Live data from Hacker News

Zoom lied to users about end-to-end encryption for years, FTC says

arstechnica.com

431–438 of 438 posts

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#431
post #355

Earlier quoted context omitted.

What does not work with jitsi? I've been using a lot recently and it is by far the easiest one to use. One link and done. I have lots of video and audio issues with zoom. Now, if you're a company, bluejeans may be the best one.

If you're going to have 10+ People in the meeting, there will be issues. Video/Audio getting bad, People loose have signal, etc. There is also a very noticable load on even more powerful PCs once you have some more people in the call. So jitsi might work for one-on-ones but slightly bigger conference calls are a no-go.

For 10-100 people, use BigBlueButton instead.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#432

Earlier quoted context omitted.

Skype's been in decline for a long time, so it's hard to say if any of that decline is attributable to loss of trust.

We're talking about legal penalties here.

No, we're talking about legal and reputation penalties.

I wrote:

> the penalties (both in terms of reputation and in terms of monetary fines) for this kind of misbehaviour

You wrote:

> What penalties?

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#434
So the takeaway here, there isn't real significant consequence for this kind of stuff. Can I just create startup and store passwords in plaintext and lie about it so that I can focus on the core user facing features of the product? Once we get big enough I'll just hire some security engineers to do things right.

I'm exaggerating a bit with the above example, but how much corners can someone cut and how much lies can they get away with when it comes to security? Because finding the right balance seems like a serious competitive advantage in the startup space.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#435

Earlier quoted context omitted.

We're talking about legal penalties here.

No, we're talking about legal and reputation penalties. I wrote: > the penalties (both in terms of reputation and in terms of monetary fines) for this kind of misbehaviour You wrote: > What penalties?

Oops, my bad, HN isn't really good at this, not showing parent comments in the list of our comments...

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#436
post #401
post #391

Earlier quoted context omitted.

That's the point. It's the companies that are little known that get squashed. I don't know much about the space, but I tried Google and chose zoom instead because it was easier— and I pay for Google. I tried Jitsi. But what about the ones we haven't heard of, struggling to solve the problem that Zoom lied about solving, but because they're honest they never took that step forward. It's like RealPlayer. By the time th…

Too late to edit the above, but ignore the last sentence. It was written first, and when I rewrote the comment I somehow forgot to delete.

No worries.

Zoom, unbelievably, built a better video conferencing solution than any product by any other company. Their top competitors were Google, Microsoft, and Cisco - several orders of magnitude larger than them.

In this case, I believe the underdog won.

InfoSec cuts both ways in the market. Sure, products with lower standards “poison the well.” But purchasers with burdensome, pointless, obsolete security audits do far more damage to the ecosystem. It certainly cost my startup a tremendous amount of potential growth. We far exceeded security standards like SOC Type II, but still had to bend how we solved security/user problems to Excel sheet checklists.

Zoom was facing a similar issue - they delivered “secure enough” until it wasn’t. Then they, in months, made massive, productive, effective changes that addressed the new issues from skyrocketing growth.

If our standards for good actors in the tech space is higher than that, I don’t know how humans can achieve them.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#437

Earlier quoted context omitted.

Gag orders don't force you to state wrong facts about your products in the first place.

What if they do?

Look up "warrant canary". IANAL, but my understanding is that you can be secretly compelled to not speak, but you cannot be legally compelled to actively tell a lie -- the Wikipedia page agrees with my interpretation. So, you can just publish "I am not subject to a gag order" every day until you are subject to one.

Re: Zoom lied to users about end-to-end encryption for years, FTC says

#438
post #401

Earlier quoted context omitted.

Too late to edit the above, but ignore the last sentence. It was written first, and when I rewrote the comment I somehow forgot to delete.

No worries. Zoom, unbelievably, built a better video conferencing solution than any product by any other company. Their top competitors were Google, Microsoft, and Cisco - several orders of magnitude larger than them. In this case, I believe the underdog won. InfoSec cuts both ways in the market. Sure, products with lower standards “poison the well.” But purchasers with burdensome, pointless, obsolete security audits…

Several days later, but I have to say I agree with you.
Post reply on HN