Jump to content

Zoom lied to users about end-to-end encryption for years, FTC says

GDRRiley

Summary

 

zoom claimed they were using end to end 256bit encryption but kept the keys on their servers, this has been going on sense at least 2016. They claimed to be during 2016 and 2017 HIPAA complaints guides. (medical privacy laws)

 

Quotes

Quote

"In fact, Zoom did not provide end-to-end encryption for any Zoom Meeting that was conducted outside of Zoom's 'Connecter' product (which are hosted on a customer's own servers), because Zoom's servers—including some located in China—maintain the cryptographic keys that would allow Zoom to access the content of its customers' Zoom Meetings," the FTC complaint said.

 

The FTC announcement said that Zoom also "misled some users who wanted to store recorded meetings on the company's cloud storage by falsely claiming that those meetings were encrypted immediately after the meeting ended. Instead, some recordings allegedly were stored unencrypted for up to 60 days on Zoom's servers before being transferred to its secure cloud storage."

 

To settle the allegations, "Zoom has agreed to a requirement to establish and implement a comprehensive security program, a prohibition on privacy and security misrepresentations, and other detailed and specific relief to protect its user base, which has skyrocketed from 10 million in December 2019 to 300 million in April 2020 during the COVID-19 pandemic," the FTC said.

 

My thoughts

Not a big shock, they aren't using end to end while claiming they do. I don't trust almost any of the video calling providers but signal.

 

Sources

https://arstechnica.com/tech-policy/2020/11/zoom-lied-to-users-about-end-to-end-encryption-for-years-ftc-says/

Good luck, Have fun, Build PC, and have a last gen console for use once a year. I should answer most of the time between 9 to 3 PST

NightHawk 3.0: R7 5700x @, B550A vision D, H105, 2x32gb Oloy 3600, Sapphire RX 6700XT  Nitro+, Corsair RM750X, 500 gb 850 evo, 2tb rocket and 5tb Toshiba x300, 2x 6TB WD Black W10 all in a 750D airflow.
GF PC: (nighthawk 2.0): R7 2700x, B450m vision D, 4x8gb Geli 2933, Strix GTX970, CX650M RGB, Obsidian 350D

Skunkworks: R5 3500U, 16gb, 500gb Adata XPG 6000 lite, Vega 8. HP probook G455R G6 Ubuntu 20. LTS

Condor (MC server): 6600K, z170m plus, 16gb corsair vengeance LPX, samsung 750 evo, EVGA BR 450.

Spirt  (NAS) ASUS Z9PR-D12, 2x E5 2620V2, 8x4gb, 24 3tb HDD. F80 800gb cache, trueNAS, 2x12disk raid Z3 stripped

PSU Tier List      Motherboard Tier List     SSD Tier List     How to get PC parts cheap    HP probook 445R G6 review

 

"Stupidity is like trying to find a limit of a constant. You are never truly smart in something, just less stupid."

Camera Gear: X-S10, 16-80 F4, 60D, 24-105 F4, 50mm F1.4, Helios44-m, 2 Cos-11D lavs

Link to comment
Share on other sites

Link to post
Share on other sites

18 minutes ago, GDRRiley said:

Not a big shock, they aren't using end to end while claiming they do. I don't trust almost any of the video calling providers but signal.

Zoom isn't supposed to be a video calling app like facetime, signal and whatnot, it's targeted for meetings among groups of people. Sure just two people can use it for meetings and it's like facetime at that point but that's not the intended purpose.

 

Edit:

If you group Zoom as a video call service like Telegram, Signal, etc. then you might as well call WebEx, Jitsi, Microsoft Teams, GoToMeeting, etc. video calling services too but that's not what they are used for because that's not their target market or function.

Current Network Layout:

Current Build Log/PC:

Prior Build Log/PC:

Link to comment
Share on other sites

Link to post
Share on other sites

Wait, your telling me that Zoom, the company with more data breaches than the US Government, ISNT VERY SECURE!?!?!??!

I could use some help with this!

please, pm me if you would like to contribute to my gpu bios database (includes overclocking bios, stock bios, and upgrades to gpus via modding)

Bios database

My beautiful, but not that powerful, main PC:

prior build:

Spoiler

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

39 minutes ago, Lurick said:

Zoom isn't supposed to be a video calling app like facetime, signal and whatnot, it's targeted for meetings among groups of people. Sure just two people can use it for meetings and it's like facetime at that point but that's not the intended purpose.

 

Edit:

If you group Zoom as a video call service like Telegram, Signal, etc. then you might as well call WebEx, Jitsi, Microsoft Teams, GoToMeeting, etc. video calling services too but that's not what they are used for because that's not their target market or function.

thing is I expect them all to decent security, and often time it is less than 5 people which almost all video calling services can do

Good luck, Have fun, Build PC, and have a last gen console for use once a year. I should answer most of the time between 9 to 3 PST

NightHawk 3.0: R7 5700x @, B550A vision D, H105, 2x32gb Oloy 3600, Sapphire RX 6700XT  Nitro+, Corsair RM750X, 500 gb 850 evo, 2tb rocket and 5tb Toshiba x300, 2x 6TB WD Black W10 all in a 750D airflow.
GF PC: (nighthawk 2.0): R7 2700x, B450m vision D, 4x8gb Geli 2933, Strix GTX970, CX650M RGB, Obsidian 350D

Skunkworks: R5 3500U, 16gb, 500gb Adata XPG 6000 lite, Vega 8. HP probook G455R G6 Ubuntu 20. LTS

Condor (MC server): 6600K, z170m plus, 16gb corsair vengeance LPX, samsung 750 evo, EVGA BR 450.

