Zoom to bring end-to-end encryption to all users, including non-paying
blog.zoom.us
blog.zoom.us
1. Pre-COVID Zoom claims it has E2E encryption for everyone.
2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate.
3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers.
4. Zoom gets another wave of criticism for restricting its new E2E encryption service so it walks back to its original message that all accounts get E2E encryption.
Given their track record I’d expect this timeline to repeat itself so after they release this E2E encryption feature, security researchers will discover that it’s not true E2E encryption again.
Technically, the exact packets of the data you send is E2E encrypted... but the copies they make for themselves aren't.
And if so then what's the term for encryption that a middle man cannot decrypt?
No, it only implies avoiding a central server (and not even for every aspect of the service), you still run through routers, ISPs, NSA etc.
If you are certain that there's no middleman, you don't need encryption.
N.B. Maybe someone defines it in another way today, but when the term became popular, with Napster, it really meant simply not having a central server for certain functions, or even more banally not downloading your mp3s from a web site or ftp server; it did have some significance also because the legal aspect of it was more uncertain; when people started getting 100k dollars fines, peer-to-peer stopped meaning much, sometimes it's better to send packets directly to each other, other times through a server, but you almost always encrypt and almost always ought to encrypt end-to-end
I never implied a need for encryption associated with peer-to-peer. The parent comment asked about avoiding a middleman.
I have no idea what "end-to-end encryption" means, nor do I seek to know. I do not wish to be part of that debate. The record of how that term is being applied speaks for itself.
I do know of the term "end-to-end" as in https://en.wikipedia.org/wiki/End_to_end_principle One can find this concept in many of the early RFCs.
To me, "peer-to-peer" (with no central server) is in the spirit of end-to-end. This is why for example, people will sometimes say, "The internet was originally peer-to-peer."
Which I think it's pretty much how you defined it too in your (last) comment, so I'm not sure what we're debating.
The important thing was that no one reading these comments get the impression that the multitude of systems that describe themselves as "peer-to-peer" are for sure using "encryption that a middle man cannot decrypt".
---
> The parent comment asked about avoiding a middleman
Middle man in cryptography is anyone intercepting a message
---
> I have no idea what "end-to-end encryption" means, nor do I seek to know
Well, I don't mean to be rude, but then there's not much you can say in a discussion about encryption...
---
Look, the important thing was to underscore that the https://news.ycombinator.com/item?id=23554823 comment was (apparently) wrong, I don't have any interest in winning a battle, I appreciate your enthusiasm, you probably currently don't know everything about cryptography or networking and there's nothing wrong with that, no one is born expert and no one knows everything there is to know. I have to go to sleep, bye
All I said and cared to stress, to avoid that someone reading this make mistaken assumptions about p2p software (although probably few of this site's users would run the risk), is that ^^^they don't, as you claimed in https://news.ycombinator.com/item?id=23554823 , automatically imply "encryption that a middle man cannot decrypt"^^^.
You admitted you don't even know what end-to-end encryption is, and apparently don't know much about encryption, what are you debating?
---
> The term the parent comment used was "middle man" not man-in-the-middle
It's the same thing (unless the post author meant "a man of middle age")
---
> As for "E2EE", I have never seen djb even use that term
You mean Daniel J. Bernstein with djb? Do you mean that you are actually knowledgeable about encryption? I don't mean to be insulting but it didn't seem so (and there wouldn't be anything bad in that), it's hard to believe that someone with basic familiarity with encryption wouldn't know what end-to-end encryption is.
If with "that term" you meant the E2EE acronym, I indeed wouldn't be surprised if Daniel J. Bernstein never used it, it's the first time I see it myself (but it obviously doesn't mean anything more than "end-to-end encryption").
---
I don't know why you took it so personally, maybe I sounded aggressive in saying NO in uppercase, if so I'm sorry, it was just to make it more visible
https://web.archive.org/web/20051029045942/http://www.unc.ed...
Example comment: "Peer-to-peer is a viable design for videoconferencing for small groups. If one is concerned about a "middle man" then it is worth investigating a peer-to-peer design."
I don't know if there's a term, but short of exchanging public keys in person there will always be a theoretical attack vector because there's always some[one|thing] in between you and your recipient.
It's shocking to me how often this is glossed over when discussing E2EE services: you still must trust the platform.
The implementation of E2EE must be robust and there must be somebody who is actually checking the source code (plus verifiable builds)
Nothing makes software automatically super-crazy-secure. Absolute security doesn't exist.
It's simpler to set up (accounts and password protection are optional), IMO easier to use (eg. the hand button is on the bottom bar with mute, etc. and not in a menu labeled "Participants") and higher quality according to the New York Times, who deemed it "reliable and easy to use": https://www.nytimes.com/wirecutter/reviews/best-video-confer.... I've introduced it to extended family members who've used Zoom prolifically, with zero complaints.
Can you name a single disadvantage?
Participant limits in Jitsi Meet are a bit confusing. There's a lot of variables to consider. https://community.jitsi.org/t/jitsi-meet-performance-compari...
> 1. Room hard limit is 75 users, recommended 35 users. > 2. The limit with more than 15 users with camera is the user’s PC. > 3. Working test with a good bare metal servers, 115 mute users and 5 users with camera. > 4. Test in progress for 500 simultaneous users.
We are available at hello@3esofttech.com
Audio capture APIs often suggest it may be possible to use very small frame sizes, which naturally promise much improved latency. Going from 100ms of audio latency to 20ms is great so surely going from 20ms to 5ms is even better right? Well, the hardware underneath that API may not be able to deliver, at least it may not be able to deliver consistently. If your 5ms buffer isn't filled on time, what do you send? A partially filled buffer? Silence? The last 5ms of filled buffer again? All bad answers.
Tool A with 40ms of latency may feel imperceptibly worse than Tool B with 30ms of latency. But Tool C with 10ms of latency but frequent "drain piping" as audio frames are garbled or undelivered is clearly much worse than either.
I'm not being facetious. If you compare the name Zoom to Jitsi, people will choose Zoom 9 out of 10 times. You won't get many people to even try Jitsi.
Zoom is quickly becoming a verb similar to what Skype used to be. Let's Skype. Let's Zoom. Everyone understands what that means.
Let's Jitsi... Let's what?
Come on, the market wouldn't permit that to happen! They'd lose all their customers!
/s
Edit: on a less sarcastic note, I'd be less critical of Zoom if their software were open source.
Meanwhile the companies in question universally refuse to acknowledge THEY NEVER ACTUALLY VERIFIED ANY of the claims around encryption. It would be hilarious if it weren't so terrifying. And oh, by the way, all of those companies refuse to admit they messed up so they ALSO haven't switched to another service, so Zoom is literally still selling on "If we weren't secure, these big guys wouldn't be paying for our service". It's insanity.
Saving face by not admitting egregious mistakes and even lying about making or not making them even after the evidence is public and irrefutable is just the human ego defending itself.
I'm starting to get past taht sort of childishness in my own life but having lived it for a long time I see it easily in others.
In most companies I've observed, the people deciding what products to buy are not capable of reviewing any of the products claims. If they happen to have an employee that is capable, and that employee points out a problem, they are usually ignored. Especially if it would make someone in management look bad for spending money on something they shouldn't have, or even worse if it would make them lose their free lunches and golf trips with their vendor buddy.
