Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

51–60 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#51

So will they get fined more than Snapchat for lying about ephemeral messaging or will this be the usual American "slap on the wrist" thing we usually see to protect the investors?

A slap on the wrist would be something [1]

They don't even need to tell their customers that they lied [2]

1: https://www.ftc.gov/system/files/documents/cases/1923167zoom... 2: https://www.ftc.gov/system/files/documents/public_statements...

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#52

Earlier quoted context omitted.

> Even with open source software you will never know what is actually running on the servers. If the clients are open-source and properly implement end-to-end encryption, and you verify that they are not sending your keys to the servers, then what is running on the servers is irrelevant.

... if you have the technical expertise to audit the full source code, and run and audit your own build (on both ends).

Sure, but that's a different argument than what parent was making.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#53
post #6
post #3

Earlier quoted context omitted.

Customers or users? There’s a huge difference between the 2, and this excerpt uses the 2 words like if those were interchangeable.

What's the difference? Aren't they the same group of people in this context?

I'm sorry, I'm not a native English speaker. According to the Oxford dictionary customers are people who buy a product or service.

Zoom was thinking of giving only them E2E encryption, and actually I would pay for that service if I would trust Zoom. Currently I use telegram to speak with my friends, but the call drops quite often as we don't have stable internet connection.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#54

All E2E encryption claims in closed source software are untrustworthy. What're you expecting?

Even with open source software you will never know what is actually running on the servers. It's best to assume none of the services are e2e encrypted and you should provide your own encryption on top of the medium you communicate with if you require privacy. By own encryption I mean exchanging keys and encrypting offline using oss tools.

Isn't the whole point of e2e that you don't need to worry about what runs on the server, unless you're worried about metadata leakage.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#55
post #21

Earlier quoted context omitted.

Not defending them in any way - but don't think security was the primary reason for Zoom taking off. It was stability - it just worked and at the same time competitors didn't. Everybody used to have Skype and I would have gladly handed over my data to MS if only it would have been able to do stable video calls. It was often a disaster for just 2-way calls, let alone group.

Skype was better before the MS aquisition... and it used to be P2P. It'd be nice if the pre-MS source would leak somehow.

I'm not sure what would be accomplished if the source leaked. Someone would still need to maintain both the client and now a new set of servers. This would be difficult given that Microsoft would almost certainly use whatever means they could to stop this from happening.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#56
post #21

Earlier quoted context omitted.

Not defending them in any way - but don't think security was the primary reason for Zoom taking off. It was stability - it just worked and at the same time competitors didn't. Everybody used to have Skype and I would have gladly handed over my data to MS if only it would have been able to do stable video calls. It was often a disaster for just 2-way calls, let alone group.

> don't think security was the primary reason for Zoom taking off. It was stability Stability was the main draw, but company IT departments would have had more power to ban it if there were bigger and clearer risks of corporate secrets escaping.

Industrial espionage is real. There are many companies who are concerned about this and take active steps to keep data secret who would likely not have approved zoom use if they'd known e2e encryption wasn't to the level they were told.

Some folks are concerned with more than stability and ease of use.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#57
post #21

Earlier quoted context omitted.

Not defending them in any way - but don't think security was the primary reason for Zoom taking off. It was stability - it just worked and at the same time competitors didn't. Everybody used to have Skype and I would have gladly handed over my data to MS if only it would have been able to do stable video calls. It was often a disaster for just 2-way calls, let alone group.

Skype was better before the MS aquisition... and it used to be P2P. It'd be nice if the pre-MS source would leak somehow.

Fun fact, the original Skype developers also developed the great (for its time) P2P filesharing app/network Kazaa/FastTrack.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#58

Earlier quoted context omitted.

Skype was better before the MS aquisition... and it used to be P2P. It'd be nice if the pre-MS source would leak somehow.

I'm not sure what would be accomplished if the source leaked. Someone would still need to maintain both the client and now a new set of servers. This would be difficult given that Microsoft would almost certainly use whatever means they could to stop this from happening.

Wasn’t Skype pre-MS P2P, not server based?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#59
post #21

If Zoom made clear to users that connections were not secured to the same standards as competitors, and that potentially hundreds of employees could be silently listening in on any call, I think that would have prevented them becoming a leader in video conference tech. So the right fine here is their entire market cap. That would put them back at square one, which is where an honest competitor would be right now.

Not defending them in any way - but don't think security was the primary reason for Zoom taking off. It was stability - it just worked and at the same time competitors didn't. Everybody used to have Skype and I would have gladly handed over my data to MS if only it would have been able to do stable video calls. It was often a disaster for just 2-way calls, let alone group.

> It was stability - it just worked

Also due to deception, it auto reinstalled on macs until they were caught.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#60
post #20

Why would any company with valuable IP use Zoom after this security blunder, along with the fact they "accidentally" routed domestic US calls via China. Zoom is software developed almost entirely in China, meaning it is subject to Chinese law and the very strong influence of the CCP. It is fact to say that Zoom could be compelled by the CCP to plant backdoors in software to siphon valuable IP for use by Chinese compa…

Many companies work WFH these days, so intercepting dev and r&d meeting would be a dream for CCP. Can't see why they wouldn't do it.
Post reply on HN