back
156 comments
I'm curious about what they call "enhanced AES-GCM encryption". Because to me that smells like "roll your own crypto" kind of deal, where "moar perf" quickly ends up being "moar sidechannels" (whether willingly or not).

It does sound very intriguing to me at least.

In both the "normal" case and in situations where end-to-end encryption is enabled, the audio and visual streams are individually encrypted with AES-GCM-256 using a key derived from a shared per-meeting key. The difference is that in the normal case, the per-meeting key is stable for the entire meeting and is available to Zoom (as is needed for POTS bridge, cloud recordings, etc...). When the meeting is E2EE, the key is generated by the host, distributed to the other attendees, and rotated as the meeting participants change.

Details: https://github.com/zoom/zoom-e2e-whitepaper/blob/master/zoom...

Zoom's development team is based in China [1]. Could the government there force these devs to "enhance" this encryption with a backdoor or two for "state security" reasons?

[1] https://www.forbes.com/sites/thomasbrewster/2020/04/03/warni...

What was published not too long ago: https://github.com/zoom/zoom-e2e-whitepaper
AES-GCM has serious problems with nonce reuse when you have encrypted a lot of data. As I recall, solving that problem was part of the CESAR competition a couple years back.
I'm also very curious about this. AES-GCM satisfies my threat model, "enhanced" does not.
I clearly read it as enhanced compared to the previous versions, which used to be AES-ECB until earlier this year.

Note how it mentions "How is this different from Zoom’s enhanced GCM encryption?", which means enhanced also applies to the normal Zoom meetings which are encrypted but not E2E, and supports this interpretation.

Yeah symmetric ciphers are easy (TM), it's the pub key shit that really gets you.
Perhaps enhanced means backdoor-ed.
Isn't the whole point of end-to-end encryption -- not to have to trust any third party -- undermined by secret source? If one does not trust Zoom not to snoop on content passing unencrypted through their servers, why should one trust them to provide true end-to-end encryption? And, if one does trust them to provide true end-to-end encryption, why might one not as well trust them not to snoop on unencrypted content?
The point of end-to-end encryption is to prevent a government from being able to access your communications afterwards. Zoom or any other private company is much more able to implement a standard technical solution like end-to-end encryption than to resist legal subpoenas for information they have but would prefer to not have.
They are not opening their source code, as far as I know, so who is auditing this supposed end-to-end encryption?
I agree. But I suppose it does have a slight benefit that if you trust the individuals at Zoom who implemented the encryption, now you no longer need to also trust the individuals at Zoom who have access to network traffic and/or server-side code but not client application code.

This slight benefit is fairly silly, because we have no reason to give greater credibility (regarding ethics) to one set over another. At least it's a smaller set, though.

Ask HN: Who of the readers here believe this is a true E2E encryption - so that even government can not see the content?
Well they previously claimed their service was E2E, then there was a furore when it was discovered that was not true, after which they claimed their service was E2E, when it still was not.

Considering their growth throughout, why would they waste their time implementing it fully and correctly?

With a closed-source client, how do we know Zoom does not add itself as a un-anounced participant in a meeting??

I assume there will be analysis done in the near future by third parties, but even that analysis is not sufficient to protect against a future change or a one-off, court-mandated targeted "switch" to join a un-announced participant to a meeting. The client can be designed to be 'dumb' in this regard.

They acquired the Keybase team to implement this. If there is a backdoor, I'd expect a mass exodus of the team.
Honestly, I know they hired a good team to do it and stand to lose everything if they didn't implement it properly... but they lied about it once and that was so brazen that I won't believe it until it's confirmed by at least a few independent experts. Zoom, in my mind, is synonymous with invaded privacy, poor security and lies.
It appears to tick all the boxes other than verifiable client binaries...

So ahead of things like iMessage. About the same as stuff like Whatsapp. Behind things like Signal, Telegram, PGP and the like.

Noob question here: is it difficult to implement E2E encryption one would think Zoom has all the resources required to build such a system?
> Who of the readers here believe this is a true E2E encryption - so that even government can not see the content?

Pfahahahahahaha.

More seriously, my understanding is that Zoom uses automatic updates, so it can never be secure even in the unlikely event the code that's on your machine this week actually does correctly implement end-to-end encryption. Also, if you're trusting Zoom's servers to give you the encryption keys you have a MitM attack waiting to happen.

I think it won't be designed with a built-in backdoor, but probably also not designed very well. Like WhatsApp instead of Signal. Closed source, edge cases not covered well, etc. Not going to be anyone's go to for high-assurance protection from state actors.
It's kind of a moot point since the government already has backdoors built into operating systems, hardware chips, browsers (therefore can enable screen-sharing + other hardware settings remotely), etc.

"True" E2E encryption doesn't really exist nowadays, at least in the context of being spied on by governments.

Edit: Direct sources don't really exist for obvious reasons. Google it, and there's plenty of articles to help you read between the lines. If you think the govt isn't capable or interested in this, you're being naive.

Didn't they claim this before, when it was just fake end-to-end encryption? How do we know it's real this time?
IIRC they even were marketing their usage of SSL as e2ee in their website for some time.
You can never trust that your connection is end to end encrypted unless you run encryption yourself. Someone who could come up with a way to asymetrically encrypt video before it goes to any app would certainly make a lot of money and probably put a target on his or hers back for upset governments as they will have no way to decrypt it (now they can ask provider for the tap, but if you encrypt yourself it won't work).
>You can never trust that your connection is end to end encrypted unless you run encryption yourself

I also can't trust that the meat I buy in the supermarket actually has in it what it says on the packaging technically speaking unless I slaughter a pig myself. Obviously this isn't a reasonable standard to treat anything by.