Spirt  (NAS) ASUS Z9PR-D12, 2x E5 2620V2, 8x4gb, 24 3tb HDD. F80 800gb cache, trueNAS, 2x12disk raid Z3 stripped

PSU Tier List      Motherboard Tier List     SSD Tier List     How to get PC parts cheap    HP probook 445R G6 review

 

"Stupidity is like trying to find a limit of a constant. You are never truly smart in something, just less stupid."

Camera Gear: X-S10, 16-80 F4, 60D, 24-105 F4, 50mm F1.4, Helios44-m, 2 Cos-11D lavs

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, GDRRiley said:

thing is I expect them all to decent security, and often time it is less than 5 people which almost all video calling services can do

That's a fair enough assessment, I guess I'm more focused on corporate environments so I've got a skewed view of what they do and should do :)

I do agree 100% on the security front though, regardless of target, they shouldn't falsely advertise capabilities and compliance.

Current Network Layout:

Current Build Log/PC:

Prior Build Log/PC:

Link to comment
Share on other sites

Link to post
Share on other sites

46 minutes ago, Letgomyleghoe said:

telegram...

I mostly use it for stickers tbh. Sure encryption is nice but animated stickers tho.

Our Grace. The Feathered One. He shows us the way. His bob is majestic and shows us the path. Follow unto his guidance and His example. He knows the one true path. Our Saviour. Our Grace. Our Father Birb has taught us with His humble heart and gentle wing the way of the bob. Let us show Him our reverence and follow in His example. The True Path of the Feathered One. ~ Dimboble-dubabob III

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Lurick said:

That's a fair enough assessment, I guess I'm more focused on corporate environments so I've got a skewed view of what they do and should do :)

I do agree 100% on the security front though, regardless of target, they shouldn't falsely advertise capabilities and compliance.

I spend at least an hour a day for work on a zoom call with less than 10 people. it could be done over a conference call wouldn't matter. my school could just be done as a YT/twitch livestream

 

Good luck, Have fun, Build PC, and have a last gen console for use once a year. I should answer most of the time between 9 to 3 PST

NightHawk 3.0: R7 5700x @, B550A vision D, H105, 2x32gb Oloy 3600, Sapphire RX 6700XT  Nitro+, Corsair RM750X, 500 gb 850 evo, 2tb rocket and 5tb Toshiba x300, 2x 6TB WD Black W10 all in a 750D airflow.
GF PC: (nighthawk 2.0): R7 2700x, B450m vision D, 4x8gb Geli 2933, Strix GTX970, CX650M RGB, Obsidian 350D

Skunkworks: R5 3500U, 16gb, 500gb Adata XPG 6000 lite, Vega 8. HP probook G455R G6 Ubuntu 20. LTS

Condor (MC server): 6600K, z170m plus, 16gb corsair vengeance LPX, samsung 750 evo, EVGA BR 450.

Spirt  (NAS) ASUS Z9PR-D12, 2x E5 2620V2, 8x4gb, 24 3tb HDD. F80 800gb cache, trueNAS, 2x12disk raid Z3 stripped

PSU Tier List      Motherboard Tier List     SSD Tier List     How to get PC parts cheap    HP probook 445R G6 review

 

"Stupidity is like trying to find a limit of a constant. You are never truly smart in something, just less stupid."

Camera Gear: X-S10, 16-80 F4, 60D, 24-105 F4, 50mm F1.4, Helios44-m, 2 Cos-11D lavs

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, GDRRiley said:

Summary

 

zoom claimed they were using end to end 256bit encryption but kept the keys on their servers, this has been going on sense at least 2016. They claimed to be during 2016 and 2017 HIPAA complaints guides. (medical privacy laws)

 

Quotes

 

My thoughts

Not a big shock, they aren't using end to end while claiming they do. I don't trust almost any of the video calling providers but signal.

 

Sources

https://arstechnica.com/tech-policy/2020/11/zoom-lied-to-users-about-end-to-end-encryption-for-years-ftc-says/

I’m tempted to trust the HIPPA stuff after I saw how hard it was to find a hippa approved one.  The ones I know of that have hippa approved sections (how publicly available those sections are I don’t know) appear to include Lifesize and a couple others. FaceTime isn’t on it, and if zoom is it’s quite new.

Not a pro, not even very good.  I’m just old and have time currently.  Assuming I know a lot about computers can be a mistake.

 

Life is like a bowl of chocolates: there are all these little crinkly paper cups everywhere.

