12 ms·
End-to-end encryption has been named as a required feature for telehealth in Australia. Interest in telehealth has gone from zero to infinity over the past two
by mabcat 6y ago
End-to-end encryption has been named as a required feature for telehealth in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks for obvious reasons. So I've been trying really hard to work out if Zoom is E2E, and reached the same conclusions as the article. First, it isn't, and second, Zoom are really going out of their way to obscure that fact.
It's great that The Intercept is taking a look at this, because it's absolutely beyond the capabilities of healthcare practitioners and the professional bodies to get to the bottom of. There's a ridiculous amount of confusion here, compounded by "you need to get the HIPAA version because HIPAA means privacy".
- PudgePacket 6y agoHopefully we've reconsidered the laws of mathematics in the last few years ... https://www.newscientist.com/article/2140747-laws-of-mathematics-dont-apply-here-says-australian-pm/ https://www.newscientist.com/article/2140747-laws-of-mathema... "“The laws of mathematics are very commendable, but the only law that applies in Australia is the law of Australia,” said Turnbull. Turnbull’s comments came as he proposed a new law to force tech companies to give security services access to encrypted messages." "The UK home secretary Amber Rudd has previously called encryption “completely unacceptable” and the UK prime minister Theresa May has said that the big internet companies give terrorists “safe spaces” to communicate." Going to have to get over this first :/
- ignoramous 6y ago> The UK home secretary Amber Rudd has previously called encryption "completely unacceptable" ... Theresa May has said that the big internet companies give terrorists "safe spaces" to communicate. Ironically, the UK government in fact uses Zoom for all its meetings depsite privacy and security implications. Saudi Arabia, take note. Ref: https://www.businessinsider.com/coronavirus-boris-johnson-zoom-private-government-meeting-2020-3?IR=T https://www.businessinsider.com/coronavirus-boris-johnson-zo...
- ragebol 6y agoSo with the right URL, you can tell them yourself!
- ragebol 6y agoActually: Just a screenshot tweeted by Boris Johnson himself should be enough (if he was faster to tweet it): https://twitter.com/BorisJohnson/status/1244985949534199808 https://twitter.com/BorisJohnson/status/1244985949534199808
- tonyztan 6y agoThat's terrible for national security. Zoom engineers are based in China: https://www.cnbc.com/2019/03/26/zoom-key-profit-driver-ahead-of-ipo-engineers-in-china.html https://www.cnbc.com/2019/03/26/zoom-key-profit-driver-ahead...
- davedx 6y agoComponents of the GB 5g network are also being outsourced to China. Some of the ruling party's MP's are not happy about it.
- bogle 6y agoThe noisy back-benchers are a little silly as all of Huawei's work is scrutenised: https://www.wired.co.uk/article/huawei-gchq-security-evaluation-uk https://www.wired.co.uk/article/huawei-gchq-security-evaluat... Of course, in the UK, calling Tory back-benchers "a little silly" is an understatement.
- davedx 6y agoAre the NATO countries refusing to use Huawei's work for their 5g networks also all "a little silly"? What if Huawei was Russian, would it still be "a little silly"?
- krageon 6y ago
- cyphar 6y agoIt goes far further than stupid comments by our (former) prime minister. The current legislation (passed in 2018) allows the government to force the installation of backdoors through a process that doesn't have any judicial overview or substantial public scrutiny whatsoever.
- maze-le 6y agoNumber one reason we dropped JIRA.
- sebiol 6y agoOut of curiosity, what did you switch to?
- 101404 6y agoWhy? How is it related to Jira?
- lvh 6y agoAtlassian is an Australian company, headquartered in Sydney, though the current plc is legally in the UK. (I have no idea if that means they're bound by said backdoor law.)
- cyphar 6y agoThey are because they provide services to Australians and have an Australian subsidiary -- just as anyone in Australia must comply with a warrant or any other lawful request by law enforcement.
- marcus_holmes 6y agoIf they employ a single Aussie developer, or have foreign developers on Australian soil, the government can coerce those developer to insert anything they like.
