Live data from Hacker News

Zoom sued for overstating, not disclosing privacy, security flaws

uk.reuters.com

11–20 of 166 posts

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#14
post #3

Will be interesting if Zoom is compelled to disclose their security architecture. On the same page can they be forced, in court, to make a statement on the interference by the Chinese government?

What interference by the Chinese government?

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#15
post #11

Note that the lawsuit is a class action for shareholders of Zoom stock. Filing: https://i.judge.sh/natural/Babs/1-main.pdf

Interesting that shareholders are the one to fill a lawsuit.

"Everything everywhere is securities fraud." [1] -- Matt Levine, Money Stuff

[1] https://www.bloomberg.com/opinion/articles/2019-06-26/everyt...

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#17

Blows my mind that a shareholder might have a cause of action for this. 1) Buy volatile stock with recent IPO 2) Sue them for their volatility 3) ?????

Shareholders can sue you for pretty much anything you do that damages your value that you didn't warn them about.

I.e. they put in their IPO prospectus that there might be a negative impact on their reputation from them having Chinese R&D, so they have a defense against that. They didn't put "We have misleading marketing materials that might become subject to widespread public attention" in there I think.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#18

Blows my mind that a shareholder might have a cause of action for this. 1) Buy volatile stock with recent IPO 2) Sue them for their volatility 3) ?????

> Zoom documentation claims that the app uses “AES-256” encryption for meetings where possible. However, we find that in each Zoom meeting, a single AES-128 key is used in ECB mode by all participants to encrypt and decrypt audio and video. The use of ECB mode is not recommended because patterns present in the plaintext are preserved during encryption. https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto...

You know, I had never considered being a shareholder and using said standing to sue a company into security best practices when they lie about it, considering regulation has failed to create the appropriate incentives.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#19

Earlier quoted context omitted.

> Zoom documentation claims that the app uses “AES-256” encryption for meetings where possible. However, we find that in each Zoom meeting, a single AES-128 key is used in ECB mode by all participants to encrypt and decrypt audio and video. The use of ECB mode is not recommended because patterns present in the plaintext are preserved during encryption. https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto...

You know, I had never considered being a shareholder and using said standing to sue a company into security best practices when they lie about it, considering regulation has failed to create the appropriate incentives.

Neither have I, but figured I’d link this since it is more than likely why they are suing
Post reply on HN