Now these are small to medium-ish size companies (20-500 people), so maybe it's not a big deal to Zoom's marketing bottom line. But it's definitely a thing.
Teams or Meet works fine (unlike the train wreck of Skype), have improved recently and are already paid for.
People are doing 50-200 person video meetings with Google? Has Meet really improved that much since March/April? That’s not that long ago. Otherwise it seems more like cost is the reason. Not anything relating to quality.
While we pay lip service to Zoom's super shitty security stance, we now run a video meeting service where it's trivially easy to click the "turn on captions" button, and see how good a job the world's biggest advertising agency is doing of transcribing all the audio in our most sensitive business WFH calls... :sigh:
(I have my own Jitsi Meet instance running on AWS, but there's me and about four of my tinfoil headwear sporting friends who care enough to bother using it...)
For the business model, it is the same as other OS, there are companies that want a tech insurance policy.
I disagree. Plenty of video chat software has comparable reliability and "just works"-ity.
Google Meet, Skype, Microsoft Teams, Discord...
Hell, Apple has had "just works" and "reliability" in their walled garden since FaceTime was introduced -- if you're willing to look only in their walled garden.
Zoom is almost as good on a laptop as dedicated Cisco gear.
I have been video conferencing mostly for work for almost a decade, and Zoom is the best solution for that that I've encountered.
I recently changed roles, and the use of Zoom was a small reason to go with the company I did.
The idea that a business needs a moat to be profitable is a problem endemic to business.
The value add would be in hosting services and support contracts. Video chat is needed by a lot of non-technical people. Furthering, plenty of people don't have sufficient bandwidth to host their own video chat even with just their own friends or teams. Even technical people often don't understand how to write secure software.
I'm pretty econ-left philosophically (socdem short-term, mutualist/ancom long-term), so you can't get much argument from me here. :)
But I want to steelman the other perspective: so long as we live in a pre-post-scarcity market economy, having some kind of moat is part of how one gains bargaining leverage in a price negotiation. (Think of "moat" in this context as influencing cost/benefit incentives, rather than an absolute barrier: the customer could build a boat to cross it, or they could pay the toll to cross the bridge, with the latter being usually cheaper.)
One answer is as you describe: hosting services and support contracts, in a market ecosystem of interoperable commodity services. Sign me up! But: such an ecosystem has a free-rider problem when it comes to the non-trivial expense of creating and maintaining the client software (including the risk of front-loading the 0-to-1 effort of building it before you know it will be adopted). In a FOSS model, other players in that ecosystem can obviously contribute to that effort, but those who don't contribute will have a competitive advantage, since commodity markets tend to viciously compete until margins are as near-zero as possible.
There are "moats" / competitive advantages that have nothing at all to do with the software itself: superior support experience, brand reputation, efficient hosting services through economy of scale. So I don't at all claim your model is unworkable, and there are many successful companies who do just that.
I don't disagree that the world would be a better place (and the overall economy perhaps more efficient), if most/all software was FOSS, and business models required less centralized control. (Note that nothing has stopped us from a building a pure FOSS E2EE VC client with a comparable feature-set; we still could.) But say I'm a board member or an investor in Zoom, whether pre- or post-success: how would you pitch me on the business value of open-sourcing the expensive-to-produce client software?
Okay. Consider the following fantastical talk from technical me to you, oh dear fantastical board member:
Let's face a fact: yeah open source software is "free (as in free speech)" and it can also be "free (as in free beer)". Anyone can inspect it. Anyone can "steal" it so-to-speak and set up a competitor. That will always be the case. Just look at how many stolen software products end up in your favorite app store. Games are ripped off right down to their copyrightable artwork, malvertisements added, and reuploaded with a new name. But I think worrying about that is like worrying about the people brewing their own beer. I think that's preventing us from building a brewery.
Let's face another fact: what's expensive isn't software. That's pretty cheap. That's just man-hours. A kid in a garage can build video chat over a weekend or two. What's expensive is experience. Experience is basically an impossible-to-estimate number of man-hours. We'll never be able to pay one person or one team to understand all of the pieces and platforms and make it work for everyone.
Customers want to run Windows, Mac, Linux, iOS, Android... and all of that is hard to keep up with. Customers have a plethora of network and hardware configurations. Customers have crazy different bandwidth and latency profiles. It's really hard for us to make our software work in all of that. But some of our customers are experienced and they're curious and they are looking at our software with a fine toothed comb. We simply can't stop them from doing so. That's how we got into these repeated PR messes after all. So let's embrace that. I think there's a good chance that some of those customers would solve our problems for us if only there was a way they could contribute fixes.
Like I said, experience is expensive. With experience comes ideas. Ideas are gold. That's why we're worried about our competitors after all. We don't really have any solid ideas. Neither do they. Even if we did have a solid idea, they'd create a competing idea or even just outright steal ours. And we'll still be left holding the bag, we'll still have these PR details for not getting things right in the first place. So let's turn that on its head.
If we open source our software, we give these technical people the opportunity to help us fix problems before they become problems. There's a ton of home brewers out there and some of them would love to be able to help our big brewery. We're not going to stop home brewers. So we shouldn't even try. But home brewers do need tools. Let them come up with their own recipes.
So, we provide the tools for free. But we can sell the recipe. Or, technically: provide a cheap service for the people who need something they know is secure but don't have the technical know-how and/or time to set it up themselves. Lawyers have a legal requirement to keep their conversations private. Schools have a legal requirement to keep their children safe from stalkers. Even citizens have a right to privacy. We'll make all of the tools available for anyone to audit and validate. The recipe to use those tools is where we make profit.
The recipe is the environment. We'll provide, for a fixed cost, the ingress bandwidth and compute needed. We'll provide secure storage of recorded conversations and an audit history of who's accessed it. We'll provide the experienced technical support to directly either fix problems or point at misconfigured devices outside of our control (and why it's the source of a problem); we'll be able to understand the debug logs that the software provides. Of course, any other technical person could too. But that's already the case so we're not really losing anything here. Indeed, we're gaining here. We're gaining the trust of law firms and governments; the trust that they're getting the value that they want for the services they need and that they can go directly to us if they need troubleshooting.
I'm not arguing against centralization. Centralization is good for us and for our customers. It's an anchor point for experience to grow from. I'm saying that open source software can help us avoid further technical problems from our lack of security experience. And who knows? Maybe some of those home brewers are interested in a paying job at our brewery -- if only they could prove they knew a little bit about beer, if it was free. We could definitely use the experience.
/pitch
it would be very dangerous for the primary value add to be in hosting services. any hyperscale cloud provider could offer the service and undercut zoom (based on superior unit economics and market reach)
most of 8x8 revenue comes from sources and products unrelated to jitsi.
so, i don't think you can say that it seems to work fine for them compared to zoom.
You scoff, but isn’t that exactly what we’re all doing to Zoom right now?
And they can be changed without you knowing it. Do you have a Fingerprint that what you get is what they share?
It would be super interesting if there was a way to abstract out encryption on the camera itself, where the video call software gets an encrypted video stream and its only job is to convey that stream to the other side, which decrypts it.