- Veedrac 6y agoI realize HN will think much the same of it either way, but AFAICT that second quote of yours is a lie; she called WhatsApp's encryption unacceptable, not encryption in general.
- kevin_thibedeau 6y ago"Encryption we can't backdoor isn't acceptable"
- lozf 6y ago> ... the [former] UK prime minister Theresa May has said that the big internet companies give terrorists “safe spaces” to communicate. Yes, IIRC she also said wanted to enter a dialogue about this "with the people that know the right hashtags"!
- kristianc 6y agoThat was Amber Rudd.
- rurp 6y ago> The laws of mathematics are very commendable, but the only law that applies in Australia is the law of Australia,” said Turnbull. Heh, that reminds me of the Indiana Pi Bill[0], where the state tried to legislate the value of pi to be 3.2. [0]https://en.wikipedia.org/wiki/Indiana_Pi_Bill https://en.wikipedia.org/wiki/Indiana_Pi_Bill
- BrandiATMuhkuh 6y agoNow I know why it was the only video conferencing service that worked in Dubai. Others, like meet, WhatsApp - video are not working for censorship reasons.
- bad_user 6y agoI'm pretty sure that Google Meet isn't end-to-end encrypted either. Nothing that Google does is. WhatsApp does claim that videos are end-to-end encrypted as well, although given Facebook announced they'll implement client-side agents for processing user data and given its proprietary nature, I avoid WhatsApp for anything very sensitive as well.
- Adverblessly 6y ago> I'm pretty sure that Google Meet isn't end-to-end encrypted either. Nothing that Google does is. To the best of my understanding, they say that it is https://support.google.com/a/answer/7582940?hl=en https://support.google.com/a/answer/7582940?hl=en EDIT: On rereading they actually just say that it is encrypted, not neccesarily end-to-end encrypted.
- viraptor 6y agoGoogle provides close captioning for meet calls. That means it's not E2E. Also pretty much no service can provide multi-party video call with adaptive quality without completely destroying your bandwidth.
- relaunched 6y agoI'm interested in knowing more about why closed captions would imply not end-to-end encrypted. Wouldn't it be possible to build a model and distribute the model with the client-side application, and run it at the edge?
- krageon 6y ago
- riedel 6y agoActually zoom despite its privacy concerns is on the whitelist for telemedical application by the insurers in Germany, so I think they understand how to play the game...
- killerpopiller 6y agoreally? Psychotherapists are required to use one of the certified providers to be able to bill for tele sessions. https://www.kbv.de/media/sp/Liste_zertifizierte_Videodienstanbieter.pdf https://www.kbv.de/media/sp/Liste_zertifizierte_Videodiensta...
- SkyPuncher 6y agoHipaa has additional restriction/controls for psychotherapy notes as they are considered highly sensitive. I'd expect this is the same line of thinking in Germany. Discussing your heart disease or skin condition is sensitive, but it's not as sensitive as discussing deeply personal thoughts or inner monologues.
- germanier 6y agoIt's not (see the list in the sibling comment). To get certified you need to transport the video/audio stream peer-to-peer between the clients only and end-to-end encrypted, see § 5 of the agreement https://www.kbv.de/media/sp/Anlage_31b_Videosprechstunde.pdf https://www.kbv.de/media/sp/Anlage_31b_Videosprechstunde.pdf The regulatory bodies took some time to understand the issues and this is why it took so long until it arrived at all. Private consultations not billed through public insurance is not quite as regulated though.
- riedel 6y agoThanks for pointing out. I thought the false claim of E2EE was exactly the reason. I got the false (?) info from my neighbor working for a large AT provider. They are making money exactly with such regulational requirements, so I am really puzzled on the actual state of affairs.
