Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

281–290 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#281
post #230

Earlier quoted context omitted.

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

As another poster said, the very large company I work at bans Zoom. We can use Teams, Webex, Skype, etc. How can you say there is no alternative?

I know of more than one company where installing zoom on any company owned equipment, or using zoom on your own client devices for company business is a fireable offense.

These are companies that deal with some very sensitive data.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#282

Earlier quoted context omitted.

My therapist uses Zoom for her clients, as she was assured that the E2E would help her meet HIPAA requirements and protect her patients. If someone can get a transcript of what was said, let alone record, in these therapy sessions, they'd have a goldmine to blackmail from. Please note, this has legal significance for her and other doctors, who'd started seeing patients over Zoom. So it's not just an abstract, "lulz s…

> E2E would help her meet HIPAA requirements e2e is not a hipaa requirement. > So it's not just an abstract, "lulz security" by all means, show me all the concrete harm zoom has done.

> e2e is not a hipaa requirement.

Encryption between the last HIPAA covered entity (including business associates) on one end and the first covered entity (including BAs) on the other (or between covered entity on one end and patient on the other) is effectively a requirement of HIPAA in communications between HIPAA covered entities of PHI, since anything else would constitute an unauthorized intentional disclosure of PHI to the third party intermediary (which is a crime, as well as triggering civil liability), and even a third party gaining access to unencrypted PHI without an intentional disclosure is a breach of unsecured PHI triggering mandatory reporting requirements under the HITECH Act.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#283

Earlier quoted context omitted.

Perhaps. But at minimum there would still be some server necessary for discovery purposes.

The client application was also the server application. Clients with good connections which appeared to always be online became super nodes which were the directory "servers" you would connect to. The code base contained a long list of previously known super nodes and would attempt to connect to those on first start. As it ran it would keep syncing the list of close super nodes. There were many hundreds of super node…

Isn’t that also how BitTorrent’s DHT works?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#284

Earlier quoted context omitted.

That's kind of the point isn't it? You can't know, because it wasn't actually e2ee, eh? That's the harm. Also, think of the competitors of zoom who lost customers to them due to their lying, that's a harm too, eh? These are hard to quantify but they're not nothing.

Well, we can know. It was encrypted, but not E2EE, so the only person who could have spied was Zoom itself, and we know the how too - by the same mechanism it performs a video recording, for example. We just don't know if . But seeing as we've had zero reports of any real-world consequences that could only have come about by Zoom spying, combined with the fact that "spying on your customers" is anathema to your busin…

"We can know" ... "We just don't know if." ??

And that's not what Occam's Razor means.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#285
post #265

Earlier quoted context omitted.

Regulation should prevent this from occurring. If you use a product that claims it is E2E and it is not, you should be able to sue wildly for potential damages given the sensitive nature of the software.

Well, there might be conflicting interests within government. From a consumer advocate perspective government might want to demand this. From an intelligence services perspective you might want companies to lie.

> From an intelligence services perspective you might want companies to lie.

No, I don't. I don't want companies to lie. You can collect intelligence the same way we've been collecting intelligence for our entire history on this planet prior to E2E comms. E2E isn't a hindrance, it's a way to enforce limitations on government overreach.

No freedom is without compromise.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#286
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

Oh man I had a great one last week.

We're migrating stuff to a cloud provider, and they wanted to expose an internal only API to the internet so that the things could reach it. I was strongly against that, as it has no security involved at all. Fast and loose and all of that.

Two, count them, two people wanted to "just change it to use port 443, that way it's encrypted". I had to explain that you could pick any valid TCP port to pass TCP traffic, but simply changing a nonstandard port to "443" doesn't automatically make it start being encrypted. I had to explain that several times in order for it to sink in.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#287
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

A working alternative is google _meet_

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#288
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

> from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations

Unless I'm misunderstanding what you mean by that, I don't really see the point in it, TBH.

Have there been cases of Zoom infecting machines with malware or transmitting viruses? The whole concern, as far as I know, is terrible security on their end, allowing people into calls without permission, not having E2E encryption, etc, and running as an unprivileged user won't help with that at all.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#289

Earlier quoted context omitted.

Well, we can know. It was encrypted, but not E2EE, so the only person who could have spied was Zoom itself, and we know the how too - by the same mechanism it performs a video recording, for example. We just don't know if . But seeing as we've had zero reports of any real-world consequences that could only have come about by Zoom spying, combined with the fact that "spying on your customers" is anathema to your busin…

You definitely can’t apply Occam’s razor simply because you don’t have access to information.

[deleted]

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#290
post #214

Earlier quoted context omitted.

From https://www.cnbc.com/2020/04/15/oracles-larry-ellison-calls-... : Along with is growth in users, Zoom has seen concerns spike about how it is protecting users’ privacy. The Senate advised members not to use the service, according to Ars Technica and the New York City Department of Education banned its use for remote learning. A group of state attorneys general are probing the company after one of the officials w…

So Ellison 'supports' Zoom, but as far as I can tell the connection with Trump is pure speculation.

It is was a prelude to what happened to TikTok. Or almost happened to TikTok as now with the Trump administration is gone, it makes no sense to do a deal with Oracle.
Post reply on HN