Zoom says it won’t encrypt free calls so it can work more with law enforcement
twitter.com
twitter.com
The relevant bits I got from it were that there are a bunch of bad actors who create new Zoom identities and host meetings a few times before moving on, and Zoom needs a means by which they “can, if they have a strong belief that the meeting is abusive, enter the meeting visibly and report it if necessary.” Their E2EE design will make it impossible for Zoom employees to enter E2EE meetings without permission, so giving E2EE to the free tier will enable people to use Zoom meetings to facilitate abuse.
I think Zoom is wrong.
End-to-end encryption should be available to everybody no matter who they are. This means making it available to bad actors too. Expanding the scope of human communication should not be used to justify state surveillance. Privacy is a fundamental human right and one we should not be forced into giving up because it annoys the government.
The reason "think of the kids" works so well to justify blocking E2E all the time is because child abuse happens literally all the time.
When someone solves this problem, and I don't think any of us really believe it to be solvable, we can move on. I don't want the government in my private conversations, but I don't want my kids in someone elses either.
To extend this - we recognise a duty of care to our users and their privacy when we build these systems, but if those users plan and carry out an act of terrorism did we not also have a duty of care to their victims to not aid their killers in planning their murder?
We can't shunt this responsibility forever, the public will not take our side down the road - because we are ignoring the counter-argument even if we wedge our fingers in our ears.
As an illustration, if we get reasonable evidence suggesting that someone is growing marijuana in their ranch, we can get a warrant and go inside. There's not too much the owner can do to stop it. However a perfectly encrypted iphone cannot be broken into, no matter if the entire world agrees that there's evidence of crime in it.
From what I can see, no one argues against warranted search of personal property in the physical world, except maybe some sovereign citizen crazies. Given this, why can't we strive for a similar system on the virtual world as well? I too agree warrantless or unfettered govt surveillance of technology is bad, but that's a policy failing not a technology one. We should try to focus on how we can hold governments responsible instead of making fully protected crime caves for anyone who cannot whip up a conscience.
I agree privacy should be a right, but not at the expense of many people enduring a life of hell in these cordoned spaces for that cause.
When you actually see the horrors of abuse, helped by internet and you realize that there are voluntary walls to protect these people (encryption for instance, but others too) you may have a different position. I would willingly give up that just to see children (or whoever) saved.
You may not, that's a choice. I would just like to know whether you have seen what actually happens in these circles before making a decision.
Also, I live in a normal country where this concern (state surveillance) is less of an issue.
2) None of the major players offer E2E by default (Google Meet, Microsoft Teams, Cisco WebEx, BlueJeans). WebEx has an E2E option for enterprise users only, and it requires you to run the PKI and won't work with outsiders.
Any E2E shipping in Zoom will be groundbreaking.
What a few good examples of "abusive" meetings?
this is a hydra that shows up every time someone creates a video chat there is a problem with sausage parties and sextual blackmail that needs work arounds
If this is acceptable to view a meeting without permission under abuse pretense, then it's also possible to do so even if someone's doing nothing wrong.
Even worse, if their system is compromised, a bad actor could monitor free users' meetings without any protections. And what is stopping those bad actors from getting a paid subscription, or maliciously gaining access to a paid account? Or these bad actors could use another system that doesn't compromise (Signal) or host their own.
Security comes in layers and logs. A system without these layers and accountability isn't secure. Zoom isn't secure, and is using law enforcement as a scapegoat and pretense to keep their security low.
https://blog.zoom.us/wordpress/2020/05/07/zoom-acquires-keyb...
>We also do not have a means to insert our employees or others into meetings without being reflected in the participant list. We will not build any cryptographic backdoors to allow for the secret monitoring of meetings.
They get to pick between headlines like the current one, and claims that they support child porn rings (he isn't saying it explicitly, but everything I saw looks like that is the problem they're trying to fight).
Zoom needs a business model and saying "if you want encryption you need to pay for it", to me sounds like a reasonable approach to making money.
