Zoom strong-armed by US watchdog to beef up security after boasting of end-to-end encryption that didn't exist
- Reference: 1604955812
- News link: https://www.theregister.co.uk/2020/11/09/zoom_ftc_deal/
- Source link:
The [1]pact [PDF], [2]announced Monday, obliges the video-conferencing giant to carry out an annual security assessment of its software and have its internal security program assessed by a third-party every two years. It also has to create a vulnerability management program, and add security safeguards, such as multi-factor authentication and proper data deletion.
Zoom staff will have to review software updates for security flaws and make sure they don’t impede third-party security measures – as happened with in July 2018 when a Zoom update bypassed an anti-malware feature in Apple’s Safari browser and fired up a web server called ZoomOpener that directly launch the Zoom App.
Zealous Zoom's zesty zymotic zone zinger: Zestful zealots zip zillions [3]READ MORE
The commission's investigation also dug into Zoom’s earlier claim it offered 256-bit end-to-end encryption when in fact the feature [4]didn't actually exist – the software maker says it has [5]since implemented the technology. To address that part of the FTC's grumbles against Zoom, the settlement prohibits the biz from “making misrepresentations about its privacy and security practices, including about how it collects, uses, maintains, or discloses personal information; its security features; and the extent to which users can control the privacy or security of their personal information.” Zoom, which was previously [6]slammed for its earlier problematic privacy policy, admitted no culpability under the terms of the deal.
Thanks to the COVID-19 pandemic, Zoom’s user-friendly video conferencing software went from a popular tool to an essential piece of software as people isolated themselves at home – and a household name. Its share price has quintupled since the beginning of the year – from $100 to $500, after user numbers ballooned from 10 million in December to 300 million in April.
Price drop
That connection was in full view this morning when its share price dropped 13 per cent – not as a result of the FTC settlement but rather the announcement by pharmaceutical giant Pfizer that its COVID-19 vaccine is claimed to be 90 per cent effective in the latest set of tests. That result has pointed to a possible ending of the pandemic in 2021, which would greatly reduce the use of Zoom.
It is notable however that the FTC settlement only passed 3-2 with the regulator’s two Democratic commissioners dissenting. Rebecca Kelly Slaughter [7]noted [PDF] that while the settlement addresses security concerns, it does not tackle related privacy concerns and argued in a statement that “Zoom’s approach to user privacy was fundamentally reactive rather than proactive.”
There is no mention of privacy in the settlement: something that Commissioner Slaughter says “reflects a failure by the majority to understand that the reason customers care about security measures in products like Zoom is that they value their privacy.”
Meanwhile, Commissioner Rohit Chopra [8]said [PDF] that the settlement “includes no help for affected parties, no money, and no other meaningful accountability” and argued that the FTC approaches issues like this in the wrong way: “The FTC’s status quo approach to privacy, security, and other data protection law violations is ineffective.”
He argues that small businesses that signed contracts with Zoom should be allowed to be released from them, or seek refunds, because they were based “on false representations.” And he balks at the fact that Zoom does not have to admit to fault: “Zoom admits nothing and the Commission’s investigation makes no significant conclusions.”
Aside by introducing fines, Chopra also argues that the FTC’s investigative teams need more technical expertise and as a start it should restore the role of FTC Chief Technologist. ®
Get our [9]Tech Resources
[1] https://www.ftc.gov/system/files/documents/cases/1923167zoomacco2.pdf
[2] https://www.ftc.gov/news-events/press-releases/2020/11/ftc-requires-zoom-enhance-its-security-practices-part-settlement
[3] https://www.theregister.com/2020/06/03/zoom_q1_fy2021/
[4] https://www.theregister.com/2020/04/01/zoom_spotlight/
[5] https://www.theregister.com/2020/10/27/zoom_endtoend_encryption/
[6] https://www.theregister.com/2020/03/27/doc_searls_zoom_privacy/
[7] https://www.ftc.gov/system/files/documents/public_statements/1582918/1923167zoomslaughterstatement.pdf
[8] https://www.ftc.gov/system/files/documents/public_statements/1582914/final_commissioner_chopra_dissenting_statement_on_zoom.pdf
[9] https://whitepapers.theregister.com/
Re: End-to-end?
Five eyes end-to-end encryption is encryption at the start, decryption in the middle and encryption at the other end - this is approved by five-eyes so Zoom is meeting the requirements?
"So which video services actually do offer true end-to-end encryption"
Well, Zoom now says it's doing proper E2EE after earlier trying to claim its use of vanilla TLS was E2E. Here's its statement:
"Zoom’s E2EE offering uses public key cryptography. In short, the keys for each Zoom meeting are generated by participants’ machines, not by Zoom’s servers. Encrypted data relayed through Zoom’s servers is indecipherable by Zoom, since Zoom’s servers do not have the necessary decryption key. This key management strategy is similar to that used by most end-to-end encrypted messaging platforms today."
Take that into account as you will.
C.
Re: End-to-end?
"Wire" says that separate streams are required for true e2ee in a group chat...
[1]https://medium.com/@wireapp/video-conferencing-end-to-end-encrypted-1270ab1c16fe
However, google says a group can share common keys: [2]https://support.google.com/duo/answer/9280240?hl=en-GB - the main thing is that the shared keys are renegotiated when a user joins or leaves the chat.
Edit: Accidentally posted "anonymous", and trying to fix that using "edit post" doesn't work - "Jamie Jones"
[1] https://medium.com/@wireapp/video-conferencing-end-to-end-encrypted-1270ab1c16fe
[2] https://support.google.com/duo/answer/9280240?hl=en-GB
Alternative, higher quality services exist...
I've been converting all of my musician and music teacher friends from Zoom and teams to Rock Out Loud Live.
Great audio quality and as low latency as I've seen in any streaming service. They deliberately limit session connections to ensure QOS for small groups as opposed to supporting huge gatherings and live concerts. Very focused in their mission.
They don't advertise and are little known outside of the music teaching community. Won't post their URL here but they are easy enough to find.
End-to-end?
So which video services actually do offer true end-to-end encryption with no man-in-the-middle?
I've been reading through the issues facing Nextcloud Talk and Jitsi. The basic problem seems to be that if the stream is encrypted properly, each client needs a "direct link" with each other client - and this doesn't really scale. NCT claims that you need to budget 1Mbit/s per connected user, which quickly becomes impossible if you're the wrong side of an ADSL connection with a capped uplink speed of 1Mbps.
Google Meet and Zoom seem to work reasonably well down to speeds of 300kbit/s here but this is one stream only outgoing - we were in a Google Meet call with nearly 40 others on Sunday and our upstream bitrate for two connections (don't ask) didn't top 800kbps so obviously Google's doing something in the middle.
Current solutions for scaling seem pretty much all to involve client-server-client connection models, with the server in the middle decoding and routing, pretty much as Zoom does at the moment. Jitsi has plans for some kind of two-layer encryption but I read the notes and still didn't have a clue exactly how that solved the issue.
Any pointers for a good introduction to the subject?
M.