It does sound very intriguing to me at least.
Details: https://github.com/zoom/zoom-e2e-whitepaper/blob/master/zoom...
[1] https://www.forbes.com/sites/thomasbrewster/2020/04/03/warni...
Note how it mentions "How is this different from Zoom’s enhanced GCM encryption?", which means enhanced also applies to the normal Zoom meetings which are encrypted but not E2E, and supports this interpretation.
This slight benefit is fairly silly, because we have no reason to give greater credibility (regarding ethics) to one set over another. At least it's a smaller set, though.
Considering their growth throughout, why would they waste their time implementing it fully and correctly?
I assume there will be analysis done in the near future by third parties, but even that analysis is not sufficient to protect against a future change or a one-off, court-mandated targeted "switch" to join a un-announced participant to a meeting. The client can be designed to be 'dumb' in this regard.
So ahead of things like iMessage. About the same as stuff like Whatsapp. Behind things like Signal, Telegram, PGP and the like.
Pfahahahahahaha.
More seriously, my understanding is that Zoom uses automatic updates, so it can never be secure even in the unlikely event the code that's on your machine this week actually does correctly implement end-to-end encryption. Also, if you're trusting Zoom's servers to give you the encryption keys you have a MitM attack waiting to happen.
"True" E2E encryption doesn't really exist nowadays, at least in the context of being spied on by governments.
Edit: Direct sources don't really exist for obvious reasons. Google it, and there's plenty of articles to help you read between the lines. If you think the govt isn't capable or interested in this, you're being naive.
I also can't trust that the meat I buy in the supermarket actually has in it what it says on the packaging technically speaking unless I slaughter a pig myself. Obviously this isn't a reasonable standard to treat anything by.
When a company goes out of their way to actually sell you E2E encryption and the company actually is fairly known and thus liable I can at the very least assume, for practical purposes that they're not lying to me until proven otherwise because they're risking their entire reputation and probably a very costly legal battle.
Do-it-yourself encryption isn't really realistic because it's not going to be used by ~99% of people.
A market cap of $129 billion (with a B) with annual revenues of 600 million? I feel like this is a crazy gone bad joke, how in the world do they expect to justify that kind of valuation?
Can someone please explain what is their current business plan, and what is their future one? They don't have ad space to generate revenue, they don't have a viable subscription based model, they are not a real B2B product, and they are not going to keep adding users forever. This was once in a lifetime situation where a majority of people were using it, and they still weren't able to capitalize on them in a way of monetizing them.
I feel like they hit their peak without reaping the milestones and achievements along the way (except getting out like a bandit from the stock market).
Am I taking crazy pills or?
For zoom though, I think that they will continue to find ways to extract more revenue per users. I think what will increase in the future is more and more economy will be digital economy, and people will be more willing to pay for and do commerce in a virtual platform. And companies will find ever more commerce opportunities with digital technologies. So I think they will continue to increase their revenue.
Sounds like they got a sudden spike in interest, realized that their customers were angry, admitted the error, bought keybase, and provided what their customers asked them for.
E2E in the sense that security nerds bang their chests about isn't what customers want. Boards of directors of public companies, some attorneys, and some others need it. Almost nobody else does. It means that you don't have cloud recording, can't use POTS phones to connect to the meetings, etc. People with those needs have security controls beyond the software, so they probably need something like Webex, or should be using directly connected room systems. Someone who needs E2E for real reasons aren't doing it from home, for example, as you need to take other measures to protect that meeting content.
Zoom acquires Keybase: https://news.ycombinator.com/item?id=23102430
There are secondary benefits, the acquisition did bring some probably-helpful talent around encryption/infosec, but as you said the rollout seems really fast vs acquisition time for a product that size.
> Zoom’s end-to-end encryption (E2EE) offering will be available as a technical preview, which means we’re proactively soliciting feedback from users for the first 30 days.
It is a commendable step forward, but I wonder what their concerns are about this feature with such a careful rollout schedule. The difference seems only about who generates/manages the key, so unless they were decrypting the packets in transit, they should not be concerned about this.
However since they claim that it is only the key acquisition that is changing it seems likely that it will work.
It's the same issue with WhatsApp. I hear rumors that law enforcement can access WhatsApp messages so i guess there must be a backdoor like this.
So, it disables all the parts of video conferencing that make it a somewhat suitable stand-in for in-person meetings?