- bad_user 6y agoEnd-to-end encryption is hard to implement, might cost more processing or bandwidth or storage (depending on the product) and does not yield benefits for companies interested in processing user data. If it's not clearly advertised on the front page, _emphasized_ and not a foot note, then it's NOT e2e encrypted. Example: https://signal.org https://signal.org
- tantalor 6y ago> hard to implement https://en.wikipedia.org/wiki/One-time_pad https://en.wikipedia.org/wiki/One-time_pad
- mjlee 6y agoIt's not clear from the context if you mean to say that's simple or hard with that link. A OTP might be mathematically simple, but logistically it's very hard - you have to safely distribute the key and that key must be at least as long as the message you're passing.
- krageon 6y agoGiven that Signal doesn't have reproducible builds and may therefore have absolutely anything inside of it's distributed binaries, I'm not sure if this is meant to be a good or a bad example.
- pthatcherg 6y agoThere are 2 different kinds of video calls: 1:1 and group calls. For 1:1 calls, e2e encryption incurs negligible processing and bandwidth. Do you worry about the processing and bandwidth increase when using HTTPS/SSL? Probably not. Same goes for 1:1 calls. For group calls, it depends on how it's implemented, but many group calls are implemented using what's called a Selective Forwarding Unit (SFU). One benefit of SFUs is that they take much less processing for the server than the other kinds (where the video is re-encoded by the server). For those types of group calls, e2e encryption can be implemented with negligible increases to processing and bandwidth. However, you are correct that it is harder to implement correctly. And it does prevent certain features to be added to the product, such as recording and server-based processing of information (for example, meeting transcriptions). (I used to work at Google on WebRTC, Duo, and Hangouts, but now work on video calling at Signal).
- anitil 6y agoDo you have any opinions on Pexip Infinity? Would Zoom be a better replacement if it did have E2E?
- anotherevan 6y agoI have a telehealth appointment (in Australia) this week, and they are using https://doxy.me/ https://doxy.me/ Anybody know much about that one?
- Krasnol 6y ago> LD video TIL: there is a quality below SD.
- bogle 6y agoHow is a doctor supposed to do a video consultation if the blotches on your bum, purely for example, are all blurry because the definition is less than HD?
- viraptor 6y agoYou get most of the consultation with history, described symptoms, etc. handled over telehealth and a quick follow-up in person if you require a physical examination. The process has to cover people who call from a landline as well.
- catalogia 6y agoPerhaps the system could allow users to send high resolution still photographs alongside the low-quality video stream.
- jermaustin1 6y agoMy wife uses this when talking to clients (shes a psychologist), but she has the upgraded version that is HD. If your doctor is on the free plan, it is highly pixelated, and because they offer a hippa-compliant free plan, most providers are on the free plan. They had a 3-4 hour outage recently. Assuming because of the number of new free users.
- SamuelAdams 6y agoHold on, E2E encryption is now required for telehealth in Australia, yet the Australian government passed laws that required LEO's to have access to E2E encrypted data [1]? How are tech companies supposed to comply with that? [1]: https://www.wired.com/story/australia-encryption-law-global-impact/ https://www.wired.com/story/australia-encryption-law-global-...
- viraptor 6y agoIt's not incompatible technically. The law requires access on request, not all the time. If LEO doesn't ask, it may be still E2E.
- zo1 6y agoThat adds an even bigger layer of complexity for people to understand. The whole point of E2E was so that only the two ends could decrypt the data being transferred. If we now add "except if government agency requests it" then we're hijacking the term and making it no more meaningful that saying "yeah our app has encryption".
- viraptor 6y agoI'm not trying to hijack the term. Once LEO puts in the request the system stops being E2E - that's true. It would be good if this wasn't possible, but for that we need the whole stack of: open protocol, opensource implementation, signed verified release, and people keen to verify fingerprints. And if we're pedantic, also a verifiable execution environment.
- Zenbit_UX 6y agoA requirement for e2e is that the company doesn't hold the keys, otherwise it's just regular transport encryption + a promise that they'll never peak at the your data, even though they can. So yes, it's very much incompatible technically.
