TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Zoom lied to users about end-to-end encryption for years, FTC says

1616 pointsby eddieozover 4 years ago

50 comments

bborudover 4 years ago
Over the past decade I&#x27;ve had to deal with a lot of executives and security people who don&#x27;t actually understand security all that well. Or at all. (Not that I&#x27;m a security expert, but that hardly makes it better when even I can see that something is nonsense).<p>Right now I know of at least half a dozen products that are marketed as having E2E encryption but do not actually implement this (no, I&#x27;m not going to out them. See second to last paragraph as to when to be wary). In part because executives, marketers and salespeople don&#x27;t know what it means. And in part because when explained what it means they will insist on their own definition&#x2F;interpretation and demand the product is marketed as E2E.<p>It is also important to note that quite often you are not dealing only with the company that makes a product, but the regulatory bodies that can pressure companies into complying with their wishes.<p>As for Zoom, I don&#x27;t understand why people trust them or still use their product if they are at all concerned about security. It makes very little sense.
评论 #25047136 未加载
评论 #25047518 未加载
评论 #25048568 未加载
评论 #25047172 未加载
评论 #25047081 未加载
评论 #25047265 未加载
评论 #25048688 未加载
评论 #25047226 未加载
评论 #25049020 未加载
评论 #25053599 未加载
评论 #25047374 未加载
评论 #25051504 未加载
评论 #25053159 未加载
评论 #25049880 未加载
评论 #25068505 未加载
评论 #25057103 未加载
评论 #25047798 未加载
评论 #25047628 未加载
kevincoxover 4 years ago
&gt; Zoom has agreed to a requirement to establish and implement a comprehensive security program, a prohibition on privacy and security misrepresentations, and other detailed and specific relief to protect its user base<p>What a slap on the wrist. &quot;You blatantly lied to your customers for years. How about you just continue to implement the thing that you were working on anyways.&quot;<p>I don&#x27;t think punishment is always the best solution but it seems that you should at least set some sort of example.
评论 #25046097 未加载
评论 #25047278 未加载
评论 #25046800 未加载
评论 #25046848 未加载
评论 #25046178 未加载
meowfaceover 4 years ago
All they had to do was say &quot;encrypted&quot; instead of explicitly saying &quot;end-to-end encrypted&quot; when it very clearly wasn&#x27;t end-to-end.<p>The former still could&#x27;ve been a bit weaselly and misleading (many non-technical users would probably have assumed &quot;encrypted&quot; implied total confidentiality), but what they actually did was so much worse. I hope they get hit hard on that.
评论 #25046062 未加载
评论 #25045430 未加载
upofadownover 4 years ago
I think the assumed implication with E2EE is that no one other than the partcipants can get at the content of your communications. To do that you need:<p>1. All cryptographic keys controlled by the users.<p>2. Some way to confirm you are actually connected to who you think you are connected to.<p>3. A way to confirm that the code you are running is not leaking keys&#x2F;content.<p>So Zoom failed on all 3 points. There are lots of things out there claiming E2EE that fail on one or more of these points. Almost all fail on point 2 unless the user does things that they almost never do. Is the FTC going to come up with a E2EE definition for trade and start prosecuting those that don&#x27;t meet that definition? Otherwise it would seem unfair that they only went after the entity that ended up in the general media.
评论 #25046327 未加载
eddieozover 4 years ago
&quot;[S]ince at least 2016, Zoom misled users by touting that it offered &#x27;end-to-end, 256-bit encryption&#x27; to secure users&#x27; communications, when in fact it provided a lower level of security,&quot; the FTC said today in the announcement of its complaint against Zoom and the tentative settlement. Despite promising end-to-end encryption, the FTC said that &quot;Zoom maintained the cryptographic keys that could allow Zoom to access the content of its customers&#x27; meetings, and secured its Zoom Meetings, in part, with a lower level of encryption than promised.&quot;<p>That&#x27;s the concept of E2Z2EE (End2Zoom2End Encryption)
评论 #25044443 未加载
_jalover 4 years ago
A deeper issue is how hard it is to &quot;know&quot; if companies hawking products with security implications (which is nearly everything, today) are lying.<p>I&#x27;m not even talking about the gradient ranging from innocent bugs to incompetent coders and how that gets papered over. When you buy shoddy physical goods, there are typically characteristics you can&#x27;t hide, like cheap materials. But with software like this of course the only function your average person can verify is that the transmission happens, not how it is encoded. Neither Grandma nor your manager are likely to break out tcpdump to check.<p>And of course the DMCA complicates this in the US, and things are even worse for researchers elsewhere.<p>Third party audit and reputation are the only fixes I see. And the second one requires a commercial environment that rewards it. The current one doesn&#x27;t; it rewards novelty and lies, so that&#x27;s what we get.
