Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

401–410 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#401
post #391

Earlier quoted context omitted.

Sincerely curious - what competitors do you believe were harmed here?

That's the point. It's the companies that are little known that get squashed. I don't know much about the space, but I tried Google and chose zoom instead because it was easier— and I pay for Google. I tried Jitsi. But what about the ones we haven't heard of, struggling to solve the problem that Zoom lied about solving, but because they're honest they never took that step forward. It's like RealPlayer. By the time th…

Too late to edit the above, but ignore the last sentence. It was written first, and when I rewrote the comment I somehow forgot to delete.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#402
I'm not in the least surprised.

Think of other popular messaging systems that claim to offer some kind of E2EE, but are proprietary software: WhatsApp, Skype, FB Messenger, Viber, Threema, Line…

Distrust by default!

I am always amazed when folks even consider the alleged support for strong E2E encryption in those apps… the value of those claims is exactly zero.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#403
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

"In part because executives, marketers and salespeople don't know what it means." Being a technical founder, I found some non-technical founders use this an advantage. They can lie to customers without guilt or investors with brimming confidence about their "MVP". They can use "making it simple" or "ignorance" as an excuse, if at all they get caught. These kind of lies are grey lines and exist everywhere.

Willful ignorance as a mask for fraud seems like a week defense when one is targeting regulated industries.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#404

Earlier quoted context omitted.

> Does that mean whenever medical information is sent via phone or Fax, HIPAA is being violated today? Phone and fax are not considered “electronic” under HIPAA, so the rules, including the rule regarding encryption for exposed PHI to be considered secured vs. unsecured, specific to electronic communication don't apply. I think they may be explicitly given special treatment for some of the not-electronic-specific rul…

> Phone and fax are not considered “electronic” Lolwut? Have they confused "electronic" with "computerized" ?

Keep in mind that, while the current phone system is very much electronic, the phone system historically predates electronics. It is electric, but not inherently electronic.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#405
Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out them. See second to last paragraph as to when to be wary). In part because executives, marketers and salespeople don't know what it means. And in part because when explained what it means they will insist on their own definition/interpretation and demand the product is marketed as E2E.

It is also important to note that quite often you are not dealing only with the company that makes a product, but the regulatory bodies that can pressure companies into complying with their wishes.

As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#406

Earlier quoted context omitted.

In an unfortunately rare case of reason conquering madness, a VW exec (Oliver Schmidt) was extradited and convicted over the diesel emissions scandal, instead of the engineers taking the brunt of the punishment. We expect name brand products to indemnify their vendors to an extent. Consumers don't want to chase down the guy who made the screw that failed and caused a bunch of excess deaths. You put the screw in the a…

> In an unfortunately rare case of reason conquering madness, a VW exec (Oliver Schmidt) was extradited and convicted over the diesel emissions scandal, instead of the engineers taking the brunt of the punishment. Side note but I think he was grabbed at the airport, not extradited from abroad.

I was trying to recall his name and did some googling. One of the first articles said that he had been approved for extradition. Sounds like they just got to him before the state department had to step in.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#407

Earlier quoted context omitted.

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

Google's Meet has improved considerably and most importantly it comes free with G-Suite. They are also pushing it quite hard as every calendar invite has a Google Meet link automatically included. The reason that people went with Zoom is "because it worked." As other products improve it's hard to see what Zoom's moat is and why we should continue to pay for it.

[deleted]

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#408
post #359

Earlier quoted context omitted.

Google's Meet has improved considerably and most importantly it comes free with G-Suite. They are also pushing it quite hard as every calendar invite has a Google Meet link automatically included. The reason that people went with Zoom is "because it worked." As other products improve it's hard to see what Zoom's moat is and why we should continue to pay for it.

> The reason that people went with Zoom is "because it worked." As other products improve it's hard to see what Zoom's moat is and why we should continue to pay for it. Ironically, I would say Google Meet defines "it just works" for me way more than does Zoom. Joining a Google Meet: 1. Enter the URL in your browser. 2. Click join. Joining a Zoom: 1. Enter the URL in your browser. 2. Accept launching an executable. 3.…

It's not necessary for everyone to have a Google account?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#409
post #237

Earlier quoted context omitted.

There was a period a few months ago where jitsi was consistently crashing chromebooks. Obviously, if a webpage can crash the OS, it's an OS problem, but it still made jitsi unusable for those with chromebooks.

Well, obviously you're not going to have good performance from a web app. Why didn't they install the native app ?

The native app doesn't work with the free 8x8 rooms, as far as I could tell.

I'm not sure I consider not crashing the OS when the conference starts 'good performance' so much as 'working'. Running it in Firefox at the time was bad performance (sluggish), haven't tested since.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#410
post #18

Pretty scandalous stuff. But to be fair it seems pretty likely that any or all of the major players (Apple, Google, MS, Facebook, AWS, etc) to be maintaining some sort of back-door access to the channels they control for spying purposes. I suppose the risk with Zoom is leaks due to incompetence rather than leaks due to government intervention.

Apple claims that FaceTime is end-to-end encrypted (and makes some pretty strong statements about not having access to the content of communications). Facebook similarly claims that WhatsApp is end-to-end encrypted. Whilst I have little love for either company, do you have any evidence that these claims are lies?

I've got https://news.ycombinator.com/item?id=25058783 . There is substantial evidence that the American spying agencies are willing to use anything with a reputation for neutrality as a vehicle for spying.

"Apple has a market incentive not to lie!" is an argument I find compelling, but the NSA has a bigger incentive to make Apple lie, and more power than Apple. If Apple & friends were ever offering a truly secure communication channel it is unlikely that was/will be allowed to continue.

Post reply on HN