Live data from Hacker News

SpaceX bans Zoom over privacy concerns

reuters.com

21–30 of 301 posts

Re: SpaceX bans Zoom over privacy concerns

#21

This is a knee-jerk reaction. Zoom was indirectly sending information to Facebook as part of their Facebook SDK integration to enable login, not directly as part of explicit information gathering. Any app that integrates with the Facebook SDK does this, and they've also patched it already [1]. The supposed root exploit found in Zoom also requires physical, logged-in access to the machine, at which point a Zoom exploi…

> This is a knee-jerk reaction.

When you make weapons technology (as SpaceX does; rockets are weapons technology) and are involved in launching military satellites (as SpaceX is), you kinda have to take security issues seriously.

Re: SpaceX bans Zoom over privacy concerns

#22

Spacex is a targeted environment. It's smart for them to not use such a service. Many years back it was getting hardware shipments intercepted and bugged. A company was spun out of just dealing with the amount of attempts to root Elons devices.

Which company?

Re: SpaceX bans Zoom over privacy concerns

#23

This is a knee-jerk reaction. Zoom was indirectly sending information to Facebook as part of their Facebook SDK integration to enable login, not directly as part of explicit information gathering. Any app that integrates with the Facebook SDK does this, and they've also patched it already [1]. The supposed root exploit found in Zoom also requires physical, logged-in access to the machine, at which point a Zoom exploi…

> This is a knee-jerk reaction.

Large part of, if not entire, Zoom engineering is based in China, so just based on that singular fact IMHO this is not at all a knee-jerk reaction.

Add to that numerous security found in Zoom just over the last few days, and I'm surprised why more companies are not doing the same.

Re: SpaceX bans Zoom over privacy concerns

#24

This is a knee-jerk reaction. Zoom was indirectly sending information to Facebook as part of their Facebook SDK integration to enable login, not directly as part of explicit information gathering. Any app that integrates with the Facebook SDK does this, and they've also patched it already [1]. The supposed root exploit found in Zoom also requires physical, logged-in access to the machine, at which point a Zoom exploi…

> Zoom is a solid piece of software, and the developers are responsive and seem to care.

The dodgy things they've been doing suggest otherwise.

* Hijacking package preflight script rather than standard package installation mechanism, so their software is installed before the user clicks Install.

* Installing a hidden web server without user consent.

Re: SpaceX bans Zoom over privacy concerns

#25
post #4

The fact that they show end users (no pun intended) an "end-to-end encrypted" badge on the meeting window itself, and elsewhere explain how a Zoom server (not Zoom client) is what constitutes an "end" despite the whole rest of the electronic communication industry using "end-to-end" to refer exclusively to user agents, is bonkers.

they appear to have already changed this to "your client connection is encrypted"

Re: SpaceX bans Zoom over privacy concerns

#26
post #2

I looked into adding Zoom to our Slack workspace this morning, and was beside myself with the set of permissions they requested — reading the contents of every channel and private chat they're included in? For a slash command? That's a hard no. Turned me off the service entirely.

It's only available in the paid version, but slack's video conferencing works pretty well.

It works, but it burns through so much CPU your computer will be a gibbering mess. There's some pretty silly inefficiencies going on, for example; if you switch away to another window, they display a small video player while keeping the big one running the background. Each time you switch into screen sharing mode, they drag you back to the app again. If you draw on the screen, someone has screwed up their linear algebra so you end up seeing double with an extra copy of what you're drawing, in totally the wrong place.

Annoyingly it's a bit too convenient, so going out of band is a pain.

Re: SpaceX bans Zoom over privacy concerns

#27

This is a knee-jerk reaction. Zoom was indirectly sending information to Facebook as part of their Facebook SDK integration to enable login, not directly as part of explicit information gathering. Any app that integrates with the Facebook SDK does this, and they've also patched it already [1]. The supposed root exploit found in Zoom also requires physical, logged-in access to the machine, at which point a Zoom exploi…

From the article it seems like Elon is mostly worried about meeting IDs leaking and letting any random connect:

> The FBI’s Boston office on Monday issued a warning about Zoom, telling users not to make meetings on the site public or share links widely after it received two reports of unidentified individuals invading school sessions, a phenomenon known as “zoombombing.”

Re: SpaceX bans Zoom over privacy concerns

#28
post #23

This is a knee-jerk reaction. Zoom was indirectly sending information to Facebook as part of their Facebook SDK integration to enable login, not directly as part of explicit information gathering. Any app that integrates with the Facebook SDK does this, and they've also patched it already [1]. The supposed root exploit found in Zoom also requires physical, logged-in access to the machine, at which point a Zoom exploi…

> This is a knee-jerk reaction. Large part of, if not entire, Zoom engineering is based in China, so just based on that singular fact IMHO this is not at all a knee-jerk reaction. Add to that numerous security found in Zoom just over the last few days, and I'm surprised why more companies are not doing the same.

exactly, plus when you're spaceX or a similar tech company it's much better to be safe than sorry. you don't always have the luxury to assume good intentions.

Re: SpaceX bans Zoom over privacy concerns

#29

This is a knee-jerk reaction. Zoom was indirectly sending information to Facebook as part of their Facebook SDK integration to enable login, not directly as part of explicit information gathering. Any app that integrates with the Facebook SDK does this, and they've also patched it already [1]. The supposed root exploit found in Zoom also requires physical, logged-in access to the machine, at which point a Zoom exploi…

> Zoom is a solid piece of software, and the developers are responsive and seem to care.

I get the exact opposite impression. Not just due to these bugs, but also the hidden webserver thing [1] a while back.

Recurring theme in this (the webserver and the installer issue) seems to be an unhealthy obsession with reducing the number of clicks the user needs to perform. They deliberately chose dubious, hacky solutions over doing things the right way due to this. It makes you wonder what other bad decisions they made in the client or server code.

[1] https://www.theverge.com/2019/7/10/20689644/apple-zoom-web-s...

Re: SpaceX bans Zoom over privacy concerns

#30
post #24

This is a knee-jerk reaction. Zoom was indirectly sending information to Facebook as part of their Facebook SDK integration to enable login, not directly as part of explicit information gathering. Any app that integrates with the Facebook SDK does this, and they've also patched it already [1]. The supposed root exploit found in Zoom also requires physical, logged-in access to the machine, at which point a Zoom exploi…

> Zoom is a solid piece of software, and the developers are responsive and seem to care. The dodgy things they've been doing suggest otherwise. * Hijacking package preflight script rather than standard package installation mechanism, so their software is installed before the user clicks Install. * Installing a hidden web server without user consent.

Claiming they have end to end encryption when they don't.
Post reply on HN