Once you start dragging other reasons into it, you need to start defending them.
Well he didn't use the word "rings" but he did says CSAM (Child Sexual Abuse Material).
There are other ways to track these criminals and we should be using those. We know they are smart enough to stop using Zoom once its no longer encrypted. Meanwhile normal people will be left holding the bag of surveillance.
I don’t think this argument really holds but I think it’s funny how quick we are to downplay our own “bad apples” and say that encryption is more important.
When he puts it in the context of their typical abuse pattern - anonymous emails, VPNs, and just a few meetings - this decision makes much more sense.
I hope they expand on their thought process in a blog post at some point, I'd love to read more.
For harassment / offensive content, if anything E2EE will make it easier to prove where offensive content came from. You've got a cryptographic chain leading to the source after all. All you need is a button to record and report things (which admittedly seems to be exactly what they intent to build). The E2EE aspect doesn't really change things, except that Zoom can't record things themselves, which they claim they didn't do in the first place (although they might have relied on the small server side buffer they had, but that's an iffy solution at best).
Also not sure what to think of Zoom's Trust and Safety team breaking into a private conversation when they think some kind of abuse is going on. Yes E2EE would make it impossible, but why on earth would Zoom want that kind of role?
Do you want to:
a) accept lack of E2EE
or
b) do you hate children? Pick one.
Hurry up, your precious internet points™ are at stake here.
“So what you’re saying is that Zoom is fine protecting pedophiles from law enforcement, as long as you profit?”
This is why you shouldn’t play such dumb games as a company, there is only downsides from a PR perspective.
1. you end up getting more responses
2. more responses === a higher probability of seeing gems like this wikipedia wormhole I'm about to get sucked into:) I had no idea about the horsemen/chans or that May identified the reason behind the alpha particle problem. Cheers.
At the risk of being pedantic: it’s not new at all. That’s part of almost every political campaigns from the past century. Technically “reductio ad hitlerum” is the new “protect the children” argument.
https://en.wikipedia.org/wiki/Thought-terminating_clich%C3%A...
But... what the fuck?
Also... I have a paid account. How can I tell if my connection is encrypted or not? Is it only if all other parties have paid accounts? Is there an indicator?
Under an "encrypt some calls" approach, if even paid users can't tell easily and reliably if they have an encrypted connection... basically nobody can count on it.
Working with law enforcement might be true, but it doesn't make sense that it has anything to do with free calls. Again, they have the encryption keys so they could decrypt any calls that they want to work with law enforcement on. This might even be a really poor attempt at upselling to paid accounts.
If you're concerned about security, I don't think zoom is the conference tool of choice -- maybe they've fixed everything I mentioned, but they still have among the worst track records.
Security aside, the feature set and user experience is attractive. Except for one thing, why does it take two clicks to end a call? That's awkward every time. If people are accidentally leaving calls, that's a different problem and two clicks is a lazy solution.
Are they saying that WHEN they implement true e2e encryption, it will only be for paid accounts?
Or are they saying the encryption they've already got, which they are inaccurately calling "e2e" when it is not, was formerly enabled for free accounts, but no longer will be?
Or something else?
(Who would have thunk that lying and calling something "e2e" that wasn't would end up confusing!)
I also still don't understand if you get the encryption (whichever one they are disabling for free accounts) if the 'host' is a paid account but some/all of guests are not...
Sometimes the distinction between physical and digital security is brought up in these discussions, the idea that physical security is imperfect (you can always break a lock) but that digital security may truly be impenetrable. This is a false dichotomy.
If people have a conversation in a pub or on a park bench, then law enforcement can surveil them individually or bug the venues in a targeted manner.
But the same methods can also be applied to digital communication. This is opsec 101 right - if one happens to be a high value target, one would totally expect their house/apartment to be surveilled - no amount of digital privacy can make up for a pinhole camera installed on the wall behind one's monitor, LE doesn't even need the keys, they see the content directly.
