Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

141–150 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#141

Earlier quoted context omitted.

Good example. If you bought a $40k car and it didn't come with wheels, the damages would be the amount to remedy the missing wheels, not $40k.

I don't think the example vindicates you in the manner you believe. The damages would surely exceed the missing wheels if resolved in the courtroom.

Regardless, it wouldn't be a full refund, which is my point.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#142
> Zoom has agreed to a requirement to establish and implement a comprehensive security program, a prohibition on privacy and security misrepresentations, and other detailed and specific relief to protect its user base

What a slap on the wrist. "You blatantly lied to your customers for years. How about you just continue to implement the thing that you were working on anyways."

I don't think punishment is always the best solution but it seems that you should at least set some sort of example.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#143

If Zoom made clear to users that connections were not secured to the same standards as competitors, and that potentially hundreds of employees could be silently listening in on any call, I think that would have prevented them becoming a leader in video conference tech. So the right fine here is their entire market cap. That would put them back at square one, which is where an honest competitor would be right now.

I wish that was true, but in practice I think it wouldn't matter. Zoom was the only one ready with infrastructure, multiple clients, automatic quality adjustment, screen sharing options, scheduling, and many other needed features. Otherwise we had hangouts/meet with very basic features and jet-taking-off Mac behaviour, chime which is really good but nobody heard of it (Amazon is not interested in that market apparent…

"chime which is really good but nobody heard of it"

So there was a competitor after all?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#144

Earlier quoted context omitted.

I don't think the example vindicates you in the manner you believe. The damages would surely exceed the missing wheels if resolved in the courtroom.

Regardless, it wouldn't be a full refund, which is my point.

Could well be much more than that, if i have proof that you did it knowingly and systemically.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#145
post #18

Pretty scandalous stuff. But to be fair it seems pretty likely that any or all of the major players (Apple, Google, MS, Facebook, AWS, etc) to be maintaining some sort of back-door access to the channels they control for spying purposes. I suppose the risk with Zoom is leaks due to incompetence rather than leaks due to government intervention.

Apple claims that FaceTime is end-to-end encrypted (and makes some pretty strong statements about not having access to the content of communications). Facebook similarly claims that WhatsApp is end-to-end encrypted. Whilst I have little love for either company, do you have any evidence that these claims are lies?

Whatsup is "end to end encrypted", but I had seen an article here on HN about how Whatsup would snatch your data before it begun transit, if needed - for "security reasons" - after performing a local analysis on the messages. I don't know if this has been implemented as of yet, but you can see the intent for circumventing actual encryption - they can do it, and since e2e has become a bother, they certainly will.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#146

All they had to do was say "encrypted" instead of explicitly saying "end-to-end encrypted" when it very clearly wasn't end-to-end. The former still could've been a bit weaselly and misleading (many non-technical users would probably have assumed "encrypted" implied total confidentiality), but what they actually did was so much worse. I hope they get hit hard on that.

Per the article, they are not getting "hit hard." No fines and no compensation for their customers.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#147
I think the assumed implication with E2EE is that no one other than the partcipants can get at the content of your communications. To do that you need:

1. All cryptographic keys controlled by the users.

2. Some way to confirm you are actually connected to who you think you are connected to.

3. A way to confirm that the code you are running is not leaking keys/content.

So Zoom failed on all 3 points. There are lots of things out there claiming E2EE that fail on one or more of these points. Almost all fail on point 2 unless the user does things that they almost never do. Is the FTC going to come up with a E2EE definition for trade and start prosecuting those that don't meet that definition? Otherwise it would seem unfair that they only went after the entity that ended up in the general media.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#148

> Zoom has agreed to a requirement to establish and implement a comprehensive security program, a prohibition on privacy and security misrepresentations, and other detailed and specific relief to protect its user base What a slap on the wrist. "You blatantly lied to your customers for years. How about you just continue to implement the thing that you were working on anyways." I don't think punishment is always the be…

Punishment is the best solution. Incentives are what drive behavior, and learning that you can get away with lying will just lead to more getting away with lying.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#149
post #9

So will they get fined more than Snapchat for lying about ephemeral messaging or will this be the usual American "slap on the wrist" thing we usually see to protect the investors?

In a world where US and EU are willing to ban Signal because it doesn't allow a 'master key', Zoom is the BFF of governments and regulators.

Aren't government officials using Signal themselves precisely because it is so secure?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#150

Earlier quoted context omitted.

What? ” The European Commission has told its staff to switch to the encrypted Signal messaging app in a move that’s designed to increase the security of its communications.” This was February 2020, has something changed?

That's encryption for the state, not for us peasants.

Can the govenment somehow restrict end-to-end encrypted messaging to officials only?
Post reply on HN