Live data from Hacker News

Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

vice.com

261–270 of 375 posts

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#261
post #216

If you have a Facebook account and are curious what other apps and websites are sending data about you to Facebook, check out this link: https://www.facebook.com/off_facebook_activity/activity_list (click the area with the various app & website icons to expand into a more detailed view) I was pretty surprised the first time I came across that list, there are a lot of apps on there that I never did a Facebook login wi…

So I do not have facebook installed on my phone but I do have instagram and whatsapp. A large amount of phone apps seem to appear in that list. I guess Whatsapp/Instagram creates a fingerprint of my device and then uses that for tracking?

I believe that is in fact the case. I removed all Facebook owned apps from my phone a few weeks ago and I stopped seeing reports show up there. Experimentally, it seems like an uninstall disassociates the ID from your facebook account.

That doesn’t mean facebook stopped getting those reports, only that they are no longer associating them with my account.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#262
post #2

> There is nothing in the privacy policy that addresses [that data is being sent to Facebook] > The Zoom app notifies Facebook when the user opens the app, details on the user's device such as the model, the time zone and city they are connecting from, which phone carrier they are using, and a unique advertiser identifier created by the user's device which companies can use to target a user with advertisements So Zoo…

The kindle app contacts facebook too. All KINDS of webpages and apps contact facebook. It's a mess that I only figure legislation can help correct.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#263
post #82

Earlier quoted context omitted.

It's past time for us to get serious and apply HIPAA-style protection to the storage and transmission of PII, without exemptions. Companies like Facebook will complain loudly that they won't be able to survive, but that is not our problem. If we pass legislation with teeth, they will need to change their business model. That would be the point.

I disagree with this — more regulation will make it harder to innovate. For example, I’ve met several founders who wanted to enable tele-medicine years ago but decided against it because “the lawyers cost more than the engineers”, and walking-on-eggshells destroys morale & iteration speed. I’m not arguing to de-regulate heath data — my point is that we should selectively apply regulation. It’s likely a great thing to…

It makes it harder to innovate in anti-social directions, and may catch some useful things in the crossfire. But on balance, slowing the rate of "innovation" for these companies that want you to shovel all data everywhere into their gaping maw? Not a problem for me.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#264
post #2

> There is nothing in the privacy policy that addresses [that data is being sent to Facebook] > The Zoom app notifies Facebook when the user opens the app, details on the user's device such as the model, the time zone and city they are connecting from, which phone carrier they are using, and a unique advertiser identifier created by the user's device which companies can use to target a user with advertisements So Zoo…

It's past time for us to get serious and apply HIPAA-style protection to the storage and transmission of PII, without exemptions. Companies like Facebook will complain loudly that they won't be able to survive, but that is not our problem. If we pass legislation with teeth, they will need to change their business model. That would be the point.

HIPAA ha...

Kaiser Permanente will contact google analytics and doubleclick as you navigate their website, even when checking test results and contacting your doctor.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#265
post #250

Earlier quoted context omitted.

it's time to stop using the f'ing apps mate

Most users of Zoom aren't choosing it–it is being chosen for them. Both of my children's schools (preschool and elementary) started using Zoom this week, so it is either use Zoom or they do not get to participate.

Zoom has a web version.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#266

Earlier quoted context omitted.

Then don't use the startup? Not everyone has the same calculus as you. You don't need regulation in order for you to not use a product.

Regulation exists to protect citizens at scale. “Don’t use the business” isn’t how we’ve built society, rightfully so. If you believe the regulation to be onerous, fix it. One is not entitled to do whatever one wants to generate a profit, at the detriment to uneducated or unsophisticated citizens, or society as a whole.

> If you believe the regulation to be onerous, fix it.

Well, that's what they're doing by not wanting it.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#267

Earlier quoted context omitted.

>So facebook sent me a cease and desist threat for revealing that they were tracking all vehicles driving by their campus and then telling the city of menlo park of this. Do you have a blog or some such going into more details? This raises all sorts of curiousness. How did you find out this is what was going on? What justifications did FB claim for doing the tracking? What justifications did FB claim for stopping you…

..

thanks!

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#268

Earlier quoted context omitted.

> If you don't store any data you won't need any lawyers. Wrong. HIPAA applies to any business that transmits and/or has access to PHI. You don't need to be storing data on your own hard drives to be subject to these laws. This is exactly my point. You are thinking like an engineer, and Congress is not. You cannot assume anything . You need to hire a lawyer, or you are opening yourself up to serious liability.

I worded that poorly. How about this: If you don't own, manage, solicit or control any servers having access to PHI or PII you don't have any risk of being liable. Put all of that on the client, do your best to protect it but ultimately make it the clients responsibility. I still haven't seen any lawsuits or regulation targeting software in that sense, apart from DRM.

There is no distinction between client vs server when it comes to the law. The same organization created and operates both and is liable as a data processor in both situations.

This is again the difference between engineer vs policymaker.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#269

Earlier quoted context omitted.

Regulation exists to protect citizens at scale. “Don’t use the business” isn’t how we’ve built society, rightfully so. If you believe the regulation to be onerous, fix it. One is not entitled to do whatever one wants to generate a profit, at the detriment to uneducated or unsophisticated citizens, or society as a whole.

> If you believe the regulation to be onerous, fix it. Well, that's what they're doing by not wanting it.

[deleted]

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#270
post #250

Earlier quoted context omitted.

Most users of Zoom aren't choosing it–it is being chosen for them. Both of my children's schools (preschool and elementary) started using Zoom this week, so it is either use Zoom or they do not get to participate.

Zoom has a web version.

Except Zoom web version doesn't work: the incoming/outgoing audio is garbled (tested with Chrome, they do not support Firefox). This is in part because they were obviously too good for WebRTC native audio and instead gutted ffmpeg and compiled it to WebAssembly (I wish I was kidding but I'm not: https://webrtchacks.com/zoom-avoids-using-webrtc/).

Moreover, Zoom has a history of RCEs (leaving an active web server after you uninstall Zoom? so that a website can reinstall Zoom without any user interaction? why not! https://medium.com/bugbountywriteup/zoom-zero-day-4-million-...), and anti-privacy behavior: meeting host gets a copy of all private messages sent between participants (there is no notice of this; https://twitter.com/rcalo/status/1237957509324746752); host can monitor if your Zoom window is active (https://twitter.com/zoom_us/status/1241768006327336963); and Zoom has audio fingerprint tracing (so if you get a leaked recording Zoom can blame a particular participant: https://venturebeat.com/2019/01/22/zoom-is-bringing-ultrason...). Running it under strace reveals it is fingerprinting your device as well (idk if that gets sent anywhere but iOS app sends stuff to Facebook...).

Zoom is creepy and should not be used. I keep a separate VM for it, as it clearly can not be trusted.

Post reply on HN