Stories
Slash Boxes
Comments

SoylentNews is people

posted by martyb on Thursday April 02 2020, @11:09PM   Printer-friendly
from the too-much-privacy dept.

Elon Musk's SpaceX bans Zoom over privacy concerns-memo

[...] In an email dated March 28, SpaceX told employees that all access to Zoom had been disabled with immediate effect.

"We understand that many of us were using this tool for conferences and meeting support," SpaceX said in the message. "Please use email, text or phone as alternate means of communication."

[...] NASA, one of SpaceX's biggest customers, also prohibits its employees from using Zoom, said Stephanie Schierholz, a spokeswoman for the U.S. space agency.

The Federal Bureau of Investigation's Boston office on Monday issued a warning about Zoom, telling users not to make meetings on the site public or share links widely after it received two reports of unidentified individuals invading school sessions, a phenomenon known as "zoombombing."

Also consider that one way to claim to have "end to end encryption" is to simply re-define the term. Zoom Meetings Aren't End-to-End Encrypted, Despite Misleading Marketing:

Zoom, the video conferencing service whose use has spiked amid the Covid-19 pandemic, claims to implement end-to-end encryption, widely understood as the most private form of internet communication, protecting conversations from all outside parties. In fact, Zoom is using its own definition of the term, one that lets Zoom itself access unencrypted video and audio from meetings.

With millions of people around the world working from home in order to slow the spread of the coronavirus, business is booming for Zoom, bringing more attention on the company and its privacy practices, including a policy, later updated, that seemed to give the company permission to mine messages and files shared during meetings for the purpose of ad targeting.

Still, Zoom offers reliability, ease of use, and at least one very important security assurance: As long as you make sure everyone in a Zoom meeting connects using "computer audio" instead of calling in on a phone, the meeting is secured with end-to-end encryption, at least according to Zoom's website, its security white paper, and the user interface within the app. But despite this misleading marketing, the service actually does not support end-to-end encryption for video and audio content, at least as the term is commonly understood.

[...] Matthew Green, a cryptographer and computer science professor at Johns Hopkins University, points out that group video conferencing is difficult to encrypt end to end. That's because the service provider needs to detect who is talking to act like a switchboard, which allows it to only send a high-resolution videostream from the person who is talking at the moment, or who a user selects to the rest of the group, and to send low-resolution videostreams of other participants. This type of optimization is much easier if the service provider can see everything because it's unencrypted.

[...] "They're a little bit fuzzy about what's end-to-end encrypted," Green said of Zoom. "I think they're doing this in a slightly dishonest way. It would be nice if they just came clean."

The only feature of Zoom that does appear to be end-to-end encrypted is in-meeting text chat.

Be aware, too, of the potential for "zoombombing"; here is a selection of articles: 'Zoombombing': When Video Conferences Go Wrong, A Zoom Meeting For Women Of Color Was Hijacked By Trolls Shouting The N-Word , and Beware of 'ZoomBombing': screensharing filth to video calls.

Previously:
(2020-03-28) Now That Everyone's Using Zoom, Here Are Some Privacy Risks You Need to Watch Out For
(2020-03-27) School Quits Video Calls After Naked Man ‘Guessed’ the Meeting Link
(2020-03-14) Student Privacy Laws Still Apply if Coronavirus Just Closed Your School


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1)
  • (Score: 3, Interesting) by takyon on Thursday April 02 2020, @11:12PM (1 child)

    by takyon (881) <takyonNO@SPAMsoylentnews.org> on Thursday April 02 2020, @11:12PM (#978480) Journal

    FBI warns video calls are getting hijacked. It's called 'Zoombombing' [cnn.com]

    Never heard of it before today, and it's a top headline on Google News.

    --
    [SIG] 10/28/2017: Soylent Upgrade v14 [soylentnews.org]
  • (Score: 1, Insightful) by Anonymous Coward on Thursday April 02 2020, @11:31PM (2 children)

    by Anonymous Coward on Thursday April 02 2020, @11:31PM (#978486)

    My elderly mother wants to set up Zoom with me and my siblings. She already uses it to talk to her siblings. I'm trying to figure out the best way for me to use it with minimal footprint and impact on me. Perhaps set up a throwaway email address for starters, but what is a good way to sandbox the app so that I can use it?

