Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

151–160 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#151

> Zoom has agreed to a requirement to establish and implement a comprehensive security program, a prohibition on privacy and security misrepresentations, and other detailed and specific relief to protect its user base What a slap on the wrist. "You blatantly lied to your customers for years. How about you just continue to implement the thing that you were working on anyways." I don't think punishment is always the be…

>What a slap on the wrist. "You blatantly lied to your customers for years. How about you just continue to implement the thing that you were working on anyways."

Honestly - that's inline with the severity of the crime.

>I don't think punishment is always the best solution but it seems that you should at least set some sort of example.

I'm not a fan of regulatory bodies making examples of companies for minor infractions. And this is a very minor infraction.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#152
post #106

All they had to do was say "encrypted" instead of explicitly saying "end-to-end encrypted" when it very clearly wasn't end-to-end. The former still could've been a bit weaselly and misleading (many non-technical users would probably have assumed "encrypted" implied total confidentiality), but what they actually did was so much worse. I hope they get hit hard on that.

Zoom lied. People spied.

>People spied.

Did they? Which people? When? How?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#153
A deeper issue is how hard it is to "know" if companies hawking products with security implications (which is nearly everything, today) are lying.

I'm not even talking about the gradient ranging from innocent bugs to incompetent coders and how that gets papered over. When you buy shoddy physical goods, there are typically characteristics you can't hide, like cheap materials. But with software like this of course the only function your average person can verify is that the transmission happens, not how it is encoded. Neither Grandma nor your manager are likely to break out tcpdump to check.

And of course the DMCA complicates this in the US, and things are even worse for researchers elsewhere.

Third party audit and reputation are the only fixes I see. And the second one requires a commercial environment that rewards it. The current one doesn't; it rewards novelty and lies, so that's what we get.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#154

If Zoom made clear to users that connections were not secured to the same standards as competitors, and that potentially hundreds of employees could be silently listening in on any call, I think that would have prevented them becoming a leader in video conference tech. So the right fine here is their entire market cap. That would put them back at square one, which is where an honest competitor would be right now.

I don't think anyone except crypto-nerds cares about this. Normal people just assume everything can be wiretapped and Zuckerberg and friends are always listening.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#157
post #56

Earlier quoted context omitted.

> don't think security was the primary reason for Zoom taking off. It was stability Stability was the main draw, but company IT departments would have had more power to ban it if there were bigger and clearer risks of corporate secrets escaping.

Industrial espionage is real. There are many companies who are concerned about this and take active steps to keep data secret who would likely not have approved zoom use if they'd known e2e encryption wasn't to the level they were told. Some folks are concerned with more than stability and ease of use.

It's difficult to imagine a company that cares that much about keeping their video chat data private, but would use any third party service.

That doesn't justify zoom making false claims--I just don't think the companies you're describing would be using zoom.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#158
post #153

A deeper issue is how hard it is to "know" if companies hawking products with security implications (which is nearly everything, today) are lying. I'm not even talking about the gradient ranging from innocent bugs to incompetent coders and how that gets papered over. When you buy shoddy physical goods, there are typically characteristics you can't hide, like cheap materials. But with software like this of course the…

Freely licensed software would allow for audits.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#159

All E2E encryption claims in closed source software are untrustworthy. What're you expecting?

Not only is the source closed and proprietary, the company and the product themselves have terrible reputations when it comes to security. Why would anyone even consider trusting whatever encryption they offer?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#160

> Zoom has agreed to a requirement to establish and implement a comprehensive security program, a prohibition on privacy and security misrepresentations, and other detailed and specific relief to protect its user base What a slap on the wrist. "You blatantly lied to your customers for years. How about you just continue to implement the thing that you were working on anyways." I don't think punishment is always the be…

>What a slap on the wrist. "You blatantly lied to your customers for years. How about you just continue to implement the thing that you were working on anyways." Honestly - that's inline with the severity of the crime. >I don't think punishment is always the best solution but it seems that you should at least set some sort of example. I'm not a fan of regulatory bodies making examples of companies for minor infractio…

Is it minor?

From my perspective, making security guarantees about a product is the same whether that product is software or hardware. If somebody guaranteed that their ferris wheel had x safety feature, then it turned out to be untrue, nobody would call that a minor infraction.

Post reply on HN