Earlier quoted context omitted.
Each of those alternatives is just as likely to offer government wiretap support to any government that asks as Zoom is, unless I’ve missed statements of refusal to do so to the contrary from them.
I think the concern is trade secret theft. Sure the US or EU might demand a wiretap but their goals are different. You don't see the CIA stealing trade secrets and handing them over to Apple or Microsoft. Businesses are primarily worried about their IP.
Zoom lied to users about end-to-end encryption for years, FTC says
381–390 of 438 posts
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#382Earlier quoted context omitted.
As another poster said, the very large company I work at bans Zoom. We can use Teams, Webex, Skype, etc. How can you say there is no alternative?
Sorry, I didn't think in terms of degrees of untrustworthiness. What I miss is an open-source alternative. Doesn't Microsoft let the NSA tap into Skype calls?
For instance Big Blue Button : it's not perfect, because it's Canadian, it's hosted on Microsoft's Github, and might have some outstanding security issues [1], but I would probably still trust it more than Zoom or anything GAFAM.
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#383Earlier quoted context omitted.
What does not work with jitsi? I've been using a lot recently and it is by far the easiest one to use. One link and done. I have lots of video and audio issues with zoom. Now, if you're a company, bluejeans may be the best one.
There was a period a few months ago where jitsi was consistently crashing chromebooks. Obviously, if a webpage can crash the OS, it's an OS problem, but it still made jitsi unusable for those with chromebooks.
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#384Earlier quoted context omitted.
My boss is one of those people. He insists to our customers (and engineers) our product has encryption. It does not.
had a boss that marketed our product as having AI solutions while it had nothing to do with AI, lol.
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#385A deeper issue is how hard it is to "know" if companies hawking products with security implications (which is nearly everything, today) are lying. I'm not even talking about the gradient ranging from innocent bugs to incompetent coders and how that gets papered over. When you buy shoddy physical goods, there are typically characteristics you can't hide, like cheap materials. But with software like this of course the…
Legal / Terms of Service / Terms of Use / Usage Policy
I find that a majority don't even hide unreasonable conditions in 'legal' terms anymore. Whilst there may be tens, hundreds, of pages in that ToS you tick before using the product - there's a few solid, clear, one sentence dot points that protect from all issues. The best of these is similar to: "We reserve the right to amend, change, or otherwise modify this agreement with - or without - notice.", or "We reserve the right to withdraw services/solutions with - or without - notice." Some, like the famous early React licenses (by Facebook), had indemnity clauses for simply using the product - even if your then legal engagement was entirely unrelated to your use of React. Impacted by Cambridge Analytica? Sorry. Many years ago you experimented with React. Immunity.
I don't think a third party audit is a fix. Even dismissing these previous statements. The volume of 'independent' auditors that are then found corrupt, or otherwise bias/incompetent in result, is pretty regular news. More often than not. Based on some experience with how contracts and engagements go with big corporations - some even factor in known 'expected losses' (such as fines, failing to meet SLA, etc) in their actual budget of contract.
The real fix is users taking responsibility. Don't like the ToS (And, believe me; you won't..). Don't accept it.
(@USERS, not @_jal) But don't complain that the product you did, or did not, pay a cent for - but blindly accepted the ToS - fails to deliver to your expectation. Sure.. It suggested, or possibly even states 'end to end encryption'. But the ToS clarifies context of that.
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#386Earlier quoted context omitted.
Does that mean whenever medical information is sent via phone or Fax, HIPAA is being violated today? Because plain old telephone service is not E2E and the phone company can eavesdrop on you quite easily (as can the government with a warrant, or a bad guy with a phone tap on your line...) Not saying that e2e shouldn’t be used when practicable but a blanket assertion that e2e is required for HIPAA seems a little unbel…
> Does that mean whenever medical information is sent via phone or Fax, HIPAA is being violated today? Phone and fax are not considered “electronic” under HIPAA, so the rules, including the rule regarding encryption for exposed PHI to be considered secured vs. unsecured, specific to electronic communication don't apply. I think they may be explicitly given special treatment for some of the not-electronic-specific rul…
Lolwut? Have they confused "electronic" with "computerized" ?
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#387https://news.ycombinator.com/item?id=25028411
Where the EU is planning to add backdoors to E2E services.
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#388Earlier quoted context omitted.
That still requires you to trust the client software. I trust Telegram’s E2E, but not Zoom - unless Zoom’s client is on GitHub with deterministic build steps?
Telegram's crypto is shoddy [1]. It may not be a complete train wreck, but if you value good crypto and privacy, Signal is probably your only option. It also offers E2EE group chats, unlike Telegram. [1] https://security.stackexchange.com/a/49802/29703 (a bit dated but AFAIK nothing changed)
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#389Earlier quoted context omitted.
True enough. But they are comprised entirely of people. To change their behavior you must appeal to the people running them.
Not necessarily. Corporations are more than just sum of the people - they are a process that runs on top of people. People themselves are replaceable - and if you change the behavior of one to something the corporation doesn't want, it'll replace that person with someone new. You want to change the behavior of the corporation itself - and that's best done by creating monetary incentives and disincentives (i.e. punish…
Re: Zoom lied to users about end-to-end encryption for years, FTC says
#390A deeper issue is how hard it is to "know" if companies hawking products with security implications (which is nearly everything, today) are lying. I'm not even talking about the gradient ranging from innocent bugs to incompetent coders and how that gets papered over. When you buy shoddy physical goods, there are typically characteristics you can't hide, like cheap materials. But with software like this of course the…
How 'hard it is to "know"' is irreverent, and you agree to this when you accept the 'contract'. This isn't an issue of honesty, in fact; quite the contrary. They are extremely honest. It's just in the fine print. Legal / Terms of Service / Terms of Use / Usage Policy I find that a majority don't even hide unreasonable conditions in 'legal' terms anymore. Whilst there may be tens, hundreds, of pages in that ToS you ti…