News: 1602747184

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Remember when Zoom was rumbled for lousy crypto? Six months later it says end-to-end is ready

(2020/10/15)


The world’s plague-time video meeting tool of choice, Zoom, says it’s figured out how to do end-to-end encryption sufficiently well to offer users a tech preview.

News of the trial comes after April 2020 awkwardness that followed the revelation that Zoom was fibbing about its service using end-to-end encryption.

As we [1]reported at the time, Zoom ‘fessed up but brushed aside criticism with a [2]semantic argument about what "end-to-end" means.

“When we use the phrase ‘End-to-end’ in our other literature, it is in reference to the connection being encrypted from Zoom end point to Zoom end point,” the company said. The commonly accepted definition of end-to-end encryption requires even the host of a service to be unable to access the content of a communication. As we [3]explained at the time, Zoom’s use of TLS and HTTPS meant it could intercept and decrypt video chats.

Come May, Zoom quickly [4]acquired secure messaging Keybase to give it the chops to built proper crypto.

To use it, customers must enable E2EE meetings at the account level and opt-in to E2EE on a per-meeting basis

Now Zoom reckons it has cracked the problem.

A Wednesday [5]post revealed: “starting next week, Zoom’s end-to-end encryption (E2EE) offering will be available as a technical preview, which means we’re proactively soliciting feedback from users for the first 30 days.”

Sharp-eyed Reg readers have doubtless noticed that Zoom has referred to “E2EE”, not just the “E2E” contraction of "end-to-end".

What’s up with that? The company has offered the following explanation:

“Zoom’s E2EE uses the same powerful GCM encryption you get now in a Zoom meeting. The only difference is where those encryption keys live.

In typical meetings, Zoom’s cloud generates encryption keys and distributes them to meeting participants using Zoom apps as they join. With Zoom’s E2EE, the meeting’s host generates encryption keys and uses public key cryptography to distribute these keys to the other meeting participants. Zoom’s servers become oblivious relays and never see the encryption keys required to decrypt the meeting contents.”

Don’t go thinking the preview means Zoom has squared away security, because the company says: “To use it, customers must enable E2EE meetings at the account level and opt-in to E2EE on a per-meeting basis.”

With users having to be constantly reminded to use non-rubbish passwords, not to click on phish or leak business data on personal devices, they’ll almost certainly choose E2EE every time without ever having to be prompted, right? ®

Get our [6]Tech Resources



[1] https://www.theregister.com/2020/04/01/zoom_spotlight/

[2] https://www.theregister.com/2020/04/03/dont_use_zoom_if_privacy/

[3] https://www.theregister.com/2020/04/01/zoom_spotlight/

[4] https://www.theregister.com/2020/05/07/zoom_buys_keybase/

[5] https://blog.zoom.us/zoom-rolling-out-end-to-end-encryption-offering/

[6] https://whitepapers.theregister.com/

The best software features ...

ComputerSays_noAbsolutelyNo

are those you manage your users to gaslight into believing that they are there.

"End-to-end encryption?" "Yeah, definitely!" followed by nearly in-audible small-print caveat.

This is end to end encryption

Dan 55

Except when it's not.

I'm sure it will be held up as an example of how to crack the problem by [1]the usual organsations .

[1] https://www.theregister.com/2020/10/11/international_statementon_end_to_end_encryption_and_public_safety/

David Brownell wrote:
> AMD told me I'd need an NDA to learn their workaround, and I've not
> pursued it. (Does anyone already know what kind of NDA they use?)

It varies depending on the info. They may well be able to sort out a sane
NDA with you. If they dont want to then I guess it would be best if the
ohci driver printing a message explaining the component has an undocumented
errata fix, gave AMD's phone number and refused to load..

- Alan Cox