Link to comment
Share on other sites

Link to post
Share on other sites

tbf they've made a strong effort to fix what they haven't been doing all these years and I greatly respect it. They've had a strong flow of money come in this year, and they actually used it to better what they already have instead of just focusing solely on their shareholders which is what a lot of companies do nowadays. 

 

even went as far as to discontinue and not even support old zoom client versions when they actually implemented encryption. 

"If a Lobster is a fish because it moves by jumping, then a kangaroo is a bird" - Admiral Paulo de Castro Moreira da Silva

"There is nothing more difficult than fixing something that isn't all the way broken yet." - Author Unknown

Spoiler

Intel Core i7-3960X @ 4.6 GHz - Asus P9X79WS/IPMI - 12GB DDR3-1600 quad-channel - EVGA GTX 1080ti SC - Fractal Design Define R5 - 500GB Crucial MX200 - NH-D15 - Logitech G710+ - Mionix Naos 7000 - Sennheiser PC350 w/Topping VX-1

Link to comment
Share on other sites

Link to post
Share on other sites

6 hours ago, DildorTheDecent said:

I mostly use it for stickers tbh. Sure encryption is nice but animated stickers tho.

Nah, telegram is slowly turning into a honeypot for authorities, time for you to switch to Riot instead.

Specs: Motherboard: Asus X470-PLUS TUF gaming (Yes I know it's poor but I wasn't informed) RAM: Corsair VENGEANCE® LPX DDR4 3200Mhz CL16-18-18-36 2x8GB

            CPU: Ryzen 9 5900X          Case: Antec P8     PSU: Corsair RM850x                        Cooler: Antec K240 with two Noctura Industrial PPC 3000 PWM

            Drives: Samsung 970 EVO plus 250GB, Micron 1100 2TB, Seagate ST4000DM000/1F2168 GPU: EVGA RTX 2080 ti Black edition

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, williamcll said:

time for you to switch to Riot instead.

I hope you're getting paid, lol.

Our Grace. The Feathered One. He shows us the way. His bob is majestic and shows us the path. Follow unto his guidance and His example. He knows the one true path. Our Saviour. Our Grace. Our Father Birb has taught us with His humble heart and gentle wing the way of the bob. Let us show Him our reverence and follow in His example. The True Path of the Feathered One. ~ Dimboble-dubabob III

Link to comment
Share on other sites

Link to post
Share on other sites

5 hours ago, Bombastinator said:

I’m tempted to trust the HIPPA stuff after I saw how hard it was to find a hippa approved one.  The ones I know of that have hippa approved sections (how publicly available those sections are I don’t know) appear to include Lifesize and a couple others. FaceTime isn’t on it, and if zoom is it’s quite new.

zoom tried to be in 2016 and 2017 when they claimed the had end to end encryption

Good luck, Have fun, Build PC, and have a last gen console for use once a year. I should answer most of the time between 9 to 3 PST

NightHawk 3.0: R7 5700x @, B550A vision D, H105, 2x32gb Oloy 3600, Sapphire RX 6700XT  Nitro+, Corsair RM750X, 500 gb 850 evo, 2tb rocket and 5tb Toshiba x300, 2x 6TB WD Black W10 all in a 750D airflow.
GF PC: (nighthawk 2.0): R7 2700x, B450m vision D, 4x8gb Geli 2933, Strix GTX970, CX650M RGB, Obsidian 350D

Skunkworks: R5 3500U, 16gb, 500gb Adata XPG 6000 lite, Vega 8. HP probook G455R G6 Ubuntu 20. LTS

Condor (MC server): 6600K, z170m plus, 16gb corsair vengeance LPX, samsung 750 evo, EVGA BR 450.

Spirt  (NAS) ASUS Z9PR-D12, 2x E5 2620V2, 8x4gb, 24 3tb HDD. F80 800gb cache, trueNAS, 2x12disk raid Z3 stripped

PSU Tier List      Motherboard Tier List     SSD Tier List     How to get PC parts cheap    HP probook 445R G6 review

 

"Stupidity is like trying to find a limit of a constant. You are never truly smart in something, just less stupid."

Camera Gear: X-S10, 16-80 F4, 60D, 24-105 F4, 50mm F1.4, Helios44-m, 2 Cos-11D lavs

Link to comment
Share on other sites

Link to post
Share on other sites

16 hours ago, GDRRiley said:

video calling providers but signal.

Does Signal have group video calling?

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

The only advantage Zoom has over Microsoft Teams and Google Meet is the ability to host up to 1000 participants in a meeting with a higher tier plan. But if an organization is already paying for Google Workspace or Microsoft 365, there’s no need to use Zoom since Meet and Teams are included. 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

52 minutes ago, Kajoor said:

And still zoon is most popular video communication source.

May have gotten hit by autocorrect there. A zoon is this old microsoft music player designed to compete with the iPod. 

Not a pro, not even very good.  I’m just old and have time currently.  Assuming I know a lot about computers can be a mistake.

 

Life is like a bowl of chocolates: there are all these little crinkly paper cups everywhere.

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Bombastinator said:

May have gotten hit by autocorrect there. A zoon is this old microsoft music player designed to compete with the iPod. 

Fixed 😂

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×