Live data from Hacker News

Zoom’s Use of Facebook’s SDK in iOS Client

blog.zoom.us

251–260 of 272 posts

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#251
post #179
post #62

Earlier quoted context omitted.

I don't want to live in a world where my parents and grandparents are expected to pull up Wireshark to figure out if the app they're using will record their front camera without consent. Blaming Zoom and FB is entirely acceptable here, it is their responsibility to keep my data private. Blaming Apple? Why, when Zoom is on the Play Store as well? https://play.google.com/store/apps/details?id=us.zoom.videom... >As long…

Little Snitch seems to have solved it fairly well on macOS. Apple doesn’t allow software like that on iOS.

My copy of Charles on iOS disagrees.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#252
Thank you zoom.us for the best tool available right now with a fair and acceptable price model. A special thank you also for the great Linux support, that is absolutely unmatched from all other "solutions".

I am very sorry that so many bad publicity happens right now, but as far I know even bad publicity is good in the end.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#253
post #252

Thank you zoom.us for the best tool available right now with a fair and acceptable price model. A special thank you also for the great Linux support, that is absolutely unmatched from all other "solutions". I am very sorry that so many bad publicity happens right now, but as far I know even bad publicity is good in the end.

well, you know, bad publicity because of bad practices.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#254

Earlier quoted context omitted.

Agreed. Apps on iOS (IMO) should have to declare what domains they'll access and otherwise get no other network access with special exceptions for browsers and network tools. I hope Apple will prevent apps from seeing SSIDs. I also hope Apple will come up with some similar solution for bluetooth so that apps can only see the devices the user selects and not just scan for all devices.

> declare what domains they'll access and otherwise get no other network access So Facebook will just provide an SDK for app developers to integrate server-side that lets their app send the data to their own domain, and the server passes it on to FB. Developers will install it, because they want the analytics and ad conversion tracking. There probably isn't a great technical solution to this problem.

This would be leagues better than what we have now since we know that (at least a handful of) companies don't know or actively audit what their SDKs are doing - the Zoom situation here has plausible deniability. If they requires some server-site SDK to do this, some/many would do it, but that increases the cost of running the SDK and there wouldn't be any way to say "we didn't know FB used us as a privacy trojan".

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#255
post #62

Earlier quoted context omitted.

I don't want to live in a world where my parents and grandparents are expected to pull up Wireshark to figure out if the app they're using will record their front camera without consent. Blaming Zoom and FB is entirely acceptable here, it is their responsibility to keep my data private. Blaming Apple? Why, when Zoom is on the Play Store as well? https://play.google.com/store/apps/details?id=us.zoom.videom... >As long…

This whole Zoom revelation reminds me of the Cambridge Analytica scandal. This has been going on for a long time now, and it wasn't until one specific company did it that everyone is now concerned. If you want to be creeped out, go to https://www.facebook.com/off_facebook_activity/ and find out how many apps have been quietly reporting all your usage activity to Facebook. I have 100's of websites which managed to ide…

Mine shows nothing: "You have no available activity to show at this time."

I have been running Facebook in the special Firefox container pretty much since it was available. I took off the WhatsApp and Instagram apps from my phone months ago. For me, the number of ads (on Instagram) and integration into Facebook made them expendable.

I don't know if Facebook really has no information or they do but are not showing it to me.

I'd like to do the same with Google but the Google container wants to force all interactions with Google into one container. I've got dedicated containers for different Gmail identities - it was very handy to have a Gmail identity while I was president of the kids' soccer club and then turn the account over to someone else.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#256

Earlier quoted context omitted.

Opt-out of sending anonymised data, to the company providing the credit service.

It doesn't matter how anonymized they claim it to be, it should be opt-in, not opt-out. Of course virtually nobody would choose to opt-in, which is the point.

> it should be opt-in, not opt-out

Sure, it would be nice if no company ever shared data with any other company, but that does not track in this case.

People signing up for an Apple branded Goldman Sachs credit card shouldn't be surprised or affronted by the fact Goldman Sachs gets anonymised data from Apple.

Why the hell anyone would sign up for this crap is beyond me. But it's not a reason to drag Apple into the context of a thread about a company guilty of basic privacy failures -- sending personal data to a 3rd party social network the user has no connection to.

Please also understand what 'anonymised' means, it means _not reversible_ i.e. you _cannot_ tell who the user is.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#257
post #83

Earlier quoted context omitted.

Does this work with apps that do their own TLS using their own pinned certs? I don't see how it could. Surely that's a lot of high profile apps these days. If this app works without root, it must be possible to apps on iPhone to add their own certificates to the system, which are then trusted by other applications - that would already be pretty alarming. I think Android still requires certificates to be manually impo…

If you've got a Jailbroken phone, this post explains how to extract the TLS keys (to decrypt the traffic) using a Frida script https://andydavies.me/blog/2019/12/12/capturing-and-decrypti...

For sure, it can be done, I was just thinking that MITMing yourself on iPhone is not so easy these days as just installing this one app.

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#258

Earlier quoted context omitted.

It doesn't matter how anonymized they claim it to be, it should be opt-in, not opt-out. Of course virtually nobody would choose to opt-in, which is the point.

> it should be opt-in, not opt-out Sure, it would be nice if no company ever shared data with any other company, but that does not track in this case. People signing up for an Apple branded Goldman Sachs credit card shouldn't be surprised or affronted by the fact Goldman Sachs gets anonymised data from Apple. Why the hell anyone would sign up for this crap is beyond me. But it's not a reason to drag Apple into the co…

Have you never heard of deanonymization? In many cases you most certainly can. https://arxiv.org/pdf/1902.09897.pdf

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#259

Earlier quoted context omitted.

> Getting mad at Zoom for using the Facebook SDK is missing the point. They and a million others are always going to be doing this. Get mad at Apple for not letting you wireshark your own iPhone. There’s plenty of anger to go around. Get mad all all three: Facebook for making an SDK that tracks you, Zoom for integrating it, and Apple for letting it through unencumbered.

I can't tell if your comment is intentionally funny, but I got a good laugh out of it.

I wasn't trying to; what about it did you find humorous?

Re: Zoom’s Use of Facebook’s SDK in iOS Client

#260
post #172

Earlier quoted context omitted.

This is true, but Apple touts how much better they are about Privacy, and charges a premium for it. Google is more up front that they make little money on the initial sale, and are dependent on advertising to make money.

> Privacy is built in from the beginning. Our products and features include innovative privacy technologies and techniques designed to minimize how much of your data we — or anyone else — can access https://www.apple.com/privacy/features/ Apple sells privacy, brags about privacy - yet Privacy is abused in from the beginning in the store apps.

And the lesson is - you can't buy privacy but you can sell it.
Post reply on HN