Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

181–190 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#181
post #84

Earlier quoted context omitted.

Most videoconferencing systems are not E2E-encrypted. They encrypt the link between each participant and the central server. This makes implementation simpler in a few ways. A good E2E-encrypted system would involve Zoom never having the keys at all, so "key storage" would be irrelevant. The issue here is merely that Zoom claimed to be E2E-encrypted when they were not. They could have simply said "encrypted" and ther…

Wouldn't E2E encryption of a call with 40 participants require each user to have 39 times the upload bandwidth, in order to send 39 video streams encrypted with different keys? And potentially several times the computational cost on the client, in order to downsample video according to the different available download bandwidth of every other participant? Is there anyone doing group videoconferencing with E2E encrypt…

>Wouldn't E2E encryption of a call with 40 participants require each user to have 39 times the upload bandwidth, in order to send 39 video streams encrypted with different keys?

I think you use public key cryptography to securely distribute an encryption key for that call. So the host sends 39 messages encrypted with different keys containing a shared key. Then everyone uses the shared key to encrypt/decrypt the call data.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#182
post #23

Does it open Zoom to being sued by clients? If a company signed a contract with Zoom in which e2e encryption was stated.

Like a class action lawsuit? I think there have to be evidence of damage done in that case.

If a company signed a contract with Zoom in which e2e encryption was stated.

It sounds like OP is referring to a breach of contract. Even if they can't prove damages, they could still be entitled to some other remedy, like a partial refund. It would depend on the language of the contract, of course.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#183

Earlier quoted context omitted.

Is it minor? From my perspective, making security guarantees about a product is the same whether that product is software or hardware. If somebody guaranteed that their ferris wheel had x safety feature, then it turned out to be untrue, nobody would call that a minor infraction.

I agree. I see false advertising as a serious crime. Obviously we should be utilizing critical thinking ourselves, but I think that we also need the threat of punishment. Because if we have that threat one critical thinker can report the problem and it will be solved for everyone. If there is no punishment then there is no incentive for companies to tell the truth.

Exactly. Zoom should pay. Not crippling amounts, but non-trivial ones.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#184

> Zoom has agreed to a requirement to establish and implement a comprehensive security program, a prohibition on privacy and security misrepresentations, and other detailed and specific relief to protect its user base What a slap on the wrist. "You blatantly lied to your customers for years. How about you just continue to implement the thing that you were working on anyways." I don't think punishment is always the be…

Certainly with government access to messages. The minds in charge would never let such an opportunity slip. They are set in the cold war of terror and that won't change for the current generation. So it is still not a good idea to use Zoom.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#185
post #148

> Zoom has agreed to a requirement to establish and implement a comprehensive security program, a prohibition on privacy and security misrepresentations, and other detailed and specific relief to protect its user base What a slap on the wrist. "You blatantly lied to your customers for years. How about you just continue to implement the thing that you were working on anyways." I don't think punishment is always the be…

Punishment is the best solution. Incentives are what drive behavior, and learning that you can get away with lying will just lead to more getting away with lying.

[deleted]

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#186

Earlier quoted context omitted.

Is it minor? From my perspective, making security guarantees about a product is the same whether that product is software or hardware. If somebody guaranteed that their ferris wheel had x safety feature, then it turned out to be untrue, nobody would call that a minor infraction.

I agree. I see false advertising as a serious crime. Obviously we should be utilizing critical thinking ourselves, but I think that we also need the threat of punishment. Because if we have that threat one critical thinker can report the problem and it will be solved for everyone. If there is no punishment then there is no incentive for companies to tell the truth.

Especially if one is ideologically committed to light touch regulation / free market economics. This makes false advertising a particularly serious crime because it introduces a false information asymmetry between the customer and supplier that damages the effective functioning of the market.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#187
post #169
post #148

Earlier quoted context omitted.

Punishment is the best solution. Incentives are what drive behavior, and learning that you can get away with lying will just lead to more getting away with lying.

When it comes to training humans and animals, positive punishment is far less effective than most other training techniques like positive reinforcement. Don't Shoot the Dog[1]! [1] https://www.amazon.com/Dont-Shoot-Dog-Teaching-Training/dp/0...

Actually intermittent reinforcement is much more effective. If it's offered every time, then when it is not offered it is less likely to trigger the desired behavior. Operant conditioning using intermittent reinforcement trains to not expect the reinforcement mechanism every time, so when it doesn't come, the desired behavior is still displayed:

https://www.sciencedirect.com/topics/psychology/intermittent...

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#188

Earlier quoted context omitted.

> don't think security was the primary reason for Zoom taking off. It was stability Stability was the main draw, but company IT departments would have had more power to ban it if there were bigger and clearer risks of corporate secrets escaping.

Any company IT department's power to ban something is inversely related to how much it's users want to use it. Also, the videoconference provider stealing company secrets it not part of most companies threat model. Teams and Slack are incredibly popular corporate tools, and neither of them offer this feature. WebEx is the only reasonably popular tool I can think of that supports it, and any security department that c…

Why isn’t it? I highly suspect the CCP stole trade secrets with zoom.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#189
post #169

Earlier quoted context omitted.

When it comes to training humans and animals, positive punishment is far less effective than most other training techniques like positive reinforcement. Don't Shoot the Dog[1]! [1] https://www.amazon.com/Dont-Shoot-Dog-Teaching-Training/dp/0...

Well, corporations aren't humans, contrary to what some might try to argue.

"Corporations are people my friend"

--Mitt Romney [0]

So we should all remember that Zoom is probably depressed right now and could probably use some support from its friends. Maybe urge GCal to send it a nice note.

[0] https://www.npr.org/sections/itsallpolitics/2011/08/11/13955...

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#190

> Zoom has agreed to a requirement to establish and implement a comprehensive security program, a prohibition on privacy and security misrepresentations, and other detailed and specific relief to protect its user base What a slap on the wrist. "You blatantly lied to your customers for years. How about you just continue to implement the thing that you were working on anyways." I don't think punishment is always the be…

Certainly with government access to messages. The minds in charge would never let such an opportunity slip. They are set in the cold war of terror and that won't change for the current generation. So it is still not a good idea to use Zoom.

Is that a reference to the Chinese government because it appears in Canada we are using Zoom as well.

https://www.theglobeandmail.com/opinion/article-participatin...

Post reply on HN