Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

301–310 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#301

Earlier quoted context omitted.

I've worked with these types of people and what I've noticed is, even after you explain to them simply what they're saying is false, they insist or pushing those statements or as close to those labels as they can. They may even be angry after you inform them because they lose plausible deniability. I've also been in situations where an ultimatum like E2E encryption is dictated by a marketing team and then expected to…

> Your competitors are doing it, if you don't, you lose. What's far more interesting to me is the fact that your vendors are doing it. I wonder how much business efficiency could be gained by taking advantage of the fact that we all know the products our businesses are buying are oversold?

You may find it interesting that recently Malwarebytes was mentioned in relation to 230 of the DMCA which to my mind relates directly to this. They are an AV solution that holds "legitimate" software vendors that operate an above board business to the fire when they start any practice that they (Malwarebytes) determines is violating a PC users reasonable expectations. That software begins to be detected as "potentially unwanted software" and recommended for quarantine just like any other virus.

Malwarebytes spends a whole lot of time defending the fact it recommends software from these companies for removal and the recent SCOTUS memo on the topic sort of implies that the problem -- how do we determine the voracity of statements made by businesses regarding their software, especially software which exists in a constantly changing state -- may be headed towards getting worse as so few people are familiar with legislation also have good understanding of the inherent complexity of software.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#302
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

Google's Meet has improved considerably and most importantly it comes free with G-Suite. They are also pushing it quite hard as every calendar invite has a Google Meet link automatically included.

The reason that people went with Zoom is "because it worked." As other products improve it's hard to see what Zoom's moat is and why we should continue to pay for it.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#303
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

"In part because executives, marketers and salespeople don't know what it means." Being a technical founder, I found some non-technical founders use this an advantage. They can lie to customers without guilt or investors with brimming confidence about their "MVP". They can use "making it simple" or "ignorance" as an excuse, if at all they get caught. These kind of lies are grey lines and exist everywhere.

Some non-technical founders will just make stuff up. If they think it's a "small change", it may as well be done, so they speak about it as if it is. You correct them and you are ignored, or they tell you it's just for a high level discussion, so it doesn't matter. Sometimes they're right, sometimes they're not. It is a very fine line between stretching the truth and exaggeration, outright lies. As "technical" people we try to be precise on our language and want statements to reflect reality.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#304
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense.

Actually it makes a lot of sense. Your boss sends you a Zoom link and asks you to install Zoom. Or you're having a meeting with the CEO of some company and they send you a Zoom link, saying it's the only thing their company uses. Or you are a high school student learning online and your teacher only delivers lectures on Zoom. Most people listen to their bosses and superiors instead of protesting their viewpoints about security.

Only privileged people can protest. Others just lose their jobs, or don't get their high school diploma.

No, it's not right, but it is the reality.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#305

Earlier quoted context omitted.

> e2e is not a hipaa requirement. Encryption between the last HIPAA covered entity (including business associates) on one end and the first covered entity (including BAs) on the other (or between covered entity on one end and patient on the other) is effectively a requirement of HIPAA in communications between HIPAA covered entities of PHI, since anything else would constitute an unauthorized intentional disclosure o…

Does that mean whenever medical information is sent via phone or Fax, HIPAA is being violated today? Because plain old telephone service is not E2E and the phone company can eavesdrop on you quite easily (as can the government with a warrant, or a bad guy with a phone tap on your line...) Not saying that e2e shouldn’t be used when practicable but a blanket assertion that e2e is required for HIPAA seems a little unbel…

> Does that mean whenever medical information is sent via phone or Fax, HIPAA is being violated today?

Phone and fax are not considered “electronic” under HIPAA, so the rules, including the rule regarding encryption for exposed PHI to be considered secured vs. unsecured, specific to electronic communication don't apply. I think they may be explicitly given special treatment for some of the not-electronic-specific rules, too. They are well-known to be legacy loopholes to HIPAA privacy/security rules, which is one of the reasons fax held on so long in healthcare as a way of minimizing compliance costs.

You absolutely should not try to intuit what HIPAA requires for anything else by how fax and phone communication in healthcare operates.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#306

Earlier quoted context omitted.

I've worked with these types of people and what I've noticed is, even after you explain to them simply what they're saying is false, they insist or pushing those statements or as close to those labels as they can. They may even be angry after you inform them because they lose plausible deniability. I've also been in situations where an ultimatum like E2E encryption is dictated by a marketing team and then expected to…

> Your competitors are doing it, if you don't, you lose. What's far more interesting to me is the fact that your vendors are doing it. I wonder how much business efficiency could be gained by taking advantage of the fact that we all know the products our businesses are buying are oversold?

