Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

71–80 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#71
post #56

Earlier quoted context omitted.

Industrial espionage is real. There are many companies who are concerned about this and take active steps to keep data secret who would likely not have approved zoom use if they'd known e2e encryption wasn't to the level they were told. Some folks are concerned with more than stability and ease of use.

Once can't just delegate responsibility like that. Any company should enage in some form of due dilligence before procuring software. If there are expecations of privacy then those should be proven by the company procuring the software, not the vendor.

So it's okay that Zoom lied because users should have reverse engineered it to verify that what Zoom said about their own product was true?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#72
post #20

Why would any company with valuable IP use Zoom after this security blunder, along with the fact they "accidentally" routed domestic US calls via China. Zoom is software developed almost entirely in China, meaning it is subject to Chinese law and the very strong influence of the CCP. It is fact to say that Zoom could be compelled by the CCP to plant backdoors in software to siphon valuable IP for use by Chinese compa…

(Industrial) Espionage is the ius prima noctis of superpowers.

http://cryptome.org/echelon-nh.htm

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#73
post #21

If Zoom made clear to users that connections were not secured to the same standards as competitors, and that potentially hundreds of employees could be silently listening in on any call, I think that would have prevented them becoming a leader in video conference tech. So the right fine here is their entire market cap. That would put them back at square one, which is where an honest competitor would be right now.

Not defending them in any way - but don't think security was the primary reason for Zoom taking off. It was stability - it just worked and at the same time competitors didn't. Everybody used to have Skype and I would have gladly handed over my data to MS if only it would have been able to do stable video calls. It was often a disaster for just 2-way calls, let alone group.

and it could be more stable because it didn't implement e2e encryption.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#74
post #56

Earlier quoted context omitted.

Industrial espionage is real. There are many companies who are concerned about this and take active steps to keep data secret who would likely not have approved zoom use if they'd known e2e encryption wasn't to the level they were told. Some folks are concerned with more than stability and ease of use.

Once can't just delegate responsibility like that. Any company should enage in some form of due dilligence before procuring software. If there are expecations of privacy then those should be proven by the company procuring the software, not the vendor.

How would you verify e2e encryption on a proprietary protocol? Not every company that cares about privacy has crypto experts on staff. They should have a reasonable expectation that the vendor is telling the truth.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#75

If Zoom made clear to users that connections were not secured to the same standards as competitors, and that potentially hundreds of employees could be silently listening in on any call, I think that would have prevented them becoming a leader in video conference tech. So the right fine here is their entire market cap. That would put them back at square one, which is where an honest competitor would be right now.

Is this about the audio streams? I imagine that if at any time there are a million video streams happening, and zoom wanted to sneak into 1% of them, it would pretty much need 10000 vCPUs of compute to do that? The current tech scales affordably because only the encoded packets get transmitted between callers (via "selective forwarding units") without needing server-side re-encoding?

edit: That was for video streams. For audio streams, certainly the cpus cost is lower - about 10%.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#76

Earlier quoted context omitted.

Even with open source software you will never know what is actually running on the servers. It's best to assume none of the services are e2e encrypted and you should provide your own encryption on top of the medium you communicate with if you require privacy. By own encryption I mean exchanging keys and encrypting offline using oss tools.

> Even with open source software you will never know what is actually running on the servers. If the clients are open-source and properly implement end-to-end encryption, and you verify that they are not sending your keys to the servers, then what is running on the servers is irrelevant.

But they may run modified software e.g. with added backdoors and you wouldn't know as you cannot check what is actually running on servers.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#77

Earlier quoted context omitted.

> Even with open source software you will never know what is actually running on the servers. If the clients are open-source and properly implement end-to-end encryption, and you verify that they are not sending your keys to the servers, then what is running on the servers is irrelevant.

But they may run modified software e.g. with added backdoors and you wouldn't know as you cannot check what is actually running on servers.

Yes, but the servers only transfer encrypted payloads for which the servers do not have the decryption keys, and you can verify that just by looking at the clients (which are open source in this scenario). That is the entire point of end-to-end encryption.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#78
post #21

If Zoom made clear to users that connections were not secured to the same standards as competitors, and that potentially hundreds of employees could be silently listening in on any call, I think that would have prevented them becoming a leader in video conference tech. So the right fine here is their entire market cap. That would put them back at square one, which is where an honest competitor would be right now.

Not defending them in any way - but don't think security was the primary reason for Zoom taking off. It was stability - it just worked and at the same time competitors didn't. Everybody used to have Skype and I would have gladly handed over my data to MS if only it would have been able to do stable video calls. It was often a disaster for just 2-way calls, let alone group.

THIS THIS THIS. End users (generally) do not care about security they just need it to work.

That is what was great about zoom. The security becomes important after it works.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#80
post #67

Earlier quoted context omitted.

Apple claims that FaceTime is end-to-end encrypted (and makes some pretty strong statements about not having access to the content of communications). Facebook similarly claims that WhatsApp is end-to-end encrypted. Whilst I have little love for either company, do you have any evidence that these claims are lies?

I thought the lesson is clear. All e2e claims with closed source software must be dismissed by default. The burden of proof is on the seller.

I mean, I agree with you, and I guess the "surely Apple is not blatantly lying about being unable to read the content of your communication" argument has eroded a bit after Zoom's behaviour. But the penalties (both in terms of reputation and in terms of monetary fines) for this kind of misbehaviour are already large, and are likely to increase over time, and it seems an unnecessarily extreme risk for these companies to take.

But yes, impossible-to-verify claims are not worth very much at all.

Post reply on HN