评论 #25046612 未加载
评论 #25057674 未加载
评论 #25046244 未加载
Quarrelsomeover 4 years ago
So will they get fined more than Snapchat for lying about ephemeral messaging or will this be the usual American &quot;slap on the wrist&quot; thing we usually see to protect the investors?
评论 #25045396 未加载
评论 #25044554 未加载
评论 #25044808 未加载
londons_exploreover 4 years ago
If Zoom made clear to users that connections were not secured to the same standards as competitors, and that potentially hundreds of employees could be silently listening in on any call, I think that would have prevented them becoming a leader in video conference tech.<p>So the right fine here is their entire market cap. That would put them back at square one, which is where an honest competitor would be right now.
评论 #25044657 未加载
评论 #25044662 未加载
评论 #25044632 未加载
评论 #25044609 未加载
评论 #25045397 未加载
评论 #25045564 未加载
评论 #25044593 未加载
评论 #25045016 未加载
评论 #25045077 未加载
评论 #25046662 未加载
评论 #25046213 未加载
评论 #25044721 未加载
vinniejamesover 4 years ago
Don&#x27;t forget the hidden web server fiasco <a href="https:&#x2F;&#x2F;medium.com&#x2F;bugbountywriteup&#x2F;zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5" rel="nofollow">https:&#x2F;&#x2F;medium.com&#x2F;bugbountywriteup&#x2F;zoom-zero-day-4-million-...</a>
aofeishengover 4 years ago
All E2E encryption claims in closed source software are untrustworthy. What&#x27;re you expecting?
评论 #25046249 未加载
评论 #25044773 未加载
buryatover 4 years ago
Does it open Zoom to being sued by clients? If a company signed a contract with Zoom in which e2e encryption was stated.
评论 #25044693 未加载
WhyNotHugoover 4 years ago
I find it amusing that congress is seeking to ban E2EE, yet the FTC fining a company that lied about doing it.
评论 #25045657 未加载
PradeetPatelover 4 years ago
It&#x27;s situations like this that makes me wonder whether there should be more efforts put into education and awareness regarding ethics in software engineering. We teach ethics to other STEM disciplines such as biotechnology and aeronautics, why is it left out of software engineering?
评论 #25055580 未加载
einpoklumover 4 years ago
Zoom is also in the habit of censoring content it doesn&#x27;t approve of politically: <a href="https:&#x2F;&#x2F;www.insidehighered.com&#x2F;quicktakes&#x2F;2020&#x2F;10&#x2F;27&#x2F;zoom-faces-more-allegations-censorship" rel="nofollow">https:&#x2F;&#x2F;www.insidehighered.com&#x2F;quicktakes&#x2F;2020&#x2F;10&#x2F;27&#x2F;zoom-fa...</a><p>so, drop Zoom, use a Free and Open-Source alternative. Example: Jitsi (jitsi.org) . It has more rough edges, but it works.
peterwwillisover 4 years ago
This is like suing Hillshire Farms because their bacon wasn&#x27;t as maple-honey-bourbon-flavored as they claimed. Nobody is buying bacon just for flavoring. People use Zoom because it&#x27;s a free digital telephone with screen sharing. Not because it&#x27;s super duper secure.<p>Telephones (VoIP, PSTN, SMS, etc) do not have end-to-end encryption - or <i>any</i> encryption - and we&#x27;ve been using them for conferences since <i>always</i>. Hell, <i>we use them for Zoom calls!</i><p>This is some kind of government vendetta, probably pushed by Zoom&#x27;s competitors who make a bundle in government contracts. Because they&#x27;re currently the biggest provider, they&#x27;re the biggest target. But this standard has not been (and will not be) held up to any of its competitors who make similar claims. The political party that is sabre-rattling in this article is just making themselves look good to their constituents.
