Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

261–270 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#261

Earlier quoted context omitted.

> I don't understand why people trust them or still use their product if they are at all concerned about security. I've been a Zoom apologist from the beginning, and this is the money shot for me. What exactly do you mean by "security"? You're concerned zoom servers are recording your video - on purpose or because theyre compromised? thats too much data to dragnet (even for the NSA), so you think the servers are reco…

My therapist uses Zoom for her clients, as she was assured that the E2E would help her meet HIPAA requirements and protect her patients. If someone can get a transcript of what was said, let alone record, in these therapy sessions, they'd have a goldmine to blackmail from. Please note, this has legal significance for her and other doctors, who'd started seeing patients over Zoom. So it's not just an abstract, "lulz s…

> E2E would help her meet HIPAA requirements

e2e is not a hipaa requirement.

> So it's not just an abstract, "lulz security"

by all means, show me all the concrete harm zoom has done.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#262

Earlier quoted context omitted.

Perhaps. But at minimum there would still be some server necessary for discovery purposes.

The client application was also the server application. Clients with good connections which appeared to always be online became super nodes which were the directory "servers" you would connect to. The code base contained a long list of previously known super nodes and would attempt to connect to those on first start. As it ran it would keep syncing the list of close super nodes. There were many hundreds of super node…

Interesting. I didn't realize that Skype was really P2P. Thanks for sharing :)

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#263
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

"In part because executives, marketers and salespeople don't know what it means." Being a technical founder, I found some non-technical founders use this an advantage. They can lie to customers without guilt or investors with brimming confidence about their "MVP". They can use "making it simple" or "ignorance" as an excuse, if at all they get caught. These kind of lies are grey lines and exist everywhere.

I've worked with these types of people and what I've noticed is, even after you explain to them simply what they're saying is false, they insist or pushing those statements or as close to those labels as they can. They may even be angry after you inform them because they lose plausible deniability.

I've also been in situations where an ultimatum like E2E encryption is dictated by a marketing team and then expected to be created without adequate budgeting or time, essentially creating pressures on development teams, project/product managers, etc to lie.

The conclusion I've come to in business is that ultimately, your product or service is going to be falsely advertised and oversold one way or another. It's a lot easier for some to lie, act deceitful, and/or feign ignorance than it is to actually deliver. Your competitors are doing it, if you don't, you lose.

The way I deal with this nonsense is that I make it a point at least once in meeting or fairly tracable record like an email that others know what is and isn't true once and it's up to them to decide who they want to lie to. I've been on the other side being pressured to lie and its not fun so I'll happily pass that responsibility. I didn't pursue a career in computing to be a constant liar, I'll let the people who want to lie, lie.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#264
post #230

Earlier quoted context omitted.

As another poster said, the very large company I work at bans Zoom. We can use Teams, Webex, Skype, etc. How can you say there is no alternative?

Sorry, I didn't think in terms of degrees of untrustworthiness. What I miss is an open-source alternative. Doesn't Microsoft let the NSA tap into Skype calls?

How about Jitsi?

https://meet.jit.si/

https://jitsi.org/

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#265
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

Regulation should prevent this from occurring. If you use a product that claims it is E2E and it is not, you should be able to sue wildly for potential damages given the sensitive nature of the software.

Well, there might be conflicting interests within government. From a consumer advocate perspective government might want to demand this. From an intelligence services perspective you might want companies to lie.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#267

Earlier quoted context omitted.

"In part because executives, marketers and salespeople don't know what it means." Being a technical founder, I found some non-technical founders use this an advantage. They can lie to customers without guilt or investors with brimming confidence about their "MVP". They can use "making it simple" or "ignorance" as an excuse, if at all they get caught. These kind of lies are grey lines and exist everywhere.

I've worked with these types of people and what I've noticed is, even after you explain to them simply what they're saying is false, they insist or pushing those statements or as close to those labels as they can. They may even be angry after you inform them because they lose plausible deniability. I've also been in situations where an ultimatum like E2E encryption is dictated by a marketing team and then expected to…

>Your competitors are doing it, if you don't, you lose.

What's far more interesting to me is the fact that your vendors are doing it. I wonder how much business efficiency could be gained by taking advantage of the fact that we all know the products our businesses are buying are oversold?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#268

Earlier quoted context omitted.

Any software you don't have the source for, haven't built yourself, and don't host yourself is immediate suspect. Third party audits aren't a silver bullet. Enron and Worldcom had third party audits.

You're right, but 3rd party audits can help, especially because the precedent set by Arthur Andersen w/ Enron. It destroyed their business completely when their fraud was discovered, so there would be a strong incentive for auditors to get it right. As you said, not a silver bullet, but it's a step up from nothing.

> It destroyed their business completely when their fraud was discovered...

I suppose rebranding and transferring assets is kind of like a Chapter 7 "destroyed their business completely", but no one involved went to jail, no one lost their Series 7 or any other kind of licensing, no one was ever barred for life from ever managing at a public company ever again, etc. Sure, to laypeople a selling off of assets and rebranding sounds pretty "destroyed...completely", but unless there are lifelong, severe, natural person repercussions, business people are thrilled with the results. No clawbacks, no offender registration, can always point the blame elsewhere in future discussions (like job interviews). This is mostly regulatory theater, and all net upside for those who benefited by unethical action or by unethical omission.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#269
post #131

Earlier quoted context omitted.

Yep. They're fining the customer fraud, not the lack of E2EE. I wish executives would start going to jail over this stuff. Bet they'd stop lying to their customers then.

Yeah, I get the impression that if some guy frauds a bunch of rich guys, he goes to jail, but if a corporation frauds millions of users, they're just politely asked to behave.

Indeed. The government basically says "Please give us 1% of the profit you made from defrauding millions, and we will call it a day."

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#270

Earlier quoted context omitted.

Any software you don't have the source for, haven't built yourself, and don't host yourself is immediate suspect. Third party audits aren't a silver bullet. Enron and Worldcom had third party audits.

You're right, but 3rd party audits can help, especially because the precedent set by Arthur Andersen w/ Enron. It destroyed their business completely when their fraud was discovered, so there would be a strong incentive for auditors to get it right. As you said, not a silver bullet, but it's a step up from nothing.

> Firms That Imploded Have Something in Common: Ernst and Young Audited Them

https://www.wsj.com/articles/string-of-firms-that-imploded-h...

https://news.ycombinator.com/item?id=24802741

Nobody at Arthur Andersen went to prison and SCOTUS reversed their conviction. The firm may have gone up in smoke, but nobody was actually punished for their crimes. Who at Ernst and Young has gone to prison for Wireguard or WeWork? None by my count.

Post reply on HN