Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

251–260 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#251
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

Yes, retention by strong network effect is scary. But I'm being Captain Obvious here :-)

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#252
post #232

Earlier quoted context omitted.

Our system has an AI module. AI module: If something Else if something else Else if Else if ... Else Call Human

To be honest, before the modern machine learning approach, this was known as a decision tree and was thought to be a valid way to approach "artificial intelligence". Lots of "AI" hype in the 80s was based around "Expert systems" and "Decision trees".

And there are even modern tree based approaches, that beat some of the modern artificial neural network approaches! It's not like it has become an absolutely unusable class of algorithms.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#253
post #179

Earlier quoted context omitted.

All network traffic in the US should be seen as the opposite of innocent untill proven guilty: Unless you can prove otherwise, everything we know of surveillance tells us that of course everything and everyone was spied upon. I can't think of any reason the NSA and/or CIA should not have spied when they do so on everything else they can get their hands on.

Years ago, this attitude was seen as paranoid and bonkers. Then Snowden proved it true. Not only true, but barely scratching the surface. What's actually happening is beyond the wildest fever-dreams of the most extreme 90s crypto-punk ever. Why are people still able to pretend otherwise without being laughed out of the room?

> Why are people still able to pretend otherwise without being laughed out of the room?

It is a variant of a Bible Thumper & Bootlegger coalition.

A large portion of the population really doesn't want to believe it. A small population with a vested interest (and lots of relevant tools at its disposal) is happy to help them.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#254
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

> I don't understand why people trust them or still use their product if they are at all concerned about security. I've been a Zoom apologist from the beginning, and this is the money shot for me. What exactly do you mean by "security"? You're concerned zoom servers are recording your video - on purpose or because theyre compromised? thats too much data to dragnet (even for the NSA), so you think the servers are reco…

Therapists, lawyers, courts including closed door courts, confidential internal meetings for publically traded companies, doctors appointments, exchanging passwords/etc. Even my mom just telling me about a medical situation she's having.

All of those have legal requirements for privacy, and many of them used Zoom because it was supposed to meet those requirements. Zoom lied and failed to meet those requirements. There are other ways to meet those requirements (instead of E2E encryption you can have other kinds of controls) but since Zoom claimed to have E2E, they didn't bother with those other ways of meeting the requirements.

This wasn't an accident or a discrepency. Zoom didn't accidentally have some kind of fancy attack that could be pulled off. They literally, knowingly and plainly misrepresented their product, to get sales they shouldn't have. There are words for that like "Fraud".

People at Zoom should be getting jail sentences.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#255
post #230

Earlier quoted context omitted.

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

As another poster said, the very large company I work at bans Zoom. We can use Teams, Webex, Skype, etc. How can you say there is no alternative?

Each of those alternatives is just as likely to offer government wiretap support to any government that asks as Zoom is, unless I’ve missed statements of refusal to do so to the contrary from them.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#256
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

Tell us!

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#257
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

My boss is one of those people. He insists to our customers (and engineers) our product has encryption. It does not.

I would have a conversation with your companies legal department.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#258

Earlier quoted context omitted.

That's encryption for the state, not for us peasants.

Can the govenment somehow restrict end-to-end encrypted messaging to officials only?

They can try the same as they can pass any other law. Of course, whether or not practically they can do it is another issue altogether...

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#259
post #216
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

Hi there! I'm in the video meeting space, and always looking to find that blend between usable and secure. I'm curious - is there a video service out there you would recommend if you're conscious about security? Your third paragraph makes me think your opinion will be that no large company can be trusted, because they become a target for nation-state regulatory bodies.

Yes, although there are degrees and differences in culture.

For instance in the telco world you have a much more direct dependence on regulators because you need a stack of expensive and hard to acquire licenses to operate a network in most parts of the world. Some worse than others. In that environment there is a very high degree of compliance with regulators because they have to be given explicit permission to operate.

For pure internet services or P2P applications it is quite a bit different. You don't actually need anyone's permission to distribute software. And you can move your servers around the world. You don't depend on permission - just that nobody comes after you with warrants you cannot ignore.

So the advice is really to look at who you are dealing with and how dependent they are on regulators to operate.

Large internet companies tend to have entire divisions whose job it is to tell regulators to get lost or at the very least maintain a really high bar for interference. Of course, this becomes difficult when the government is also a large customer. So for instance you might want to be careful with vendors who make a lot of money in / off of the defense and intelligence sectors.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#260

Earlier quoted context omitted.

That's encryption for the state, not for us peasants.

Can the govenment somehow restrict end-to-end encrypted messaging to officials only?

Given the opportunity, most governments would. Just look at the US's attempts to force phone OS vendors to include backdoors
Post reply on HN