Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

21–30 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#21

If Zoom made clear to users that connections were not secured to the same standards as competitors, and that potentially hundreds of employees could be silently listening in on any call, I think that would have prevented them becoming a leader in video conference tech. So the right fine here is their entire market cap. That would put them back at square one, which is where an honest competitor would be right now.

Not defending them in any way - but don't think security was the primary reason for Zoom taking off. It was stability - it just worked and at the same time competitors didn't.

Everybody used to have Skype and I would have gladly handed over my data to MS if only it would have been able to do stable video calls. It was often a disaster for just 2-way calls, let alone group.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#22

If Zoom made clear to users that connections were not secured to the same standards as competitors, and that potentially hundreds of employees could be silently listening in on any call, I think that would have prevented them becoming a leader in video conference tech. So the right fine here is their entire market cap. That would put them back at square one, which is where an honest competitor would be right now.

I wish that was true, but in practice I think it wouldn't matter. Zoom was the only one ready with infrastructure, multiple clients, automatic quality adjustment, screen sharing options, scheduling, and many other needed features.

Otherwise we had hangouts/meet with very basic features and jet-taking-off Mac behaviour, chime which is really good but nobody heard of it (Amazon is not interested in that market apparently), Skype which aims for social chat consumers, slack which works only within the org, jitsi, and a thousand of me-too apps with very basic feature set.

Zoom could kick your puppy at the end of each call, and it would likely still be the best choice at the time :-(

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#25
I don't understand how the FTC arrived at the conclusion they're not E2E? Or have I missed something?

>Despite promising end-to-end encryption, the FTC said that "Zoom maintained the cryptographic keys that could allow Zoom to access the content of its customers' meetings, and secured its Zoom Meetings, in part, with a lower level of encryption than promised."

Not wonderful but that still, technically, is an E2E encryption scheme. Is it not? Or do they mean one end terminates in Zoom's servers and it's not E2E through the whole pipe, but rather two pipes stitched together?

Agreed it's not as secure as they marketed, but this seems to suggest if you want to offer E2E you need a specific kind of key storage to meet this new precedent. Good in practice, but maybe the FTC are not the right people to placing such a hurdle down?

I'm sure I've missed something though.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#26

If Zoom made clear to users that connections were not secured to the same standards as competitors, and that potentially hundreds of employees could be silently listening in on any call, I think that would have prevented them becoming a leader in video conference tech. So the right fine here is their entire market cap. That would put them back at square one, which is where an honest competitor would be right now.

Is it really different from competitors like Cisco (webex, jabber, ...)? A big selling point of all those is phone dial in which can't be done with e2e encryption (the phone gateway run by the operator has to have the keys)

The thing is: Our team doesn't use phone dial-in, haven't even seen the feature so I guess it's not enabled, but still we don't have e2e encryption.

That doesn't make sense.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#27

I don't understand how the FTC arrived at the conclusion they're not E2E? Or have I missed something? >Despite promising end-to-end encryption, the FTC said that "Zoom maintained the cryptographic keys that could allow Zoom to access the content of its customers' meetings, and secured its Zoom Meetings, in part, with a lower level of encryption than promised." Not wonderful but that still, technically, is an E2E encr…

The zoom definition of E2E is that the one end is one user and the other end is the zoom server.

At no point is there encryption directly from one user to anothre.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#28

I don't understand how the FTC arrived at the conclusion they're not E2E? Or have I missed something? >Despite promising end-to-end encryption, the FTC said that "Zoom maintained the cryptographic keys that could allow Zoom to access the content of its customers' meetings, and secured its Zoom Meetings, in part, with a lower level of encryption than promised." Not wonderful but that still, technically, is an E2E encr…

A lot of the servers are in China. So You have state actors involved.

Our company had stop using zoom for security reasons.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#30

I don't understand how the FTC arrived at the conclusion they're not E2E? Or have I missed something? >Despite promising end-to-end encryption, the FTC said that "Zoom maintained the cryptographic keys that could allow Zoom to access the content of its customers' meetings, and secured its Zoom Meetings, in part, with a lower level of encryption than promised." Not wonderful but that still, technically, is an E2E encr…

I'm not sure what you mean by "you need a specific kind of key storage". You don't need any kind of key storage for e2e. You only need to facilitate the key exchange as a server, then push the opaque data both ways. If zoom (the company, not the software client) can get the encryption key, the call is not e2e encrypted.
Post reply on HN