Live data from Hacker News

Zoom’s Use of Facebook’s SDK in iOS Client

blog.zoom.us

161–170 of 272 posts

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#161

Earlier quoted context omitted.

> Blaming Apple? Why, when Zoom is on the Play Store as well? Blame Apple because they constantly tout the iPhone as being "privacy respecting" and "what happens on your iPhone stays on your iPhone"[0], while they A. Apple doesn't default to "limit tracking", or at least make "limit tracking" an option on setup/iOS upgrade B. Apple doesn't penalize developers for using Facebook's SDK with auto data collection (ie. pu…

> the Facebook SDK was collecting device information unnecessary for us to provide our services. Sorry state of Apple App security and privacy - all your apps are swarms of data collection and privacy abuses. Apple built this world - and Apple is to blame. Zoom is to blame too. And finally individual app developers should also alert everyone on what's truly happening in their apps.

While I have zero love for any given hyper capitalistic business like Apple, Android is not any better on the whole in this space, and in some ways measurably worse (especially when you take into account what devices actually hold the largest market share)

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#162
post #150

Earlier quoted context omitted.

I'm really liking Zoom's responses to incidents lately. Both this and the "oops we implemented certain features by leaving a localhost webserver gaping open" fiasco fairly recently got extremely nimble responses from them, and the responses were absolutely the right thing to do. They could have hand-waved the http server away and claimed to have "secured" it, and they could have hand-waved this away as "standard prac…

in the end they did the right thing with the local web server, but iirc their first response was "this is a non issue and needed for proper operation". a definite improvement in this case and so far.

I agree that they started out kinda shitty on the web server thing, but they corrected pretty decisively. The web server was gone within days.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#163
post #62

Earlier quoted context omitted.

I don't want to live in a world where my parents and grandparents are expected to pull up Wireshark to figure out if the app they're using will record their front camera without consent. Blaming Zoom and FB is entirely acceptable here, it is their responsibility to keep my data private. Blaming Apple? Why, when Zoom is on the Play Store as well? https://play.google.com/store/apps/details?id=us.zoom.videom... >As long…

> Blaming Apple? Why, when Zoom is on the Play Store as well? Blame Apple because they constantly tout the iPhone as being "privacy respecting" and "what happens on your iPhone stays on your iPhone"[0], while they A. Apple doesn't default to "limit tracking", or at least make "limit tracking" an option on setup/iOS upgrade B. Apple doesn't penalize developers for using Facebook's SDK with auto data collection (ie. pu…

It seems whoever is gathering that info and sending it is Facebook

Blame them. Not Apple

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#164

Earlier quoted context omitted.

They are changing because right now they are growing like crazy without the need to do much on user acquisition, and a bad PR is just too costly right now. But good to see them doing it.

Sure, good they are changing. And Zoom is definitely not alone in this. Facebook SDK usage is widespread and it's a horrible thing. And even then, the fault ultimately resides with Apple and Google that provide cross-application unique identifiers.

Yup, cross application unique identifiers are such a bad idea that it is hard to believe they exist. Maybe for Google I understand, since their entire business is advertising and android is more like a live billboard to display ads from their POV, but Apple, the company crying privacy, still provides an advertising id is shocking.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#165
post #116

Earlier quoted context omitted.

What industry do you work in and what country are you in right now?

Fortune 500 consulting, European Union market. Webex, Teams, Slack are the only ones that matter.

"Webex, Teams"

Yeah some companies are behind the curve (not blaming you).

Zoom is getting very popular

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#166
post #116

Earlier quoted context omitted.

What industry do you work in and what country are you in right now?

Fortune 500 consulting, European Union market. Webex, Teams, Slack are the only ones that matter.

I'd guess you work mainly with slower players (the mention of webex surely suggests so). Zoom as been very much on the rise for a year or so, and is riding the coronavirus WFH wave very well. IME quality is better than competitors, but boy do they use dark patterns. Finding the link to the web version in the meeting page becomes harder every day.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#167

Earlier quoted context omitted.

I've worked at places where "cowboy coding" was the norm and people would just look up how to do something on StackOverflow and copy/paste it. But to pull in a major 3rd party dependency like this and just "YOLO" ship it in your company's product? That's almost unbelievable. Didn't anyone have a look to see what the thing does? Assuming the SDK comes with source code, and if they integrated a 3rd party library that d…

Conversely, I’ve never worked anywhere, in 10+ years, where “we shouldn’t be sending this data to X, it’s bad for our users”, would have got further than the developers. Marketing, Product and management rarely care: in many cases they want the data to go to as many analytics and targeting services as they can.

Since the GDPR came into effect, at least in Germany I notice how product managers and other parties are involved in stuff like this, and not only devs and dev leads.

As an example, 2 weeks ago I had to implement Instabug's SDK for one of our app brands, and created a no-op fake library [0] in order not to shop any Instabug code to the other 5+ apps.

Simply because our PM was afraid of possibly sending stuff to them while not having added them to the privacy policy.

[0]: https://medium.com/@orhanobut/no-op-versions-for-dev-tools-b...

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#168
post #62

Earlier quoted context omitted.

I don't want to live in a world where my parents and grandparents are expected to pull up Wireshark to figure out if the app they're using will record their front camera without consent. Blaming Zoom and FB is entirely acceptable here, it is their responsibility to keep my data private. Blaming Apple? Why, when Zoom is on the Play Store as well? https://play.google.com/store/apps/details?id=us.zoom.videom... >As long…

> Blaming Apple? Why, when Zoom is on the Play Store as well? Blame Apple because they constantly tout the iPhone as being "privacy respecting" and "what happens on your iPhone stays on your iPhone"[0], while they A. Apple doesn't default to "limit tracking", or at least make "limit tracking" an option on setup/iOS upgrade B. Apple doesn't penalize developers for using Facebook's SDK with auto data collection (ie. pu…

Not just that Apple has actually started to sell users' data to Goldman Sachs as well. The worst part is, this is opt-in. Not opt out. And opt out is incredibly so backward that you need to email some address instead of just clicking a button.

So I don't see how they're a "privacy respecting company" either. It's just marketing BS.

https://techcrunch.com/2020/03/24/apple-card-gets-updated-pr...

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#169
post #45

So it sounds like Zoom was using the Facebook SDK, and now they're not. I've been and iOS developer for a long time. I can tell you from experience that everyone does this. I have never worked for anyone who didn't ask for their app to include some combination of Facebook, Google, Flurry, AppCenter, Segment, Intercom, Parse, or whatever other random analytics framework the PM happens to be infatuated with. Getting ma…

When you say 'everyone' in your second paragraph, really you mean 'all of the Silicon Valley style employers I'm aware of'.

That's a tiny proportion of the user population and doesn't imply agreement or consent to the information the Facebook SDK shares. And even if it it did, it wouldn't automatically mean that it's an acceptable or good behaviour by those apps and Facebook.

Bringing widely-distributed privacy breaches to a wider audience's attention can help those users provide feedback regarding products and then allow them to select vendors who respect their values.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#170

Nice way to bury an innocuous "iOS Advertiser ID" in the middle of the list. What "iOS Advertiser ID" means is, to a very good degree of approximation, your deanonimized identity. Also, that just linking the SDK in your app deanonimzes the user to Facebook is very, very clear in its documentation. It's not like Zoom didn't notice until someone told them. They made a decision, and now they're changing it because they…

The Advertising Identifier is app-specific, and if Limit Ad Tracking is enabled, it is set to all zeros. So it's not accurate to say that it's "your deanonimized identity".
Post reply on HN