Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

371–380 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#371
post #230

Earlier quoted context omitted.

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

As another poster said, the very large company I work at bans Zoom. We can use Teams, Webex, Skype, etc. How can you say there is no alternative?

never heard of these also-rans

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#372
post #345

Earlier quoted context omitted.

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

I have an entire Windows VM set up just for Zoom meetings.

that's kind of sad if you really think about it.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#373

Earlier quoted context omitted.

> As for Zoom, I don't understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense. I certainly don't trust them, but I do use Zoom (from a dedicated unprivileged user, so it can't do any harm beyond recording my conversations), because my colleagues use Zoom, and because there doesn't seem to be any working alternative. I got them to try Jitsi o…

A working alternative is google _meet_

right - since google is well know for its privacy and telling the truth.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#374
post #216
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

Hi there! I'm in the video meeting space, and always looking to find that blend between usable and secure. I'm curious - is there a video service out there you would recommend if you're conscious about security? Your third paragraph makes me think your opinion will be that no large company can be trusted, because they become a target for nation-state regulatory bodies.

https://xroom.app/

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#375
post #79

What other popular group video meeting tools are e2e? I know of none. I remember reading a while back that Zoom claimed a few times they were e2e-encrypted, but what they meant was transport encryption.

https://xroom.app/

p2p tech that uses e2e and only uses servers to establish a key handshake

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#377
post #196

Over the past decade I've had to deal with a lot of executives and security people who don't actually understand security all that well. Or at all. (Not that I'm a security expert, but that hardly makes it better when even I can see that something is nonsense). Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I'm not going to out the…

> And in part because when explained what it means they will insist on their own definition/interpretation and demand the product is marketed as E2E.

That is the moment when one calls up the corporate lawyer and asks about "false advertising"...

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#379

Earlier quoted context omitted.

Like a class action lawsuit? I think there have to be evidence of damage done in that case.

Why does there have to be damages? You paid for something, and didn't get it. Go to the supermarket, but a box that says "ten apples". You get home and open it, there's just five apples. You'll want money back. What "damages" do you have to prove?

It's much more complicated when other risks are involved. It's like someone sold you a bun by labeling it as gluten-free, but it was not. Maybe you're just slightly intolerant and nothing lasting happened to you, but you could still sue them.

Unlike that example, it's difficult to know if there were direct damages, but some big companies can come together and try to make a case and sue them and demand huge compensations. Zoom could have spied on your conversations and sold your information to competitors even though they sold the product claiming that they couldn't.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#380
post #342

Earlier quoted context omitted.

> It is also important to note that quite often you are not dealing only with the company that makes a product, but the regulatory bodies that can pressure companies into complying with their wishes. While considering the regulatory requirements helps explain the desire to lie, it does not make the lie any more defensible. Even if a regulatory body is making impractical demand, I very much doubt they are demanding co…

Unless there was a gag order. We should make gag orders unconstitutional.

It's probably more feasible to require them to be disclosed after a period of time
Post reply on HN