Live data from Hacker News

Zoom’s Use of Facebook’s SDK in iOS Client

blog.zoom.us

181–190 of 272 posts

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#181

Earlier quoted context omitted.

As nice as it would be, auditing everything you use is almost impossible, especially for smaller teams.

See, one way I often solve this is by reducing my reliance on third-party dependencies.

Which is also a hard thing to do on small teams.

I think for small teams this is a near impossible task. For big corporations it should be doable and expected. They actually have some leverage to push the other big companies to track less. Something a small company simply can't do.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#182
post #95

Earlier quoted context omitted.

So if you can't stop ALL of them, you stop NONE of them.

This is unsustainable. It requires constant vigilance and turns the privacy matter into a cat and mouse game where we are constantly one step behind the worst actors. These systems exist everywhere in the world and they’re fundamentally inefficient. E.g. recycling, or “please bring your own plastic bag”, which relies on goodwill. Compare to a system where you fix the incentives to automatically align everyone’s inter…

> bottle deposits, or a small fee for plastic bags

You know how these programs started? They started small. A few stores requiring them. Eventually, they become a law.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#183
post #45

So it sounds like Zoom was using the Facebook SDK, and now they're not. I've been and iOS developer for a long time. I can tell you from experience that everyone does this. I have never worked for anyone who didn't ask for their app to include some combination of Facebook, Google, Flurry, AppCenter, Segment, Intercom, Parse, or whatever other random analytics framework the PM happens to be infatuated with. Getting ma…

Don’t blame the drunk driver, blame the auto manufacturer...

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#184
post #179
post #62

Earlier quoted context omitted.

I don't want to live in a world where my parents and grandparents are expected to pull up Wireshark to figure out if the app they're using will record their front camera without consent. Blaming Zoom and FB is entirely acceptable here, it is their responsibility to keep my data private. Blaming Apple? Why, when Zoom is on the Play Store as well? https://play.google.com/store/apps/details?id=us.zoom.videom... >As long…

Little Snitch seems to have solved it fairly well on macOS. Apple doesn’t allow software like that on iOS.

i wonder if apple configurator “filtering” profile [0] could be used?...

[0] https://support.apple.com/en-is/guide/mdm/mdmc77c9609/1/web/...

maybe some kind of automated little snitch settings ⇄ profile converter?

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#185
post #45

So it sounds like Zoom was using the Facebook SDK, and now they're not. I've been and iOS developer for a long time. I can tell you from experience that everyone does this. I have never worked for anyone who didn't ask for their app to include some combination of Facebook, Google, Flurry, AppCenter, Segment, Intercom, Parse, or whatever other random analytics framework the PM happens to be infatuated with. Getting ma…

Hello fellow iOS developer. I have two apps on the Apple store. I never used any external SDK/libraries, only the built-in Xcode ones. I preferred to spent a bit more time in writing/testing but I would never accept that FB and other scum (privacy standpoint) track children (I wrote the apps for my nephews and nieces and I put them in the Apple store just for them)(I don't advertise them at all and I won't do so here either).

Regarding the issue that started this Zoom-FB dialogue I have commented a dozen (or more) times on the necessity to have a firewalled phone that a user (unfortunately the user needs to have basic knowledge of firewall admin) can decide what to allow and what to block. Your point on who audits is valid (I am a CISA and CISM of many years), and, well, nobody does. Each user will have to do his/her own work/effort to keep their family clear of these scum.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#186
post #148

Earlier quoted context omitted.

The list is in alphabetical order. It's not malicious...

Alphabetical order is neither mandated by any rule, nor deterministic since you can choose how to call things. "Application Bundle Identifier" made it to the top of the list, but if it was "iOS Application Bundle Identifier" it would be below the Advertiser ID. Do you really think they prepared a PR statement to respond to harsh criticism and just decided to toss in there the list of information sent without crafting…

> Do you really think they prepared a PR statement to respond to harsh criticism and just decided to toss in there the list of information sent without crafting the order of the items?

Yes, because it's in alphabetical order.

You don't have to craft anything for it to be in alphabetical order.

You just put it in alphabetical order.

The sorts of people who are going to read that list and understand any of it are the sorts of people for whom the order doesn't matter one iota — they will see the information.

For the majority of people, putting it at the top of the list would, equally, not matter one iota — they won't know what it means.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#187
I'm happy the Zoom doesn't want to help Facebook spy on me. Unfortunately the chosen solution is still a privacy nightmare. Basically they let you login to Facebook via an in app browser. The problem is an app can spy on all activity of an in app browser. That means you have to trust that Zoom is not recording your facebook password as you type it in. We need a better system.

Also scary. I have never ever logged in to Facebook on my iPhone except via the Facebook app and it was the first time I've installed Zoom. When I went into the Zoom app and picked login via Facebook, somehow it knew who I was and asked if I wanted to login as me. How is this possible? Is iOS sharing cookies across apps? I feel like maybe I need to reset my phone. WTF

I also feel like the best solution for this case is to somehow login via the facebook app. I know that used to be an option but it seems facebook deprecated it. My argument would be (a) I don't have to worry Zoom (or any other app) is getting my Facebook credentials (b) If actually do want to login via Facebook it's almost guaranteed I have the app installed.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#188
post #179

Earlier quoted context omitted.

Little Snitch seems to have solved it fairly well on macOS. Apple doesn’t allow software like that on iOS.

i wonder if apple configurator “filtering” profile [0] could be used?... [0] https://support.apple.com/en-is/guide/mdm/mdmc77c9609/1/web/... maybe some kind of automated little snitch settings ⇄ profile converter?

The problem is the lack of notification/visibility into what hosts to which the app is connecting.

It’s possible that your solution might work for some small fraction of users, some of the time, for known spying hosts. Many people still want to access Facebook and Instagram, though.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#189

Earlier quoted context omitted.

>Getting mad at Zoom for using the Facebook SDK is missing the point. It's really hard to believe this point given that... getting mad seems to have worked.

Doesn't scale. We can't have 1,000,000 front page "App X uses Y SDK" posts. People will stop caring. Nobody's made a post of that flavor in awhile, and Zoom got caught in the crossfire. Honestly, if anything it shields other apps. People have a limited capacity for repeatedly addressing the same thing.

I pay $20 a month for Zoom and consider it a business product. Collecting analytics via Facebook is unacceptable in this context.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#190
post #45

So it sounds like Zoom was using the Facebook SDK, and now they're not. I've been and iOS developer for a long time. I can tell you from experience that everyone does this. I have never worked for anyone who didn't ask for their app to include some combination of Facebook, Google, Flurry, AppCenter, Segment, Intercom, Parse, or whatever other random analytics framework the PM happens to be infatuated with. Getting ma…

You can listen to the iPhone with wireshark using OWASP zap as a proxy.
Post reply on HN