Live data from Hacker News

Zoom sued for overstating, not disclosing privacy, security flaws

uk.reuters.com

71–80 of 166 posts

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#71

Note that the lawsuit is a class action for shareholders of Zoom stock. Filing: https://i.judge.sh/natural/Babs/1-main.pdf

Presumably the zoom user agreements include arbitration clauses, etc that prevent users from filing class actions or lawsuits. It's a get out of jail free card they'd be dumb not to have included.

Shareholders don't sign user agreements.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#72
post #66
post #57

Earlier quoted context omitted.

Why is having engineers in China cause for suspicion? Lots of tech companies have engineers in China. Eg Microsoft.

But if Microsoft has teams in China, Russia work on MS Teams, I will be very concerned. The same goes with Slack, that many companies now rely on to keep business going.

Are you certain they don’t?

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#73
post #39

Earlier quoted context omitted.

Seeing as encryption is illegal in China, I don't think they will need to give up any keys.

>Seeing as encryption is illegal in China Source for this? That would make any https site in china illegal.

I'm sorry, I was wrong. It requires a license from the State Encryption Management Commission: http://www.cryptolaw.org/cls2.htm#prc

I am not a lawyer nor a cryptography expert who can advise whether licenses are granted easily or whether they are revoked if you fall out of favour.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#74
post #71

Earlier quoted context omitted.

Presumably the zoom user agreements include arbitration clauses, etc that prevent users from filing class actions or lawsuits. It's a get out of jail free card they'd be dumb not to have included.

Shareholders don't sign user agreements.

I don't think there was an implication to the contrary. I read that comment as an explanation for why any lawsuit would come from the shareholders rather than the users.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#75
post #22

my employer currently signs up for zoom, apparently managed via our SSO-solution. so far so good. Right now, I got an email from Zoom, not showing any relation to my employer or mentioning its name: "congratulations for signup, use your account now". Ok. Password reset yields an usable basic account. Seems like somehow Zoom created a personal account for me with my work email. As I didn't get the activation email I g…

I set up Zoom for our company and nothing like this happened. It seems much more likely (than your wild conspiracy theory) that your company added a "basic", rather than "licensed" account for you and you got an email as a result.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#76
post #11

Note that the lawsuit is a class action for shareholders of Zoom stock. Filing: https://i.judge.sh/natural/Babs/1-main.pdf

Interesting that shareholders are the one to fill a lawsuit.

They aren't. The lawsuit is really being filed by lawyers hoping to get a windfall. They don't even need to have much of a case, at worst Zoom will pay their fees and more for the nuisance to go away.

However, they do need to pretend for the court that this more than just a lawyer led money grab and that they actually represent the interest of a plaintiff. Enters Michael Drieu. If you read the complaint [1] you'll see Michael Drieu claim damages of ... $300. He's basically enabling a shakedown out of either malice or stupidity but not greed.

So no, it is not as if the shareholders of Zoom were up in arms against the company, this is just ambulance chasing with a puppet plaintiff.

https://www.scribd.com/embeds/455562311/content?start_page=1...

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#77
post #57
post #50

Don't know what is going on at Zoom, but I suspected at least part of it sneaky. For example, about 3 or 4 weeks ago I heard about this company, and learned that it has R&D in China per its SEC filing at IPO. However, checked its website, the career section led me to https://jobs.lever.co/zoom , and there was ONLY one opening at China per the website (I remember it was a position at marketing department). Then I sear…

Why is having engineers in China cause for suspicion? Lots of tech companies have engineers in China. Eg Microsoft.

Because the CCP has no qualms about threatening an employee’s family to insert a backdoor or exfiltrate information, for one.

The decoupling has begun. Sentiment in the US toward China has never been as negative as it is now, from both sides of the aisle. I wouldn’t be surprised if we even see sanctions against China after the dust settles on this COVID fiasco.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#78

Earlier quoted context omitted.

Yeah right, oops

Yes it definitely is an "oops". I'm not excusing it, but offering an alternative explanation to the "zoom is evil" thinking. If zoom was truly trying to market themselves as e2e, why is this only buried in one document rather than shouted from the hills?

They claim HIPAA compliance due to e2e encryption. That is far from an oops.

They updated their documents since, but last week they had documentation up that said they were HIPAA compliant due to end to end encryption.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#79
post #57
post #50

Don't know what is going on at Zoom, but I suspected at least part of it sneaky. For example, about 3 or 4 weeks ago I heard about this company, and learned that it has R&D in China per its SEC filing at IPO. However, checked its website, the career section led me to https://jobs.lever.co/zoom , and there was ONLY one opening at China per the website (I remember it was a position at marketing department). Then I sear…

Why is having engineers in China cause for suspicion? Lots of tech companies have engineers in China. Eg Microsoft.

I think OP was alluding to Zoom not showcasing the reqs on the US careers site. Most companies including Microsoft do display open positions in all countries including China on their US page.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#80
post #50

Don't know what is going on at Zoom, but I suspected at least part of it sneaky. For example, about 3 or 4 weeks ago I heard about this company, and learned that it has R&D in China per its SEC filing at IPO. However, checked its website, the career section led me to https://jobs.lever.co/zoom , and there was ONLY one opening at China per the website (I remember it was a position at marketing department). Then I sear…

Unlikely IMO.

"Zoom, a Silicon Valley-based company, appears to own three companies in China through which at least 700 employees are paid to develop Zoom’s software. This arrangement is ostensibly an effort at labor arbitrage: Zoom can avoid paying US wages while selling to US customers, thus increasing their profit margin. However, this arrangement may make Zoom responsive to pressure from Chinese authorities."

https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto...

Post reply on HN