The hard part is sending an encrypted stream that can be programatically degraded based on available bandwidth, and still be cryptographically secure.
Your smart tv recording has nothing to do with this, but one does still need to trust that it isn't happening. In the case of the smart tv we can attempt to look for microphones or other components that are able to be used as microphones. Software offers a more difficult path in verification.
Denying E2EE is a cost as you are punishing people for the crimes of another, this is depriving them of their hard-earned freedoms and liberties, for something someone else has done or may do.
Look at the activism going on today. BLM, dissidents in China, the rise of oppressive far-right governments in Europe like Hungary. I am sure if you dig far enough, you could find many people fighting in obscure causes, high profile causes, in a number of countries, who would fear the fist of an oppressive government.
What if the FBI / NSA decides to surveil BLM, as they already are? What if the CCP strikes down a dissident as they already have on Zoom? What if Orban decides you are a secret agent of George Soros plotting to undermine the government? Is it the case that everyone should roll over because a criminal might use the same means as them?
Jokes aside, with Zoom's track record, it's not worth using anymore regardless of what features they implement. Not having E2E encryption is no where near as much of a red flag as lying about it is to me.
The company my wife works for can't get a reliable Teams conference going with anyone in France.
The company lied about their encryption.
Both of these statements can be true, it's just a question of trade offs.
I know they just announced their own "Ring central video" But im weary of that for the time being.
It's in here somewhere: https://jitsi.org/security/
Separately: affordable servers likely are accessible to infrastructure providers (whether a VPS, or bare metal at a colo, etc.) so it's tough to say that "my own server" is usable exclusively by me and therefore not adversarial. Plus, maybe people want to use my server and consider me adversarial for whatever reason; they should use their own server instead, but might not have the skills.
I've also have been using Discord for voice almost daily for a little over a year and it just works 99% of the time. Unfortunately, it suffers from "gamer" branding that makes it awkward suggesting for work. They should try offering a "business skin" that interops with discord.
Mind you, I only host it at home on a VM for personal use. Have had sessions with 6 people with one of them a Europe-Australia connection. All fine on default 720p.
If I were looking for 20+ meeting software though I'd consider something else. I would consider it a case for streaming to faceless attendees. I have never had a meeting with useful input from more than 10 people.
It's just a means of communicating, people. Maybe a few Discord features aren't useful outside of gaming and a few Slack features aren't useful outside of the workplace. I find that to be a stupid reason not to generalize the use of these products. Skinning (and filtering away those specific features) just might be the ticket.
Not to me. I would just assume they don't have E2E encryption and wouldn't base my calls around the idea of needing that. The claim is never worth it without an independent review and then thinking about the attack surface you actually want to shield against.
I mean, in another market, if you have ever investigated VPN providers you would see 100% conflicts of interest with affiliate marketing everywhere and the articles never acknowledge that the business of reselling internet access has inherent trust and unverifiable claims involved. A government can always tap the source with a legal order and there will always be information available to them.
For a video chat service, them merely saying E2E doesn't mean anything without a way to verify it, or host the whole stack myself and this is incompatible with being a company.
I'm no Zoom fan (I'd even use BlueJeans first), but people on HN are always so eager to crucify a company for its past. If it made mistakes, get out the tar and feathers! If it doesn't fix those mistakes, get out more tar and feathers! If it fixes the mistakes, even more tar and feathers!
Crucifying Zoom over this while letting virtually every other company in the space (inc. Hangout/Meet and MS Teams/Skype) go free seems quite hypocritical from an HN community that's comprised of many startupers and startup wannabees who spend their professional lives working for entities with similar practices.
How is saying "yes we can scale" when you're not sure if you can, aren't you essentially implying that you have the infrastructure to deliver on that promise? And if you don't actually have that infrastructure yet/built/proven, then you're essentially selling a feature that doesn't exist.
It's shades of grey from lying about E2EE, but seems pretty similar imo
That's very different than making a specific claim that you already have a feature right now, that you in fact don't. That claim cannot possibly be made in good faith, as it's currently outright false, and you can never retroactively apply end to end encryption on conversations that have already happened.
Really? Do you think they would/could lie on the features of a product that they deliver to a client. If they did, do you think they should get away with that?
'We have that capability' claim is totally not the same.
The only alternative I ever looked into was Jitsi (because it was the first alternative I started doing research on, and by the time I'd finished researching it there was no doubt that it was more than good enough -- and super easy to build our own cloud instance so that, even though it wasn't E2E, we had total control of the server that managed the encryption), but I don't recall hearing arguments that any of the other major competitors were actually E2E encrypted.
(I think I'm preaching to the choir here; just clarifying for anyone else reading your comment)
Perhaps. In my case it's less crucifying a company despite intentions to fix and more crucifying a company because I'm tired of hearing the same PR nonsense and not seeing real improvement to the industry as a whole.
What you're seeing is the flip side of the whole "it's easier to ask forgiveness than permission" nonsense.
Criticisms of large corporations is a healthy part of the HN community IMO. In fact, if we didn’t criticize Zoom they might still be lying about their E2EE capabilities.
Zoom isn't learning from mistakes and making improvements that the market demands. It's providing a feature it said it already had.
Zoom knew E2EE was something the market demanded, so it lied about having E2EE. This was a blatant lie to get more people to use its platform. Then Zoom got caught. Now it's actually trying to provide what it said it provided in the first place.
Unfortunately, it didn't end there. Rather than earning back their reputation, they have continued to burn through it with blunder after blunder.
The company has proven itself ethically corrupt and that's not something that can be made up for with apologies and product improvements. It will take time, demonstrations of humility, and a healthy dose of transparency to restore their reputation with me.
I mean, you can already look at the design if you wish, it was disclosed by Alex Stamos: https://twitter.com/alexstamos/status/1268061790954385408
TBH I'm sort of surprised they gave in to the new wave of criticism, their arguments for not giving E2E to free accounts were pretty decent.
The real reason is they want to be able to hand data over to China / NSA / marketers.
It's honestly the first time I heard this justification - where else did you hear it in the last twenty years?
Also do you have some concrete reasons to believe Zoom hands over data to marketers? That's the first time I personally heard this claim - can you link me some evidence?
As for the same old same old? It hasn't been precisely in that form but criminals have used Facebook, Tor, Email, Discord, YouTube, Usenet, Skype, MySpace, and other technologies / sites to facilitate abuse. This is merely the newest iteration.
Also, you seem to acknowledge that there are legitimate concerns/ reasons to NOT offer E2E encryption for free users. Unlike all the other services you mention - Zoom users that care about illegitimate interference in their communications would actually have a way to get E2E encryption. Unlike FB/Youtube/etc, Zoom doesn't need to offer the "free" service in order to exist - it does this as a marketing ploy to get you accustomed to their services. In that sense, withholding functionality from free accounts seems perfectly reasonable?
Yes, it is a problem, it's been a problem for a very long time. Criminals gravitate to the most convenient platform like anyone else but otherwise don't stop being criminals. It only serves to punish other people.
Yes, we know its easy to use.
I agree, evidence shows most people are not willing to go very far out of their way to defend their privacy. But I also think privacy is a genuine virtue, and a desire for it is present and often untapped. Why else would Apple have run privacy-centric ad campaigns? Attempting to tap into the weak but widespread desire for privacy, I think
Also, side note, lgbtq people make up somewhere in the range of 2-7% of the population, not 1%.
