Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

61–70 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#61
post #19

I thought they made a deal with Trump/Oracle and that fixed all this stuff?

You're thinking of Tiktok.

From https://www.cnbc.com/2020/04/15/oracles-larry-ellison-calls-... :

Along with is growth in users, Zoom has seen concerns spike about how it is protecting users’ privacy. The Senate advised members not to use the service, according to Ars Technica and the New York City Department of Education banned its use for remote learning. A group of state attorneys general are probing the company after one of the officials was “zoombombed” on a forum about the Census, meaning the chat box was filled with profanities.

Ellison’s support could prove useful to Zoom as it wades through the new challenges of becoming a consumer tech company. Ellison is an influential billionaire with ties to the Trump administration. He has supported Trump’s campaign and even told the President about an anti-malaria drug Trump ended up touting as a possible treatment for the coronavirus, according to The New York Times. Oracle CEO Safra Catz served on Trump’s transition team in 2016.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#63
post #18

Pretty scandalous stuff. But to be fair it seems pretty likely that any or all of the major players (Apple, Google, MS, Facebook, AWS, etc) to be maintaining some sort of back-door access to the channels they control for spying purposes. I suppose the risk with Zoom is leaks due to incompetence rather than leaks due to government intervention.

Incompetence? That Zoom team has been working on video communication for many many years over in China.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#64
post #21

If Zoom made clear to users that connections were not secured to the same standards as competitors, and that potentially hundreds of employees could be silently listening in on any call, I think that would have prevented them becoming a leader in video conference tech. So the right fine here is their entire market cap. That would put them back at square one, which is where an honest competitor would be right now.

Not defending them in any way - but don't think security was the primary reason for Zoom taking off. It was stability - it just worked and at the same time competitors didn't. Everybody used to have Skype and I would have gladly handed over my data to MS if only it would have been able to do stable video calls. It was often a disaster for just 2-way calls, let alone group.

It's much easier to make a stable communication product if you don't need to worry about security and privacy.

Just look at the troubles and hurdles Signal messenger need to overcome to implement some features, while the competition that is not so security focused has them since forever.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#65

Earlier quoted context omitted.

Skype was better before the MS aquisition... and it used to be P2P. It'd be nice if the pre-MS source would leak somehow.

I'm not sure what would be accomplished if the source leaked. Someone would still need to maintain both the client and now a new set of servers. This would be difficult given that Microsoft would almost certainly use whatever means they could to stop this from happening.

https://escargot.log1p.xyz/

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#66
post #21

Earlier quoted context omitted.

Not defending them in any way - but don't think security was the primary reason for Zoom taking off. It was stability - it just worked and at the same time competitors didn't. Everybody used to have Skype and I would have gladly handed over my data to MS if only it would have been able to do stable video calls. It was often a disaster for just 2-way calls, let alone group.

> It was stability - it just worked Also due to deception, it auto reinstalled on macs until they were caught.

"this software I uninstalled keeps reinstalling itself. oh well, I guess I will have to use it!" said no one ever.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#67
post #18

Pretty scandalous stuff. But to be fair it seems pretty likely that any or all of the major players (Apple, Google, MS, Facebook, AWS, etc) to be maintaining some sort of back-door access to the channels they control for spying purposes. I suppose the risk with Zoom is leaks due to incompetence rather than leaks due to government intervention.

Apple claims that FaceTime is end-to-end encrypted (and makes some pretty strong statements about not having access to the content of communications). Facebook similarly claims that WhatsApp is end-to-end encrypted. Whilst I have little love for either company, do you have any evidence that these claims are lies?

I thought the lesson is clear.

All e2e claims with closed source software must be dismissed by default. The burden of proof is on the seller.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#68
post #56

Earlier quoted context omitted.

> don't think security was the primary reason for Zoom taking off. It was stability Stability was the main draw, but company IT departments would have had more power to ban it if there were bigger and clearer risks of corporate secrets escaping.

Industrial espionage is real. There are many companies who are concerned about this and take active steps to keep data secret who would likely not have approved zoom use if they'd known e2e encryption wasn't to the level they were told. Some folks are concerned with more than stability and ease of use.

Once can't just delegate responsibility like that. Any company should enage in some form of due dilligence before procuring software. If there are expecations of privacy then those should be proven by the company procuring the software, not the vendor.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#70
post #66

Earlier quoted context omitted.

> It was stability - it just worked Also due to deception, it auto reinstalled on macs until they were caught.

"this software I uninstalled keeps reinstalling itself. oh well, I guess I will have to use it!" said no one ever.

Users were unaware this was happening. "It just worked" because it would install itself in the background unbeknownst to the user, thus obviating the need to take time to install it when needed.
Post reply on HN