Live data from Hacker News

Zoom sued for overstating, not disclosing privacy, security flaws

uk.reuters.com

31–40 of 166 posts

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#31

Earlier quoted context omitted.

> Zoom documentation claims that the app uses “AES-256” encryption for meetings where possible. However, we find that in each Zoom meeting, a single AES-128 key is used in ECB mode by all participants to encrypt and decrypt audio and video. The use of ECB mode is not recommended because patterns present in the plaintext are preserved during encryption. https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto...

Oh wow. ECB mode? That's horrifying.

For those that don't know much about encryption, here is an example image for why ECB mode is trash: https://i.stack.imgur.com/bXAUL.png

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#32
I don't think this is likely to succeed -- Zoom can argue that the stock price has gone down because of "Zoombombing" and security/privacy concerns that have nothing to do with exact details of what was disclosed in privacy/security documents, which barely anyone reads anyways.

Also, it's awfully hard to argue losing shareholder value when the stock has still more than doubled in the end -- Zoom can easily make the plausible-enough case that it made the right tradeoffs in the end for shareholder value that allowed it to scale. (I'm not saying that's true, just that it's plausible.)

Could it be fined by the SEC for misstating key details in their public filing? Maybe, although these are tiny details. But a class-action suit by shareholders? This feels like a stunt to me. Also, since a suit by shareholders could depress the stock price further, this feels like a short-seller trying to profit, no?

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#33

Am i the only one struggling to use Zoom properly since they introduced the latest security changes? The slack integration (write /zoom to start a meeting) was working ok-ish even though we always had problem with the meeting not starting unless the host of the meeting was logged in (gosh...why so complicated?) Now they added this waiting room, there is no sound notification to let you know that people are waiting. D…

I think most of these are settings that can be changed in the advanced settings menu. Zoom changed the defaults, but you can still change the settings to what you prefer them to be

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#34
post #16
post #13

It's a bit odd how everyone's attacking Zoom when none of the other common solutions have proper e2e encryption either.

Do the other common solutions claim to have e2e encryption?

Yeah. The problem here is that Zoom lied about it.

And, like, why? Sure, if no one ever caught them, e2e could be a reason to choose Zoom—but it's like lying on a resumé. Which, I guess is also a thing that happens sometimes, but it's generally understood to be a bad idea.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#35

I don't think this is likely to succeed -- Zoom can argue that the stock price has gone down because of "Zoombombing" and security/privacy concerns that have nothing to do with exact details of what was disclosed in privacy/security documents, which barely anyone reads anyways. Also, it's awfully hard to argue losing shareholder value when the stock has still more than doubled in the end -- Zoom can easily make the p…

> Zoom can argue that the stock price has gone down because...

Two general steps to a securities suit.

First, show the company defrauded investors. That can be as simple as omitting or mis-stating material information. (Zoom publicly claimed to use certain encryption standards that it didn't.) So the battle, here, will be around materiality. Critically, this step does not typically require proving damages.

Once materiality is met, the second step is showing damages. At this point, the change in (and attribution of) stock prices comes into play.

Once fraud is shown, the company is in a bad place. Even if a particular investor faced no discernible loss, everyone who bought at higher prices will now sue. It also invites state and federal investigators to start pursuing management and senior staff.

> this feels like a short-seller trying to profit, no?

No. You have to disclose your positions when entering into a shareholder lawsuit. Shareholder lawsuits are comically common. And there is limited precedent for short sellers doing this.

Disclaimer: I am not a lawyer. This is not legal advice. Don't buy or sell securities based on my internet comments.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#36

Not surprising. Crazy how zoom in the beginning of the crisis was hailed for helping folks get together, but now with all the highlighted security concerns they are receiving a ton backlash. Hopefully they can recover and learn from this.

I’m more shocked that this massive tech industry has like one decent solution to remote video conferencing. Maybe we really have gone too far down the road of making bullshit apps, and stopped solving real problems.

Shame on us.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#37
post #12

Does it count as lying when it's ridiculously obvious that you're lying?

Well, I mean, I’m sure it was a throw in claim made for sales. Sales is always a little sleazy. I just don’t think the company expected ... you know, the whole world to be using their product. Sleazy got caught :p

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#38
post #13

It's a bit odd how everyone's attacking Zoom when none of the other common solutions have proper e2e encryption either.

The odd thing is that EARN-IT pushers want to ban strong encryption "for the children" but they want to excoriate Zoom over weak encryption "for the children".

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#39

Earlier quoted context omitted.

Is having keys compelled a surprise? Chinese servers, operating in China legally, will usually have this issue. It's serious yes, but I'm confused if it only applied to users in China? I'm more concerned about the technical issues TBH - I assume most software sanctioned in China had to turn over keys.

Seeing as encryption is illegal in China, I don't think they will need to give up any keys.

>Seeing as encryption is illegal in China

Source for this? That would make any https site in china illegal.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#40

Not surprising. Crazy how zoom in the beginning of the crisis was hailed for helping folks get together, but now with all the highlighted security concerns they are receiving a ton backlash. Hopefully they can recover and learn from this.

I’m more shocked that this massive tech industry has like one decent solution to remote video conferencing. Maybe we really have gone too far down the road of making bullshit apps, and stopped solving real problems. Shame on us.

Shame on the telcos who prevent residential customers from using the internet as intended. If everyone was given an IPV6 address block and freedom to accept outside connections from anywhere, none of this would be an issue.
Post reply on HN