frabjousedover 4 years ago
Few years ago I noticed BBM Enterprise touts end-to-end encryption pretty strongly in their marketing, without mentioning an up-front caveat.<p><a href="https:&#x2F;&#x2F;www.blackberry.com&#x2F;us&#x2F;en&#x2F;products&#x2F;bbm-enterprise" rel="nofollow">https:&#x2F;&#x2F;www.blackberry.com&#x2F;us&#x2F;en&#x2F;products&#x2F;bbm-enterprise</a><p>Turns out that by default, BBME is not end-to-end. The initial handshake is transparent to Blackberry, and they could use that to decrypt future messages without your knowledge.<p>To enable true end-to-end, you have to opt in to an out of band handshake to start each new conversation, an option you can turn on in their admin console.<p>How many people are actually going to opt in to dealing with a confirmation SMS for every new thread?<p>I reached out to Blackberry at the time to update their literature as it was misleading, but no action was taken by them.
评论 #25049531 未加载
slostarover 4 years ago
So the takeaway here, there isn&#x27;t real significant consequence for this kind of stuff. Can I just create startup and store passwords in plaintext and lie about it so that I can focus on the core user facing features of the product? Once we get big enough I&#x27;ll just hire some security engineers to do things right.<p>I&#x27;m exaggerating a bit with the above example, but how much corners can someone cut and how much lies can they get away with when it comes to security? Because finding the right balance seems like a serious competitive advantage in the startup space.
spacemanmattover 4 years ago
Will they pay a dime in penalties or backlash for their fraud against consumers?<p>No. Because we nerds aren&#x27;t holding organizational leaders accountable for their IT staffer&#x27;s choices and diligence owed to purchases.
roenxiover 4 years ago
Pretty scandalous stuff. But to be fair it seems pretty likely that any or all of the major players (Apple, Google, MS, Facebook, AWS, etc) to be maintaining some sort of back-door access to the channels they control for spying purposes.<p>I suppose the risk with Zoom is leaks due to incompetence rather than leaks due to government intervention.
评论 #25044793 未加载
评论 #25044895 未加载
tripuover 4 years ago
I&#x27;m not in the least surprised.<p>Think of other popular messaging systems that claim to offer some kind of E2EE, but are proprietary software: WhatsApp, Skype, FB Messenger, Viber, Threema, Line…<p>Distrust by default!<p>I am always amazed when folks even <i>consider</i> the alleged support for strong E2E encryption in those apps… the value of those claims is exactly zero.
zzo38computerover 4 years ago
There are (at least) two points, I think:<p>- Open protocols would be helpful. Then you can implement it by yourself and you can see if it is encrypted (and implement whatever other features you may need, including saving energy).<p>- If they lied to users about end-to-end encryption, then it is false advertising. It is important to avoid false advertising.
lilyballover 4 years ago
&gt; <i>Amid controversy in July 2019, Zoom issued an update to completely remove the Web server from its Mac application, as we reported at the time.</i><p>Surprised to see them mention the web server thing and not mention that it was so bad that Apple actually updated its antivirus software to remove the Zoom web server.
BlueTemplarover 4 years ago
It&#x27;s kind of funny to put this article in parallel with this one :<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=25028411" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=25028411</a><p>Where the EU is planning to add backdoors to E2E services.
temp667over 4 years ago
I was never confused, but am more technical. I mean, how do you terminate to POTS, do the mix-ins etc without zoom decrypting on their end? If it&#x27;s E2E encrypted and I have a dial in number - it&#x27;s not E2E in that sense.
minusSevenover 4 years ago
I guess fake till you make it is name of the game these days. But if that is really the case why did we vilify companies like Theranos or Edison.<p>I have often wondered if I should do it at work as well.
cfstrasover 4 years ago
What other popular group video meeting tools are e2e? I know of none.<p>I remember reading a while back that Zoom claimed a few times they were e2e-encrypted, but what they meant was transport encryption.
评论 #25045219 未加载
评论 #25056474 未加载
评论 #25045829 未加载
0xyover 4 years ago
Why would any company with valuable IP use Zoom after this security blunder, along with the fact they &quot;accidentally&quot; routed domestic US calls via China. Zoom is software developed almost entirely in China, meaning it is subject to Chinese law and the very strong influence of the CCP.<p>It is fact to say that Zoom could be compelled by the CCP to plant backdoors in software to siphon valuable IP for use by Chinese companies, as is usually the case with CCP-aligned companies like Huawei (Huawei had a cash incentive program for employees who delivered stolen IP to them).