If you want to argue that your target does less to further that particular cause than you do, fine. If you want to argue the cause is misguided, fine.
But using the term is just lazy.
https://twitter.com/CraigSilverman/status/522179364767924224 and https://www.theverge.com/2014/10/22/7028983/fake-news-sites-... are good examples of its use pre-Trump. By the time Trump started applying it to actual news outlets, it was already in relatively common use.
https://www.cnn.com/2016/12/08/politics/hillary-clinton-fake...
December 2016 Hillary Clinton decides to use the term in reference to recent events like her losing the election. The media picks up on it and the term starts to lose its meaning. Then Donald Trump, always with a nose for catch phrase politics, picks up the term and runs with it, a turn of events that someone on HN called a huge "own goal" by the media, and I can't say I disagree with that assessment.
For more analysis of this cultural specimen:
In your examples the word "fake" is used as an adjective to the noun "news site". As in "a fake news site".
"fake news" as it used today is a noun in its own right. As in "that's fake news"
See also "alternative facts".
> Author Sarah Churchwell asserts that it was Woodrow Wilson who popularized the phrase 'fake news' in 1915, although the phrase had been used in the US in the previous century.
> The term actually dates from the late 19th century, when it was used by newspapers and magazines to boast about their own journalistic standards and attack those of their rivals. In 1895, for example, Electricity: A Popular Electrical Journal bragged that “we never copy fake news,” while in 1896 a writer at one San Jose, California, paper excoriated the publisher of another: “It is his habit to indulge in fake news. ... [H]e will make up news when he fails to find it.”
[1] https://en.wikipedia.org/wiki/Fake_news#20th_century
[2] https://www.csmonitor.com/The-Culture/In-a-Word/2019/0726/Su...
Virtue signaling or whatever you want to call that sort of in-group circle jerk is fundamentally unproductive and self-rewarding because it's just a reiteration of existing group beliefs that basically everyone already knows and has. There's no term you can use to describe that behavior that will not make people uncomfortable when you call it out because at the end of the day you're calling the behavior unproductive and selfish.
For example, someone goes on Reddit and asks "should I put economy tire A or economy tire B on my 20yo, $2k car, also I have $250 to spend". The most popular answers will be invariably be "you should have dedicated summer and winter tires" and "you should use jack stands when you change tires" and many duplicates thereof many of which will suggest that anyone who does not do these things is not someone of good character, deserves to rot in hell, is a burden upon society, etc, etc. Neither of these sideshows are productive discussion. Both of them serve purely to signal to the in-group that the signaler believes something the in-group already believes. Of course everybody wants the greatest tires and nobody wants a car on them but the former is not in the scope for budgetary reasons and the latter is not a concern when simply changing tires never-mind that installing tires usually adds no cost over having them put on rims. The people circle jerking it to jack stands and fancy tires are negatively affecting the discussion for anyone who cared about economy tires. Virtue signaling takes legitimate relevant content and displaces it with low quality junk. I'm more technical than I am cultured but I see this kind of behavior across multiple topics and I'm sure that any serious amateur film critic, book critic, etc. probably could come up with a similar example from their niche.
While that example is hypothetical you can see similar ones play out across a multitude of topics and I think this does legitimate damage to civil discourse. It's like how searching for a service manual for an appliance on the internet to yield results but now it yields a million sites that don't have what you're looking for but will try and sell you something. I see virtue signaling as having a similar quality degradation affect but on legitimate discussion. We can no-longer have detailed discussions about complex issues, regardless of subject because they all get derailed, bogged down and diluted by people showing up to signal their virtue on a higher level issue. Take for example the recent discussion about police. Many on the left and right have a litany of small points on which they agree. Any public discussion about common ground, like fewer MRAPs in the hands of suburban police departments, gets drowned out by riff raff showing up to tell the world which team they're on. At scale this is damaging to civil discourse.
In conclusion, I think that having a nice, short, two-word, pop culture word to describe that behavior is useful because makes it easier for those who may not be articulate enough to otherwise do a good job call it out when they see it. Of course some people are gonna abuse it but I think that's just the nature of it being a negative thing since all negative things become a name you can call someone or their actions.
ALWAYS dismissive and reductive. ALWAYS. It's not a good faith argument. If you think someone is all-talk-no-action, accuse them of being performative. If you think someone's cause is dumb, attack that. You can call ANYBODY advocating for a viewpoint a virtue signaller so it is an entirely meaningless attack.
Don’t you realize how ridiculous and useless this argument is?
Buying CFL lightbulbs is performative climate action.
Buying CFL lightbulbs is virtue signalling climate action.
One of them is about the action - buying bulbs isn't effective, the other is about the person - if you buy bulbs you are fake. Perhaps "performative" fails at making this distinction clear enough, but I'd like a way to imply that someone is all-talk-no-action, without undermining their actual belief in something.
Maybe some people are too quick with the term, there always will be people like that for any label. But just consider all the people just as tired of real conversation being shackled by "virtue signaling" as you are of being called a virtue signaler.
Also, you could write your disgruntled comments about any label. We are certainly way too quick to find racism where there isn't any. Yet there are also real racists out there complaining that the charge of racism is really getting on their nerves. Does that mean we stop charging people with racism when we see it? No, we're trying to call out unacceptable behavior.
If we're getting into pet peeves, mine is "gaslighting". Everything is "gaslighting" now. Accidentally spread a small inaccuracy? Gaslighting. Tell a public lie? You're now "gaslighting the world". Sharing my disagreement with you, like this comment? I'm gaslighting you.
If I say "don't be racist" and you call me a virtue signaller, you are implying that I don't actually care if you're racist, I just want social points for being "good". The problem is you don't know if I care or not. I might care deeply. I might dedicate my life to being anti-racist, but you can just label it virtue signalling and move on? that's an intellectually dishonest maneuver.
It can be incomparably frustrating as it focuses on non-issues or minor issues and misses the bigger picture. I personally don't see it used outside of those contexts but it shouldn't be used to dismiss actual action like doing your part against climate change.
Signaling being a term used by some niche fields. We have that happen all the time. It’s how language evolves.
The article says to use show off instead of virtue signaling. Right after the next argument is assuming the person is disingenuous. Which is exactly what you’re doing if you say they’re showing off. The two arguments can’t both be used. They are arguments against different things.
It’s like the derogatory “social justice warrior.” What? It’s bad to give a damn about people and advocate on their behalf? If having empathy means I’m “an SJW” then I’ll gladly wear that moniker.
https://slatestarcodex.com/2014/09/30/i-can-tolerate-anythin...
If you say you care about privacy but do nothing to protect your privacy, you don't really care about privacy in any way that matters. Since you mildly inconvenience yourself for the sake of privacy, I can conclude based on this very limited evidence that you mildly care about privacy, which is a whole lot more than most people care about it.
Apple markets itself as privacy conscious because that makes Apple look like a trustworthy company. That's a rare and beneficial appearance that a company can maintain to get more business.
Not all gay people care about their privacy. Plenty live in states where they feel more free to open up to their friends, family, and neighbors.
