Live data from Hacker News

Zoom sued for overstating, not disclosing privacy, security flaws

uk.reuters.com

101–110 of 166 posts

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#102

How many of Zoom's recent issues can be explained by just bad engineering? Because my personal gripes with Zoom are mostly about its quality as a software product, which I find to be abysmal for my use cases.

From a purely functional standpoint, that is -- does this software do what I need it to do?, I have had absolutely no problems with zoom. What issues have come up for you?

I don't really want to go through the laundry list of issues I have because none are critical, just the software is very rough around the edges on Linux. It just feels less than flushed out, and I've had a million little problems and bugs that I've reported and never heard anything back (as a paying user!).

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#103

Not surprising. Crazy how zoom in the beginning of the crisis was hailed for helping folks get together, but now with all the highlighted security concerns they are receiving a ton backlash. Hopefully they can recover and learn from this.

Apart from that FBI warning of Zoombombing, I don't know a single non-tech person that's actually aware of all these security concerns, including China privacy.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#104

Good. There needs to be a serious crackdown on 'puffery' aka lying ( whether lying about product feature or anything else is irrelevant ). Fingers crossed and it will go beyond $2 credit on future Zoom services for affected users.

I'm betting the payout will be a custom emoji for affected users. Maybe a tinfoil hat. And the court will be ok with that so long as the lawyers get paid in hard currency.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#105
post #84
post #80

Earlier quoted context omitted.

Unlikely IMO. "Zoom, a Silicon Valley-based company, appears to own three companies in China through which at least 700 employees are paid to develop Zoom’s software. This arrangement is ostensibly an effort at labor arbitrage: Zoom can avoid paying US wages while selling to US customers, thus increasing their profit margin. However, this arrangement may make Zoom responsive to pressure from Chinese authorities." htt…

So Zoom is essentially a Chinese company with a formal outer shell in the US and 81% of its revenue coming from North America?

[deleted]

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#106
post #66
post #57

Earlier quoted context omitted.

Why is having engineers in China cause for suspicion? Lots of tech companies have engineers in China. Eg Microsoft.

But if Microsoft has teams in China, Russia work on MS Teams, I will be very concerned. The same goes with Slack, that many companies now rely on to keep business going.

If you have eng in US, having a decent chunk of it in China is much less threatening. For example, your internal controls can specify code review by american employees. Your key servers can remain in America or EU with stronger privacy protection regimes (not necessarily strong; just stronger than China).

This isn't perfect, but it makes subversion (1) more difficult, (2) probably more targeted (see eg Saudi Arabia using Saudi nationals employed by Twitter to steal identities of critics on Twitter), (3) more likely to be discovered.

My company's security model doesn't include the Chinese government / national security / military, but it could include the Chinese government giving our sales leads (which are evident if you can see our Zoom calls) to a domestic competitor. Broad exfiltration of data like that is much much harder if the engineering core is in the US or EU.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#107
post #22

my employer currently signs up for zoom, apparently managed via our SSO-solution. so far so good. Right now, I got an email from Zoom, not showing any relation to my employer or mentioning its name: "congratulations for signup, use your account now". Ok. Password reset yields an usable basic account. Seems like somehow Zoom created a personal account for me with my work email. As I didn't get the activation email I g…

I set up Zoom for our company and nothing like this happened. It seems much more likely (than your wild conspiracy theory) that your company added a "basic", rather than "licensed" account for you and you got an email as a result.

no, don't know what kind of mess they made; the official login is via SSO (and works with .zoom.us). to my understanding the account is typically created on login there (otherwise we would sync our whole list of employees with 100s of services...). and even if it was just a random invitation sent to an email they bought somewhere, it doesn't really explain how I could reset the password for my email then (without ever activating an account)?!

It might be a messup from someone but it's definitely strange and I just didn't sign up there, yet got spam and had a working basic account...

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#108
post #57
post #50

Don't know what is going on at Zoom, but I suspected at least part of it sneaky. For example, about 3 or 4 weeks ago I heard about this company, and learned that it has R&D in China per its SEC filing at IPO. However, checked its website, the career section led me to https://jobs.lever.co/zoom , and there was ONLY one opening at China per the website (I remember it was a position at marketing department). Then I sear…

Why is having engineers in China cause for suspicion? Lots of tech companies have engineers in China. Eg Microsoft.

I very much doubt Microsoft does any serious development of their core products in China. Localisation,some local support and other,less sensitive stuff.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#109
post #11

Earlier quoted context omitted.

Interesting that shareholders are the one to fill a lawsuit.

In the US lying to users is merely frowned upon while lying to investors is illegal.

False advertising of services (amongst other things) is illegal in the US.

https://www.law.cornell.edu/uscode/text/15/52#b

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#110
post #80
post #50

Don't know what is going on at Zoom, but I suspected at least part of it sneaky. For example, about 3 or 4 weeks ago I heard about this company, and learned that it has R&D in China per its SEC filing at IPO. However, checked its website, the career section led me to https://jobs.lever.co/zoom , and there was ONLY one opening at China per the website (I remember it was a position at marketing department). Then I sear…

Unlikely IMO. "Zoom, a Silicon Valley-based company, appears to own three companies in China through which at least 700 employees are paid to develop Zoom’s software. This arrangement is ostensibly an effort at labor arbitrage: Zoom can avoid paying US wages while selling to US customers, thus increasing their profit margin. However, this arrangement may make Zoom responsive to pressure from Chinese authorities." htt…

I mean, this is incredibly common. Is there a large software company that doesn't do this? Labor competition is a real thing.
Post reply on HN