Live data from Hacker News

Zoom sued for overstating, not disclosing privacy, security flaws

uk.reuters.com

121–130 of 166 posts

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#122
post #90

Earlier quoted context omitted.

Because the CCP has no qualms about threatening an employee’s family to insert a backdoor or exfiltrate information, for one. The decoupling has begun. Sentiment in the US toward China has never been as negative as it is now, from both sides of the aisle. I wouldn’t be surprised if we even see sanctions against China after the dust settles on this COVID fiasco.

Enforcing US IP protections isn't a partisan issue. I think it's crazy that people are trusting zoom for their critical communications (like design review meetings and screen sharing schematics/process diagrams!) when there's a non-zero chance that the CCP/PLA has the infrastructure to: cat '$COMPANY/zoom-chat.log' | grep '$TRADE_SECRET' | local_industry_boost.bash inb4 the whataboutism: yes, the US Government has (a…

Please share your grep binary that allows me to search countless hours of boring video for actionable content.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#123
post #57
post #50

Don't know what is going on at Zoom, but I suspected at least part of it sneaky. For example, about 3 or 4 weeks ago I heard about this company, and learned that it has R&D in China per its SEC filing at IPO. However, checked its website, the career section led me to https://jobs.lever.co/zoom , and there was ONLY one opening at China per the website (I remember it was a position at marketing department). Then I sear…

Why is having engineers in China cause for suspicion? Lots of tech companies have engineers in China. Eg Microsoft.

Anti-China sentiment is being stoked heavily in the US right now. Anything China-related is widely seen as evil and/or untrustworthy. Usually these opinions are expressed on China-sourced hardware.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#124

Looking back, there isn't actually any evidence that Zoom is not, as they put it, "encrypted from end point to end point". But it is clear that Zoom itself is kind of confused about the whole thing. I don't think that Zoom is all that good with technical stuff... To have any assurance that a video conferencing system is actually secure e2e you would have to have access to the verified source code of the client progra…

Security audits are done all the time, for which access to the source is given. In Zoom’s case, going through an audit from a reputable firm, may just be the answer of getting the public’s confidence back.

And of course it’s fairly extreme to claim you should not use any video conference system for any sensitive discussions; security is not black and white, and each situation deserves an appropriate level of security; it needs to be balanced with convenience. There are a lot of situations where I would prefer “mostly” secure communication, rather than no communication at all.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#125
post #93

Earlier quoted context omitted.

That's an excellent business model.

It's basically what a lot of consumer goods companies are now. All the products are made and mostly designed in China, and then the US HQ does all the sales, marketing, and funneling product requirements back to China.

> and funneling product requirements

I don't think the funneling stops at product requirements.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#126
post #39

Earlier quoted context omitted.

>Seeing as encryption is illegal in China Source for this? That would make any https site in china illegal.

Not an expert, but I searched and found this link which seems to explain it well: https://www.freshfields.com/en-us/our-thinking/campaigns/dig... tl;dr: encryption is not completely illegal, but it sounds like it's pretty tightly controlled.

I didn't think they'd be foolish enough to completely ban it.

They're not comically evil, they just have certain incentives.

Key escrow meets those goals.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#127

Earlier quoted context omitted.

Because the CCP has no qualms about threatening an employee’s family to insert a backdoor or exfiltrate information, for one. The decoupling has begun. Sentiment in the US toward China has never been as negative as it is now, from both sides of the aisle. I wouldn’t be surprised if we even see sanctions against China after the dust settles on this COVID fiasco.

Let’s get real here. The United States government is most certainly capable of doing everything we accuse China of doing and worse.

Let's get even more real. This is whataboutism and it is a false argument.

The United States government can and is often held accountable for its actions. This concept does not exist in China.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#128
post #17

Earlier quoted context omitted.

Shareholders can sue you for pretty much anything you do that damages your value that you didn't warn them about. I.e. they put in their IPO prospectus that there might be a negative impact on their reputation from them having Chinese R&D, so they have a defense against that. They didn't put "We have misleading marketing materials that might become subject to widespread public attention" in there I think.

That doesn’t mean it’s a sound policy. Public markets bid up a stock to an insane valuation in a matter of weeks and then the price comes down (due to technicals, fundamentals, whatever) and you have shareholders trying to weasel out of their gambling losses by suing company. Let a customer who was actually harmed by this sue. Much more compelling to me.

It should teach companies not to lie in their marketing, or as Zoom calls it, "have a discrepancy between the commonly accepted definition of e2e and how [they're] using it".

If they weren't making shit up, stocks go up, stocks go down, but the gamblers wouldn't have any grounds to sue.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#129
post #122
post #90

Earlier quoted context omitted.

Enforcing US IP protections isn't a partisan issue. I think it's crazy that people are trusting zoom for their critical communications (like design review meetings and screen sharing schematics/process diagrams!) when there's a non-zero chance that the CCP/PLA has the infrastructure to: cat '$COMPANY/zoom-chat.log' | grep '$TRADE_SECRET' | local_industry_boost.bash inb4 the whataboutism: yes, the US Government has (a…

Please share your grep binary that allows me to search countless hours of boring video for actionable content.

Run the audio through Google's voice API or similar. Then use grep.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#130
post #120

Earlier quoted context omitted.

Let’s get real here. The United States government is most certainly capable of doing everything we accuse China of doing and worse.

The US is no white knight. But it is not doing anything close to what the CCP does on a regular basis. When was the last time a Trump protestor or Obama protestor disappeared and was never heard from again? Or disappeared and show up again months later, 30 lbs lighter and apologetic about how wrong they were about the government?

In this sense yes, absolutely. China is known for doing grotesque humanitarian violations.

In another sense such as starting a war to deflect from problems at home, theres one champ and that is our democratic country.

Either one doesn’t mean the other is doing something legitimate and is waranted shielding from criticism

Post reply on HN