They're are plenty of things that people agree with in the abstract, but don't do enough to make a difference. Probably everyone agrees that the environment should be cleaner. If I agree with that, but "don't lift a finger" to make it better, how am a virtue signaling? It's the opposite.
"Virtue signaling" involves doing some token thing to get the kudos. Smugly saying you only use DDG for web searches. Putting a Tor sticker on your laptop. Etc.
When virtue signalling can become dangerous however is in situations where something based on a mistaken notion of doing good (when in reality it does more harm) becomes a fad and people who virtue-signal keep promoting it into wider popularity.
You think the backdoors that Zoom are likely creating for the Chinese government won't ever be found and used by malicious hackers?
You really think the Chinese-American human rights activists whose Zoom accounts were identified and banned from a private video call with Chinese-based allies and friends and family are thinking "what use is there for inferior products?"
Oh well, we live in free countries. You're free to open your company and possibly your Chinese colleagues/friends to China or whoever else is the boogeyman right now.
I don't know anything about Jitsi. Will research. Thanks.
At the start of the pandemic, my friend at this particular court was tasked with figuring something out. Initial plan was choose a web cam and software combo for everyone to use. And then they'd be futzing with Windows boxes of unknown provenance, trying to do remote tech support, etc. Whose got time for all that? For instance, they told me one of the new Logitech web cams they tried doesn't have Windows 10 drivers.
I recommended they just a cheap iPad for each location, participant. Create iCloud account for each device. Use FaceTime. Buy mounts or tripods as needed.
I haven't heard back what they finally decided.
FWIW, I since learned they were also having uninvited people join their confidential sessions, just like the naked guy showing up for online classes. Such a mess.
Downloading of Signal doesn’t signify privacy concerns. I have Signal because others do. Not because I care about signal’s privacy.
The other thing that is wrong with this sentiment is that "privacy" is not a binary thing: you don't "have privacy" or "not have privacy". You don't "want it" or "not want it".
Privacy and the need for it, is heavily dependent on context. You want more privacy when watching porn than when watching some sports. You want more privacy when you are a minority than when you are part of the ruling class. And so on.
Edit: so a person wanting to escape religion and seeking online help on how to do so needs different privacy than three friends having an online beer. Everyone has moments and time where they need (some) privacy. So probably 99% (a made up statistic) has a need to replace software in some (rare) context, over privacy matters.
Gmail does not use end to end encryption. Yet it's overwhelmingly popular, and perceived to be secure. Google has a huge incentive to keep Gmail secure, and that's enough for most people.
With respect to Zoom, I am fully convinced that if the PRC (or the USA for that matter) wants Zoom to compromise a given account they'll do it. But that's irrelevant to the overwhelming majority of people. Sure, companies like Google and Microsoft should not use Zoom nor should activists or other people that might attract the ire of governments that have leverage over Zoom. But that is a substantial minority of use cases.
Though privacy is also something people want "afterwards".
Something you'd wish you'd taken care of when its too late. When your identity is stolen, and used to get hundreds of speeding tickets on your name. When your sons pictures were lifted off your facebook to bully him after you had your 15 minutes of fame, and so on.
Yes, you have read that right. I was forced to make a zoom call and hold my passport open to the camera. No, they wouldn't accept a scan and an email, or even a call through Jitsi. This is a major public institution with a 200+ strong IT department consuming millions of pounds a year. This is the moronic "enterprise" stuff those millions of pounds buy.
The government of China border guards scan everybody's passport details.
It's unfortunate that a passport number is a form of ID.
end to end encryption would prevent lots of monetization strategies, such as indentifying people via facial recognition and voice printing and then using this data (along with transcripts for example) to "add value".
Now the "we have identified a path forward" bit makes me wonder if they can still pull it off. Maybe it's client-side identification with out-of-band notification.
Google makes an enormous amount of money identifying people.
Perfect instrument to collect more personal data.
The objective behind verifying accounts is to prevent spammers creating lots of spam accounts and using those to spam.
However, spammers rarely care if their spam is encrypted, so putting E2E behind verification won't do anything as far as spammers are concerned - they'll happily keep spamming using the unencrypted accounts.
There's some other reason behind this that isn't about reducing spam.
The public is willing trade away privacy in exchange for protection from certain categories of risk. Instead of denying that, one can lean into it by ensuring strict definitions and enforcement options within those categories while preserving full privacy for those without. Arguing pedophile rings and terrorism are a cost of a privacy policy is a good way to sink that policy.
My personal political answer to "how to have end-to-end encryption and prevent its use for child rape" would be to tax the companies which profit from E2EE, and use that money to fund death squads, which livestream dragging child rapists out of their home, anywhere in the world, and beating them to death with truncheons.
I'm joking, of course (or am I?) but I do consider this the general shape of a viable solution. E2EE is essential for a modern life which isn't a hellish surveillance dystopia, and the detection and prosecution of child rape is criminally underfunded.
Yup. This.
In which ways do you think it is underfunded?
CPS should be able to spot children in abusive homes and respond to reports of unusual activity. They should be able to spot clearly unstable caretakers.
Counsellors and teachers should be able to spot unusual behaviour from children. Mental health services can help someone escape falling into such a situation in the first place by keeping them from falling into depression which leads them to rely on such a person.
Local police shouldn't dismiss leads so readily. This is the it is impossible for him or her to do such a thing mindset which prevails so frequently.
Parents shouldn't trust their relatives so readily and should keep an eye out. 90% of cases happen at home.
If they stopped showing off their crimes online, would the entire system come to a crawl? I'm worried by how much of a reliance there is on divining crimes off the internet.
Now, I'm not saying there is nothing that can be done to reduce it. I very much hope there can be, especially if counsellors can find warning signs and we can better figure out how to spot the danger signs, both online and off.
Facebook took a good step forward by putting warnings up to minors when someone outside of their social circles has contacted many others, although there are other things which could be done.
Should they be allowed to contact them through onion routing during such situations? Where do you draw the line of when such technologies can be used? Is it better not to open this can of worms and risk a slippery descent? What are the chances of false positives, will it unfairly impact relatives? Will it give a black mark to privacy technologies and civil liberties to be associated with automatic blocks? What if minors want to engage in activism, should this be limited? At what point does pushing and pushing start the lie about your age shenanigans again?
This is about Facebook here but it ties back to arguments about doing this or that for the greater good.
Is a more grounded approach better? Ensure minors are well-educated of the risks and dangers online? Invest in mental health services to avoid minors falling into depressive slumps where they might be susceptible to such criminals? In the rare event they drag anyone back home, whether they think they're of a similar age or not, they bring them before the parents first?
I know this argument is often quickly dismissed on HN since people see child abuse or 'going dark' as an easy excuse for the government to leverage to get more control (and it has been used for this), but that doesn't mean the problem isn't serious or doesn't exist.
See this: https://www.nytimes.com/interactive/2019/09/28/us/child-sex-...
The resources fighting this are relatively small in comparison the scale of the problem: https://www.freethink.com/videos/child-exploitation
The people carrying out the abuse are sophisticated.
I have a friend that works at WhatsApp and their entire team is focused on trying to remove groups that exist to share child abuse imagery (via metadata since content is encrypted).
I fall on the side that secure encryption is critical for all of the reasons that technical people normally argue that it's critical and breaking it doesn't work/is a bad idea, but I also understand and empathize with the difficulty encryption by default causes for the organizations fighting this abuse.
