Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

331–340 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#331

Earlier quoted context omitted.

Therapists, lawyers, courts including closed door courts, confidential internal meetings for publically traded companies, doctors appointments, exchanging passwords/etc. Even my mom just telling me about a medical situation she's having. All of those have legal requirements for privacy, and many of them used Zoom because it was supposed to meet those requirements. Zoom lied and failed to meet those requirements. Ther…

> Zoom lied and failed to meet those requirements. did it? non-e2e is not the same as non-encrypted. > They literally, knowingly and plainly misrepresented their product Where has that been proven? as the parent pointed out, there is a wide gulf between misunderstanding and knowingly misrepresenting. > People at Zoom should be getting jail sentences. this is precisely why i lean against the anti-zoom sentiment. jail…

>> They literally, knowingly and plainly misrepresented their product

> Where has that been proven? as the parent pointed out, there is a wide gulf between misunderstanding and knowingly misrepresenting.

...Is this not literally the point of the article that we're discussing? Relevant sections:

> "[S]ince at least 2016, Zoom misled users by touting that it offered 'end-to-end, 256-bit encryption' to secure users' communications, when in fact it provided a lower level of security," the FTC said today in the announcement of its complaint against Zoom and the tentative settlement. Despite promising end-to-end encryption, the FTC said that "Zoom maintained the cryptographic keys that could allow Zoom to access the content of its customers' meetings, and secured its Zoom Meetings, in part, with a lower level of encryption than promised."

> The FTC complaint says that Zoom claimed it offers end-to-end encryption in its June 2016 and July 2017 HIPAA compliance guides, which were intended for health-care industry users of the video conferencing service. Zoom also claimed it offered end-to-end encryption in a January 2019 white paper, in an April 2017 blog post, and in direct responses to inquiries from customers and potential customers, the complaint said.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#332
post #136

Earlier quoted context omitted.

I don't think I'd happily pay for Zoom, regardless of their encryption promises. I've personally struggled more with zoom call quality issues and hardware conflicts than I have with any other video conference provider.

Also anecdotally, I hear the opposite from every single person I know. Zoom has been the video conferencing system that works the best. Have you ever used Go2Meeting, WebEx, Teams? Constant struggles with those applications for me, my friends, and my co-workers.

You really have to use Teams every day to appreciate just how buggy it is on all three platforms. I used slack video for remote standups for a year or so and aside from the odd little hiccup it was boringly stable. Teams fails at least once a week.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#333
post #234

Earlier quoted context omitted.

True enough. But they are comprised entirely of people. To change their behavior you must appeal to the people running them.

My gripe is the companies who failed to implement because they couldn't do security in a way that was easy to use and resulted in a good user experience, but chose to be honest. I hate the (1) cheat to win and vanquish your competitors (2) when you're caught, say you're sorry, (3) win anyway because your competitors are gone progression. It seems like the penalty for that should be existential or at least something p…

Sincerely curious - what competitors do you believe were harmed here?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#334

Earlier quoted context omitted.

> E2E would help her meet HIPAA requirements e2e is not a hipaa requirement. > So it's not just an abstract, "lulz security" by all means, show me all the concrete harm zoom has done.

> e2e is not a hipaa requirement. Encryption between the last HIPAA covered entity (including business associates) on one end and the first covered entity (including BAs) on the other (or between covered entity on one end and patient on the other) is effectively a requirement of HIPAA in communications between HIPAA covered entities of PHI, since anything else would constitute an unauthorized intentional disclosure o…

Yes, this is a long way of saying e2e is not a hipaa requirement.

are you saying you have evidence of zoom retaining PHI and not safeguarding appropriately? because that would be a different conversation than everyone yelling because zoom said they were e2e and werent.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#335
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

you could try: https://xroom.app or https://go.xroom.app

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#336

Earlier quoted context omitted.

I've worked with these types of people and what I've noticed is, even after you explain to them simply what they're saying is false, they insist or pushing those statements or as close to those labels as they can. They may even be angry after you inform them because they lose plausible deniability. I've also been in situations where an ultimatum like E2E encryption is dictated by a marketing team and then expected to…

In an unfortunately rare case of reason conquering madness, a VW exec (Oliver Schmidt) was extradited and convicted over the diesel emissions scandal, instead of the engineers taking the brunt of the punishment. We expect name brand products to indemnify their vendors to an extent. Consumers don't want to chase down the guy who made the screw that failed and caused a bunch of excess deaths. You put the screw in the a…

I doubt the case of the VW manager can be adressed to reason (alone). Lots of politics going on, too. US vs. EU.

I doubt the same would have happened, if Ford or GM would have been the one caught in the act.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#337
post #39
post #35

Earlier quoted context omitted.

Sure, if you don't worry about privacy.

You can care about privacy yet still prioritize not killing your company in a pandemic. Very few things that are hosted are immune to employee buggery, that’s why companies invest in third party risk management; to assess those risks, which are always material and non-zero and determine if they are within the appetite of the organization.

true. one could just use onsite or p2p tech that avoids using servers beyond handshakes.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#339

Earlier quoted context omitted.

Any company IT department's power to ban something is inversely related to how much it's users want to use it. Also, the videoconference provider stealing company secrets it not part of most companies threat model. Teams and Slack are incredibly popular corporate tools, and neither of them offer this feature. WebEx is the only reasonably popular tool I can think of that supports it, and any security department that c…

Why isn’t it? I highly suspect the CCP stole trade secrets with zoom.

Because in order to operate a business (or any organization), you have to at some point decide on a group of service providers and other 3rd parties that you trust. For most organizations, trusting a major videoconferencing vendor is going to be within their risk tolerance. For some organizations (or for some use-cases within organizations) this wouldn't be acceptable (or perhaps trusting Zoom wouldn't be acceptable, where a different vendor might be), but at this point you're starting to stray outside of Zoom's target market and into a set of more specialized requirements.

Defending against sophisticated state-level actors goes even further beyond the requirements of most businesses. Unless you had a specific reason to believe that you were a target of such actors (dealing with national security, or matters of significant national strategic importance), you couldn't justify investing much resource into such defensive measures.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#340
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

"In part because executives, marketers and salespeople don't know what it means." Being a technical founder, I found some non-technical founders use this an advantage. They can lie to customers without guilt or investors with brimming confidence about their "MVP". They can use "making it simple" or "ignorance" as an excuse, if at all they get caught. These kind of lies are grey lines and exist everywhere.

I totally agree with you.

I am sure they already lied in the past too https://news.ycombinator.com/item?id=22711169 preaching ignorance as an excuse.

Post reply on HN