- bscphil 6y ago
- mox1 6y agoHow do you E2E encrypt a video stream and still allow adaptive bit rates? If the server can't read (decrypt) the video, it cannot re-encode the video at different bitrates for different clients. Or the Zoom client has to encode multiple steams and upload them locally...or it just downgrades to the bitrate of the slowest client... You get shitty video and E2E encryption or good video and transport encryption.
- gnud 6y agoSure. Then maybe don't claim that the service is e2e-encrypted?
- gruez 6y agoProbably something like this: https://en.wikipedia.org/wiki/Bitrate_peeling https://en.wikipedia.org/wiki/Bitrate_peeling
- bscphil 6y agoI'd probably have each client encode one high quality stream that's targeted to be accessible to 90+% of clients, and a very low quality stream that's 5% of the bitrate of the high quality one. Low encoding complexity and adds a negligible amount to your upload bandwidth requirements. (Obviously if a client can't meet the upload quota for the highest quality, you max out at whatever they can do.)
- Ididntdothis 6y agoI used to work in video and if I remember correctly there were I, P and B frames. You need I and P but the B frames are optional. So if some meta data is unencrypted the server can tell which packets are B frames and decide not to send them to slow clients. The actual data is still encrypted.
- pthatcherg 6y agoFirst of all, there are 2 different kinds of video calls: 1:1 and group calls. For 1:1 calls, e2e encryption doesn't cause any problem at all. For group calls, it depends on how it's implemented, but many group calls are implemented using what's called a Selective Forwarding Unit (SFU) and the sending clients send multiple resolutions (either independent, called "Simulcast" or dependent, called "SVC"). In that case, the adaptation is done by the server in selecting which resolution to forward at any given time. This is fairly common practice in the industry. For example: https://github.com/jitsi/jitsi-videobridge https://github.com/jitsi/jitsi-videobridge and https://tools.ietf.org/html/draft-aboba-avtcore-sfu-rtp-00 https://tools.ietf.org/html/draft-aboba-avtcore-sfu-rtp-00 and https://www.w3.org/TR/webrtc-svc/ https://www.w3.org/TR/webrtc-svc/. For those types of group calls, the server only needs to know the sizes of the various streams and which packet is for what stream. It does not need to see the decrypted media, so one can implement e2e encryption for such types of group calls. This is less common in the industry, but is possible. For example: https://support.google.com/duo/answer/9280240?hl=en https://support.google.com/duo/answer/9280240?hl=en (I used to work at Google on WebRTC, Duo, and Hangouts, but now work on video calling at Signal).
- gumby 6y agoI'm concerned that the exigencies of pandemic will cause people to get used to a system that tosses privacy out the door. Not sure how to stop this. A couple of nits to pick: > in Australia. Interest in telehealth has gone from zero to infinity over the past two weeks Slight exaggeration; wouldn't you call the royal flying doctors service telehealth? And HIPPA is a US law.
- eskaytwo 6y agoThe key point is that a video consult with a doctor is now (as of last week) available to most of the population, including those in the city, and can be claimed on Medicare. That’s a huge change from previously where it only applied in specific scenarios. I’m sure the RFDS did some video/phone consults but their patients are literally remote - some hundreds of kilometres from the next property.
- cbsmith 6y agoI'm not sure that you can really say "a system that tosses privacy out the door". There's lots of privacy protections in place. Sure, it requires trustworthy providers, but that's largely true of a non-open source E2E solution as well. Nit: HIPPA is not a US law, but HIPAA is. ;-)
- gumby 6y ago> Nit: HIPPA is not a US law, but HIPAA is. ;-) Touché! I'm even HIPAA trained and have to deal with it all the time yet I chronically make that error. I can't even see it when proof reading. Ouch.
