Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

191–200 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#191

> Zoom has agreed to a requirement to establish and implement a comprehensive security program, a prohibition on privacy and security misrepresentations, and other detailed and specific relief to protect its user base What a slap on the wrist. "You blatantly lied to your customers for years. How about you just continue to implement the thing that you were working on anyways." I don't think punishment is always the be…

> What a slap on the wrist.

Exactly. Any small startup owners would see jail time. Similar case in recent History is Trump non-profit (please no flamewars). There are tens of thousands of business-owners rotting in jail today because they embezzled half a million bucks or more - here with Trump charity you have case of at least $2 million stolen plus self-dealing and basically living your whole life/paying personal bills out of charity and what does the judge do? - "Here Mr. Trump is a $99 training seminar on "How not to steal" from your own charity. Go get you and your children watch this online class and report back when you done".

Unbelievable.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#192
post #153

A deeper issue is how hard it is to "know" if companies hawking products with security implications (which is nearly everything, today) are lying. I'm not even talking about the gradient ranging from innocent bugs to incompetent coders and how that gets papered over. When you buy shoddy physical goods, there are typically characteristics you can't hide, like cheap materials. But with software like this of course the…

Any software you don't have the source for, haven't built yourself, and don't host yourself is immediate suspect. Third party audits aren't a silver bullet. Enron and Worldcom had third party audits.

I completely agree, and that's a huge topic unto itself.

Briefly, the issue with auditing, as with most things, is incentives over time. The difference between fraud in finance and software engineering is how long the bezzle[1] lasts. In finance, it can last a very long time in up economies, leaving Big Three auditors plenty of time to scurry off. In software you have to deliver at some point, leaving lying auditors exposed to discovery by security researchers immediately.

There is certainly still room for shenanigans if not set up correctly, but less than in finance.

[1] https://moneyfyi.wordpress.com/2013/11/15/5358/

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#193

Earlier quoted context omitted.

>People spied. Did they? Which people? When? How?

That's kind of the point isn't it? You can't know, because it wasn't actually e2ee, eh? That's the harm. Also, think of the competitors of zoom who lost customers to them due to their lying, that's a harm too, eh? These are hard to quantify but they're not nothing.

Well, we can know.

It was encrypted, but not E2EE, so the only person who could have spied was Zoom itself, and we know the how too - by the same mechanism it performs a video recording, for example.

We just don't know if. But seeing as we've had zero reports of any real-world consequences that could only have come about by Zoom spying, combined with the fact that "spying on your customers" is anathema to your business model and therefore a risk no sane and rational board of directors would ever approve (moderate upside, enormous possibly business-ending downside if ever discovered)... Occam's Razor says no spying ever occurred.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#195
post #140

The relationship between Zoom and China should outright disqualify it from being used in any Democratic countries.

I don't see how democracy has anything to do with wanting to secure video calls or not but anyways, how is this worse than trusting anything from the US? Not trying to add whataboutism, but curious if you have the same look on security when made by companies that share data with someone that realistically could come after you for anything done in those calls. PRC clearly can't unless you live in PRC while the FBI and CIA operate in most of the world, more often than not hand in hand with local police or agencies.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#196
Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense).

Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out them. See second to last paragraph as to when to be wary). In part because executives, marketers and salespeople don't know what it means. And in part because when explained what it means they will insist on their own definition/interpretation and demand the product is marketed as E2E.

It is also important to note that quite often you are not dealing only with the company that makes a product, but the regulatory bodies that can pressure companies into complying with their wishes.

As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#198
post #153

A deeper issue is how hard it is to "know" if companies hawking products with security implications (which is nearly everything, today) are lying. I'm not even talking about the gradient ranging from innocent bugs to incompetent coders and how that gets papered over. When you buy shoddy physical goods, there are typically characteristics you can't hide, like cheap materials. But with software like this of course the…

Any software you don't have the source for, haven't built yourself, and don't host yourself is immediate suspect. Third party audits aren't a silver bullet. Enron and Worldcom had third party audits.

You're right, but 3rd party audits can help, especially because the precedent set by Arthur Andersen w/ Enron. It destroyed their business completely when their fraud was discovered, so there would be a strong incentive for auditors to get it right. As you said, not a silver bullet, but it's a step up from nothing.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#199
post #169

Earlier quoted context omitted.

When it comes to training humans and animals, positive punishment is far less effective than most other training techniques like positive reinforcement. Don't Shoot the Dog[1]! [1] https://www.amazon.com/Dont-Shoot-Dog-Teaching-Training/dp/0...

Unfortunately, the positives are customer adoption, and customers have already adopted zoom. This is like continuing to feed the dog treats because it's what you're used to, regardless of the outcome of their actions. But more generally, it's not obvious that individual , "reptile-brain" incentives translate to large company leadership. I'd be hugely skeptical of applying positive psychology to international corporat…

Agree with your first paragraph, less so the second. People learn corporate leadership in steps, starting with a small group. The style of successful leadership doesn't change IMO, just the number of variables and possibility for greater success/failure.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#200
post #169

Earlier quoted context omitted.

When it comes to training humans and animals, positive punishment is far less effective than most other training techniques like positive reinforcement. Don't Shoot the Dog[1]! [1] https://www.amazon.com/Dont-Shoot-Dog-Teaching-Training/dp/0...

Well, corporations aren't humans, contrary to what some might try to argue.

True enough. But they are comprised entirely of people. To change their behavior you must appeal to thepeople running them.
Post reply on HN