I think the argument that digital security is 'too perfect' falls apart if you take into account the reality that physical security is a component of that. "If you control the physical hardware" and all that.
TL;DR Digital security is just a subset of physical security. You can always just drill through the side of the safe.
It seems like law enforcement wants to be able to use digital communication to discover criminals, and
privacy experts want law enforcement to rely on HUMINT, a traditional warrant, and physical access.
I believe the second method is far more just, but I seldom see anyone acknowledge that it's almost certainly less effective.
The distinction is between targeted and untargeted surveillance.
Digital communication is so easy to monitor, particularly by a state-level actor, that if it's unencrypted, it's pretty much all being hoovered up by someone by definition.
That's not the case for physical security, even if everyone leaves their doors unlocked, their windows open, and their notes on the kitchen table; everyone is not automatically a suspect, so most people aren't being put under the microscope.
The government likely has the ability to know, instantly, within milliseconds, everything I've ever done on the Internet that's unencrypted.
By contrast, they will likely never see the contents of the love note on my kitchen table. Well, if that pinhole camera isn't there, anyway. ;)
All of the approaches applicable to physical communications apply to digital communications too.
It's just that the _additional_ level, which in the physical world would be equivalent to knowing the contents of all of the conversations/interactions that people are having in person, is something that people wish to fight against and prevent from becoming normalised.
I think you have a good point. The reason I'd like to see it acknowledged is because the two sides of the argument often talk past each other. Police power should not be unlimited, and it's clear that our constitution intended for the power of the state to be limited, with the intent of maximizing liberty.
However, for years people made the claim that the "liberty vs. security" argument was a false premise. ie, that ultimate liberty and ultimate security are both possible. I don't believe this is correct. (Broadly I think liberty is more important than security, but everyone has their set of exceptions to this rule) I might just be dating myself. People had this debate constantly in the years after 9/11. Maybe this argument is not getting made any longer?
In either case, I often hear these two sides talking past each other. I wish instead that both sides were more overt. Digital information can make police work more broad and effective, but we should treat it with quite a bit of cautious. We don't want police effectiveness to encroach on liberty in most cases.
In democratic societies, law enforcement usually has no right to run "criminal discovery" processes like those. That's why they don't cite their intentions, because it's illegal (more often than not, a crime).
Notice that limits on crime policing are a very important factor on maintaining a democracy.
E.g. looking at the logs of relevant servers and waiting for someone to login without their VPN at some point.
Using digital communications to discover criminals can accidentally sweep in many more innocents, who would then have to hire lawyers and carry all kinds of other costs to defend themselves.
Then there are the unintended outcomes. What does the correctness look like for those found crimes based on bits from a sea of untapped information when Bayes theorum is applied to an entire populace? And if crimes are prosecuted before being verified using the real world investigation methods already in use?
That's public. You can analyze all of those. The NSA is free to pull them just as much as you and I.
And they don't as far as we can tell. Is it the cost of analyzing that much content? Is it that the NSA doesn't care? Is there something difficult about stripping audio off a video for keyword spotting?
Well I have a theory, and the theory is based off what little comes out of that side of the community. The theory is that the NSA can't meaningfully process the data it ingests. There's too much, it's too hard to query and they hit the same roadblocks of telling the difference between an actual crime and a videogame or fiction story.
So then we must ask, why do they want more? They have more data than they can analyze, why even bother ingesting more? It's not because it helps their mission, it's not because there's some value to it.
Well, why do we see, regular businesses fall into this trap? A billion points of analytics data that they can't make sense of. When I see it, it's because it's easier to blame a lack of data than to explain the difficulty of the problem. You can always say "Well I just don't have enough data" but it's much harder to explain that a bunch of crappy error-filled data isn't good for anything except wild goose chases. Adding more bad data doesn't improve the quality of your data, it just adds more of it.
So, no, they can't process all of it. But they can more easily trawl it for specific data they need. Especially 10 years from now.
That's wishful thinking which you have no evidence for. But let's assume that you're correct - eventually they will have a way to analyse it en masse.