评论 #25044981 未加载
评论 #25044885 未加载
jimnotgymover 4 years ago
Disrupting an industry seems to mean breaking the rules. When there is no financial penalty it must be read as a tacit approval from government.
29athrowawayover 4 years ago
Companies that mine data from users will often mislead users when it comes to privacy.<p>e.g.: &quot;You have control over your data&quot;... no, you don&#x27;t.
benkarstover 4 years ago
Oh you know that private video chat that that literally everyone uses, it&#x27;s not private.<p>How is this getting almost no attention from the ms media?
golemotronover 4 years ago
&gt; Democrats blast FTC&#x2F;Zoom settlement because users won&#x27;t get compensation.<p>Are they the same people who want to get rid of encryption?
joeblauover 4 years ago
I wonder if this is the source for any “leaks” from tech companies who use Zoom as their office communication tool?
ineedasernameover 4 years ago
Companies that make claims like this should provide an external audit to support their claims.
cwkossover 4 years ago
Every business customer should now sue zoom for the full cost of what they previously paid.
morpheuskafkaover 4 years ago
Pretty ridiculous for the US to be enforcing this while they try to ban and reduce availability of E2EE worldwide. Zoom et all are doing them a great service by spreading FUD and confusion about what E2EE even is. Once it&#x27;s reduced to &quot;complex math thing&quot; in people&#x27;s minds no one will know or care when they ban it.
评论 #25046724 未加载
noyoukhkhover 4 years ago
if security is that much important to you, your company may be you, your company should build a communication platform for itself right!?<p>you, people should believe or trust no one! thats the number one rule for [e2e, or else] security I think.
评论 #25045362 未加载
120photoover 4 years ago
Oh no, a company based out of China lied to everyone? Say it ain&#x27;t so.
评论 #25047178 未加载
tsjqover 4 years ago
How long before it is discovered that such fake encryption led to some killings &#x2F; illegal arrests or meddling with Elections ?
plucover 4 years ago
Where is the consequences addendum?
评论 #25045680 未加载
m3kw9over 4 years ago
Old news, is just FTC judgement but security has already proven that back in April it wasn’t E2E
vmceptionover 4 years ago
2020 Zoom lied about end to end encryption<p>2021 Nobody can have end to end encryption
zelphirkaltover 4 years ago
Hmmm, why am I not surprised right now?
residentfoamover 4 years ago
fake it until you make it
micropoetover 4 years ago
Is this the reason stock price going down? or Covid vaccine?
ahmetyas01over 4 years ago
why the servers are in Chine ? For asia market or for communist part?
jtdevover 4 years ago
The relationship between Zoom and China should outright disqualify it from being used in any Democratic countries.
评论 #25046922 未加载
throwaway4goodover 4 years ago
I thought they made a deal with Trump&#x2F;Oracle and that fixed all this stuff?
评论 #25044646 未加载
a_narover 4 years ago
I saw this on &#x2F;r&#x2F;privacy a few hours ago. Funny how things from reddit can appear on HN, and vice-versa
评论 #25044798 未加载
feralimalover 4 years ago
No! Corporations lie?!<p>At least their feet will held to the fire!<p>&#x2F;s<p>Tbh though, they will only be held to account, if another big player wants to cripple them and take their market.
smokey_circlesover 4 years ago
I don&#x27;t understand how the FTC arrived at the conclusion they&#x27;re not E2E? Or have I missed something?<p>&gt;Despite promising end-to-end encryption, the FTC said that &quot;Zoom maintained the cryptographic keys that could allow Zoom to access the content of its customers&#x27; meetings, and secured its Zoom Meetings, in part, with a lower level of encryption than promised.&quot;<p>Not wonderful but that still, technically, is an E2E encryption scheme. Is it not? Or do they mean one end terminates in Zoom&#x27;s servers and it&#x27;s not E2E through the whole pipe, but rather two pipes stitched together?<p>Agreed it&#x27;s not as secure as they marketed, but this seems to suggest if you want to offer E2E you need a specific kind of key storage to meet this new precedent. Good in practice, but maybe the FTC are not the right people to placing such a hurdle down?<p>I&#x27;m sure I&#x27;ve missed something though.
评论 #25044700 未加载
评论 #25044691 未加载
评论 #25044771 未加载
评论 #25044679 未加载
评论 #25044712 未加载