Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

171–180 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#171

Earlier quoted context omitted.

What? ” The European Commission has told its staff to switch to the encrypted Signal messaging app in a move that’s designed to increase the security of its communications.” This was February 2020, has something changed?

Yes https://news.ycombinator.com/item?id=25028411

The EU isn't a single individual. It isn't even a group of individuals with aligned interests. As such, its many different heads shouldn't be expected to have consistent messaging. This is a draft so, as of now, it's factually untrue to say the EU are willing to ban encryption.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#172
post #169
post #148

Earlier quoted context omitted.

Punishment is the best solution. Incentives are what drive behavior, and learning that you can get away with lying will just lead to more getting away with lying.

When it comes to training humans and animals, positive punishment is far less effective than most other training techniques like positive reinforcement. Don't Shoot the Dog[1]! [1] https://www.amazon.com/Dont-Shoot-Dog-Teaching-Training/dp/0...

Well, corporations aren't humans, contrary to what some might try to argue.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#173
post #136

Earlier quoted context omitted.

I'm still not a native English speaker, but a Google search shows that non-paying customers are people who don't pay their bills, which is not the same thing as users who don't have bills to pay. Also as I wrote, Zoom was thinking of selling E2E encryption as a payed feature, that's why the distinction really matters (I would happily pay for it if that would give me a strong assurance that I just don't have so far).

I don't think I'd happily pay for Zoom, regardless of their encryption promises. I've personally struggled more with zoom call quality issues and hardware conflicts than I have with any other video conference provider.

Also anecdotally, I hear the opposite from every single person I know. Zoom has been the video conferencing system that works the best. Have you ever used Go2Meeting, WebEx, Teams? Constant struggles with those applications for me, my friends, and my co-workers.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#174
post #153

A deeper issue is how hard it is to "know" if companies hawking products with security implications (which is nearly everything, today) are lying. I'm not even talking about the gradient ranging from innocent bugs to incompetent coders and how that gets papered over. When you buy shoddy physical goods, there are typically characteristics you can't hide, like cheap materials. But with software like this of course the…

Any software you don't have the source for, haven't built yourself, and don't host yourself is immediate suspect.

Third party audits aren't a silver bullet. Enron and Worldcom had third party audits.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#175

If Zoom made clear to users that connections were not secured to the same standards as competitors, and that potentially hundreds of employees could be silently listening in on any call, I think that would have prevented them becoming a leader in video conference tech. So the right fine here is their entire market cap. That would put them back at square one, which is where an honest competitor would be right now.

> If Zoom made clear to users that connections were not secured to the same standards as competitors…

Which competitors offered true E2E?

I think mostly they were (misleadingly/lyingly) promissing something above what most of their competitors offered, no?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#176
Pretty ridiculous for the US to be enforcing this while they try to ban and reduce availability of E2EE worldwide. Zoom et all are doing them a great service by spreading FUD and confusion about what E2EE even is. Once it's reduced to "complex math thing" in people's minds no one will know or care when they ban it.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#177
post #106

Earlier quoted context omitted.

Zoom lied. People spied.

>People spied. Did they? Which people? When? How?

That's kind of the point isn't it? You can't know, because it wasn't actually e2ee, eh? That's the harm.

Also, think of the competitors of zoom who lost customers to them due to their lying, that's a harm too, eh?

These are hard to quantify but they're not nothing.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#178

Pretty ridiculous for the US to be enforcing this while they try to ban and reduce availability of E2EE worldwide. Zoom et all are doing them a great service by spreading FUD and confusion about what E2EE even is. Once it's reduced to "complex math thing" in people's minds no one will know or care when they ban it.

The US has more than one actor in it, only some of them care about E2EE. This is true for literally everywhere.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#179
post #106

Earlier quoted context omitted.

Zoom lied. People spied.

>People spied. Did they? Which people? When? How?

All network traffic in the US should be seen as the opposite of innocent untill proven guilty: Unless you can prove otherwise, everything we know of surveillance tells us that of course everything and everyone was spied upon. I can't think of any reason the NSA and/or CIA should not have spied when they do so on everything else they can get their hands on.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#180
post #153

A deeper issue is how hard it is to "know" if companies hawking products with security implications (which is nearly everything, today) are lying. I'm not even talking about the gradient ranging from innocent bugs to incompetent coders and how that gets papered over. When you buy shoddy physical goods, there are typically characteristics you can't hide, like cheap materials. But with software like this of course the…

Any software you don't have the source for, haven't built yourself, and don't host yourself is immediate suspect. Third party audits aren't a silver bullet. Enron and Worldcom had third party audits.

I agree. I am writing my project a certain way to achieve a goal I call reimplementability.

This means that I try to design in such a way that a reasonably competent dev could sit down and rewrite the whole system in a couple hours/days/weeks.

Post reply on HN