Earlier quoted context omitted.
That's kind of the point isn't it? You can't know, because it wasn't actually e2ee, eh? That's the harm. Also, think of the competitors of zoom who lost customers to them due to their lying, that's a harm too, eh? These are hard to quantify but they're not nothing.
Well, we can know. It was encrypted, but not E2EE, so the only person who could have spied was Zoom itself, and we know the how too - by the same mechanism it performs a video recording, for example. We just don't know if . But seeing as we've had zero reports of any real-world consequences that could only have come about by Zoom spying, combined with the fact that "spying on your customers" is anathema to your busin…
Zoom lied to users about end-to-end encryption for years, FTC says
291–300 of 438 posts
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#292Re: Zoom lied to users about end-to-end encryption for years, FTC says
#293Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…
Phone calls and text messages aren't particularly secure either, doesn't stop people using them
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#294I think the assumed implication with E2EE is that no one other than the partcipants can get at the content of your communications. To do that you need: 1. All cryptographic keys controlled by the users. 2. Some way to confirm you are actually connected to who you think you are connected to. 3. A way to confirm that the code you are running is not leaking keys/content. So Zoom failed on all 3 points. There are lots of…
> almost all fail on point 2 unless the user does things that they almost never do Are you referring to the "scan this QR code to verify your partner's key" function in secure messaging apps? I definitely use that. I try to keep all my primary contact's keys verified. It's harder during COVID when you're not meeting up in person as often, because anything besides meeting in person and verifying the two devices direct…
Yes. Or read the weird numbers/letters over the phone. Or look at the strange image and compare it somehow.
For all I know there is something out there that wants you to compare a tune...
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#295Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…
> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. Phone calls and text messages aren't particularly secure either, doesn't stop people using them
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#296Earlier quoted context omitted.
> E2E would help her meet HIPAA requirements e2e is not a hipaa requirement. > So it's not just an abstract, "lulz security" by all means, show me all the concrete harm zoom has done.
> e2e is not a hipaa requirement. Encryption between the last HIPAA covered entity (including business associates) on one end and the first covered entity (including BAs) on the other (or between covered entity on one end and patient on the other) is effectively a requirement of HIPAA in communications between HIPAA covered entities of PHI, since anything else would constitute an unauthorized intentional disclosure o…
Because plain old telephone service is not E2E and the phone company can eavesdrop on you quite easily (as can the government with a warrant, or a bad guy with a phone tap on your line...)
Not saying that e2e shouldn’t be used when practicable but a blanket assertion that e2e is required for HIPAA seems a little unbelievable to me when I’ve recently received COVID test results from providers via a cell phone call.
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#297Earlier quoted context omitted.
had a boss that marketed our product as having AI solutions while it had nothing to do with AI, lol.
Given how most actual AI solutions work under the hood, this might not even be a lie!
Even back in the 80's, the computer algorithms that played the other side in computer games was called "the AI".
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#298Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…
Regulation should prevent this from occurring. If you use a product that claims it is E2E and it is not, you should be able to sue wildly for potential damages given the sensitive nature of the software.
It already exists. It's called "fraud".
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#299Earlier quoted context omitted.
"In part because executives, marketers and salespeople don't know what it means." Being a technical founder, I found some non-technical founders use this an advantage. They can lie to customers without guilt or investors with brimming confidence about their "MVP". They can use "making it simple" or "ignorance" as an excuse, if at all they get caught. These kind of lies are grey lines and exist everywhere.
I've worked with these types of people and what I've noticed is, even after you explain to them simply what they're saying is false, they insist or pushing those statements or as close to those labels as they can. They may even be angry after you inform them because they lose plausible deniability. I've also been in situations where an ultimatum like E2E encryption is dictated by a marketing team and then expected to…
We expect name brand products to indemnify their vendors to an extent. Consumers don't want to chase down the guy who made the screw that failed and caused a bunch of excess deaths. You put the screw in the assembly, you took most of the profit margins. So you get the lawsuit.
If you want to go and sue your vendor to recover damages, that's between you and the vendor. But the class action goes to Acme Inc, not Acme Screws and Fasteners.
Similarly, I'm not getting a mansion. I can barely get you to buy the servers we need to make half of what you say not a blatant lie. I'm not the one who should be punished when they find out about it. I'm not the one lying to people's faces while I pocket their checks.
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#300Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…
Hi there! I'm in the video meeting space, and always looking to find that blend between usable and secure. I'm curious - is there a video service out there you would recommend if you're conscious about security? Your third paragraph makes me think your opinion will be that no large company can be trusted, because they become a target for nation-state regulatory bodies.