Live data from Hacker News

SpaceX bans Zoom over privacy concerns

reuters.com

41–50 of 301 posts

Re: SpaceX bans Zoom over privacy concerns

#41
Zoom is such a bizarre product. For huge video calls, it tends to perform as well or better than everything else out there. Yet at the same time it literally seems like straight-up malware and seems to violate your trust and privacy left and right every step of the way, even in the installer (!).

Re: SpaceX bans Zoom over privacy concerns

#42
The rumor that I've heard is that the "security and privacy concerns" are that Boeing has somehow gotten access to their Zoom. I don't know what that means, exactly, but it's at least somewhat more rational than being concerned that facebook is siphoning up the data.

Re: SpaceX bans Zoom over privacy concerns

#43
post #24

This is a knee-jerk reaction. Zoom was indirectly sending information to Facebook as part of their Facebook SDK integration to enable login, not directly as part of explicit information gathering. Any app that integrates with the Facebook SDK does this, and they've also patched it already [1]. The supposed root exploit found in Zoom also requires physical, logged-in access to the machine, at which point a Zoom exploi…

> Zoom is a solid piece of software, and the developers are responsive and seem to care. The dodgy things they've been doing suggest otherwise. * Hijacking package preflight script rather than standard package installation mechanism, so their software is installed before the user clicks Install. * Installing a hidden web server without user consent.

That's more about management decisions and unethical developers. It still could be a solid software despite those issues.

Re: SpaceX bans Zoom over privacy concerns

#44

This is a knee-jerk reaction. Zoom was indirectly sending information to Facebook as part of their Facebook SDK integration to enable login, not directly as part of explicit information gathering. Any app that integrates with the Facebook SDK does this, and they've also patched it already [1]. The supposed root exploit found in Zoom also requires physical, logged-in access to the machine, at which point a Zoom exploi…

> I'm disappointed to see it getting dumped on during the past few days.

They have what is commonly referred to as form.

Consider the past year's highest voted stories whose title includes the word 'zoom'

https://hn.algolia.com/?dateRange=pastYear&page=0&prefix=fal...

This is certainly not a 'knee-jerk reaction' to the use of the Facebook SDK, but presumably extrapolates from the history of false uninstallation, insecurity by obscurity, false advertising, etc.

Each of those things has been, as you intimate, patched or resolved -- but does that give you increasing or decreasing confidence in their product and priorities?

Re: SpaceX bans Zoom over privacy concerns

#45
post #4

The fact that they show end users (no pun intended) an "end-to-end encrypted" badge on the meeting window itself, and elsewhere explain how a Zoom server (not Zoom client) is what constitutes an "end" despite the whole rest of the electronic communication industry using "end-to-end" to refer exclusively to user agents, is bonkers.

Agreed. It's unlikely they stumbled onto an industry standard phrase like that alone, then innocently used it without knowing the generally accepted meaning. This is deceptive advertising.

Not just "deceptive" nor "unlikely", it's blatant false advertising.

Re: SpaceX bans Zoom over privacy concerns

#46
post #4

The fact that they show end users (no pun intended) an "end-to-end encrypted" badge on the meeting window itself, and elsewhere explain how a Zoom server (not Zoom client) is what constitutes an "end" despite the whole rest of the electronic communication industry using "end-to-end" to refer exclusively to user agents, is bonkers.

Using their definition, one would wonder what non-end-to-end encryption would look like.

Re: SpaceX bans Zoom over privacy concerns

#47
post #14

As they should, since they're subject to ITAR regulations, and ITAR is not a joke.

Came to say the same thing. Zoom is impossible if you are considered part of the DoD supply chain. Most of the public products are untenable if you need to talk about ITAR projects or about anything considered CUI.

Re: SpaceX bans Zoom over privacy concerns

#48

Earlier quoted context omitted.

Also can't have too many attendees

You can have 200, and you can also live-stream large meetings. It is a bit weird that you have to split the stream, but it's worked great for us doing ~300 person all-hands meetings.

Google Meet also works well if you have G Suite: https://gsuite.google.com/products/meet/

Re: SpaceX bans Zoom over privacy concerns

#49
post #41

Zoom is such a bizarre product. For huge video calls, it tends to perform as well or better than everything else out there. Yet at the same time it literally seems like straight-up malware and seems to violate your trust and privacy left and right every step of the way, even in the installer (!).

To be fair it does perform better than everything else, which is why people are so forgiving of it, but it still doesn't excuse their ineptitude on privacy and security.

Re: SpaceX bans Zoom over privacy concerns

#50
post #4

The fact that they show end users (no pun intended) an "end-to-end encrypted" badge on the meeting window itself, and elsewhere explain how a Zoom server (not Zoom client) is what constitutes an "end" despite the whole rest of the electronic communication industry using "end-to-end" to refer exclusively to user agents, is bonkers.

Agreed. It's unlikely they stumbled onto an industry standard phrase like that alone, then innocently used it without knowing the generally accepted meaning. This is deceptive advertising.

Using industry standard phrases without a complete understanding of meanings is... well, industry standard. ;)
Post reply on HN