Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

391–400 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#391
post #234

Earlier quoted context omitted.

My gripe is the companies who failed to implement because they couldn't do security in a way that was easy to use and resulted in a good user experience, but chose to be honest. I hate the (1) cheat to win and vanquish your competitors (2) when you're caught, say you're sorry, (3) win anyway because your competitors are gone progression. It seems like the penalty for that should be existential or at least something p…

Sincerely curious - what competitors do you believe were harmed here?

That's the point. It's the companies that are little known that get squashed. I don't know much about the space, but I tried Google and chose zoom instead because it was easier— and I pay for Google. I tried Jitsi. But what about the ones we haven't heard of, struggling to solve the problem that Zoom lied about solving, but because they're honest they never took that step forward.

It's like RealPlayer. By the time the courts catch up, the game is over.

Several people are on zoom instead of Google, for instance, even though I pay for Google. I don't know the other players in the space.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#392
post #308

Earlier quoted context omitted.

Can the govenment somehow restrict end-to-end encrypted messaging to officials only?

They would just have a single state-run CA and ban all E2E messaging apps from app stores. Only state employees would have access to an E2E messaging app that would only use govt certs from the CA. Any apps that continue to operate outside of an app store could have their domestic servers seized and anything foreign would be blocked by all domestic ISPs. The govt could allow for civilian apps to use weak encryption a…

> if large corporations can come around to the idea of giving the govt an unlimited backdoor to their internal communications, say good bye to any/strong encryption for the average person.

You mean like what happened with PRISM ?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#393

Earlier quoted context omitted.

Why isn’t it? I highly suspect the CCP stole trade secrets with zoom.

Because in order to operate a business (or any organization), you have to at some point decide on a group of service providers and other 3rd parties that you trust. For most organizations, trusting a major videoconferencing vendor is going to be within their risk tolerance. For some organizations (or for some use-cases within organizations) this wouldn't be acceptable (or perhaps trusting Zoom wouldn't be acceptable,…

Does it really take that much for a company to be an interesting target for industrial espionage ?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#394
post #16

Earlier quoted context omitted.

Some reports say the whole video conferencing market, being very optimistic, will reach $50B in 2026 (considering Covid-19 - https://www.gminsights.com/industry-analysis/video-conferenc... ) But Zoom, alone, already has a marketcap of $117.534B ( https://finance.yahoo.com/quote/ZM/ ) I really think there is an unsustainable distortion happening.

> I really think there is an unsustainable distortion happening. Yes, soon any website can have their own videoconferencing using web technology like WebRTC. And implementation will be as simple as running "npm install". > But Zoom, alone, already has a marketcap of $117.534B Yes. Zoom having a market cap that's more than half of Intel? Come on now ...

I'll take one good native app over a thousand of crappy websites.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#395
post #67

Earlier quoted context omitted.

I thought the lesson is clear. All e2e claims with closed source software must be dismissed by default. The burden of proof is on the seller.

I mean, I agree with you, and I guess the "surely Apple is not blatantly lying about being unable to read the content of your communication" argument has eroded a bit after Zoom's behaviour. But the penalties (both in terms of reputation and in terms of monetary fines) for this kind of misbehaviour are already large, and are likely to increase over time, and it seems an unnecessarily extreme risk for these companies…

What penalties? The NSA boasted (internally) about how much they were spying on Skype, and I'm not aware of Microsoft having been penalized in any way for lying about it, probably even the opposite?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#396
post #94

Earlier quoted context omitted.

If you want my popular products then nobody can answer because you'd know of them already. So I'll generalize to what group video tools are e2ee: -> Jami (according to their website, I only ever used their chat and regular one-on-one calls) -> Wire (client and server open source, but not community-lead development) -> WhatsApp (if you trust Facebook, proprietary back-end) And if you consider open source & on-premises…

- I was looking for "desktop-solutions" comparable to Zoom, so WhatsApp and Telegram are out of the question (Telegram doesn't do group calls AFAICS). Some notes: - Wire has published a detailed whitepaper on e2ee. https://wire-docs.wire.com/download/Wire+Security+Whitepaper... - Jami (formerly GNU Ring) has an interesting post about having e2e here: https://security.stackexchange.com/a/162603/243716 - Jitsi e2e is t…

Can the key exchange even be both automatic and secure?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#397
post #357

Earlier quoted context omitted.

Oh man I had a great one last week. We're migrating stuff to a cloud provider, and they wanted to expose an internal only API to the internet so that the things could reach it. I was strongly against that, as it has no security involved at all. Fast and loose and all of that. Two, count them, two people wanted to "just change it to use port 443, that way it's encrypted". I had to explain that you could pick any valid…

If it's AWS, the quickest path to doing this securely is AWS API Gateway mTLS authN[0]. You generate some certs, stuff the public halves in S3, slap an ACM cert on the Gateway, and you're done. I have also used certificate authentication on TLS-terminating reverse proxies (e.g., this is easy to do with HAProxy) to do the same in other environments. You can pin the API's certificate on the client end in order to furth…

Thanks a lot for this comment. I really appreciate it. That mTLS solution is something that would solve this problem immediately.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#398

Earlier quoted context omitted.

I think the concern is trade secret theft. Sure the US or EU might demand a wiretap but their goals are different. You don't see the CIA stealing trade secrets and handing them over to Apple or Microsoft. Businesses are primarily worried about their IP.

That would probably be the NSA, and why would you expect them to NOT do industrial espionage ?

Well they do...it's not new:

https://www.bbc.com/news/25907502

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#399

Earlier quoted context omitted.

My boss is one of those people. He insists to our customers (and engineers) our product has encryption. It does not.

I would have a conversation with your companies legal department.

A lot of startups don't have a legal department.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#400

Earlier quoted context omitted.

> Does that mean whenever medical information is sent via phone or Fax, HIPAA is being violated today? Phone and fax are not considered “electronic” under HIPAA, so the rules, including the rule regarding encryption for exposed PHI to be considered secured vs. unsecured, specific to electronic communication don't apply. I think they may be explicitly given special treatment for some of the not-electronic-specific rul…

> Phone and fax are not considered “electronic” Lolwut? Have they confused "electronic" with "computerized" ?

Former HIPAA security officer here. Yes, mostly.

We had a dedicated room with a single computer hooked up only to a dial-up line to submit claims forms to a specific insurance company.

Post reply on HN