Zoom plans to roll out strong encryption for paying customers
reuters.com
reuters.com
For better or worse Zoom has obtained “iPhone status” in corporate IT.
What killed the Blackberry was when decision makers had a personal iPhone and a work Blackberry and they finally turn up in the head of IT’s office and say “hey these things you’re making us use really suck, please just make it so we can use these iPhones which are soooo much better.”
I see exactly the same thing happening now with Zoom. I see IT types saying “but encryption” yadda yadda yadda and decision makers tuning up saying:
“This conferencing software you’re forcing us to use really stinks. I had a meeting with our soccer parents group on Zoom and it was so much better. Please switch us to this.”
A product that reaches that status stands to really disrupt the enterprise if they’re smart and take advantage of it.
If zoom can capitalize on this and stay the darling of enterprise while simple enough that anyone cares to use it, at low cost, they'll absolutely dominate this space within a couple of years I'm sure. I'd be surprised if they aren't acquired by Apple, Google or Microsoft, frankly.
We already have many Google Meet room with dedicated hardware and it's quite intuitive to use.
Edit: their conference room support with the iPad app was especially good. Most people won’t use that in a personal capacity. But it’s one of the biggest selling points at enterprises. People just find it easy to use. I don’t remember us calling “AV support” in a long time.
WebEx over Jitsi?! I must be missing something huge, here.
I rather zoom become a product that earns money by providing value to customers, rather than having the "customer" as the product like google's offerings.
> But Jon Callas, a technology fellow of the American Civil Liberties Union, said the strategy seemed a reasonable compromise.
> Safety experts and law enforcement have warned that sexual predators and other criminals are increasingly using encrypted communications to avoid detection.
> “Those of us who are doing secure communication believe we need to do things about the real horrible stuff,” said Callas, who previously sold paid encryption services
Why do people still believe that preventing civilians from using encryption is going to stop criminals? Is there a name for this fallacy?
What does Zoom’s premium subscription offer? Jitsi supports unlimited participants and runtime for free, and soon E2E encryption.
Even if you take his perspective, why is child porn OK in the enterprise?! Especially after Jeffrey Epstein?!
I’m reminded of when the ACLU defended a white supremacist and many were upset, even to the point of leaving the ACLU.
After a quick search i found the base rate fallacy which maybe could be applicable (no idea if it is really).
> If presented with related base rate information (i.e. generic, general information) and specific information (information pertaining only to a certain case), the mind tends to ignore the former and focus on the latter.
https://en.m.wikipedia.org/wiki/Base_rate_fallacy
There's also the general fallacy around security (a non technical term I've made up on the spot):
> The only truly secure computer is one that is disconnected from any and all networks, turned off, buried in the ground, and encased in concrete. But that computer isn't terribly useful.
Kinda applies to both parties of the argument because there's often an idea behind both that there is such a thing as "perfect security".
https://particular.net/blog/the-network-is-secure
Theres also possibly some agenda bias going on.
--------
> What does Zoom’s premium subscription offer? Jitsi supports unlimited participants and runtime for free, and soon E2E encryption.
The biggest thing around this is to remember that >90% of users are not tech nerds:
* The Jitsi webclient isn't the nicest UI and a nice UI is really important for non-nerds.
* Jitsi Dial in options are a bit limited (from what I remember, could be wrong). Zoom offers a package for toll-free dial in in US + Canada, for example.
* No dedicated support for Jitsi (unless you know how to create a GitHub ticket and scoure through forums).
* There's no dedicated physical meeting room connector service for Jitsi.
* Also don't think there's any sign up for Jitsi. So while zoom has the problem that anyone with an email address can join a meeting, Jitsi has the problem that anyone with the meeting ID can join a meeting. This then becomes a problem when you want to report a user.
* Jitsi meeting IDs can be lower entropy compared to Zoom. Often they're just names for the meeting.
* Join the Jitsi meeting called "test" and you can see the problem with the last two points
Ive set up local public (ish) nightly meetings on Zoom and help to maintain it. Several people have talked about Jitsi and Google services. In a ideal world I would set up a private and dedicated Jitsi server at home for it. But it's not an ideal world and that's too much maintenance for me to do.
Zoom basically provides a decent feature set, with a nice and intuitive UI, and all the set up is handled by Zoom for you. For people who "just want the thing to work so I can do stuff" it makes sense.
If there is no name for this, I suggest Congressman fallacy, since they're mostly clueless about this kind of stuff technology-wise and use But Think Of The Children™ as an argument to erode the privacy of its citizens.
Or I could just be completely wrong about that. If that turns out to be the case I'll just use it in-crowd.
I highly suspect the vast majority of home users, who are using Zoom to host weekly quiz nights with friends, particularly care about strong encryption....
I'll liken it to healthcare despite the US not figuring this out yet. Healthcare for all helps everyone, which consequently is a value creating proposition. The fallout from a lack of healthcare negatively impacts the rich in the longterm
When security is widespread, everyone benefits. A culture which make security default off is one that throws everyone under the bus for nickles & dimes. You don't vaccinate only 10% of the population
Up to 3 people in a meeting is unlimited. Over 3 is limited to 40ish minutes.
The Facebook pixel SDK etc etc stuff you're probably thinking of got removed from recently updated clients. Check out their privacy policy to have a look at the actual data they retain from actual meetings. it's fairly limited and only to do with account management / meeting management from what I recall.
It's not about how hard it is to break but rather where it's encrypted/not.
How does that work with GDPR?
Now, if they required you to, say, mail a letter to cancel, I could understand a chargeback. But a chargeback because you didn’t Google “how to cancel Zoom subscription” is overkill.
Then there's an orange "add/edit subscription" link and a "cancel subscription" link.
The process is well documented in an article on their help centre.
A simple DuckDuckGo search brings up the help centre article as one of the first results.
Pretty much the exact opposite of hidden.
It may not be related, but the homepage now instead has phrases like 'for things that matter', and the slogan at the bottom is 'because safety first'. I can't be certain, but I think it said 'for everyone' on the site too, not just app-stores pre-Zoom.
It's a real shame, but I did start my de-Keybasing yesterday. Making it profitable without losing the acqui-hired team would obviously be best for users, but I think most likely is axing it, followed by butchering it into a niche security nerd product without the interest or direction of the original team.
Zoom will still get hacked if the minimum security isn't enough, then they will have to blame their potential customers for their own problems while their brand is smeared.
Edit: It's so odd what gets downvoted sometimes. Anyone care to enlighten me on what could be controversial about my statement?
This is technically a white label I guess you would say, but if you download the code, a majority of the files begin with the prefix Zoom and what not: https://cc.cstcloud.cn
They took RTP and just encrypted the data with ECB mode, using the same keys on every node. It's what a child would do, or somebody who either didn't know or didn't care to do better.
Well over a decade ago the standard way to do that (named SRTP following the usual convention) uses a counter mode instead of ECB, with separate keys on each node. That's still pretty poor, but it's like SRTP is a Yale lock and what Zoom chose to do is use one of those "handcuff key" locks that's just a single lever. Can a specialist open that Yale lock? Yeah, probably in a minute or two, with the right tools - but any idiot can open the handcuff key lock with a bent twig, it's not security it's the barest effort to not just emit plaintext.