There are, then, two things we need to bear in mind:
- is the time horizon likely to be close enough that data currently collected will be relevant then - if we allow the collection now, will it be easy to roll back that collection later when the threat is on the horizon
The answer to both of those questions is yes. Similarly, we use high strength encryption now, even if we think 128-bit is fine, because in time it won't be.
The above is theoretical. The next bit isn't - they will _always_ be able to decide that agent A should look at video B from N years ago.
They can't do that for a letter on the hypothetical table, or a message stored with strong encryption that stands the test of time - it won't exist in N years.
I have the opposite opinion: it is trivial and inexpensive to create and store an indexed archive of text from speech in audio, and to run image recognition models on video and pictures. There's value in having that data archived, so that they can go back and go through it should whoever created the data become a target in the future.
However, I doubt the NSA would waste resources investigating a street fight, but I'm pretty sure the video would be mined of any valuable data that could be gleaned from it.
How do you know they want more?
[edit] Or was this meant as a rhetorical? ie, "who would want more in this case?"
That is primarily a problem even at the best of times that law enforcement wants to create criminals whenever it fits their fancy; Even more ominously, if police had any greater command of the voluminous criminal codes and the incentive structure is changed, they could basically be charging/locking up most people they ever come across for any number of arbitrary violations of convoluted laws.
Maybe it is being a bit anxious, but with the full on surveillance state unfolding right before our eyes where wrongthink has you "cancelled", we seem to be racing, headlong into something not all that different than what Orwell envisioned would be the consequences of self-righteously benevolent tyranny … for our own good, of course.
This is evidenced by stop-and-frisk, which was effective only in finding criminality among select individuals.
Nope. Please remember these words. The surveillance system is about control, not security (finding criminals).
William Binney and thinthread are a great starting place to understand this.
If the same physical system were to work in a digital age, a company could share a special encryption key with LE for the collecting evidence part provided they get a legit warrant for that. Physical security was never perfect, but we aspired it to be as close to perfect as we could. Same applies to digital as well.
Unencrypted communications will be intercepted by default with no warrant, no oversight, no limitations on its processing and on a world-wide scale.
My home internet connection could have spies from 30 different countries all over it and I wont see anything. If I'm sat on a park bench then anyone with a Russian accent asking for directions to Salisbury Cathedral is going to stand out somewhat.
In this scenario the person on the park bench with you.
Hollywood and co. doesn't get out much or something.
1. There is no way to verify that you are actually connected to a particular person. i.e. Zoom has no identity management.
2. The client is closed source and can't be verified.
3. Zoom can trivially impersonate any participant as they control the servers. They can MITM at will and they won't get caught at it.
This discussion is like talking about the security of the bank vault door when you are planning to make the vault out of drywall.
US citizens should have a 'right to privacy'. But that's been stripped away due to post-9/11 reforms, among others.
“Free users for sure we don’t want to give that because we also want to work together with FBI, with local law enforcement in case some people use Zoom for a bad purpose,”
So they want to keep the data unencrypted so they can give it to the feds. That doesn't sound like privacy to me.
edit: So I mean, something like that should not be allowed by law. Though it's rather the FBI that is breaking the law here, but Zoom explicitly says they want to work together with them. So that means they approve that injustice, making them also unjust. If they would encrypt their data to protect their user's privacy, they would not be unjust on this aspect.
Do you think courts shouldn't be allowed to wiretap the phones of suspected criminals? Because Zoom is just a modern phone.
https://www.fsf.org/blogs/community/fsf-gives-freedom-respec...
https://twitter.com/alexstamos/status/1268061796339814400
Eh, am I supposed to trust you just like that? If history taught is anything, it's that there will be.
E2E will be an opt in choice for paying users who are willing to sacrifice some features for the benefits from additional security.
