Live data from Hacker News

SpaceX bans Zoom over privacy concerns

reuters.com

81–90 of 301 posts

Re: SpaceX bans Zoom over privacy concerns

#81
post #4

The fact that they show end users (no pun intended) an "end-to-end encrypted" badge on the meeting window itself, and elsewhere explain how a Zoom server (not Zoom client) is what constitutes an "end" despite the whole rest of the electronic communication industry using "end-to-end" to refer exclusively to user agents, is bonkers.

Apple does the same thing, where they claim iMessage is ETE encrypted, but the keys (so capabilities to read) are stored on their servers.

Re: SpaceX bans Zoom over privacy concerns

#82
post #70

To those saying SpaceX is subject to ITAR and defence standards, what does that say for anyone in healthcare, finance, California or Europe? Zoom is looking like it’s closer to Discord than Slack.

Zoom and Slack are both FedRamp authorized for government use. Zoom is even authorized Moderate, while Slack is still being audited for that rating. https://marketplace.fedramp.gov/#/product/zoom-for-governmen... https://marketplace.fedramp.gov/#/product/slack

I'm not sure what FedRAMP is but I work at an FFRDC and Slack is explicitly banned for all ITAR materials. Mattermost is used, though

Re: SpaceX bans Zoom over privacy concerns

#83

Earlier quoted context omitted.

Yes, but what do you know about its security?

Well, it's my own server, and the code is open source, so... pretty trivial to verify.

It will never be trivial to verify outside the most basic of programs.

Re: SpaceX bans Zoom over privacy concerns

#85
post #49

Earlier quoted context omitted.

To be fair it does perform better than everything else, which is why people are so forgiving of it, but it still doesn't excuse their ineptitude on privacy and security.

In my experience Google's Hangout Meetings have been at least as good or better quality and the interface is far superior in my opinion. For example it works in the browser without any plugins (even in Firefox.)

The quality send to suffer when there are a large number of participants.

Which is the reason zoom gets used so much.

Re: SpaceX bans Zoom over privacy concerns

#86
post #41

Zoom is such a bizarre product. For huge video calls, it tends to perform as well or better than everything else out there. Yet at the same time it literally seems like straight-up malware and seems to violate your trust and privacy left and right every step of the way, even in the installer (!).

It was one of the fastest-growing SAAS companies before coronavirus hit despite all the free competition. The reason? "It just works." It's clear their singular focus on making it "just work" for even the least tech-savvy users has led them to prioritise user experience over security/privacy. I imagine a rebalancing is coming.

Hopefully soon! A signal-like group video package that "just worked" with some processes for key verification would be outstanding.

Re: SpaceX bans Zoom over privacy concerns

#87

Earlier quoted context omitted.

Agreed. It's unlikely they stumbled onto an industry standard phrase like that alone, then innocently used it without knowing the generally accepted meaning. This is deceptive advertising.

Not defending zoom here -- they done fucked up -- but there is a huge disconnect between the marketing folks and the technical folks. It's possible that E2E Encryption was something they planned on implementing but haven't, and the marketing department either didn't get the memo or didn't understand and still kept the wording.

That's not an excuse. Sooner or later it'll become a faux pas to mis-use basic security terminology. Obviously most of the public doesn't care about most of the terminology. But "end to end" has been trending for a decade at least.

Re: SpaceX bans Zoom over privacy concerns

#88
post #81
post #4

The fact that they show end users (no pun intended) an "end-to-end encrypted" badge on the meeting window itself, and elsewhere explain how a Zoom server (not Zoom client) is what constitutes an "end" despite the whole rest of the electronic communication industry using "end-to-end" to refer exclusively to user agents, is bonkers.

Apple does the same thing, where they claim iMessage is ETE encrypted, but the keys (so capabilities to read) are stored on their servers.

No, it doesn't.

https://support.apple.com/guide/security/how-imessage-sends-...

Re: SpaceX bans Zoom over privacy concerns

#89
post #2

I looked into adding Zoom to our Slack workspace this morning, and was beside myself with the set of permissions they requested — reading the contents of every channel and private chat they're included in? For a slash command? That's a hard no. Turned me off the service entirely.

> reading the contents of every channel and private chat they're included in? For a slash command?

This may improve soon. Slack is starting to force apps to request granular permissions (vs a big-tent "bot" scope like before) and when you submit to their store, they vet each permission and verify what you're using it for. They don't let you request permissions "just because" in my experience.

Re: SpaceX bans Zoom over privacy concerns

#90

Earlier quoted context omitted.

Agreed. It's unlikely they stumbled onto an industry standard phrase like that alone, then innocently used it without knowing the generally accepted meaning. This is deceptive advertising.

Not defending zoom here -- they done fucked up -- but there is a huge disconnect between the marketing folks and the technical folks. It's possible that E2E Encryption was something they planned on implementing but haven't, and the marketing department either didn't get the memo or didn't understand and still kept the wording.

For how long do we let them slide before the FTC steps in?
Post reply on HN