Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

91–100 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#91

Earlier quoted context omitted.

I mean, I agree with you, and I guess the "surely Apple is not blatantly lying about being unable to read the content of your communication" argument has eroded a bit after Zoom's behaviour. But the penalties (both in terms of reputation and in terms of monetary fines) for this kind of misbehaviour are already large, and are likely to increase over time, and it seems an unnecessarily extreme risk for these companies…

I don't... did you even read TFA? All the order says is that they can't lie about it again. They don't have to pay anything, they don't have to actually fulfill their prior claims, and the other parts of the agreement they likely already comply with, and if not it'll be quite cheap (relatively) to do so.

> I don't... did you even read TFA?

Yes, I did. Thanks for asking.

> They don't have to pay anything

Yes, but they endured reputational damage, and companies hypothetically lying about it now could reasonably expect to have to pay something in future enforcements, which is what I was trying to get at in my previous comment. Reading it now, it was really sloppily worded by lumping together those things, but I'll leave it as it was so that the rest of this thread makes sense.

> they don't have to actually fulfill their prior claims

Given that they don't claim it any more, I'm not sure that they could be forced to start doing it -- put another way, not having E2E encryption is not a crime as long as you don't claim to have it.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#92
post #84

Earlier quoted context omitted.

Most videoconferencing systems are not E2E-encrypted. They encrypt the link between each participant and the central server. This makes implementation simpler in a few ways. A good E2E-encrypted system would involve Zoom never having the keys at all, so "key storage" would be irrelevant. The issue here is merely that Zoom claimed to be E2E-encrypted when they were not. They could have simply said "encrypted" and ther…

Wouldn't E2E encryption of a call with 40 participants require each user to have 39 times the upload bandwidth, in order to send 39 video streams encrypted with different keys? And potentially several times the computational cost on the client, in order to downsample video according to the different available download bandwidth of every other participant? Is there anyone doing group videoconferencing with E2E encrypt…

Typically, the central server does not transcode. Participants simulcast a few bitrates, and the central server forwards to each other participant the sub-stream with the appropriate bitrate for the bandwidth capacity of that participant. This is compatible with E2E encryption, by individually encrypting each sub-stream. Participants can share a session key that is unknown to the central server.

FaceTime supports group calls and claims E2E encryption for them. WhatsApp does too, I believe? I'm not sure how many participants you can have.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#94
post #79

What other popular group video meeting tools are e2e? I know of none. I remember reading a while back that Zoom claimed a few times they were e2e-encrypted, but what they meant was transport encryption.

If you want my popular products then nobody can answer because you'd know of them already. So I'll generalize to what group video tools are e2ee:

-> Jami (according to their website, I only ever used their chat and regular one-on-one calls)

-> Wire (client and server open source, but not community-lead development)

-> WhatsApp (if you trust Facebook, proprietary back-end)

And if you consider open source & on-premises / "can be completely locked off from the Internet so only you can access it" software to be end to end encrypted (if you personally run the server, you're one of the endpoints):

-> Jitsi Meet (full e2ee is under development, collab with Matrix I think)

-> BigBlueButton

-> Apache OpenMeetings (I never used this one, can't vouch for it)

Signal and Threema don't do group calls as far as I can quickly find online, correct me if I'm wrong.

Anyhow, plenty of options whether you like to self host (saves a ton of CPU on encryption and lets the server do stream mixing) or have full end to end encryption. Why do you care whether they're used by a billion people / "popular"? You can still choose to use them and improve the status quo because why not?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#95
post #21

Earlier quoted context omitted.

Not defending them in any way - but don't think security was the primary reason for Zoom taking off. It was stability - it just worked and at the same time competitors didn't. Everybody used to have Skype and I would have gladly handed over my data to MS if only it would have been able to do stable video calls. It was often a disaster for just 2-way calls, let alone group.

> don't think security was the primary reason for Zoom taking off. It was stability Stability was the main draw, but company IT departments would have had more power to ban it if there were bigger and clearer risks of corporate secrets escaping.

Or state secrets, or court secrets, or just preventing random zoom admins from watching children in virtual class rooms.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#96

Earlier quoted context omitted.

I don't... did you even read TFA? All the order says is that they can't lie about it again. They don't have to pay anything, they don't have to actually fulfill their prior claims, and the other parts of the agreement they likely already comply with, and if not it'll be quite cheap (relatively) to do so.

> I don't... did you even read TFA? Yes, I did. Thanks for asking. > They don't have to pay anything Yes, but they endured reputational damage, and companies hypothetically lying about it now could reasonably expect to have to pay something in future enforcements, which is what I was trying to get at in my previous comment. Reading it now, it was really sloppily worded by lumping together those things, but I'll leave…

How much actual reputational damage could they have possibly endured? I haven't noticed any fewer people using Zoom.

It's a consent order. They're willingly agreeing to it in order to avoid other costs (like fines and a lengthy trial). There's no "forced to" involved.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#97
post #21

Earlier quoted context omitted.

Not defending them in any way - but don't think security was the primary reason for Zoom taking off. It was stability - it just worked and at the same time competitors didn't. Everybody used to have Skype and I would have gladly handed over my data to MS if only it would have been able to do stable video calls. It was often a disaster for just 2-way calls, let alone group.

> don't think security was the primary reason for Zoom taking off. It was stability Stability was the main draw, but company IT departments would have had more power to ban it if there were bigger and clearer risks of corporate secrets escaping.

Any company IT department's power to ban something is inversely related to how much it's users want to use it. Also, the videoconference provider stealing company secrets it not part of most companies threat model. Teams and Slack are incredibly popular corporate tools, and neither of them offer this feature. WebEx is the only reasonably popular tool I can think of that supports it, and any security department that cared strongly about E2EE, would be asking questions like "do you perform key escrow" if they were thinking of migrating off something like that.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#98

Earlier quoted context omitted.

Once can't just delegate responsibility like that. Any company should enage in some form of due dilligence before procuring software. If there are expecations of privacy then those should be proven by the company procuring the software, not the vendor.

So it's okay that Zoom lied because users should have reverse engineered it to verify that what Zoom said about their own product was true?

No, if a company was really worried they shouldn't have opted for a cloud product with a (partly) Chinese-owned company. A lot of companies go through the trouble of giving their employees (especially management) "throw away" phones and/or computers when they send them to "problematic" places, in particular China, but then they install Zoom for their C-level and middle management executives to use, huh?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#100

Earlier quoted context omitted.

> I don't... did you even read TFA? Yes, I did. Thanks for asking. > They don't have to pay anything Yes, but they endured reputational damage, and companies hypothetically lying about it now could reasonably expect to have to pay something in future enforcements, which is what I was trying to get at in my previous comment. Reading it now, it was really sloppily worded by lumping together those things, but I'll leave…

How much actual reputational damage could they have possibly endured? I haven't noticed any fewer people using Zoom. It's a consent order. They're willingly agreeing to it in order to avoid other costs (like fines and a lengthy trial). There's no "forced to" involved.

> I haven't noticed any fewer people using Zoom.

I think this probably varies a lot between social groups; I know of many people (including non-technical) who were motivated to explore alternatives after reading news articles about Zoom's behaviour. A bunch of non-technical friends subsequently started to use meet.jit.si for meeting up, playing board games, etc, for example.

Post reply on HN