Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

231–240 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#231
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

Regulation should prevent this from occurring. If you use a product that claims it is E2E and it is not, you should be able to sue wildly for potential damages given the sensitive nature of the software.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#232
post #225

Earlier quoted context omitted.

had a boss that marketed our product as having AI solutions while it had nothing to do with AI, lol.

Given how most actual AI solutions work under the hood, this might not even be a lie!

Our system has an AI module.

AI module:

If something

Else if something else

Else if

Else if

...

Else Call Human

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#233

Earlier quoted context omitted.

Wasn’t Skype pre-MS P2P, not server based?

Perhaps. But at minimum there would still be some server necessary for discovery purposes.

The client application was also the server application. Clients with good connections which appeared to always be online became super nodes which were the directory "servers" you would connect to. The code base contained a long list of previously known super nodes and would attempt to connect to those on first start. As it ran it would keep syncing the list of close super nodes. There were many hundreds of super nodes, so the odds of all of them changing or going offline were pretty slim.

I imagine some people at Skype probably kept a few instances of Skype running at the office. So they technically hosted a few super nodes, but it wasn't necessarily that they were running some vastly different server version of the app. It wasn't until Microsoft decided to cut down on the P2P aspect of the app and hardcode only Azure-hosted super nodes into the application that this changed.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#234

Earlier quoted context omitted.

Well, corporations aren't humans, contrary to what some might try to argue.

True enough. But they are comprised entirely of people. To change their behavior you must appeal to the people running them.

My gripe is the companies who failed to implement because they couldn't do security in a way that was easy to use and resulted in a good user experience, but chose to be honest.

I hate the

(1) cheat to win and vanquish your competitors

(2) when you're caught, say you're sorry,

(3) win anyway because your competitors are gone

progression. It seems like the penalty for that should be existential or at least something painfully severe.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#235
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

What does not work with jitsi? I've been using a lot recently and it is by far the easiest one to use. One link and done. I have lots of video and audio issues with zoom. Now, if you're a company, bluejeans may be the best one.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#236
post #230

Earlier quoted context omitted.

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

As another poster said, the very large company I work at bans Zoom. We can use Teams, Webex, Skype, etc. How can you say there is no alternative?

Sorry, I didn't think in terms of degrees of untrustworthiness. What I miss is an open-source alternative. Doesn't Microsoft let the NSA tap into Skype calls?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#237

Earlier quoted context omitted.

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

What does not work with jitsi? I've been using a lot recently and it is by far the easiest one to use. One link and done. I have lots of video and audio issues with zoom. Now, if you're a company, bluejeans may be the best one.

There was a period a few months ago where jitsi was consistently crashing chromebooks. Obviously, if a webpage can crash the OS, it's an OS problem, but it still made jitsi unusable for those with chromebooks.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#238

Earlier quoted context omitted.

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

What does not work with jitsi? I've been using a lot recently and it is by far the easiest one to use. One link and done. I have lots of video and audio issues with zoom. Now, if you're a company, bluejeans may be the best one.

I think both video and audio were skippy to the point of uselessness. I've also used Jitsi with moderate success with a couple of interlocutors, where video disappeared now and then.

I'm not a company, I'm at a university, and the u. has decided to use Zoom, perhaps because it doesn't care about security, or because it thinks being concerned about Zoom is being paranoid.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#239
This is like suing Hillshire Farms because their bacon wasn't as maple-honey-bourbon-flavored as they claimed. Nobody is buying bacon just for flavoring. People use Zoom because it's a free digital telephone with screen sharing. Not because it's super duper secure.

Telephones (VoIP, PSTN, SMS, etc) do not have end-to-end encryption - or any encryption - and we've been using them for conferences since always. Hell, we use them for Zoom calls!

This is some kind of government vendetta, probably pushed by Zoom's competitors who make a bundle in government contracts. Because they're currently the biggest provider, they're the biggest target. But this standard has not been (and will not be) held up to any of its competitors who make similar claims. The political party that is sabre-rattling in this article is just making themselves look good to their constituents.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#240
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

"In part because executives, marketers and salespeople don't know what it means."

Being a technical founder, I found some non-technical founders use this an advantage. They can lie to customers without guilt or investors with brimming confidence about their "MVP". They can use "making it simple" or "ignorance" as an excuse, if at all they get caught. These kind of lies are grey lines and exist everywhere.

Post reply on HN