> how much business efficiency could be gained by taking advantage of the fact that we all know the products our businesses are buying are oversold?

Not much tbh. Our only other option is to not buy, and build in-house instead. Sometimes that's worthwhile, but other times (like in the case of zoom) it still makes sense to buy the vendor's product, even if you know that it's not everything it's advertised as being.

The real efficiency is found in having people who can determine which and if you should buy a vendor's product, or if you should go in house. Specifically people who can see through the marketing BS and evaluate technologies without personal or hype bias.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#307

Earlier quoted context omitted.

"In part because executives, marketers and salespeople don't know what it means." Being a technical founder, I found some non-technical founders use this an advantage. They can lie to customers without guilt or investors with brimming confidence about their "MVP". They can use "making it simple" or "ignorance" as an excuse, if at all they get caught. These kind of lies are grey lines and exist everywhere.

I've worked with these types of people and what I've noticed is, even after you explain to them simply what they're saying is false, they insist or pushing those statements or as close to those labels as they can. They may even be angry after you inform them because they lose plausible deniability. I've also been in situations where an ultimatum like E2E encryption is dictated by a marketing team and then expected to…

It would be easy to ignore them, if they don't poison an entire startup ecosystem. If such founder gets into press and speaking circuit, lot of newbie founders assume such exaggeration is needed to succeed and this behavior becomes part of that ecosystem. Then it becomes hard to have authentic conversation with anyone there.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#308

Earlier quoted context omitted.

That's encryption for the state, not for us peasants.

Can the govenment somehow restrict end-to-end encrypted messaging to officials only?

They would just have a single state-run CA and ban all E2E messaging apps from app stores. Only state employees would have access to an E2E messaging app that would only use govt certs from the CA. Any apps that continue to operate outside of an app store could have their domestic servers seized and anything foreign would be blocked by all domestic ISPs. The govt could allow for civilian apps to use weak encryption as some sort of compromise but anything the govt can't crack instantly would be banned. It would require a Great Firewall-level of control with the govt playing whack-a-mole for a while but with enough time and money, civilian E2E would be near impossible. Fortunately, this is still a pipe dream for even the most extreme statists but if large corporations can come around to the idea of giving the govt an unlimited backdoor to their internal communications, say good bye to any/strong encryption for the average person.

This level of planning is like the US govt outlawing all guns tomorrow, it just isn't going to happen any time soon since not only are gun-owners usually not the type to want to give up a gun, the prevalence of gun ownership is so massive that it would take equally massive resources to run a completely successful confiscation program.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#309

Earlier quoted context omitted.

Therapists, lawyers, courts including closed door courts, confidential internal meetings for publically traded companies, doctors appointments, exchanging passwords/etc. Even my mom just telling me about a medical situation she's having. All of those have legal requirements for privacy, and many of them used Zoom because it was supposed to meet those requirements. Zoom lied and failed to meet those requirements. Ther…

> Zoom lied and failed to meet those requirements. did it? non-e2e is not the same as non-encrypted. > They literally, knowingly and plainly misrepresented their product Where has that been proven? as the parent pointed out, there is a wide gulf between misunderstanding and knowingly misrepresenting. > People at Zoom should be getting jail sentences. this is precisely why i lean against the anti-zoom sentiment. jail…

> jail sentences - seriously?! what is the maximum possible harm zoom could have caused?

People have paid them some money because of an intentional lie - that's fraud, and fraud (above a certain amount) means jail sentences. There does not necessarily need to be some grievous consequences to justify jail - let's keep things in perspective, "just" defrauding your customers isn't innocuous, it absolutely justifies a criminal investigation and putting people behind bars, not just some monetary fine to the organization.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#310

Few years ago I noticed BBM Enterprise touts end-to-end encryption pretty strongly in their marketing, without mentioning an up-front caveat. https://www.blackberry.com/us/en/products/bbm-enterprise Turns out that by default, BBME is not end-to-end. The initial handshake is transparent to Blackberry, and they could use that to decrypt future messages without your knowledge. To enable true end-to-end, you have to opt…

BlackBerry has always been untrustworthy when it comes to encryption:

> The defence in the case surmised that the RCMP must have used the "correct global encryption key," since any attempt to apply a key other than BlackBerry's own global encryption key would have resulted in a garbled mess. According to the judge, "all parties"—including the Crown—agree that "the RCMP would have had the correct global key when it decrypted messages during its investigation."

https://www.vice.com/en/article/mg77vv/rcmp-blackberry-proje...

Post reply on HN