Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

111–120 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#111
post #56

Earlier quoted context omitted.

Industrial espionage is real. There are many companies who are concerned about this and take active steps to keep data secret who would likely not have approved zoom use if they'd known e2e encryption wasn't to the level they were told. Some folks are concerned with more than stability and ease of use.

Once can't just delegate responsibility like that. Any company should enage in some form of due dilligence before procuring software. If there are expecations of privacy then those should be proven by the company procuring the software, not the vendor.

You know what it's called when you purposefully lie about your products or services to gain an advantage? Fraud.

If this was happenening in any other industry (except fonance?), the perpetrators would be in jail.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#112
post #67

Earlier quoted context omitted.

I thought the lesson is clear. All e2e claims with closed source software must be dismissed by default. The burden of proof is on the seller.

I mean, I agree with you, and I guess the "surely Apple is not blatantly lying about being unable to read the content of your communication" argument has eroded a bit after Zoom's behaviour. But the penalties (both in terms of reputation and in terms of monetary fines) for this kind of misbehaviour are already large, and are likely to increase over time, and it seems an unnecessarily extreme risk for these companies…

As for fines, companies already do sophisticated risk analysis so that the average outcome would be far more than the average potential cost. I know oil companies do highly sophisticated risk and reward calculations with violations.

As for 3reputational damage, that’s a long term effect. A few events won’t have a lasting impact. If it turns out that Apple Key Chain is not e2e, or worse iOS exfiltrates key material from apps, that would be major news, but soon people will forget (if they ever cared in the first place) and keep buying iPhones unless the misbehavior is a recurrent problem. A company like Apple will make it extremely difficult to discover such misconduct.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#113

Earlier quoted context omitted.

Skype was better before the MS aquisition... and it used to be P2P. It'd be nice if the pre-MS source would leak somehow.

I think you may be viewing history through slightly rose-tinted glasses there - I used pre-MS Skype a lot and it was never anywhere near as reliable as Zoom is and didn't support group video chat at all. And the fact that it was P2P meant that some features that everyone would expect to work these days (offline messages, mobile support) were simply not possible at all.

Amen

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#114
post #9

So will they get fined more than Snapchat for lying about ephemeral messaging or will this be the usual American "slap on the wrist" thing we usually see to protect the investors?

In a world where US and EU are willing to ban Signal because it doesn't allow a 'master key', Zoom is the BFF of governments and regulators.

What?

” The European Commission has told its staff to switch to the encrypted Signal messaging app in a move that’s designed to increase the security of its communications.”

This was February 2020, has something changed?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#115
post #3

Earlier quoted context omitted.

Customers or users? There’s a huge difference between the 2, and this excerpt uses the 2 words like if those were interchangeable.

I think a better distinction is 'paying customers' and 'non-paying customers'. Customers being a subset of users after all makes it a bit ambiguous. Not that it should matter in the context of the feature being described.

I'm still not a native English speaker, but a Google search shows that non-paying customers are people who don't pay their bills, which is not the same thing as users who don't have bills to pay.

Also as I wrote, Zoom was thinking of selling E2E encryption as a payed feature, that's why the distinction really matters (I would happily pay for it if that would give me a strong assurance that I just don't have so far).

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#116

If Zoom made clear to users that connections were not secured to the same standards as competitors, and that potentially hundreds of employees could be silently listening in on any call, I think that would have prevented them becoming a leader in video conference tech. So the right fine here is their entire market cap. That would put them back at square one, which is where an honest competitor would be right now.

> the right fine here is their entire market cap. That would put them back at square one

I don't think Zoom has transgressed anywhere nearly this badly, but even if I did it doesn't make sense to fine any company their entire value unless your goal is simply to destroy them. The company is only worth as much as it is because it is expected to continue as a company, and there would be no way for it to continue if it owed that much money to the government. Unless it was nationalized and run by the government, but I doubt you're proposing that? Which means instead the company liquidates, and its liquidation value is far less than it's value as a business.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#117
post #81

Earlier quoted context omitted.

You can sue directly, no? The damage should be easy, you thought you bought something and weren't delivered it, so just refund all costs.

Most of what was purchased was delivered.

"Here are the keys to your new car"

"Where are the wheels?"

"Well... we delivered most of what was purchased so you don't get to complain."

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#118
post #9

Earlier quoted context omitted.

In a world where US and EU are willing to ban Signal because it doesn't allow a 'master key', Zoom is the BFF of governments and regulators.

What? ” The European Commission has told its staff to switch to the encrypted Signal messaging app in a move that’s designed to increase the security of its communications.” This was February 2020, has something changed?

Yes

https://news.ycombinator.com/item?id=25028411

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#119
post #9

Earlier quoted context omitted.

In a world where US and EU are willing to ban Signal because it doesn't allow a 'master key', Zoom is the BFF of governments and regulators.

What? ” The European Commission has told its staff to switch to the encrypted Signal messaging app in a move that’s designed to increase the security of its communications.” This was February 2020, has something changed?

That's encryption for the state, not for us peasants.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#120
post #94

Earlier quoted context omitted.

If you want my popular products then nobody can answer because you'd know of them already. So I'll generalize to what group video tools are e2ee: -> Jami (according to their website, I only ever used their chat and regular one-on-one calls) -> Wire (client and server open source, but not community-lead development) -> WhatsApp (if you trust Facebook, proprietary back-end) And if you consider open source & on-premises…

- I was looking for "desktop-solutions" comparable to Zoom, so WhatsApp and Telegram are out of the question (Telegram doesn't do group calls AFAICS). Some notes: - Wire has published a detailed whitepaper on e2ee. https://wire-docs.wire.com/download/Wire+Security+Whitepaper... - Jami (formerly GNU Ring) has an interesting post about having e2e here: https://security.stackexchange.com/a/162603/243716 - Jitsi e2e is t…

Oh right sorry, Telegram indeed doesn't do group calls. Removed them from the list. Thanks!

As for Jitsi, BigBlueButton, and OpenMeetings, no indeed they don't do encryption currently, hence them being in the second section with open source self-hostable conference software rather than the e2ee section above. To me, depending on the use-case (if you can self host on a trusted system) that would be equally secure and also doesn't leak metadata (who calls who) to some central system.

Wire's most recent system (launched a few weeks ago to make the video conferencing more efficient, bumping max participants from 4 to 12) also tries to avoid learning who is in a conference with who, but fact is that if you observe their datacenter there'll be traffic going to certain IP addresses that starts and stops at the same time.

For what it's worth, to add my experience/recommendations: I really liked the BBB setups I've been in (largest was a hundred or so people) and would recommend that if you're looking for an alternative. Wire also works reasonably and because it's end to end encrypted you don't need your own setup to get started, but isn't as open source oriented as BBB/Jitsi and the CPU load from the encryption during video or screen sharing is quite significant. Jami, last I tested, was quite buggy, but that was way before the pandemic. Full disclose: so far I've only had to decline one Zoom request and so I've never been in a Zoom® call (not a single of our clients uses Zoom, yet people use the brand name as a synonym for video call? I don't get it), so I can't compare any of these with Zoom.

Post reply on HN