Live data from Hacker News

Zoom’s Use of Facebook’s SDK in iOS Client

blog.zoom.us

221–230 of 272 posts

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#221

Earlier quoted context omitted.

I'm not sure you read the article you linked to properly: > Apple is changing the privacy policy for Apple Card with iOS to share a richer, but still anonymized set of data with Goldman Sachs in order to allow the creation of a new credit assignment model, which could expand the group of users that may be able to secure credit. > There is also a beefed up fallback method in the works that will allow users to share mo…

It’s an opt-out: “You can opt out of this use or your Apple relationship information by emailing our privacy team at dpo@apple.com with the subject line ‘Apple Relationship Data and Apple Card.’”

Opt-out of sending anonymised data, to the company providing the credit service.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#222

Earlier quoted context omitted.

It’s an opt-out: “You can opt out of this use or your Apple relationship information by emailing our privacy team at dpo@apple.com with the subject line ‘Apple Relationship Data and Apple Card.’”

Opt-out of sending anonymised data, to the company providing the credit service.

It doesn't matter how anonymized they claim it to be, it should be opt-in, not opt-out. Of course virtually nobody would choose to opt-in, which is the point.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#223
post #45

So it sounds like Zoom was using the Facebook SDK, and now they're not. I've been and iOS developer for a long time. I can tell you from experience that everyone does this. I have never worked for anyone who didn't ask for their app to include some combination of Facebook, Google, Flurry, AppCenter, Segment, Intercom, Parse, or whatever other random analytics framework the PM happens to be infatuated with. Getting ma…

It doesn’t “sound like” that, it’s literally what they’re admitting to. Let’s not spin the narrative here on HN that Zoom didn’t admit to their faults.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#225

Earlier quoted context omitted.

> Blaming Apple? Why, when Zoom is on the Play Store as well? Blame Apple because they constantly tout the iPhone as being "privacy respecting" and "what happens on your iPhone stays on your iPhone"[0], while they A. Apple doesn't default to "limit tracking", or at least make "limit tracking" an option on setup/iOS upgrade B. Apple doesn't penalize developers for using Facebook's SDK with auto data collection (ie. pu…

It seems whoever is gathering that info and sending it is Facebook Blame them. Not Apple

I agree. People who send this data externally are ultimately responsible. Hypothetically, If I use the internet to steal data from my employer it’s not the network teams fault for allowing it to happen. I’m just a thief in position of trust exploiting my capabilities.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#226

Earlier quoted context omitted.

> Blaming Apple? Why, when Zoom is on the Play Store as well? Blame Apple because they constantly tout the iPhone as being "privacy respecting" and "what happens on your iPhone stays on your iPhone"[0], while they A. Apple doesn't default to "limit tracking", or at least make "limit tracking" an option on setup/iOS upgrade B. Apple doesn't penalize developers for using Facebook's SDK with auto data collection (ie. pu…

Agreed. Apps on iOS (IMO) should have to declare what domains they'll access and otherwise get no other network access with special exceptions for browsers and network tools. I hope Apple will prevent apps from seeing SSIDs. I also hope Apple will come up with some similar solution for bluetooth so that apps can only see the devices the user selects and not just scan for all devices.

> declare what domains they'll access and otherwise get no other network access

So Facebook will just provide an SDK for app developers to integrate server-side that lets their app send the data to their own domain, and the server passes it on to FB. Developers will install it, because they want the analytics and ad conversion tracking. There probably isn't a great technical solution to this problem.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#227

Earlier quoted context omitted.

> I suppose you could argue that's negligent, but if that's the case, then pretty much every company that has an app with login functionality is probably in that boat. I think every company that does this is negligent. Audit your dependencies, people!

As nice as it would be, auditing everything you use is almost impossible, especially for smaller teams.

Is this really a compelling argument for the given case? A detailed audit does not seem necessary here:

This is not some surprising behaviour hidden in some random dependency.

This is the Facebook SDK, from Facebook, and everybody knows what their business is.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#228

Considering how many apps are using Facebook's SDK, shouldn't this be something that FB should be addressing? After all, they are the ones making an SDK available to app developers to help with user-login. Shouldn't the presumption of trust rest on FB?

I can’t see the big deal. We use the Facebook SDK specifically for the free analytics. It’s just a default part of the SDK. It’s not sending anything any other analytics package wouldn’t

Could you maybe expand on what company you work for so that the rest of us can avoid it and its products?

Uploading all of this data to Facebook just so you don't have to run a Matomo instance (or whatever controlled analytics platform you use) is either laziness or disregard for your users. There's a reason the analytics are free and sacrificing your users for something this small is exactly what is wrong with the modern software ecosystem.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#229
post #116

Earlier quoted context omitted.

Fortune 500 consulting, European Union market. Webex, Teams, Slack are the only ones that matter.

"Webex, Teams" Yeah some companies are behind the curve (not blaming you). Zoom is getting very popular

From security perspective, Companies do not like the fact that Zoom was developed in China and the vast majority of its R&D is still in China. China has different rules on security than many other countries. Particularly surrounding intellectual property. https://www.sec.gov/Archives/edgar/data/1585521/000119312519...

"Top of page 21- In addition, we have a high concentration of research and development personnel in China, which could expose us to market scrutiny regarding the integrity of our solution or data security features. Any security compromise in our industry, whether actual or perceived, could harm our reputation, erode confidence in the effectiveness of our security measures, negatively affect our ability to attract new customers and hosts, cause existing customers to elect not to renew their subscriptions or subject us to third-party lawsuits, regulatory fines or other action or liability, which could harm our business."

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#230
post #210

>> we were made aware on Wednesday, March 25, 2020, that the Facebook SDK was collecting device information unnecessary So Zoom is basically lying here Come on, the developers who takes the responsibility to use the SDK were aware of it, ok maybe the CEO of Zoom or the market guy was not but the tech team is. They are not stupid. You should have just apologise and assume your fault, that would be the courageous posit…

This is what scares most security analysts is the fact that the product was developed and stores data in a place that has incredibly sketchy laws when it comes to intellectual property.

I can't see why Zoom can't come out with a statement regarding why they are collecting all of this sensitive data.

Big corporations might be sharing stuff unwittingly with people that they don't want to share it with.

https://www.sec.gov/Archives/edgar/data/1585521/000119312519...

Top of page 21 in their SEC filing:

"In addition, we have a high concentration of research and development personnel in China, which could expose us to market scrutiny regarding the integrity of our solution or data security features. Any security compromise in our industry, whether actual or perceived, could harm our reputation, erode confidence in the effectiveness of our security measures, negatively affect our ability to attract new customers and hosts, cause existing customers to elect not to renew their subscriptions or subject us to third-party lawsuits, regulatory fines or other action or liability, which could harm our business."

Post reply on HN