See this thread for more details: https://twitter.com/alexstamos/status/1268061790954385408
Edit to credit vjeux for the thread link
If you want to look at something now, the white paper for the E2E protocol design is public and open right now: https://github.com/zoom/zoom-e2e-whitepaper
On a more serious note, until there is a protocol and implementation available then we can't say anything for sure. Us Security folks aren't magicians.
If these tools use open standards and well documented protocols this will not be a problem.
I can verify without a phd in cryptoanalyis and reverse engineering my browser is running a secure connection to a website and certificate is signed by the source(for sites enabled with FS and HSTS ).
Any sufficiently advanced cryptography is indistinguishable from magic.
Which isn’t entirely untrue from a layperson’s perspective.
Edit: fixed a word. I’d accidentally written “is” rather than “isn’t”.
That's sort of what happened with the ECB mode stuff that kicked this whole thing off in the first palace. See section 4 from the below for more info.
https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto...
In short: Zoom E2EE eventually will encrypt corporate conferences, but will not solve the privacy problems they have, because their structure stills the same.
Seems it will be a feature just to make customers have the feeling they are safe (and pay more, indeed).
But, as usual, they are not.
Poor Keybase.
Don’t shed any tears for anyone making hundreds of thousands of dollars per year while a third of the US has approximately zero income.
How do you compete with that?
Most users don't care about security/privacy and maybe that's fine but it was nice to see a company that seemed to genuinely care about these things.
[1] going by the commonly used definition
You can do all the open source e2e crypto trendiness you like, but unless you’re a nonprofit like Signal that can generate a stream of donations, if you don’t eventually get people to pay you for the service, you’re not going to be able to stick around.
This was the best possible outcome for them, given the circumstances.
I a way, any platform that is able to evade government surveillance will be deemed as an exception, and anyone using or building such platform will be a suspect.
This also makes none or very little sense - if this is actually just to cooperate with law enforcement, why would encrypting corporate (or paying) calls be any better, the bad people that are referred to in the statement could just get a paid plan?
https://www.reddit.com/r/Keybase/comments/77c241/keybase_why...
Next up: Zoom meeting attendees raided for unlawful assembly. https://www.persecution.org/2020/05/24/wuhan-preacher-taken-...
Catch up: Identifying influencers from sampled social networks. https://ui.adsabs.harvard.edu/abs/2018PhyA..507..294T/abstra...
Additionally, federal “law enforcement” (and concentration camp-operating) organizations like the CBP are engaging in domestic mass spying using aircraft to collect mobile phone identity data from millions, even for peaceful protests and the like. There isn’t really a line between “state surveillance” and “law enforcement” anymore in the US.
The title of this item as I submitted it to HN prior to its edit by mods ended in “to aid in state surveillance”, which I think is a more plain, accurate, and unbiased description of the practice, as I think that pretending that this illegal military spying practice (PRISM et al) has anything to do with legitimate “law enforcement” is basically state propaganda at this point.
I stand by my previous snarky, HN-rulebreaking flame of Zoom’s announcement of end to end encryption support from a month ago:
> I'm sure the result of this will be lots of good and secure trustworthy software that I'll be eager to install on my computer.
Its a pity there is no cross platform communication standard - it looks like it will evolve like messaging with dozens of companies.
Unrelated to this, I read yesterday that Jitsi Meet now supports E2E encryption so I look forward to trying that out.
That Bloomberg article is boring except for the sentence at the end. The submitter made the title be about the last sentence, but we changed it back to the original, which didn't satisfy anybody because the only interesting thing about the article is the last sentence.
The current post seems at first glance to be a garden-variety tweet picking up on that sentence, but someone pointed out to me that it's actually by the author of the Bloomberg article, suggesting that he might be at odds with the Bloomberg editors about what aspects of the story are significant. Suddenly that's interesting.
Given that Alex has been tweeting in response to this in detail (https://twitter.com/alexstamos/status/1268061790954385408), it seems like there's enough information here to support a substantive thread.
Given that sneak's post was the first on this and that it links to the statement by the reporter about the only thing that anyone here cares about, it seems clear that this is the post we should leave up. So I merged the comments from the other thread hither.