    • (Score: 1, Informative) by Anonymous Coward on Friday April 03 2020, @12:24AM

      by Anonymous Coward on Friday April 03 2020, @12:24AM (#978493)

      Run in a VM.

    • (Score: 0) by Anonymous Coward on Sunday April 05 2020, @03:32AM

      by Anonymous Coward on Sunday April 05 2020, @03:32AM (#979266)

      Run off of a Linux live read-only USB flash mass storage device (USB key)

  • (Score: 5, Insightful) by Snotnose on Friday April 03 2020, @12:07AM (1 child)

    by Snotnose (1623) on Friday April 03 2020, @12:07AM (#978489)

    IMHO, if you advertise end to end encryption, then it turns out you're faking it, then, well. Not only should your app be shunned by everyone, but the Cxx suite that carried on that lie should be held personally responsible.

    --
    When the dust settled America realized it was saved by a porn star.
    • (Score: 2) by DannyB on Friday April 03 2020, @04:56PM

      by DannyB (5839) Subscriber Badge on Friday April 03 2020, @04:56PM (#978793) Journal

      c'mon mcfly the jits will never know!

      --
      The lower I set my standards the more accomplishments I have.
  • (Score: 5, Informative) by richtopia on Friday April 03 2020, @12:13AM (3 children)

    by richtopia (3160) on Friday April 03 2020, @12:13AM (#978490) Homepage Journal

    I have an obsessive compulsion to promote open source software. Jitsi advertises E2E encryption by default on their Jitsi Meet service.

    https://jitsi.org/jitsi-meet/ [jitsi.org]

    • (Score: 1, Interesting) by Anonymous Coward on Friday April 03 2020, @01:16AM

      by Anonymous Coward on Friday April 03 2020, @01:16AM (#978515)

      Thank you very much for this! Now I have to figure out how to get my other family members on it. Can it all be done from the browser, or do you need people to install the apps on their phones?

    • (Score: 4, Informative) by Anonymous Coward on Friday April 03 2020, @04:57AM

      by Anonymous Coward on Friday April 03 2020, @04:57AM (#978591)

      When the 3rd connects to a room the peer-to-peer (thus end-to-end encrypted) connection is switched over to the jitsi videobridge, which has unencrypted access to all streams.
      This is all on their site/documentation.

      The cool thing though is that you can self host the server and it doesn't send your data to facebook and friends.

    • (Score: 2) by AnonTechie on Friday April 03 2020, @10:14AM

      by AnonTechie (2275) on Friday April 03 2020, @10:14AM (#978651) Journal

      Another encrypted open-source chat application:

      Retroshare establish encrypted connections between you and your friends to create a network of computers, and provides various distributed services on top of it: forums, channels, chat, mail... Retroshare is fully decentralized, and designed to provide maximum security and anonymity to its users beyond direct friends. Retroshare is entirely free and open-source software. It is available on Android, Linux, MacOS and Windows. There are no hidden costs, no ads and no terms of service.

      https://retroshare.cc [retroshare.cc]

      --
      Albert Einstein - "Only two things are infinite, the universe and human stupidity, and I'm not sure about the former."
  • (Score: -1, Offtopic) by Anonymous Coward on Friday April 03 2020, @12:28AM (2 children)

    by Anonymous Coward on Friday April 03 2020, @12:28AM (#978496)

    virus shit. Fuck the virus and fuck the news, too. Day in, day out, it's the same virus blahblah 24/7. Enough of this bullshit.

    • (Score: 0, Interesting) by Anonymous Coward on Friday April 03 2020, @12:41AM (1 child)

      by Anonymous Coward on Friday April 03 2020, @12:41AM (#978502)

      If you're cracking now, good luck in six months. I know it hurts to have your short American attention span tested... if it's too hard, just go outside and lick some doorknobs.

      • (Score: -1, Offtopic) by Anonymous Coward on Friday April 03 2020, @01:08AM

        by Anonymous Coward on Friday April 03 2020, @01:08AM (#978511)

        No thanks, that's what you Eurotards [dw.com] like to do [metro.co.uk].

(1)