Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

161–170 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#161

Earlier quoted context omitted.

I'm not sure what would be accomplished if the source leaked. Someone would still need to maintain both the client and now a new set of servers. This would be difficult given that Microsoft would almost certainly use whatever means they could to stop this from happening.

Wasn’t Skype pre-MS P2P, not server based?

Perhaps. But at minimum there would still be some server necessary for discovery purposes.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#162
post #65

Earlier quoted context omitted.

I'm not sure what would be accomplished if the source leaked. Someone would still need to maintain both the client and now a new set of servers. This would be difficult given that Microsoft would almost certainly use whatever means they could to stop this from happening.

https://escargot.log1p.xyz/

Wow. Brings back memories as MSN was the messenger of choice during my college years :)

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#163

Earlier quoted context omitted.

So it's okay that Zoom lied because users should have reverse engineered it to verify that what Zoom said about their own product was true?

No, if a company was really worried they shouldn't have opted for a cloud product with a (partly) Chinese-owned company. A lot of companies go through the trouble of giving their employees (especially management) "throw away" phones and/or computers when they send them to "problematic" places, in particular China, but then they install Zoom for their C-level and middle management executives to use, huh?

But everybody knows C-level and middle-management don't actually know anything or do anything. Have at it! Its like spamming the spammers.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#164
post #135

Earlier quoted context omitted.

I'm still not a native English speaker, but a Google search shows that non-paying customers are people who don't pay their bills, which is not the same thing as users who don't have bills to pay. Also as I wrote, Zoom was thinking of selling E2E encryption as a payed feature, that's why the distinction really matters (I would happily pay for it if that would give me a strong assurance that I just don't have so far).

Non-paying customers can mean either customers who are delinquent in paying their bills, or customers that are using the service for free with permission.

Non-revenue customers for the latter (from airlines)

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#165

I think the assumed implication with E2EE is that no one other than the partcipants can get at the content of your communications. To do that you need: 1. All cryptographic keys controlled by the users. 2. Some way to confirm you are actually connected to who you think you are connected to. 3. A way to confirm that the code you are running is not leaking keys/content. So Zoom failed on all 3 points. There are lots of…

> almost all fail on point 2 unless the user does things that they almost never do

Are you referring to the "scan this QR code to verify your partner's key" function in secure messaging apps? I definitely use that. I try to keep all my primary contact's keys verified. It's harder during COVID when you're not meeting up in person as often, because anything besides meeting in person and verifying the two devices directly exposes you to another unverified channel.

It's very hard to bootstrap this stuff. Sure, "web of trust" but that's hard too. Speaking of which, didn't Keybase get bought by zoom to help with exactly these issues?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#166

Earlier quoted context omitted.

"Here are the keys to your new car" "Where are the wheels?" "Well... we delivered most of what was purchased so you don't get to complain."

Good example. If you bought a $40k car and it didn't come with wheels, the damages would be the amount to remedy the missing wheels, not $40k.

A better analogy would be if the car didn't come with airbags, but even that is not as good because you have no way of knowing if someone listened into your conversations whereas airbags let you know just fine.

Ford once paid $300M for a faulty airbags thing, but that was negligence whereas this is fraud. Of course this isn't a lethal risk.

I would think the case would have legs. Haven't a clue how much for.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#167
post #116

If Zoom made clear to users that connections were not secured to the same standards as competitors, and that potentially hundreds of employees could be silently listening in on any call, I think that would have prevented them becoming a leader in video conference tech. So the right fine here is their entire market cap. That would put them back at square one, which is where an honest competitor would be right now.

> the right fine here is their entire market cap. That would put them back at square one I don't think Zoom has transgressed anywhere nearly this badly, but even if I did it doesn't make sense to fine any company their entire value unless your goal is simply to destroy them. The company is only worth as much as it is because it is expected to continue as a company, and there would be no way for it to continue if it o…

A good punishment is government nationalizes it, paying shareholders nothing, then immediately sells those shares back onto the public markets. The government would earn close-ish to the market cap.

Effectively, allow the company to continue as before, but wipe out all shareholders. After all, they are the people who allowed this behaviour. They are the ultimate decision makers.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#168

Earlier quoted context omitted.

>What a slap on the wrist. "You blatantly lied to your customers for years. How about you just continue to implement the thing that you were working on anyways." Honestly - that's inline with the severity of the crime. >I don't think punishment is always the best solution but it seems that you should at least set some sort of example. I'm not a fan of regulatory bodies making examples of companies for minor infractio…

Is it minor? From my perspective, making security guarantees about a product is the same whether that product is software or hardware. If somebody guaranteed that their ferris wheel had x safety feature, then it turned out to be untrue, nobody would call that a minor infraction.

I agree. I see false advertising as a serious crime.

Obviously we should be utilizing critical thinking ourselves, but I think that we also need the threat of punishment. Because if we have that threat one critical thinker can report the problem and it will be solved for everyone. If there is no punishment then there is no incentive for companies to tell the truth.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#169
post #148

> Zoom has agreed to a requirement to establish and implement a comprehensive security program, a prohibition on privacy and security misrepresentations, and other detailed and specific relief to protect its user base What a slap on the wrist. "You blatantly lied to your customers for years. How about you just continue to implement the thing that you were working on anyways." I don't think punishment is always the be…

Punishment is the best solution. Incentives are what drive behavior, and learning that you can get away with lying will just lead to more getting away with lying.

When it comes to training humans and animals, positive punishment is far less effective than most other training techniques like positive reinforcement. Don't Shoot the Dog[1]!

[1] https://www.amazon.com/Dont-Shoot-Dog-Teaching-Training/dp/0...

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#170
post #169
post #148

Earlier quoted context omitted.

Punishment is the best solution. Incentives are what drive behavior, and learning that you can get away with lying will just lead to more getting away with lying.

When it comes to training humans and animals, positive punishment is far less effective than most other training techniques like positive reinforcement. Don't Shoot the Dog[1]! [1] https://www.amazon.com/Dont-Shoot-Dog-Teaching-Training/dp/0...

Unfortunately, the positives are customer adoption, and customers have already adopted zoom. This is like continuing to feed the dog treats because it's what you're used to, regardless of the outcome of their actions.

But more generally, it's not obvious that individual, "reptile-brain" incentives translate to large company leadership. I'd be hugely skeptical of applying positive psychology to international corporate leadership, but what do I know anyway.

Post reply on HN