Bizarre Design Choices in Zoom’s End-to-End Encryption
soatok.blog
soatok.blog
I'm not sure who the intended audience is. It's light on crypto and it's light on furry stuff. I think both audiences will feel short-changed.
That's debatable.
Keccak's sponge construction is novel, it has some cool features compared to Merkle–Damgård but when SHA-3 was standardised we had very little experience with this construction. Now, maybe we lucked out and these are the perfect parameters, not too slow, not too weak. But most likely we went too far in one direction and so hence "Maybe Skip SHA-3"
Unfortunately, that sort of dogmatic cargo-culting is not restricted to security articles, although it seems a bit more prevalent in that area.
This might be deep lore that not everyone knows, but if you muck around with open source software for a while, you will discover that a lot of developers are somewhat impressionable. I've seen the "I did X because project Y did something similar and they were secure" genre of reasoning play out more than I care to remember.
> Why is the author so fake-surprised that the source code isn't available on the internet? Zoom isn't open source software, and has never claimed to be.
I don't use Zoom and wasn't familiar with the company before I looked at their whitepaper. It's not fake-surprised at all.
> The title is also pure clickbait, since the article itself comes to the conclusion that the design is secure and the oddities are likely due to the need for legacy support.
...Yes, but they're still oddities, right?
I wouldn't call a title clickbait when it's completely accurate.
If I found security issues, I would've titled it "Vulnerabilities in Zoom's End-to-End Encryption White Paper", if I even blogged about it at all.
I think you are in quite a rare position if you have not heard of Zoom but visit sites like this in 2020.
I am just curious with this following question. Do you usually not perform a search query before you read a paper?
I've heard of Zoom. But that doesn't mean I know their entire business strategy especially when it comes to open/closed source software.
I've also never had any reason to try it: I don't have any kids (so no school, etc.) and I lived most of my life too poor to afford health insurance, and I'm afraid to leave my house during the pandemic, so I still don't have a family doctor or anything of the sort to talk with. I work from home and use Slack for everything work-related (but Telegram elsewhere because that's where the furries all hang out for reasons I find wholly unsatisfying).
> Do you usually not perform a search query before you read a paper?
I'm curious: What precisely do you mean by "a search query"?
My search queries are usually of the form:
site:github.com zoom encryption
So if I was supposed to find something more enlightening on the subject, my search habits probably weren't conducive to discovering it.I was expecting much more.