That said, I have serious disagreements with Zoom unrelated to this particular e2ee issue (https://zalberico.com/essay/2020/06/13/zoom-in-china.html), I think they don't actually care about protecting the speech of their users or securing content from authoritarian governments. It's still good to avoid them for that reason alone.
In this case wouldn't they build their own solutions (potentially based on existing open-source solutions like Asterisk + Linphone or Jitsi Meet) or they might've built them already?
Phone numbers are also very easy to obtain anonymously, so I am not sure SMS verification would help track down abusers when it'll lead to a prepaid SIM or some innocent user's phone that happened to be compromised by malware.
I agree that these reasons are why it's not a good idea to break or outlaw encryption since bad actors can still use it and good people that need it are blocked, but this doesn't mean that making it the default doesn't enable more abusers to get away with it that might be caught otherwise.
There's a spectrum of sophistication, if it's harder more of them will make more mistakes that make them easier to catch.
Also to clarify, specifically a reasonable trade-off for Zoom (I don't think there should be a general law that requires IDs for video software use or something).
Zoom is not a company I would use at all if you're looking for secure communications (https://zalberico.com/essay/2020/06/13/zoom-in-china.html).
If you care about secure communication you should be using something else.
It depends on which country really. In some places in Europe it became almost impossible to do that (sadly).
Of course, criminals are ordinary people too. They care about convenience and network effects as much as anyone. Which is why I think it’s insane that governments want to jeopardize the trust people have in proprietary, huge E2EE platforms that actually have the means to aid them in investigations. Yes, breaking the crypto may not be an option, but at least collecting useful metadata for use in investigating, and potentially ethical hacking, is an option.
I fear the day when the trust is gone because there is a very real possibility that some day many will be using decentralized E2EE chats, maybe even P2P. It’s not just conjecture of course, Matrix exists today and is already very impressive (in my opinion) in terms of usability.
The internet is opening up the concept of having nearly private communication with pretty much any individual in the world. It isn’t free of implications, but also, as more of our lives move online I feel its absolutely crucial that every day people can feel confident they’re not being monitored. The problem of CSA and other criminal behavior existed before the internet and it will certainly exist after. It’s absolutely past time to re-evaluate laws surrounding child protection, which seem to me to mostly be reactionary at this point (in that many of them are spawned as a result of a specific incident.)
This is not the problem. The argument is hollow.
People need to take child protection laws out of political discourse, as it's now approaching silly.
There are no valid arguments against encryption
> And yes, law enforcement eavesdrops for law enforcement purposes
Lawful eavesdropping is an oxymoron
Put plainly, there will always be crimes you won't be able to catch. You prioritise resources on the most pressing ones and build up resources in the real world to tackle them in other ways. Dystopian lists on the client to control what you're allowed to say or think or report your thoughts back to the government still violates the principle E2EE is built upon.
There is no middle-ground. You either are secure or you are not. The genie is out of the bottle either way.
Individual child abusers aren’t part of a monolithic organization with training on how to secure their comms and practice OpSec.
The number of criminals who still create evidence against themselves on unencrypted platforms (SMS, phone, etc) is significant, despite E2EE options already being available. People are even being arrested for rioting after admitting on public TikTok videos to participating.
I think the only way criminals will standardize on E2EE is if every platform and communication mechanism is E2EE by default. Otherwise they will continue to make mistakes or think they can slip under the radar.
FWIW, I believe this is the future if lawmakers don’t prevent it. A look at some E2EE software today:
- Matrix
- Signal
- iMessage
- Firefox Send
- MEGA
- ...
The list will grow.
In my opinion, E2EE today is like TLS 10 years ago. TLS was once a nice-to-have when it came to communication that was not strictly necessary to encrypt. Today, TLS is more sophisticated, stronger, and easier to implement than ever, and damn near a necessity for anything, even toys.
Granted... E2EE is necessarily harder, since it requires application-level implementation of crypto primitives, things definitely get complicated. Still, I believe the state of the art will continue to improve and tooling with it. Eventually there will probably be defacto libraries and maybe even OS frameworks to deal with E2EE key management, trust, etc.
To be clear, I view this as strictly a good thing and an inevitability. I don’t think transport encryption and encryption-at-rest are good enough anymore for private communication. Of course for public sites like Twitter or Tiktok it’s all you would logically get, but for any group or direct communication I now believe E2EE is slowly becoming the new baseline, and it’s mostly the complexity of it that hampers adoption.
Now that iMessage and WhatsApp are E2EE though, there is a lot of messages flowing that, exploits notwithstanding, are “truly” private, today, and I think the number will only go up. The only real question in my mind is, who’s next?
As far as criminals making slip-ups, this is guaranteed; even the best make mistakes obviously. But assuming all criminals are foolish and stupid is a mistake; I believe there’s a lot of selection bias in there, since we don’t get to find out those who truly never get caught. Time will tell if any of this really matters, or, if, as usual, it’s just another panic that has no tangible effects. I vote on the latter, but I still do believe proliferation of E2EE will change the game in ways we can’t really anticipate 100%.
When a company says they want your phone number in order to use their resources, so they can take steps to avoid having their resources used for (certain) crimes, that's well within the bounds of reasonable.
The problem most people have is when the government tkes away the use of _super important feature_ from the populace as a whole (even using their own resources), because it _can_ be used for crimes.
Those are two VERY different things.
Lower privacy "because security" is not a reasonable trade-off. It should not be. See also: https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp...
It's not a reasonable trade off in countries where you get you legs broken, skin flayed alive, and head cut off: https://www.telegraph.co.uk/news/2019/11/18/russian-mercenar...
A likelier explanation, is they want an easy way to wash their hands off when being pressed.
What you're arguing is a strawman, we agree more than we disagree.
I read, and I think your argument is hollow, and, assuming your goodwill, you are not understanding the matter at all, and if not, I see an ill intent.
I do not appreciate all what you say at all. Any argument against encryption must be quashed without exceptions, and second thoughts.
It is only since the start of 21st century, the experience akin to "legs broken, skin flayed alive, and head cut off" has been a grim reality for far more than a million people by now, mostly for, really, nothing. What are talking about this! And what you talk about?
Attack this argument, not something not even having a passing genuine relation to the matter.
It seems any argument that you don’t already agree with (basically only your exact position) is classified this way.
The rest of your comment is basically incoherent, and the parts that do make sense are obviously wrong. It’s also a willful misinterpretation of my position.
People were flayed before the 21st century. Acknowledging the issues with encryption is a critical requirement in making an effective defense of it. I am not arguing against encryption.
If this is an issue you actually care about (which it sounds like it is), learning how to build consensus and honestly consider the positions of others would be a valuable skill to develop.
As it stands you’re doing more harm to the pro-encryption position (which is also my position) with how you’re attempting to defend it.
Child pornography gets held up to the public a lot because it's a crime nobody can defend and walk away the same they were, no matter what you say. If you publicly contest this move for privacy reasons, you're automatically defending the worst child molester someone's mind can come up with.
The one, admittedly terrible incident, will shock people and they will push exaggerated means to "stop" it. Ones which just so happen to feed tons of information into the NSA machine.