Now?
As the police are moving in to cities across the US military-style?
Another important thing to consider: Zoom is probably aware of the risks involved in this decision and, despite the PR risks, decided to go ahead. Why? Most of us here can come up with a couple of reasons.
Also Group video calling features in apps like Facetime and Facebook Messenger are in a slightly different category from meeting centric apps like Zoom and Microsoft Teams.
Non-group desktop calls are coming soon (hopefully hitting beta in a few weeks).
We're working on desktop group calls as well. That will take a bit longer, though. I don't have a good estimate of when it will be available
Gotta protect that source of revenue I suppose.
I can’t verify that Zoom actually encrypts my calls, I have to trust that they’re telling the truth. When I find out that they’re willing to turn off encryption for some calls to make spying on their users easier, the idea of holding business meetings on their platform becomes unpalatable.
I witnessed a cellular carrier discovering that they had all encryption disabled for several months. A honest mistake, but one that should have been impossible by design.
In the meantime, anyone who actually cares about their privacy can use an e2e encrypted group chat today with e.g. Wire. All this gets us is that unwitting people who can't afford to pay are in the position to get spied on.
And what reassurance do I have that they won’t do that to me, a paying customer? All I have is a little icon that says “encrypted” and Zoom’s word.
I thought we established that standard. Oh well, ride your wave Zoom, don’t get mad when the inevitable funded competitors start showing up with security as a default.
It never was. It never was.
Security was built over time, with a lot of lessons learned in between.
Browsers didn't magically start supporting SSL overnight. MSN Messenger never had any encryption, for example.
One of the first protocols to support some form of encryption was SILC, but who uses it?
The best thing, is to encrypt everything, in order to make all the traffic look noisy and randomized.
Then, for the paying customers, they can use a stronger encryption, that’s tougher to crack.
Ideally, this way, all the traffic being sniffed, will look randomized. But, with the paying customers, having a tougher encryption.
Set against the events of the past week, I strongly feel this message is quite tone deaf and we're continuing to see two classes. Those exempt from police authority and those who cannot afford to be.
Edit: Authority isn't the right word. Oppression?
Also from a customer satisfaction / PR perspective I am hard pressed to think of a worse time for a company to announce this.
2) He didn't say it was a costly operation so they're charging for it. They said it was for LEO purposes.
I still think it’s a dumb move. Imagine if “HTTPS for pay users only” was a thing.
- Special Agent Smith here, FBI - here judge sign this order?
- What is it?
- Its someone who we suspect of doing bad stuff, AND they are using paid version of Zoom.
- Oh that's the encrypted one, right?
- Yes, your Honor, the free one is non encrypted, you have to pay to hide your convo.
- Here is the paper, good luck.
And if there is a backdoor for police there is a backdoor for more than the police.
The acquisitions and hires they have made has made sense if what they are aiming for is making a more secure and private service. I don't doubt their intention. What I don't understand is why people expect them to provide all benefits for free.
Edit: does any service to multi-party e2e conferencing? What trade-offs are there?
That works only until the people you're scared of are those the government sends "to serve and protect"...
Should someone tell him?
He could be a 'PR Genius' by gently coaxing people into being paying customers, but I don't think that's it, rather, this is just mind-blowing, gigantic PR lack of self-awareness verging on disaster. To just say it as he articulated it, publicly ... my gosh man.
From a communications perspective this is like comedy.
It's that simple.
Now, if someday NAT's and firewalls die so every device can receive connections from anywhere, and packet multicast across the internet becomes a thing, then this could probably change. But I don't think anybody sees either of those happening anytime in the next decade (or ever), for both technical and security reasons.
1) Good, I guess I'll be using and promoting Zoom as much as I can
2) Well, I guess it doesn't really matter, since bad actors will have other encrypted software they can use
3) Well, I guess I'll still use and recommmend my friends use it just to avoid false-positive risks of flags from law enforcement
Yes, I know this is effectively an "if you have nothing to hide" mindset. I'm okay with that.
