Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

341–350 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#341

Earlier quoted context omitted.

Therapists, lawyers, courts including closed door courts, confidential internal meetings for publically traded companies, doctors appointments, exchanging passwords/etc. Even my mom just telling me about a medical situation she's having. All of those have legal requirements for privacy, and many of them used Zoom because it was supposed to meet those requirements. Zoom lied and failed to meet those requirements. Ther…

> Zoom lied and failed to meet those requirements. did it? non-e2e is not the same as non-encrypted. > They literally, knowingly and plainly misrepresented their product Where has that been proven? as the parent pointed out, there is a wide gulf between misunderstanding and knowingly misrepresenting. > People at Zoom should be getting jail sentences. this is precisely why i lean against the anti-zoom sentiment. jail…

> what is the maximum possible harm zoom could have caused?

+ HIPAA violation

+ Violation of jury secrecy

+ FERPA violation

+ False advertising and fraud

That's US specific. I'm sure foreign governments will have their own opinions.

You're right, you can be HIPAA compliant and not be E2E encrypted - if you have the right paperwork and auditing process. Zoom didn't because they claimed to be E2E encrypted.

There are some things you can lie about and it's crappy but not a big deal. "Lag free video streaming!" - Sure, whatever. "The best quality!" Again, don't care. When it comes to information security claims though, lying has very serious penalties because the damage you cause is extremely serious. This wasn't them telling a white lie about how awesome they are, this is them intentionally and knowingly engaging in fraudulant behavior to make profit at the expense and security of users - and we should absolutely punish the hell out of people who do that to line their own pockets with a few extra dollars.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#342
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

> It is also important to note that quite often you are not dealing only with the company that makes a product, but the regulatory bodies that can pressure companies into complying with their wishes. While considering the regulatory requirements helps explain the desire to lie, it does not make the lie any more defensible. Even if a regulatory body is making impractical demand, I very much doubt they are demanding co…

Unless there was a gag order. We should make gag orders unconstitutional.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#343
post #195
post #140

The relationship between Zoom and China should outright disqualify it from being used in any Democratic countries.

I don't see how democracy has anything to do with wanting to secure video calls or not but anyways, how is this worse than trusting anything from the US? Not trying to add whataboutism, but curious if you have the same look on security when made by companies that share data with someone that realistically could come after you for anything done in those calls. PRC clearly can't unless you live in PRC while the FBI and…

No, instead they target political dissidents and find any possible family you might have in China and threaten to hurt them if you don't either return to the PRC or commit suicide [1], much better.

[1] https://en.wikipedia.org/wiki/Operation_Fox_Hunt

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#345
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

I have an entire Windows VM set up just for Zoom meetings.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#346

Earlier quoted context omitted.

You're right, but 3rd party audits can help, especially because the precedent set by Arthur Andersen w/ Enron. It destroyed their business completely when their fraud was discovered, so there would be a strong incentive for auditors to get it right. As you said, not a silver bullet, but it's a step up from nothing.

> Firms That Imploded Have Something in Common: Ernst and Young Audited Them https://www.wsj.com/articles/string-of-firms-that-imploded-h... https://news.ycombinator.com/item?id=24802741 Nobody at Arthur Andersen went to prison and SCOTUS reversed their conviction. The firm may have gone up in smoke, but nobody was actually punished for their crimes. Who at Ernst and Young has gone to prison for Wireguard or WeWork?…

Did you mean Wirecard instead of Wireguard?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#347
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security.

The same reason I use Slack, because I have to.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#348
post #342

Earlier quoted context omitted.

> It is also important to note that quite often you are not dealing only with the company that makes a product, but the regulatory bodies that can pressure companies into complying with their wishes. While considering the regulatory requirements helps explain the desire to lie, it does not make the lie any more defensible. Even if a regulatory body is making impractical demand, I very much doubt they are demanding co…

Unless there was a gag order. We should make gag orders unconstitutional.

Gag orders don't force you to state wrong facts about your products in the first place.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#349

Earlier quoted context omitted.

>People spied. Did they? Which people? When? How?

That's kind of the point isn't it? You can't know, because it wasn't actually e2ee, eh? That's the harm. Also, think of the competitors of zoom who lost customers to them due to their lying, that's a harm too, eh? These are hard to quantify but they're not nothing.

>You can't know, because it wasn't actually e2ee, eh

You can know that nobody external to Zoom spied on those streams as they were encrypted between client and Zoom servers. The fact that Zoom had access to your stream, in principle, is par for course.

>These are hard to quantify but they're not nothing.

And they got in trouble. There is the FTC slap and the PR cost associated with the negative publicity. That feels about right for the level of infraction. But when these kinds of articles come out, people are calling for regulatory bodies to 'make examples' of the companies in question. That's not how it works. That's not how it should work.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#350
There are (at least) two points, I think:

- Open protocols would be helpful. Then you can implement it by yourself and you can see if it is encrypted (and implement whatever other features you may need, including saving energy).

- If they lied to users about end-to-end encryption, then it is false advertising. It is important to avoid false advertising.

Post reply on HN