People come up with stories of live-streamed child pornography too but do these children live in some parallel universe where crimes can be committed against them without recourse? What is the police doing? Did they not find suspicious behaviour in a neighbourhood? Did a counsellor not pick up on it?
Yeah sure, child pornography is awful but why is this part of the equation the only one that is ever mentioned? Why is it always about encryption or anonymity?
Yes.
I believe Zoomed has earned the privilege of folks being highly skeptical of their actions / motivations.
with added bonus of no central server
There is no need to use my cell phone or any telephone number when you already have a means of communication via email or any other channel.
Have they had a fundamental turnover in management, indicating a new pro-privacy culture? Did they move their development out from under the thumb of the CCP?
No and no?
So what’s changed?
If they weren’t trustworthy before, they certainly aren’t now.
They were mostly focused on workplace meetings. If that's your focus, then most of your users are employees of some company whose contact information you have. Users with unverified identities are a corner case that you may not feel is worth trying to get right.
Thanks to the pandemic, they have millions of new users who use Zoom for personal purposes (meeting with friends and family, etc.). What once was a corner case isn't anymore. It might even be their most common type of user.
I'm not arguing that Zoom can necessarily be trusted, but I can see a plausible reason how they could have gotten to where they are on this issue.
Their userbase changed in the two weeks since they announced their policy?
But yeah, while feeling that you can't trust them because they don't know what they're doing is not the same as feeling that you can't trust them because they're in cahoots with someone (governments, etc.) against your interests, in the end they're both forms of feeling that you can't trust them.
Stop looking at the empty words they say, and start looking at their very intentional and malignant actions over the last few months/years.
Why do you believe their real intention was revealed a week ago, and not today?
Trust, but verify, yes? Well, they're verifiably full of crapola.
So why would you trust?
It’s a bit of weaseling here. They say they’re offering E2E and that might be true, and it could also be true they are sticking with their original vision of cooperation with law enforcement because they “are aware criminals use the service”.
There is no required mutual exclusion.
The bright green "Start" and "Schedule Meeting" buttons just pop up an error. The correct button to progress is the dark grey (as if disabled) "Next" button.
It prompts me to create a "personal conference number", whatever that is. This errors and tells that I need set a PIN in my preferences. I search for the preferences for a while and eventually find that I _do_ have a host PIN set...
At this point I gave up.
Gripes on the participant side: Why does it ask me to provide my name in the browser when joining a meeting before launching the app which already knows my name? Why do I have to manually press the refresh button to discover scheduled meetings?
Cisco pulled a Boeing with the development of one of their crown jewels, and Zoom swooped in, even with shady practices, and snatched up significant market share.
Cisco itself has time and again bought its way into things that aren't their core competency and they fumble around with them.
They bought Flip video for 590 million years ago, despite the fact that every person in Cisco's office had a smart phone in their pocket that would render it relatively useless...
I think video conferencing applications are often doomed to turn into behemoth messes for some reason that I can't figure out.
My work uses Zoom, and it's night and day and smooth everything is.
Also IMO there's been some drastic improvements to audio quality lately. My very noisy fan that triggers my mic in Discord is totally inaudible in Google Meet, even when I'm talking.
Writing from the UK, I'm reasonably sure that (a) all my phone calls are not recorded and (b) the phone number and duration of every call absolutely is recorded (this has to be shown on your phone bill!) and is available to the police when needed.
Speculating further, with the right court orders / warrants the normal E2E encryption algorithm for a particular user could be replaced with a "law enforcement decryptable" one and, hey presto, it's a Zoom equivalent of a proportionate wiretap that only covers future calls. Certainly a lot better than encrypting the calls of all users with such an algorithm "just in case".
It would be easier to just lie about the encryption being end-to-end.
Personally, I will never use Zoom for anything, a decision I came to when my OS vendor (Apple) pushed a security update for my OS to get rid of Zoom.
With 5 / 14 eyes and no specific privacy doctrine in the UK, I have no idea why you would have that assumption at all.
Maybe not recorded indefinitely, but it seems very possible to voice to text and store that forever.
I’m glad that Zoom is finally implementing E2E encryption, but I hate that they have been (and still are) advertising “full encryption” and using jargon like “AES 256 GCM” to deceive users into thinking they’re using anything more than SSL.
This E2E encryption is on top of TLS.
AB/BC link encryption is the correct way to refer to such a scheme.
"Unlike PGP and S/MIME, STARTTLS provides hop-to-hop encryption (TLS for email), not end-to-end."
[0] https://www.eff.org/deeplinks/2018/06/technical-deep-dive-st...
* be banned by Chinese government order like https://arstechnica.com/tech-policy/2020/06/zoom-cites-chine...
* send my IPs to servers in China.
in any case, if the trust isn't there, you can't validate the E2EE, so your risk profile with regards to using the software doesn't change much.
With closed source software, though, this doesn't give as much confidence, since a company could create a version which they send to everyone but which contains an "if (userId == NSA_TARGET)" conditional branch.
If you are under serious investigation I wouldn't trust anything "smart" manufactured in a country under that investigations jurisdiction.
As for the threat model of open source E2EE apps auto-updating to an insecure version, you're right that this needs some extra defences. One way would be to use a binary-transparency log[0] to make sure that the open source project had publicly committed to a specific binary at least 24 hours in advance of pushing the auto-update.
This system relies on there being auditors out there who would raise the alarm if a malicious update was released, or a hash was included in the log for which there was no corresponding (reproducibly buildable) source code.
Good for them, but it's still going to be an uphill battle imo.
I tried updating the app and the same error occurred. Perhaps their cert had expired or it was some oversight but I'm done. I've removed Zoom.
100% do not trust.
I'm fearful that I'm being paranoid but if they want to use their native app that badly I'm pretty sure it is collecting some information that I don't want to share. I'll happily take the extra steps to keep them sandboxed in my browser.
Honestly this is one of my favourite features of Google Meet and Jisti Meet. It is so easy to send a link to anyone and they are in the meeting in seconds.
I mean, Zoom's atrocious security record aside, mistakes do happen. Microsoft recently forgot to renew some certs for Teams that caused a lot of trouble.
Some things that looked like good steps:
> we will allow the SSO IDP (Identity Provider) to sign a binding of a Zoom public key to an SSO identity, and to plumb this identity through to the UI.
> Second, we allow users to track contacts’ keys across meetings. This way, the UI can surface warnings if a user joins a meeting with a new public key.
> we will implement a mechanism that forces Zoom servers (and SSO providers) to sign and immutably store any keys that Zoom claims belong to a specific user, forcing Zoom to provide a consistent reply to all clients about these claims. Each client will periodically audit the keys that are being advertised for their own account and surface new additions to the user.
> In Phase IV, we look to the future where Bob should sign new devices with existing devices, use an SSO IDP to reinforce device additions, or delegate to his local IT manager.
All of this of course relies on a zoom client actually doing everything described in the whitepaper, but it certainly looks like a good faith effort to implement real, functional e2ee
Otherwise, it is just being stuck between rock and a hard place with no place to move.
Sadly, it is not really new. Companies will typically attempt to extract maximum amount of milk with minimum amount of moo. If they keep making mistakes, we need to keep making noise.