Does this legally qualify as extortion?
Do enough people care about privacy to warrant a "Signal for video conferencing" Zoom competitor?
There are a variety of better Zoom alternatives from fully end-to-end encrypted peer-to-peer ones like GNU Jami (which requires an install) to Jitsi Meet, which runs in a browser with better quality¹ and IMO better ease of use than Zoom but requires running everything through a central server (though at least allows you to host it on your own).
1: https://www.nytimes.com/wirecutter/reviews/best-video-confer... See also https://en.wikipedia.org/wiki/Jitsi
Do they _really_ think terrorists, counterintellegence agents, or criminal organisations can't afford $20/month???
So in order to have privacy you have to do a thing that violates your privacy. Rather problematic for people who need privacy.
If I'm organizing one of these anti-police brutality protests, I don't think I want the associated purchases to be tagged with my name in some police-accessible database.
Meanwhile the actual terrorists and foreign governments can just commit identity theft or similar.
Advertisers are nickel and dime-ing cheapskates - gotta plug into the "War on Citizens" police state money pipe to get rich these days...
"If Emil was a rogue service provider running the bridge for the meeting, he would no longer be able to eavesdrop on it and an attempt to do so would only yield, well we already said that: an endless stream of rubbish.
The only way for Emil to actually participate in the meeting would be if he was made privy to the e2ee key. In this case he was and once he enters it, everything goes back to normal"
(Sadly, Chrome only for now - so if Google and state actors are your adversary, "you're still gonna get mossad'd upon"...)
> ... this is in reference to end-to-end encryption, but simply ran out of space in the tweet. ...
A: No, because crime doesn’t pay
I’ll see myself out :-)
Subscriber calls: encrypted, subscriber list subpoena'd
no real thoughts on it, there wasn't a real expectation for me that Zoom was private, only convenient.
EDIT: We tried Meet, not Hangouts.
It's fine, not great, but the connection seems stable and we have not experienced issues with conferences. Zoom is all that plus much more intuitive and easier to use. The entire Zoom experience is great from start to finish, built in background replacement is a really big draw along with the full tile layout (Meet got tiles two weeks ago).
I would also say that Discord video has been great too. It's only downside is that you can only be in a session on one device. That is an extremely annoying limitation as I prefer to be mobile on my phone headset and present or stream on the computer.
Exactly what we've found with our GSuite and Google Meet. Works fine with 8-12 people on a call. Useable by technically adept people, but we've had to talk clients through the interface sometimes. (From today- client: "How do I share my screen" me: "click the [share screen] text in the bottom right" client: "Oh, yeah. Of course.")
(If you want background replacement enough, OBS and VirtualCam lets you do it... I did it for a gag the other week to put myself inside a Russian nuclear powerplant control room for standup. It's not something I'd recommend telling anybody who's then gonna ask you to help them set it up though...)
(I suspect many people on HN are using the web version because Zoom pushes their app aggressively and in an abusive way, which immediately makes the more paranoid among us decide that they don't want it. And I've heard that the installed version is great while the web version is not.)
Trying to provide an alternative to zoom/google.
I wrote the UI and my friend did the backend. One key point for me personally is doing privacy right. No identifiable data in logs etc. Tricky cause there will always be an element of "trust us".
Next weekend I hope to implement the experimental e2ee feature in WebRTC. Only for chrome so far, but maybe it'll take off for all browsers.
What? I usually agree with your takes but this seems out there (or did I misread/mischaracterize it)
> You agree that You will not use, and will not permit any End User to use, the Services to: (i) modify, disassemble, decompile, prepare derivative works of, reverse engineer or otherwise attempt to gain access to the source code of the Services
There is? I'm not sure what my cost for clang, python, llvm, firefox, is for being free. Even wikipedia, mdn, openstreetmaps, ...
I suggest looking elsewhere instead of supporting Zoom.
