Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

271–280 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#271

Earlier quoted context omitted.

> I don't understand why people trust them or still use their product if they are at all concerned about security. I've been a Zoom apologist from the beginning, and this is the money shot for me. What exactly do you mean by "security"? You're concerned zoom servers are recording your video - on purpose or because theyre compromised? thats too much data to dragnet (even for the NSA), so you think the servers are reco…

Therapists, lawyers, courts including closed door courts, confidential internal meetings for publically traded companies, doctors appointments, exchanging passwords/etc. Even my mom just telling me about a medical situation she's having. All of those have legal requirements for privacy, and many of them used Zoom because it was supposed to meet those requirements. Zoom lied and failed to meet those requirements. Ther…

> Zoom lied and failed to meet those requirements.

did it? non-e2e is not the same as non-encrypted.

> They literally, knowingly and plainly misrepresented their product

Where has that been proven? as the parent pointed out, there is a wide gulf between misunderstanding and knowingly misrepresenting.

> People at Zoom should be getting jail sentences.

this is precisely why i lean against the anti-zoom sentiment. jail sentences - seriously?! what is the maximum possible harm zoom could have caused? they were wrong and they deserve to be punished, but lets keep things in perspective.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#272
post #264

Earlier quoted context omitted.

Sorry, I didn't think in terms of degrees of untrustworthiness. What I miss is an open-source alternative. Doesn't Microsoft let the NSA tap into Skype calls?

How about Jitsi? https://meet.jit.si/ https://jitsi.org/

They said: "I got them to try Jitsi once, which simply didn't work."

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#274
post #195
post #140

The relationship between Zoom and China should outright disqualify it from being used in any Democratic countries.

I don't see how democracy has anything to do with wanting to secure video calls or not but anyways, how is this worse than trusting anything from the US? Not trying to add whataboutism, but curious if you have the same look on security when made by companies that share data with someone that realistically could come after you for anything done in those calls. PRC clearly can't unless you live in PRC while the FBI and…

Did the Polish scoff at the rise of the third reich simply because their existed a line on a map dividing Germany and Poland?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#275
post #259
post #216

Earlier quoted context omitted.

Hi there! I'm in the video meeting space, and always looking to find that blend between usable and secure. I'm curious - is there a video service out there you would recommend if you're conscious about security? Your third paragraph makes me think your opinion will be that no large company can be trusted, because they become a target for nation-state regulatory bodies.

Yes, although there are degrees and differences in culture. For instance in the telco world you have a much more direct dependence on regulators because you need a stack of expensive and hard to acquire licenses to operate a network in most parts of the world. Some worse than others. In that environment there is a very high degree of compliance with regulators because they have to be given explicit permission to oper…

Thank you for the explanation! Seems to me that you're describing a trust chain where the product is directly affected by the landscape in which the parent company operates and their biggest customer base.

I really appreciate your insight.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#276
post #230

Earlier quoted context omitted.

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

As another poster said, the very large company I work at bans Zoom. We can use Teams, Webex, Skype, etc. How can you say there is no alternative?

Teams does not allow users to place themselves in breakout rooms. Webex does not allow Linux users to grant control of their screens.

When you use these platforms all the time, you find these little issues. Generally speaking, Zoom does it best, despite their problems.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#277

Earlier quoted context omitted.

Once can't just delegate responsibility like that. Any company should enage in some form of due dilligence before procuring software. If there are expecations of privacy then those should be proven by the company procuring the software, not the vendor.

How would you verify e2e encryption on a proprietary protocol? Not every company that cares about privacy has crypto experts on staff. They should have a reasonable expectation that the vendor is telling the truth.

You can't. Don't trust, but verify. If a company or individual needs strong privacy, they should verify any encryption claims.

This would mean using only libre/open source software like Jitsu or Linphone, as one could verify the code or higher experts to verify the code.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#278
post #6

Earlier quoted context omitted.

What's the difference? Aren't they the same group of people in this context?

I'm sorry, I'm not a native English speaker. According to the Oxford dictionary customers are people who buy a product or service. Zoom was thinking of giving only them E2E encryption, and actually I would pay for that service if I would trust Zoom. Currently I use telegram to speak with my friends, but the call drops quite often as we don't have stable internet connection.

Maybe, since you admit your English language skills could use some work, you should give up on linguistic pedantry and find a new hobby.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#279
post #246

Earlier quoted context omitted.

Sorry, I didn't think in terms of degrees of untrustworthiness. What I miss is an open-source alternative. Doesn't Microsoft let the NSA tap into Skype calls?

>Doesn't Microsoft let the NSA tap into Skype calls? Yes, but it seems like Skype was doing that prior to being acquired (though Microsoft seems to have accelerated things). From some quick Googling to refresh on PRISM – >• In July last year, nine months after Microsoft bought Skype, the NSA boasted that a new capability had tripled the amount of Skype video calls being collected through Prism; >• Microsoft helped th…

Don't forget about teams.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#280

Earlier quoted context omitted.

My therapist uses Zoom for her clients, as she was assured that the E2E would help her meet HIPAA requirements and protect her patients. If someone can get a transcript of what was said, let alone record, in these therapy sessions, they'd have a goldmine to blackmail from. Please note, this has legal significance for her and other doctors, who'd started seeing patients over Zoom. So it's not just an abstract, "lulz s…

> E2E would help her meet HIPAA requirements e2e is not a hipaa requirement. > So it's not just an abstract, "lulz security" by all means, show me all the concrete harm zoom has done.

> e2e is not a hipaa requirement.

But HIPAA does (iirc) require not having arbitrary third-parties to communication. E2E prevents that, but if there wasn't E2E… fairly sure Zoom isn't meant to be a third-party to therapy sessions.

> by all means, show me all the concrete harm zoom has done.

“Oh, they built houses badly? Show me all the concrete harm that's done.” We might not know until the next (metaphorical) earthquake.

Post reply on HN