. Zoom seems to have focused on making a very user friendly product. Keybase focused on making security more user friendly. In many ways, the user focus of both apps is their Prime selling point.
Perhaps they weren’t buying a conscience, they were fixing a blind spot.
The disappointment comes from the loss of Keybase and what it could have been.
The main problem is Zoom having most of its development done via companies based in China. This means it is no longer possible for Keybase to achieve its original goal (and whatever encryption they add cannot fix this core problem).
It's one thing to accept the risk for video conferencing, but it's another to accept for an encryption ID standard.
I agreed with Chris Coyne's comments on HN a while back when he argued that the closed source server code didn't matter because of how they handled the encryption (when compared to Signal). While that's still true from a technical security standpoint, it looks like it does matter in a larger sense because this kind of sale shows that you can't really trust a company to act in its user's interests long-term.
Nope. Once a pariah, always a pariah.
TLS is there to break sessions that would work under TCP. GPG is there to tell you to discard some mail.
They prioritized ease of use above all to get adoption before. This is appalling to me, but I believe they are seeing enough pressure to change course. It’s believable to me that they would intend to as they have already captured much of the consumer (non-B2B) market mind share and can afford to invest in this area.
Will I be using it now? Still a no. Maybe I’m time though.
Call my cynical, but "hiring" a bunch of infosec celebrities and critics as part-time consultants or contractors should be considered nothing but a (brilliant and silencing) PR move until the day that product updates and analyses reveal otherwise.
The product (and their poor installer practice) has been updated several times in the past few months alone, and each move has made Zoom a more secure product, with the vast majority of the hubbub having been addressed. So are you simply ignoring that, or are you setting your own personal goalposts?
Frankly, I don’t care if it does or not. I was just providing some visible signs of investment.
For evidence that they've changed their focus you can see their April 1 blog post[1] and the weekly video AMAs they do that are summarised in their "90-Day Security Plan Progress Report" blog posts.[2]
They're making a lot of progress.
The Keybase acquisition is about building out a strong security team that will help them implement end-to-end encryption in 1,000 person meetings, which currently isn't possible anywhere.[3]
[1] https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u... [2] https://blog.zoom.us/wordpress/category/announcements/ [3] https://twitter.com/alexstamos/status/1258405729720918016
But I do think that company values do change.
Zoom is getting the shining light of attention globally. Even human beings, in these situations, start to act more conscientiously, and then believe their own morality after the fact!
I believe the keybase acquisition demonstrates this a bit - because they will get zero public goodwill from this - nobody on Main St. knows are cares what Keybase is, this won't be on CNN so they are probably very much trying to make things better.
Owners of the company want money - now they are popular, they have to behave well to get that money. Wanting money usually transcends everything else including loyalty to state. A Chinese CEO with a popular Western product is going to realize that if his customers are way for CCP grabbing their data, it's a problem to his business. He doesn't want CCP snooping and one of the better ways to do that is to have better encryption as well.
Doing slightly suspicious things doesn't matter if nobody is watching and therefore nobody cares, now that people care ... it matters. Just as a matter of pragmatism.
That's an intepretation you're choosing to make.
The book "The Power of Habit" has some good examples of large organizations changing course.
Ultimately, an organization's policies are a reflection of the policies of its leaders. The bigger the organization, the more leaders have to change before the organization itself can truly change. It's much more likely that those who change just move on to another organization instead.
Besides, the end-to-end encryption incident wasn't a "mistake". Zoom's response was to say that their definition of end-to-end was just different from everyone else's. They clearly knew exactly what they were doing.
Zoom can change, but given their size and past I want more than a corporate apology and pinky swear before I trust them. They are making plenty of money and aren't going anywhere. There's plenty of time for them to earn my trust. However, they haven't yet earned enough of my trust to make me comfortable with this acquisition.
Leopards can't change their spots.
“Stove is hot, be careful before touching it.”
“Microsoft sexually discriminated in executive hires because ‘women will get pregnant and quit’, stifled completion in multiple categories, expected free overtime or you’d be stack-ranked out of a job. Be careful before trusting.”
I've seen this turn out for the best literally one time, and that was Microsoft.
All the other times the bad company just continues its horrible slide into madness. It doesn't die either, just silently keeps churning out billions of dollars of shareholder value.
They are just very good at putting a dusting of Open Source sugar on things.
This phrasing is sophistry: there has never been an "era" where this was not true. Humans suck; humans have never not sucked.
I don't trust Zoom to be custodians of the Keybase company or software. This has been a real blow to my confidence in them and I'm not sure I'll continue to use Keybase :(
If Zoom is acquiring Keybase because the C-suite is pivoting culture around security, then it'll probably work. Otherwise, not much will change. So until I see more evidence that Zoom's upper management had a change of heart (creating a CISO council is a good start), I'm going to be skeptical that this will actually move the needle.
Public perception of zoom/security is "beyond horrible", thus visibly spending lots of money on an acquisition of a very well respected name in security helps them polish that image at least a little.
And who knows, maybe they'll even work on actually improving security. Always the hopeless romantic/optimist, me. ¯\_(ツ)_/¯
I'd say you overestimate that. Perhaps 0.01% of the public knows that Keybase exists and has a bad opinion of Zoom security. Expert's opinion is important, but does not automatically become general perception.
(Anecdatum, I'm far from a security expert. I know that Keybase exists, even have an unused account; I use Zoom for work and don't blame them for not locking up tighter. Their blog post on the topic sounded reasonable to me.)
This is true, but perhaps a bit short-sighted. Expert opinion on Zoom is "avoid it like the plague". This does not automatically become general perception, true, but:
- Over time, expert opinions have a marked effect on adoption by non-experts in their vicinity. See the adoption of Firefox, or Google Chrome, for example.
- For a social networking platform, powerful well-connected never-adopters can pose a problem both to growth and to a budding monopoly. If CIOs and CISOs say, "Zoom over my dead body", that will tend to discourage adoption and encourage development of good alternatives.
Hiring consultants may be perceived like starting an investigation, not getting the fix now.
The question remains how soon and how true this will translate to the stated goal of true end to end encryption.
Attention people starting businesses: VC funding is fun and all, but please, have a business model. Your users and employees depend on it.
So perhaps better advice is, start a business even if you don’t have a plan and someone may buy it anyway.
A better world for your personal pocketbook maybe, but certainly a worse world for the rest of us. I wouldn't characterize that as "better" in any general sense.
The sad thing is that you need to remind people of it. I would never start a business without an idea of a viable business model for it. What do they expect? Growing until they are too large to fail and then ... Godot arrives and everything is fine?