Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

321–330 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#321
post #301

Earlier quoted context omitted.

> Your competitors are doing it, if you don't, you lose. What's far more interesting to me is the fact that your vendors are doing it. I wonder how much business efficiency could be gained by taking advantage of the fact that we all know the products our businesses are buying are oversold?

You may find it interesting that recently Malwarebytes was mentioned in relation to 230 of the DMCA which to my mind relates directly to this. They are an AV solution that holds "legitimate" software vendors that operate an above board business to the fire when they start any practice that they (Malwarebytes) determines is violating a PC users reasonable expectations. That software begins to be detected as "potential…

Tangent: Cheat Engine, an amazing piece of software, mentions on their website that they may be detected as malicious software because they do a lot of the same things malicious software does - hook into other processes and modify their behaviour, optionally with a kernel hook.

They don't mention that their installer ships with tons of malware that they install, and more that they try to trick you into installing but you can technically opt-out.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#322

Earlier quoted context omitted.

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

Cisco Webex is used in my workplace. We forbid anyone from installing Zoom over security concerns

What specific concerns that aren't also relevant to Webex?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#323
post #230

Earlier quoted context omitted.

As another poster said, the very large company I work at bans Zoom. We can use Teams, Webex, Skype, etc. How can you say there is no alternative?

Each of those alternatives is just as likely to offer government wiretap support to any government that asks as Zoom is, unless I’ve missed statements of refusal to do so to the contrary from them.

I think the concern is trade secret theft. Sure the US or EU might demand a wiretap but their goals are different. You don't see the CIA stealing trade secrets and handing them over to Apple or Microsoft. Businesses are primarily worried about their IP.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#324

Earlier quoted context omitted.

Regulation should prevent this from occurring. If you use a product that claims it is E2E and it is not, you should be able to sue wildly for potential damages given the sensitive nature of the software.

> Regulation should prevent this from occurring. It already exists. It's called "fraud".

On one level, yes.

On the other hand, I think things involving cryptography at scale ought to come with regulations on language

For example, look at how the word "bank" is specially regulated by most governments. I can't just call myself a bank without meeting specific guidelines or else it's not just typical fraud, it's major financial fraud coupled with putting sensitive customer data at risk.

Same here. We need specific legislation targeting these scummy businesses who use corporate ignorance as an excuse for selling a product under false pretenses of end-to-end encryption.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#326

Earlier quoted context omitted.

You're right, but 3rd party audits can help, especially because the precedent set by Arthur Andersen w/ Enron. It destroyed their business completely when their fraud was discovered, so there would be a strong incentive for auditors to get it right. As you said, not a silver bullet, but it's a step up from nothing.

> It destroyed their business completely when their fraud was discovered... I suppose rebranding and transferring assets is kind of like a Chapter 7 "destroyed their business completely", but no one involved went to jail, no one lost their Series 7 or any other kind of licensing, no one was ever barred for life from ever managing at a public company ever again, etc. Sure, to laypeople a selling off of assets and rebr…

Well, you make good points. I can't argue with that.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#328

Earlier quoted context omitted.

I wish that was true, but in practice I think it wouldn't matter. Zoom was the only one ready with infrastructure, multiple clients, automatic quality adjustment, screen sharing options, scheduling, and many other needed features. Otherwise we had hangouts/meet with very basic features and jet-taking-off Mac behaviour, chime which is really good but nobody heard of it (Amazon is not interested in that market apparent…

"chime which is really good but nobody heard of it" So there was a competitor after all?

Amazon doesn't seem interested in that app being used by random consumers. There's very few accessible guides around it. It's technically good, but it's not even a competitor as such.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#329
post #265

Earlier quoted context omitted.

Well, there might be conflicting interests within government. From a consumer advocate perspective government might want to demand this. From an intelligence services perspective you might want companies to lie.

> From an intelligence services perspective you might want companies to lie. No, I don't. I don't want companies to lie. You can collect intelligence the same way we've been collecting intelligence for our entire history on this planet prior to E2E comms. E2E isn't a hindrance, it's a way to enforce limitations on government overreach. No freedom is without compromise.

You don't. But I'm afraid that is the reality. The only way to change that is by law and then vigorous enforcement of law. That isn't likely to happen.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#330
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

"As for Zoom, I don't uderstand why people trust them or still use their product if they are at all concerned about security."

Perhaps the term "security" suffers from the same problem as "E2E encryption".

Post reply on HN