Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

221–230 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#221
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

You answered your own question in your last statement. People don't care about security. They care about it being easy to use and Zoom works better and for more (non-technical) users than any other tool of its kind.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#223

> Zoom has agreed to a requirement to establish and implement a comprehensive security program, a prohibition on privacy and security misrepresentations, and other detailed and specific relief to protect its user base What a slap on the wrist. "You blatantly lied to your customers for years. How about you just continue to implement the thing that you were working on anyways." I don't think punishment is always the be…

> a prohibition on privacy and security misrepresentations

Why did they have to "agree" to that? Shouldn't that already not be allowed? Also, this sounds a bit like they're allowed to misrepresent other things...

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#225
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

My boss is one of those people. He insists to our customers (and engineers) our product has encryption. It does not.

had a boss that marketed our product as having AI solutions while it had nothing to do with AI, lol.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#226
post #169
post #148

Earlier quoted context omitted.

Punishment is the best solution. Incentives are what drive behavior, and learning that you can get away with lying will just lead to more getting away with lying.

When it comes to training humans and animals, positive punishment is far less effective than most other training techniques like positive reinforcement. Don't Shoot the Dog[1]! [1] https://www.amazon.com/Dont-Shoot-Dog-Teaching-Training/dp/0...

Wouldn't fees be considered negative punishment?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#227
Few years ago I noticed BBM Enterprise touts end-to-end encryption pretty strongly in their marketing, without mentioning an up-front caveat.

https://www.blackberry.com/us/en/products/bbm-enterprise

Turns out that by default, BBME is not end-to-end. The initial handshake is transparent to Blackberry, and they could use that to decrypt future messages without your knowledge.

To enable true end-to-end, you have to opt in to an out of band handshake to start each new conversation, an option you can turn on in their admin console.

How many people are actually going to opt in to dealing with a confirmation SMS for every new thread?

I reached out to Blackberry at the time to update their literature as it was misleading, but no action was taken by them.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#228
post #21

If Zoom made clear to users that connections were not secured to the same standards as competitors, and that potentially hundreds of employees could be silently listening in on any call, I think that would have prevented them becoming a leader in video conference tech. So the right fine here is their entire market cap. That would put them back at square one, which is where an honest competitor would be right now.

Not defending them in any way - but don't think security was the primary reason for Zoom taking off. It was stability - it just worked and at the same time competitors didn't. Everybody used to have Skype and I would have gladly handed over my data to MS if only it would have been able to do stable video calls. It was often a disaster for just 2-way calls, let alone group.

> It was stability - it just worked and at the same time competitors didn't.

This is absolutely huge. We've tried Teams (and I have previously used Webex and Hangouts).

It seems like there is _always_ one person that struggles with other video services. Can't join, video/audio issues, CPU usage, latency, etc. Painful when 10%+ of a meeting is consumed by getting one last, key person trying to fix their issues.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#229
post #225

Earlier quoted context omitted.

My boss is one of those people. He insists to our customers (and engineers) our product has encryption. It does not.

had a boss that marketed our product as having AI solutions while it had nothing to do with AI, lol.

Given how most actual AI solutions work under the hood, this might not even be a lie!

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#230
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

As another poster said, the very large company I work at bans Zoom. We can use Teams, Webex, Skype, etc.

How can you say there is no alternative?

Post reply on HN