Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Will be interesting if Zoom is compelled to disclose their security architecture. On the same page can they be forced, in court, to make a statement on the interference by the Chinese government?


If the lawsuit gets past the pleadings stage, then relevant information would be subject to discovery. So the plaintiffs would be able to get and use that info in court, but Zoom would probably ask the judge for a protective order so that it doesn’t become public.


Is having keys compelled a surprise?

Chinese servers, operating in China legally, will usually have this issue.

It's serious yes, but I'm confused if it only applied to users in China?

I'm more concerned about the technical issues TBH - I assume most software sanctioned in China had to turn over keys.


Seeing as encryption is illegal in China, I don't think they will need to give up any keys.


>Seeing as encryption is illegal in China

Source for this? That would make any https site in china illegal.


I'm sorry, I was wrong. It requires a license from the State Encryption Management Commission: http://www.cryptolaw.org/cls2.htm#prc

I am not a lawyer nor a cryptography expert who can advise whether licenses are granted easily or whether they are revoked if you fall out of favour.


Not an expert, but I searched and found this link which seems to explain it well:

https://www.freshfields.com/en-us/our-thinking/campaigns/dig...

tl;dr: encryption is not completely illegal, but it sounds like it's pretty tightly controlled.


I didn't think they'd be foolish enough to completely ban it.

They're not comically evil, they just have certain incentives.

Key escrow meets those goals.


What interference by the Chinese government?


on the latter issue: a company can not speak for each individual employee.


I don't get why this is downvoted? Maybe I was too concise. Then: even if the company may say what they do, the company cannot check and tell what each employee does. This doesn't have to be a malicious intent of the employee, but it can be.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: