Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

241–250 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#241
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

You answered your own question in your last statement. People don't care about security. They care about it being easy to use and Zoom works better and for more (non-technical) users than any other tool of its kind.

For a long time zoom was the best choice for technical users too, as webex, Skype, and everything except for google hangouts had terrible Linux support.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#242
post #225

Earlier quoted context omitted.

had a boss that marketed our product as having AI solutions while it had nothing to do with AI, lol.

Given how most actual AI solutions work under the hood, this might not even be a lie!

That many (most?) companies in this space lie through their teeth doesn't excuse the lie.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#243
post #232

Earlier quoted context omitted.

Given how most actual AI solutions work under the hood, this might not even be a lie!

Our system has an AI module. AI module: If something Else if something else Else if Else if ... Else Call Human

We practice responsible and safe approach to AI, by detecting situations the AI can't handle and deferring to human response.

(It just so happens that the set of things the AI can handle is empty.)

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#244
post #232

Earlier quoted context omitted.

Given how most actual AI solutions work under the hood, this might not even be a lie!

Our system has an AI module. AI module: If something Else if something else Else if Else if ... Else Call Human

To be honest, before the modern machine learning approach, this was known as a decision tree and was thought to be a valid way to approach "artificial intelligence". Lots of "AI" hype in the 80s was based around "Expert systems" and "Decision trees".

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#245
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

> I don't understand why people trust them or still use their product if they are at all concerned about security.

I've been a Zoom apologist from the beginning, and this is the money shot for me. What exactly do you mean by "security"? You're concerned zoom servers are recording your video - on purpose or because theyre compromised? thats too much data to dragnet (even for the NSA), so you think the servers are recording and theyre targeting your meeting specifically? the threat model here is very small and very specific.

who are the ultrasecret sensitive information folks buying the newest, shiniest, unvetted tool for use where infosec matters? i bought zoom because the ui has simple, big, colorful buttons for my unskilled users where g2m et al. are just a little too complicated.

if i needed an SLA specifying encryption models because of "security", I'd have a contract I could sue over. yes, zoom was wrong. they did a wrong thing, but the outcry against them has just been disproportionate.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#246
post #230

Earlier quoted context omitted.

As another poster said, the very large company I work at bans Zoom. We can use Teams, Webex, Skype, etc. How can you say there is no alternative?

Sorry, I didn't think in terms of degrees of untrustworthiness. What I miss is an open-source alternative. Doesn't Microsoft let the NSA tap into Skype calls?

>Doesn't Microsoft let the NSA tap into Skype calls?

Yes, but it seems like Skype was doing that prior to being acquired (though Microsoft seems to have accelerated things). From some quick Googling to refresh on PRISM –

>• In July last year, nine months after Microsoft bought Skype, the NSA boasted that a new capability had tripled the amount of Skype video calls being collected through Prism;

>• Microsoft helped the NSA to circumvent its encryption to address concerns that the agency would be unable to intercept web chats on the new Outlook.com portal;

>Eight months before being bought by Microsoft, Skype joined the Prism program in February 2011.

> According to the NSA documents, work had begun on smoothly integrating Skype into Prism in November 2010, but it was not until 4 February 2011 that the company was served with a directive to comply signed by the attorney general.

https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-...

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#247
post #230

Earlier quoted context omitted.

As another poster said, the very large company I work at bans Zoom. We can use Teams, Webex, Skype, etc. How can you say there is no alternative?

Sorry, I didn't think in terms of degrees of untrustworthiness. What I miss is an open-source alternative. Doesn't Microsoft let the NSA tap into Skype calls?

I wouldn't assume that any given service is secure just because it hasn't been outed yet. Your guess is as good as mine with regard to which service is more secure or less secure.

What is immensely important is to raise the cost of lying to where it becomes something investors care about. The only real thing a company and its investors are afraid of is losing its customers.

If we teach companies it is okay to lie by staying with them, they will lie more.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#248
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

> I don't understand why people trust them or still use their product if they are at all concerned about security. I've been a Zoom apologist from the beginning, and this is the money shot for me. What exactly do you mean by "security"? You're concerned zoom servers are recording your video - on purpose or because theyre compromised? thats too much data to dragnet (even for the NSA), so you think the servers are reco…

My therapist uses Zoom for her clients, as she was assured that the E2E would help her meet HIPAA requirements and protect her patients.

If someone can get a transcript of what was said, let alone record, in these therapy sessions, they'd have a goldmine to blackmail from.

Please note, this has legal significance for her and other doctors, who'd started seeing patients over Zoom. So it's not just an abstract, "lulz security"

There are people out there with different threat models from you. Please refrain from talking about use cases you may not understand.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#249
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

"In part because executives, marketers and salespeople don't know what it means." Being a technical founder, I found some non-technical founders use this an advantage. They can lie to customers without guilt or investors with brimming confidence about their "MVP". They can use "making it simple" or "ignorance" as an excuse, if at all they get caught. These kind of lies are grey lines and exist everywhere.

Have also encountered founders that know the difference, but lie about things by using 'weasel words' that are chosen to suit their audience, who may not be so knowledgeable :(

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#250

Earlier quoted context omitted.

Well, corporations aren't humans, contrary to what some might try to argue.

True enough. But they are comprised entirely of people. To change their behavior you must appeal to the people running them.

Not necessarily. Corporations are more than just sum of the people - they are a process that runs on top of people. People themselves are replaceable - and if you change the behavior of one to something the corporation doesn't want, it'll replace that person with someone new. You want to change the behavior of the corporation itself - and that's best done by creating monetary incentives and disincentives (i.e. punishment). The corporation will adjust the behavior of people on its own.

In other words: "appealing to the people" instead of addressing the corporation itself is like trying to heat up a climate-controlled room by lighting a small fire in it. You'll be fighting the AC unit all the way and causing lots of unnecessary damage, when the right way to do it is to adjust the thermostat on the AC unit.

Post reply on HN