Live data from Hacker News

Zoom sued for overstating, not disclosing privacy, security flaws

uk.reuters.com

21–30 of 166 posts

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#21

Note that the lawsuit is a class action for shareholders of Zoom stock. Filing: https://i.judge.sh/natural/Babs/1-main.pdf

Is there a simple way for those of us who hold index funds to check if we are shareholders?

https://www.etf.com/stock/ZM

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#22
my employer currently signs up for zoom, apparently managed via our SSO-solution. so far so good.

Right now, I got an email from Zoom, not showing any relation to my employer or mentioning its name: "congratulations for signup, use your account now". Ok. Password reset yields an usable basic account. Seems like somehow Zoom created a personal account for me with my work email. As I didn't get the activation email I got on my private spam-account, I assume somehow they got/requested all the employees email-adresses and automatically created private accounts, not related to the actual business acc..

What the actual f* is that?!? And yeah, I think conceptually this is the same behavior as shown by the ad/malware/spam campaigns ca. 2003. I wonder what had happened if I had just typed a password when signing in with my account... Maybe they just grab the passwords of the illiterate users and check them by trying to login with the university website? (that's sooo userfriendly!)

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#23
post #3

Will be interesting if Zoom is compelled to disclose their security architecture. On the same page can they be forced, in court, to make a statement on the interference by the Chinese government?

Is having keys compelled a surprise?

Chinese servers, operating in China legally, will usually have this issue.

It's serious yes, but I'm confused if it only applied to users in China?

I'm more concerned about the technical issues TBH - I assume most software sanctioned in China had to turn over keys.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#24

Blows my mind that a shareholder might have a cause of action for this. 1) Buy volatile stock with recent IPO 2) Sue them for their volatility 3) ?????

> Zoom documentation claims that the app uses “AES-256” encryption for meetings where possible. However, we find that in each Zoom meeting, a single AES-128 key is used in ECB mode by all participants to encrypt and decrypt audio and video. The use of ECB mode is not recommended because patterns present in the plaintext are preserved during encryption. https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto...

Oh wow. ECB mode? That's horrifying.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#25
post #13

It's a bit odd how everyone's attacking Zoom when none of the other common solutions have proper e2e encryption either.

Webex has optional e2e encryption, but naturally you lose some features such as network based recording.

https://help.webex.com/en-us/WBX44739/What-Does-End-to-End-E...

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#26
post #13

It's a bit odd how everyone's attacking Zoom when none of the other common solutions have proper e2e encryption either.

Webex has optional e2e encryption, but naturally you lose some features such as network based recording. https://help.webex.com/en-us/WBX44739/What-Does-End-to-End-E...

Does e2e work with multi-party? The picture only showing host/client, the host is the server or conference host?

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#27
post #3

Will be interesting if Zoom is compelled to disclose their security architecture. On the same page can they be forced, in court, to make a statement on the interference by the Chinese government?

Is having keys compelled a surprise? Chinese servers, operating in China legally, will usually have this issue. It's serious yes, but I'm confused if it only applied to users in China? I'm more concerned about the technical issues TBH - I assume most software sanctioned in China had to turn over keys.

Seeing as encryption is illegal in China, I don't think they will need to give up any keys.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#28
Am i the only one struggling to use Zoom properly since they introduced the latest security changes? The slack integration (write /zoom to start a meeting) was working ok-ish even though we always had problem with the meeting not starting unless the host of the meeting was logged in (gosh...why so complicated?)

Now they added this waiting room, there is no sound notification to let you know that people are waiting. Doing daily standup become a sufference. It's crazy how quickly they lost us as users with literally two badly implemented features.

Happy to hear if any of you also had the same struggle and if there is a good alternative.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#30

Am i the only one struggling to use Zoom properly since they introduced the latest security changes? The slack integration (write /zoom to start a meeting) was working ok-ish even though we always had problem with the meeting not starting unless the host of the meeting was logged in (gosh...why so complicated?) Now they added this waiting room, there is no sound notification to let you know that people are waiting. D…

Maybe set a (strong) password instead of using the waiting room?
Post reply on HN