Earlier quoted context omitted.
What? ” The European Commission has told its staff to switch to the encrypted Signal messaging app in a move that’s designed to increase the security of its communications.” This was February 2020, has something changed?
Yes https://news.ycombinator.com/item?id=25028411
Zoom lied to users about end-to-end encryption for years, FTC says
171–180 of 438 posts
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#172Earlier quoted context omitted.
Punishment is the best solution. Incentives are what drive behavior, and learning that you can get away with lying will just lead to more getting away with lying.
When it comes to training humans and animals, positive punishment is far less effective than most other training techniques like positive reinforcement. Don't Shoot the Dog[1]! [1] https://www.amazon.com/Dont-Shoot-Dog-Teaching-Training/dp/0...
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#173Earlier quoted context omitted.
I'm still not a native English speaker, but a Google search shows that non-paying customers are people who don't pay their bills, which is not the same thing as users who don't have bills to pay. Also as I wrote, Zoom was thinking of selling E2E encryption as a payed feature, that's why the distinction really matters (I would happily pay for it if that would give me a strong assurance that I just don't have so far).
I don't think I'd happily pay for Zoom, regardless of their encryption promises. I've personally struggled more with zoom call quality issues and hardware conflicts than I have with any other video conference provider.
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#174A deeper issue is how hard it is to "know" if companies hawking products with security implications (which is nearly everything, today) are lying. I'm not even talking about the gradient ranging from innocent bugs to incompetent coders and how that gets papered over. When you buy shoddy physical goods, there are typically characteristics you can't hide, like cheap materials. But with software like this of course the…
Third party audits aren't a silver bullet. Enron and Worldcom had third party audits.
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#175If Zoom made clear to users that connections were not secured to the same standards as competitors, and that potentially hundreds of employees could be silently listening in on any call, I think that would have prevented them becoming a leader in video conference tech. So the right fine here is their entire market cap. That would put them back at square one, which is where an honest competitor would be right now.
Which competitors offered true E2E?
I think mostly they were (misleadingly/lyingly) promissing something above what most of their competitors offered, no?
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#176Re: Zoom lied to users about end-to-end encryption for years, FTC says
#177Earlier quoted context omitted.
Zoom lied. People spied.
>People spied. Did they? Which people? When? How?
Also, think of the competitors of zoom who lost customers to them due to their lying, that's a harm too, eh?
These are hard to quantify but they're not nothing.
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#178Pretty ridiculous for the US to be enforcing this while they try to ban and reduce availability of E2EE worldwide. Zoom et all are doing them a great service by spreading FUD and confusion about what E2EE even is. Once it's reduced to "complex math thing" in people's minds no one will know or care when they ban it.
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#179Earlier quoted context omitted.
Zoom lied. People spied.
>People spied. Did they? Which people? When? How?
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#180A deeper issue is how hard it is to "know" if companies hawking products with security implications (which is nearly everything, today) are lying. I'm not even talking about the gradient ranging from innocent bugs to incompetent coders and how that gets papered over. When you buy shoddy physical goods, there are typically characteristics you can't hide, like cheap materials. But with software like this of course the…
Any software you don't have the source for, haven't built yourself, and don't host yourself is immediate suspect. Third party audits aren't a silver bullet. Enron and Worldcom had third party audits.
This means that I try to design in such a way that a reasonably competent dev could sit down and rewrite the whole system in a couple hours/days/weeks.