{"id":6829,"date":"2018-05-14T06:39:54","date_gmt":"2018-05-14T13:39:54","guid":{"rendered":"https:\/\/cldc.org\/?post_type=organizing_resources&#038;p=6829"},"modified":"2022-04-20T11:14:52","modified_gmt":"2022-04-20T18:14:52","slug":"conf-calls","status":"publish","type":"post","link":"https:\/\/cldc.org\/hi\/conf-calls\/","title":{"rendered":"Choose Wire for conference calls"},"content":{"rendered":"<p>Here&#8217;s <a href=\"https:\/\/cldc.org\/hi\/trustworthy-tech\/\">what we look for in trustworthy technology<\/a>: end-to-end encryption, open source code, and cross-platform support.\u00a0 Here we dive into the importance of end-to-end encryption and why we recommend groups <a href=\"https:\/\/wire.com\/en\/download\/\">use<\/a> the <a href=\"https:\/\/github.com\/wireapp\/wire\/projects\">open-source<\/a>, <a href=\"https:\/\/wire-docs.wire.com\/download\/Wire+Security+Whitepaper.pdf\">end-to-end encrypted<\/a>, and <a href=\"https:\/\/medium.com\/@wireapp\/making-your-conversations-secure-dab207ab77fd\">cross-platform<\/a> app <a href=\"https:\/\/wire.com\/en\/security\/\">Wire<\/a> instead of the proprietary and probably-not really end-to-end encrypted Zoom whenever possible for conference calls (especially when privacy matters).\u00a0 <a href=\"https:\/\/www.signal.org\">Signal<\/a> is also really good too, but doesn&#8217;t do conference calling.<\/p>\n<p>We still rely on Zoom for conference calls, but we now consider them to be more or less public meetings rather than a secure channel.\u00a0 Why?<\/p>\n<p>Let&#8217;s start by clarifying the phrase &#8220;End-To-End Encryption&#8221;\u2014this is a technical term meaning a message is scrambled so that it can only be read by the endpoints of a conversation.\u00a0 But here&#8217;s where confusion comes in\u2014what are the endpoints?\u00a0 Are they just you and your friends?\u00a0 Or is the server an endpoint too? It depends on the application.\u00a0 As an example, <a href=\"https:\/\/cldc.org\/hi\/layered-encryption\/\">HTTPS<\/a> (which secures communications between you and the servers hosting the webpages you visit) is encrypted so that only you and the server can decrypt the content of the webpages.\u00a0 <a href=\"https:\/\/cldc.org\/hi\/signal-activist-best-practices\/\">Signal<\/a>, a secure instant messaging app tied to your smart phone, encrypts messages so that only you and your friend that you are messaging can read your messages.\u00a0 In both cases, only the people or entities that you could imagine <strong>needing<\/strong> to know the information are able to decrypt encrypted information.\u00a0 This is the heart of end-to-end encryption.\u00a0 Please <a href=\"https:\/\/cldc.org\/hi\/direct-encryption\/\">check out our post on Direct Encryption<\/a> for more details on end-to-end encryption.<\/p>\n<p>We are concerned that the fancy webconferencing app <a href=\"https:\/\/support.zoom.us\/hc\/en-us\/articles\/201362723-End-to-end-Encryption\">Zoom<\/a> could be <a href=\"https:\/\/web.archive.org\/web\/20170301141001\/https:\/\/support.zoom.us\/hc\/en-us\/articles\/201362723-End-to-end-Encryption\">exploiting this confusion to exaggerate the security of their platform<\/a>.\u00a0 The best case scenario is that Zoom does <a href=\"https:\/\/cldc.org\/hi\/protonmail\/\">what ProtonMail does<\/a>: manage the keys needed for encryption for you.\u00a0 The reality is probably worse, since <a href=\"https:\/\/d24cgw3uvb9a9h.cloudfront.net\/static\/47884\/doc\/Zoom-Security-White-Paper.pdf\">the few technical details Zoom provides<\/a> do not describe enough technical components to actually achieve end-to-end encryption.\u00a0 Their own web portal&#8217;s menu indicates that they are not providing end-to-end encryption, but in-transit encryption, that is, encrypting messages between the participants in a conversation and Zoom&#8217;s servers:<img decoding=\"async\" class=\"alignright wp-image-6889 size-full\" src=\"https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/Enable-End-to-End-Chat-Encryption.png\" alt=\"\" width=\"866\" height=\"116\" srcset=\"https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/Enable-End-to-End-Chat-Encryption.png 866w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/Enable-End-to-End-Chat-Encryption-500x67.png 500w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/Enable-End-to-End-Chat-Encryption-700x94.png 700w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/Enable-End-to-End-Chat-Encryption-200x27.png 200w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/Enable-End-to-End-Chat-Encryption-300x40.png 300w, https:\/\/cldc.org\/wp-content\/uploads\/2018\/02\/Enable-End-to-End-Chat-Encryption-768x103.png 768w\" sizes=\"(max-width: 866px) 100vw, 866px\" \/><\/p>\n<p>That is, is appears Zoom considers their own servers an &#8220;end&#8221;.\u00a0 This language is repeated in their security white paper.\u00a0 And because the source-code for Zoom is not public, there is no way to verify any of their claims.