Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

311–320 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#311
post #230

Earlier quoted context omitted.

As another poster said, the very large company I work at bans Zoom. We can use Teams, Webex, Skype, etc. How can you say there is no alternative?

Teams does not allow users to place themselves in breakout rooms. Webex does not allow Linux users to grant control of their screens. When you use these platforms all the time, you find these little issues. Generally speaking, Zoom does it best, despite their problems.

You can set up channels in a ‘team’ and use those for breakouts.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#312

Earlier quoted context omitted.

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

> from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations Unless I'm misunderstanding what you mean by that, I don't really see the point in it, TBH. Have there been cases of Zoom infecting machines with malware or transmitting viruses? The whole concern, as far as I know, is terrible security on their end, allowing people into calls without permission, not having E2E encryption,…

There's been a few zero day client remote code execution vulnerabilities, along with some problems withe installer AFAIK.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#314
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

> In part because executives, marketers and salespeople don't know what it means. And in part because when explained what it means they will insist on their own definition/interpretation and demand the product is marketed as E2E.

This sounds like precisely how Grammarly claim they're not a keylogger by trying to change the very definition of what a keylogger is.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#315

Earlier quoted context omitted.

I'm sorry, I'm not a native English speaker. According to the Oxford dictionary customers are people who buy a product or service. Zoom was thinking of giving only them E2E encryption, and actually I would pay for that service if I would trust Zoom. Currently I use telegram to speak with my friends, but the call drops quite often as we don't have stable internet connection.

Maybe, since you admit your English language skills could use some work, you should give up on linguistic pedantry and find a new hobby.

If my English here is so bad why do I see ,,end user'' in Zoom's terms of license all the time, and customer for paying customers?

Can you provide a better legal definition than what I see? (Only the legal meaning of the word matters in the current context).

We're talking about hundreds of millions of people being effected vs few million people, it matters a lot. You would understand that it's very far from pedantry if you followed all announcements that Zoom had in the past.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#316

Earlier quoted context omitted.

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

> from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations Unless I'm misunderstanding what you mean by that, I don't really see the point in it, TBH. Have there been cases of Zoom infecting machines with malware or transmitting viruses? The whole concern, as far as I know, is terrible security on their end, allowing people into calls without permission, not having E2E encryption,…

You don't see the point of being suspicious of secret-source? and especially of an entity that is known to be dishonest? unless it is known to have been dishonest in the precise manner in question?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#317
post #116

Earlier quoted context omitted.

> the right fine here is their entire market cap. That would put them back at square one I don't think Zoom has transgressed anywhere nearly this badly, but even if I did it doesn't make sense to fine any company their entire value unless your goal is simply to destroy them. The company is only worth as much as it is because it is expected to continue as a company, and there would be no way for it to continue if it o…

A good punishment is government nationalizes it, paying shareholders nothing, then immediately sells those shares back onto the public markets. The government would earn close-ish to the market cap. Effectively, allow the company to continue as before, but wipe out all shareholders. After all, they are the people who allowed this behaviour. They are the ultimate decision makers.

No, abandoning property rights is not even close to an appropriate punishment, even for those directly responsible for the fraud, let alone for ignorant shareholders.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#318

Earlier quoted context omitted.

Teams does not allow users to place themselves in breakout rooms. Webex does not allow Linux users to grant control of their screens. When you use these platforms all the time, you find these little issues. Generally speaking, Zoom does it best, despite their problems.

You can set up channels in a ‘team’ and use those for breakouts.

This would require all the attendees to be members of the team ahead of the meeting; this isn't how we use Zoom.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#319

Earlier quoted context omitted.

"In part because executives, marketers and salespeople don't know what it means." Being a technical founder, I found some non-technical founders use this an advantage. They can lie to customers without guilt or investors with brimming confidence about their "MVP". They can use "making it simple" or "ignorance" as an excuse, if at all they get caught. These kind of lies are grey lines and exist everywhere.

I've worked with these types of people and what I've noticed is, even after you explain to them simply what they're saying is false, they insist or pushing those statements or as close to those labels as they can. They may even be angry after you inform them because they lose plausible deniability. I've also been in situations where an ultimatum like E2E encryption is dictated by a marketing team and then expected to…

> I've also been in situations where an ultimatum like E2E encryption is dictated by a marketing team and then expected to be created without adequate budgeting or time, essentially creating pressures on development teams, project/product managers, etc to lie.

Basically "Our customers have been asking for E2E encryption, so I'm adding that to our next sprint."

Post reply on HN