When a company goes out of their way to actually sell you E2E encryption and the company actually is fairly known and thus liable I can at the very least assume, for practical purposes that they're not lying to me until proven otherwise because they're risking their entire reputation and probably a very costly legal battle.

Do-it-yourself encryption isn't really realistic because it's not going to be used by ~99% of people.

I have never "run encryption myself" when connecting to my bank's web site. Have you?
Zoom continues to astound me. I am constantly dumbfounded when I see articles about Zoom breaking records, and even more shocked when I see their market valuation.

A market cap of $129 billion (with a B) with annual revenues of 600 million? I feel like this is a crazy gone bad joke, how in the world do they expect to justify that kind of valuation?

Can someone please explain what is their current business plan, and what is their future one? They don't have ad space to generate revenue, they don't have a viable subscription based model, they are not a real B2B product, and they are not going to keep adding users forever. This was once in a lifetime situation where a majority of people were using it, and they still weren't able to capitalize on them in a way of monetizing them.

I feel like they hit their peak without reaping the milestones and achievements along the way (except getting out like a bandit from the stock market).

Am I taking crazy pills or?

I think for us techy people, we image a future where people interact with each other virtually. Today in video calls, tomorrow will be in ever realistic virtual reality. Maybe at some point we will be so good at mimicking reality and also so good at creating new scenarios where it is not possible in reality. But after this experiencing this pandemic, staying home for more than half of the year, interacting people remotely, at least for me, I can't wait for the time to finally able to meet people face to face. Even though a lot of companies have offered forever working from home, I don't think I will take that offer. Its just feels so much better to talk to people, see people in person. Whether its the body language, people's emotions, or physical interactions, and the in the moment and immediateness of everything. I don't think computers, VR and AR will ever going to replace that experience.

For zoom though, I think that they will continue to find ways to extract more revenue per users. I think what will increase in the future is more and more economy will be digital economy, and people will be more willing to pay for and do commerce in a virtual platform. And companies will find ever more commerce opportunities with digital technologies. So I think they will continue to increase their revenue.

Zoom has quarterly revenue of $600 million, not annual.
The cognitive dissonance here is amazing. How do you claim you are offering E2E as an upgrade on a product you have already claimed is E2E?
I'm not sure it's still really cognitive dissonance when they admitted their error in marketing it that way, announced they were working on exactly this to provide what their claims said, and now they're saying it's done?

Sounds like they got a sudden spike in interest, realized that their customers were angry, admitted the error, bought keybase, and provided what their customers asked them for.

Zoom is guilty of alot of stupid stuff, but the "E2E" controversy is the among the dumber controversies. Zoom's characterization of end to end was referring to the transport layer between the clients and Zoom service endpoint. The more serious issue there was that until a point in the recent past, they weren't using an appropriate cipher mode.

E2E in the sense that security nerds bang their chests about isn't what customers want. Boards of directors of public companies, some attorneys, and some others need it. Almost nobody else does. It means that you don't have cloud recording, can't use POTS phones to connect to the meetings, etc. People with those needs have security controls beyond the software, so they probably need something like Webex, or should be using directly connected room systems. Someone who needs E2E for real reasons aren't doing it from home, for example, as you need to take other measures to protect that meeting content.

I wonder if their acquisition of keybase has been done long enough for it to have been helpful here.

Zoom acquires Keybase: https://news.ycombinator.com/item?id=23102430

IMHO, the acquisition was mainly for two reasons: - signaling, to its customers and the market that they are taking this issue seriously - management "cover-my-ass": if somehow the overhaul is taking longer than expected, someone can claim "we tried everything we could"

There are secondary benefits, the acquisition did bring some probably-helpful talent around encryption/infosec, but as you said the rollout seems really fast vs acquisition time for a product that size.

Probably, the blog post itself is signed by Max Krohn, Keybase.io co-founder.
> In a meeting with E2EE enabled, nobody except each participant – not even Zoom’s servers – has access to the encryption keys being used to encrypt the meeting.

> Zoom’s end-to-end encryption (E2EE) offering will be available as a technical preview, which means we’re proactively soliciting feedback from users for the first 30 days.

It is a commendable step forward, but I wonder what their concerns are about this feature with such a careful rollout schedule. The difference seems only about who generates/manages the key, so unless they were decrypting the packets in transit, they should not be concerned about this.

It doesn't say if this works on the web client or not. I prefer to keep Zoom inside the sandbox of my web browser.

However since they claim that it is only the key acquisition that is changing it seems likely that it will work.

Is it true end to end or end to China to end kind of thing?
One problem with closed source end-to-end encryption is the trust you have to put into the vendor. The encryption implementation may be excellent, but what's to stop them from adding a "upload private key" function for lawful interception, perhaps at a later time?

It's the same issue with WhatsApp. I hear rumors that law enforcement can access WhatsApp messages so i guess there must be a backdoor like this.

Does anybody know if this means that zoom will be using WebRTC for browser-based E2EE calls?
Zoom is not a solution. We need WebRTC based End-to-End encrypted solutions. I am a Node developer who is pondering on starting such a thing. Reply to me if you want to get involved.
>Enabling this version of Zoom’s E2EE in your meetings disables certain features, including join before host, cloud recording, streaming, live transcription, Breakout Rooms, polling, 1:1 private chat, and meeting reactions.

So, it disables all the parts of video conferencing that make it a somewhat suitable stand-in for in-person meetings?

The ephemeral key is regenerated when a participant leaves right?
Can I join an e2e conference through my browser or are they going to finally force me to download their crappy app?
And people will not only believe it, but defend it.