\u00a0 Even if we give Zoom the benefit of the doubt, and have faith that they are providing end-to-end encryption, the existence of such a toggle in a web menu gives the web server\u2014that is, Zoom\u2014the ability to flip this switch without your knowing.\u00a0 We&#8217;re not saying we know for a fact that Zoom would fail to play nice and violate your privacy.\u00a0 But we are saying that your privacy relies entirely on Zoom to play nice.\u00a0 Most importantly: <strong>ask yourselves what Zoom would do if asked <a href=\"https:\/\/web.archive.org\/web\/20180130132524\/https:\/\/zoom.us\/privacy\">to meet national security or law enforcement requirements<\/a>?<\/strong><\/p>\n<p>The world of digital security changes rapidly.\u00a0 We started using Zoom last year to do remote trainings and conference calls when it looked like there was no reliable, secure option for group calls.\u00a0 Zoom works really well in terms of call quality and participant management features, but the reality is that there are better security-focused options now, and we want to direct people toward using these\u2014<a href=\"https:\/\/signal.org\">Signal<\/a> and <a href=\"https:\/\/wire.com\/en\/download\/\">Wire<\/a> are our top choices\u2014whenever possible.<\/p>\n<p>Zoom isn&#8217;t the worst in terms of security (not as bad as cellphones or some random free conference call service), and Wire can&#8217;t do large conference calls, so there are still some use cases for it.\u00a0 Instead of giving up on security, it can help to think of the various options as tiers of encryption:<\/p>\n<p><strong>Tier 1 (top shelf, best possible security)<\/strong> uses truly end-to-end, <strong><a href=\"https:\/\/cldc.org\/hi\/direct-encryption\/\">Direct Encryption<\/a>.<\/strong>\u00a0 Private conversations can only be eavesdropped on by breaking into one of the participants&#8217; devices.\u00a0 Wire and Signal meet this standard, and are also open source, so their security claims can be thoroughly verified.\u00a0 If Zoom does this for 1-on-1 calls, as they claim, they could switch it off anytime&#8211;it&#8217;s a setting that zoom customers\/administrators can change via the administrator panel at zoom.us\u2014so a zoom employee could do the same thing.\u00a0 This is a pretty terrible implementation of end-to-end encryption, so we don&#8217;t count it as Direct Encryption, where\u00a0 *only* you and your friends control encryption keys.<\/p>\n<p><strong>Tier 2 (less than ideal but still hard for some adversaries to break)<\/strong> is the sort of &#8220;in transit&#8221; encryption Zoom uses for group calls where comms are encrypted from participants&#8217; devices to Zoom&#8217;s server, mixed, encrypted again then sent out to all participants&#8217; devices.\u00a0 Breaking this would likely require Zoom&#8217;s active co-operation, most likely obtained via a warrant or National Security Letter.<\/p>\n<p><strong>Tier 3 (not at all good, open to multiple adversaries including private security)<\/strong> is plain old cell phone encryption\u2014governments can relatively easily ask cell phone companies for access to their networks (and to break encryption done by the cell phone company)\u2014worse yet, cell site simulators (&#8220;Stingrays&#8221;) can force phone network security down from 4G to 3G, weakening encryption enough for anyone with access to a Stingray to break (local cops, very probably corporate security).<\/p>\n<p>This is why CLDC is recommending Wire&#8211;it&#8217;s open source, does end-to-end encrypted 1-on-1 video, and allows up to 10-people in end-to-end voice conference calls. Get it <a href=\"https:\/\/wire.com\/en\/download\/\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/p>\n<p>We&#8217;re <a href=\"https:\/\/cldc.org\/hi\/about\/contact\/\">happy to help you and your org get set up with Wire and other trustworthy tech<\/a>, and in the meantime there&#8217;s also a nice <a href=\"https:\/\/medium.com\/@mshelton\/wire-for-beginners-8ee6caef49cb\">beginners guide to Wire<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>Here&#8217;s what we look for in trustworthy technology: end-to-end encryption, open source code, and cross-platform support.  <\/p>","protected":false},"author":1,"featured_media":7449,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[25],"tags":[558,226,238,179,225,265,552,557],"class_list":["post-6829","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles","tag-digital","tag-digital-security-tools","tag-encryption","tag-security","tag-signal","tag-trusted-tech","tag-wire","tag-zoom"],"acf":[],"_links":{"self":[{"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/posts\/6829","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/comments?post=6829"}],"version-history":[{"count":0,"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/posts\/6829\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/media\/7449"}],"wp:attachment":[{"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/media?parent=6829"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/categories?post=6829"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cldc.org\/hi\/wp-json\/wp\/v2\/tags?post=6829"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}