Not fun, but someone has to do it.
https://www.theverge.com/2020/3/31/21201234/zoom-end-to-end-...
Zoom, however, denies that it’s misleading users. The company told The Intercept, “When we use the phrase ‘End to End’ in our other literature, it is in reference to the connection being encrypted from Zoom end point to Zoom end point,” and that “content is not decrypted as it transfers across the Zoom cloud.”
Whether the paper is any different is sort of irrelevant if they're starting off from a place of bad faith. One time after another this company has 'accidents' like this, while removing CCP distinguished nonpersons from the platform. A sense of skepticism is certainly justified.
https://twitter.com/alexstamos/status/1268061792527241216
He did not say they can't monitor calls.
https://twitter.com/alexstamos/status/1268061795572314113
If they can enter the meeting, either they have to get confirmation from the host who would send the keys to the person entering the meeting or they already have the keys and can enter the meeting and decrypt the stream.
Edit: Sorry for coming across a little brash, I'm quite a strong advocate of real encryption and this kind dilution of terms makes my blood boil because terms are being diluted and people have trust in something that betrays them.
Whoever controls key distribution can control the encryption channel; without a way to verify public keys, all bets are always off. You're right that auditing the client is one (if not the only?) way to do this.
[1]: https://en.wikipedia.org/wiki/Diffie%E2%80%93Hellman_key_exc...
To the contrary, you can pick the region for your servers, which presumably for 99% of people is precisely to avoid China:
https://blog.zoom.us/wordpress/2020/04/13/coming-april-18-co...
I'm not convinced that a setting alone should provide much confidence in terms of traffic routing considering that it can always be changed independent of what setting in the application you make.
Yes, zoom said it was unintentional.
For me, that's hard to believe. They weren't routing the call itself through China, they were just sending the encryption keys to a server in china. That seems pretty intentional. Even if they weren't routing the call through China from a user's perspective, their US server could still be sending the call data to China or recording the call for playback (from China) later. Their track record around security is so bad that I would stay as far away as possible.
Unfortunately for folks who are good actors in other non free countries countries... I find any sort of development or real world controls that are in a seriously non free country... automatically suspicious.
Even good individual developers who have the best of intentions in those places could be subject to pressure and the likelihood we'd ever hear about it is near zero in many of those places.
Granted that 'could' happen in more free countries, but I'll hedge my bets there as there's a great deal more likelihood I would hear about it.
If the CCP wants the keys, they'll get them.
> The statement raises questions about Zoom bowing to Chinese pressure. Unlike many Western social media platforms, it is not blocked in China. The company did not explain under what law the meetings – which were hosted outside mainland China – were deemed to be illegal.
For meetings outside of China where the Chinese government should have no jurisdiction, Zoom choose to cooperate.
Some obvious follow-up questions:
1. Where will the keys be stored? On servers in China or elsewhere? Will it depend on where the account holders are? Or are the private keys truly local?
2. What safeguards are in place to prevent further "cooperation" with Beijing in relation to supposedly encrypted traffic?
3. Zoom is not blocked in China, which is pretty rare for a supposedly US-based company. What concessions did they make to get this exemption?
4. Under what circumstances will any of your data be stored in, routed through or otherwise be accessible in mainland China?
Given China's philosophy that Chinese companies are nothing more than extensions of the state, these are entirely reasonable questions to ask. Were I the decision maker for any large company or government organization, I personally would consider use of Zoom to be too much of a security risk. And I don't think that's the slightest bit alarmist.
[1]: https://www.theguardian.com/world/2020/jun/12/zoom-admits-cu...
Is a new key generated for each stream, which is then individually encrypted with every other participants public key, and then sent to the participants for them to decrypt?
Edit: One issue is the client can run out of entropy but I think that would only happen on modern operating systems if you had hundreds of thousands of clients to negotiate with.
[0]https://en.m.wikipedia.org/wiki/Diffie%E2%80%93Hellman_key_e...
Some time ago I had to give lecture to a company who only has zoom as an option. I fired up a VM, installed zoom. Gave the lecture. Deleted the VM.
Does anyone reasonably want their "encrypted" conversation to route through servers physically in China?
I'd hope that when I Zoom with my coworkers two miles south of me in Austin, we're using AWS/Azure/Google Cloud/whatever servers in Texas, or at least within a couple thousand miles.
At work we have been looking at two fantastic "indie" alternatives:
Give me a Free software client and an open and reliable standard to encrypt. Otherwise, this is bullshit.
I still use it, don't get me wrong. My threat model for the use case that I make of zoom does not need strong encryption, only being script kiddies proof.
How will they square this with the censorship required of them in China? Presumably they are not going to shut down the service in China.
Is that what you tell to the judge to decrease your sentence?
You’d think they’d learn, but alas.
So what are they actually announcing then?
I've tried Zoom once, it was a disaster. I've tried Jitsi, it was much better. Moreover, Jitsi doesn't require any installation on the client side, and you can host your instance or join an existing one (you trust).
https://theintercept.com/2020/04/03/zooms-encryption-is-not-...
https://sneak.berlin/20200604/if-zoom-is-wrong-so-is-apple/
(Most of iCloud, including notes, photos(!), and backups, including your complete text message history(!!!), is not end to end encrypted for anyone, paid or otherwise.)
If I am sending fully encrypted high resolution video, wont a slow mobile device have trouble receiving it?
1) Adding a missing feature, which is a form of technical correction.
2) Fixing the corporate culture and their attitude to their customers. This is a form of non-technical correction.
Zoom has done a half-arsed job of (1), and one could legitimately argue that it's too little, too late. But the real issue is that nothing indicates that (2) has improved in any way. Fundamentally, the Zoom corporate default is "lie to the customers and when caught, double-down".
They're taking a page from Trump's book. I'm sure you don't need me to explain why that particular management style is unpopular here.
For a recent example, see how PostgreSQL fixed a technical issue discovered by Jepsen. They were advertising on their website that they had a certain technical guarantee related to serializability of transactions. Turns out there was an error -- an honest mistake. They immediately corrected the issue. People trusted them more because of this management attitude. [1]
Now compare with nearly the exact same technical issue with MongoDB discovered by Jepsen. Mongo's website repeatedly lied about their data integrity features, even referencing the Jepsen test as proof! Tests they failed! It's like the snake oil salesman saying "scientifically tested" as if it's a good thing that every scientific test proved that it's just oil and does nothing. Mongo was rightly derided and mocked.[2]
[1] https://news.ycombinator.com/item?id=23499667
> Personally, this kind of thing actually gives me _more_ confidence in Postgres rather than less. The core team's responsiveness to this bug report was incredibly impressive.
[2] https://news.ycombinator.com/item?id=23285768
> In the circles I run in, MongoDB is regarded as a joke and the company behind it as basically duplicitous.
Can you name a single company in China that offers true E2EE? All the messaging apps are utterly compromised and running real-time surveillance and censoring, for example.
It's ridiculous they've been dancing around this for so long.
Better video quality?
Dual-screen mode?
Or simply the superior video and audio quality compared to Meet.
I wish I could move away from Zoom, but I've yet to find something similarly useable for my use case (remote trainings).
Zoom seems to be a poster child for the surveillance state.
If you want privacy you simply have to choose another product or service.
You aren't entitled to use their service without paying for it.