Imagine being in a call with 4 people, 3 of you are paying customers and you’ll need to ask the fourth to also pay Zoom to get encryption. It’s a bad deal for the paying users as well.
All meetings recorded (for law agencies and similar future use) or paid version
*We take your privacy seriously.
If this kind of attitude picks up, of labelling domestic protest groups as terrorists, together with things like these, there won't be much separating the USA from an oppressive state
EVERY communications provider has to comply with lawful intercept [1] regulation in all the regions where they operate. If they do not they find themselves hauled before the regulator and they'll be fined or worse until they do or go out of business.
'Encryption', while it would make it harder to snoop on your calls from third parties, will not 'protect' you from lawful intercept.
Furthermore specific to the US Zoom also has to comply with the Communications Assistance for Law Enforcement Act [2]. This does in no way mean Zoom can not encrypt its traffic. It just means it has to provide law enforcement the ability to covertly wiretap every and any communication. If Zoom provides end to end encryption to its paying customers, it still has to provide access to law enforcement to the content of those communications.
[1] https://en.wikipedia.org/wiki/Lawful_interception
[2] https://en.wikipedia.org/wiki/Communications_Assistance_for_...
Yes it will, it will make the intercept so expensive that it will not make sense anymore for them to do it.
In the first case, all they need to do to intercept is to call Zoom headquarters, or even just go to some pre-setup website and just enter the identity of the user and voíla you have the data. The cost is 1 man-hour of an agent.
In the second case, the Zoom doesn't have technical ability to break the encryption, and to "lawfully intercept" they need to either break your phone or physically break into your home to install some devices, or construct elaborate servers to trick your phone into thinking it talks to real Zoom, or use the supercomputers to break some of the encryption, or use some of their hidden stashed 0-day, and thus risk exposing it by using it, and not be able to use it later for a real threat. Cost of this can be astronomical for breaking a single user. (And all of that is even more true for open-source solutions.)
Also a lot of people disdain this not because they are terrorists. They disdain this type of surveillance because it has been shown many times that governments do not just track terrorists, they always end up abusing their power and track everyone, and there are agents who sometimes just make fun of people and read their emails etc. Didn't you read any of the Snowden material that was published? Encryption prevents exactly this type of ABUSE of the power by the government.
How do you think this works? If Alice and Bob generate private keys and share only their public keys with each other over the wire how does the provider obtain the content of those communications to share? It never had them.
There is no non broken way to provide a backdoor for government while actually retaining meaningful security in the long run. See the extensive discussion on "key escrow"
Lets discuss a very old encrypted communication mechanism. PGP encrypted email. If I Bob send an encrypted email to Alice how does gmail fulfill its obligations as stated previously to law enforcement? PGP came out in 1991 and CALEA is from 1994. In the 26 years since I don't seem to recall anyone shutting down gmail.
I actually agree with you on this. I was personally involved in the past to advocate for stronger encryption ( https://archive.nytimes.com/www.nytimes.com/library/cyber/we... [1997]).
However, law enforcement agencies around the world see "broken" ways to achieve this as a 'lesser of two evils' trade-off. Am I too paranoid (I hope I am) to envisage a scenario where Sam, our friendly US law enforcement officer asks Sheila, his friendly AU counterpart to request a copy of the conversation obtained through technical capability and assistance notices and share it back under 5 eyes agreements? Add the pending bilateral CLOUD act for an extra spicy double exchange sandwich?
To the crowd who says “well you can do bad stuff if you pay” - If terrorists are paying for Zoom, they’re leaving a paper trail for the FBI. Free platforms are ripe for abuse because they’re free.
Also I’ll need a copy of your bank account statement. I just need to take a look. Make sure it’s ok. Unless someone else has recently.
The narrative that we should sack our privacy to help “law enforcement” is fucking braindead.
Terrorism is not a valid reason - well, perhaps unless you're going to take the jump to including a Chinese national that says 'Tiananmen Square' to their wife in a random call, as some 'Law Enforcement' will.