- SkyPuncher 6y agoJust an FYI, two weeks ago, CMS announced it would be suspending enforcement of telehealth tools used in good faith during the COVID pandemic. [0] Basically, if you are a family doc that's been thrown into the telehealth ringer, you can get started with everyday tools for video chat, like Facetime, Google Hangouts, Skype, etc - regardless of that tool's Hipaa compliance. Overtime I do expect they'll want to see providers transition to compliant solutions, but they understand thousands of doctors, some of whom have never delivered telemedicine, can't simply audit and on-boarding a new provider overnight. [0] https://www.cms.gov/newsroom/fact-sheets/medicare-telemedicine-health-care-provider-fact-sheet https://www.cms.gov/newsroom/fact-sheets/medicare-telemedici...
- SamuelAdams 6y agoNote this only applies to the USA, other countries might not have loosened their regulations quite yet.
- rubatuga 6y agoExtremely loose in Canada as well. Facetime, skype, phone calls are all fair game currently
- marcinzm 6y agoAs a note, HIPAA does not require end-to-end encryption as long as you have a BAA with the provider. Zoom has an option for a BAA starting at $200/month. edit: Server-client communication does need to be encrypted which zoom does.
- biggc 6y agoWhat is a BAA?
- lvh 6y agoA BAA is a Business Associate Agreement. It's a standard HIPAA document where an entity with PHI (typically a Covered Entity, which is an entity specifically mentioned by HIPAA, such as e.g. a healthcare facility) effectively puts a vendor on notice: we may stuff PHI in your service, you agree to abide by this set of rules and regulations. A big one is that the vendor agrees to disclose when they've been breached, and the timeline on which that happens. Even though a lot of online sources suggest BAAs are only for Covered Entities, that's not strictly speaking true. The standard form document doesn't require the buyer to certify they're a CE. It makes tons of sense for vendors of CEs, themselves bound by BAAs, to bind _their_ vendors to BAAs! If there's a decent chance your customers put PHI in your service, there's a decent chance they put PHI in your support system, and they don't really care if your support system is something in-house or Zendesk when that happens. There's also a good chance that PHI might end up in your logging system, and from there in your Slack instance, and... before you know it everyone's signed a BAA with everyone. The life-hack consequence for that is that you can just collect BAAs from anyone who will sign them and now you have disclosure timeline guarantees.
- cbsmith 6y agoI don't know that Zoom is really going out of its way to obscure that it is not E2E. I never for a second thought they were doing E2E when I enabled the encryption. It was very clear from how the features was described that you got TLS to Zoom's servers, not E2E.
- thoraway1010 6y agoRight - if you have used signal - I have - zoom is obviously not that. The pain to do call mixing, call recording, join a call late and do playback, join a call at all - does E2E even work in telehealth? I do virtual visits in the US and it doesn't look at all E2E to me.
- pthatcherg 6y agoAs far as I know, there's nothing special about telehealth that prevents it from using e2e encryption.
- cbsmith 6y agoYou mean, other than requirements that service provides track & preserve an audit trail for all data. ;-) I believe this is a similar problem with financial trading systems with ETS.
- thoraway1010 6y agoThe telehealth platforms I see are terminating through the health provider itself. It does the call setup, conference setup if needed, waiting room for prior call to end, if you send a photo it can be saved to your record etc. If this is e2e to the physicians home, how does the telehealth system do all these add in functions? At least in the US, the requirement have been understand to use secure transport everywhere. Folks keep on saying HIPPA requires e2e but I've literally not seen anything that looks like that out there in the actual market for this - the enterprise paying the big bucks usually wants features that are incompatible with e2e as far as I can tell.
- berkes 6y ago
- messo 6y agoFor any health professionals out there looking for a good video solution tailored for doctors and psychologists; check out Confrere. It's a Norwegian company that has built it's service on top of the webRTC-protocol. I have helped several Norwegian doctors offices to get up and running the last few weeks, and they love it!
- jiveturkey 6y agoI didn't investigate this requirement, but it's probably insufficiently thought out. Presumably you need E2E encryption so that the SP can't intercept (either willfully, compelled, or as a result of compromise) en masse. If that's the case, then you also need to have a way to verify keys of both parties, and you need a way to do that for group communications. This is hard. So even if Zoom is E2E, this is checkbox compliance. (if my assumptions are correct for the reasons behind it)