Live data from Hacker News

Zoom sued for overstating, not disclosing privacy, security flaws

uk.reuters.com

141–150 of 166 posts

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#141
post #122

Earlier quoted context omitted.

Please share your grep binary that allows me to search countless hours of boring video for actionable content.

Run the audio through Google's voice API or similar. Then use grep.

You mean Baidu’s.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#142
post #120

Earlier quoted context omitted.

The US is no white knight. But it is not doing anything close to what the CCP does on a regular basis. When was the last time a Trump protestor or Obama protestor disappeared and was never heard from again? Or disappeared and show up again months later, 30 lbs lighter and apologetic about how wrong they were about the government?

In this sense yes, absolutely. China is known for doing grotesque humanitarian violations. In another sense such as starting a war to deflect from problems at home, theres one champ and that is our democratic country. Either one doesn’t mean the other is doing something legitimate and is waranted shielding from criticism

"Starting a war to deflect from problems at home", what the heck would you call the invasion of Tibet then?

And while not literally a war, what purpose do you think the bellicose suppression of the fact of Taiwanese independence both domestically and abroad serves?

Some people seem so obsessed with the country they live in, they can't see the rest of the world properly. An over focus on domestic politics distorts everything with parochialism.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#143
post #109

Earlier quoted context omitted.

In the US lying to users is merely frowned upon while lying to investors is illegal.

False advertising of services (amongst other things) is illegal in the US. https://www.law.cornell.edu/uscode/text/15/52#b

Yes, just this week the FTC brought a tech company to justice for false and misleading promises to users about information security:

> “We allege that Tapplock promised that its Internet-connected locks were secure, but in fact the company failed to even test if that claim was true,” said Andrew Smith, Director of the FTC’s Bureau of Consumer Protection. “Tech companies should remember the basics—when you promise security, you need to deliver security.”[1]

Armed with clear and indisputable evidence of Tapplock's blatant lies, the bulldog enforcement lawyers at the FTC took the opportunity to make an example out of the company. After 18 months of hard-fought negotiations the FTC announced a settlement agreement[2] whereby the Commission agreed to resolve the matter in exchange for Tapplock's pinky promise to not get caught doing that again. Per the arduous terms of the settlement, Tapplock neither admits nor denies any of the FTC's allegations.

So when a company promises their users security that company better deliver security. Or else... absolutely fuckall will happen.

[1]https://www.ftc.gov/news-events/press-releases/2020/04/canad...

[2]https://www.ftc.gov/system/files/documents/cases/192_3011_ta...

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#144
post #84
post #80

Earlier quoted context omitted.

Unlikely IMO. "Zoom, a Silicon Valley-based company, appears to own three companies in China through which at least 700 employees are paid to develop Zoom’s software. This arrangement is ostensibly an effort at labor arbitrage: Zoom can avoid paying US wages while selling to US customers, thus increasing their profit margin. However, this arrangement may make Zoom responsive to pressure from Chinese authorities." htt…

So Zoom is essentially a Chinese company with a formal outer shell in the US and 81% of its revenue coming from North America?

so basically merging SV surveillance capitalists with PLA style APT developers. What could possibly go wrong!

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#146
post #107

Earlier quoted context omitted.

I set up Zoom for our company and nothing like this happened. It seems much more likely (than your wild conspiracy theory) that your company added a "basic", rather than "licensed" account for you and you got an email as a result.

no, don't know what kind of mess they made; the official login is via SSO (and works with .zoom.us). to my understanding the account is typically created on login there (otherwise we would sync our whole list of employees with 100s of services...). and even if it was just a random invitation sent to an email they bought somewhere, it doesn't really explain how I could reset the password for my email then (without eve…

> otherwise we would sync our whole list of employees with 100s of services

Could also have been created with SCIM and you're in a particular SCIM group that other folks are not in.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#147

Earlier quoted context omitted.

For our daily standup we use meet.google.com as it's more convenient than ZOOM. ymmv ofc

My company has been trying to find a solution since the Coronavirus hit. (We're not used to working from home) We were using Slack's built-in conferencing at first, but aside from the quality being generally bad, there was a 15 person limit, and we're ~ 17 people. I didn't want us to use Zoom with everything that's going on, so I suggested Google Meet. We tried it, and it worked, but not well—people's voices would fr…

It's hard to argue that a product from targeted-advertising companies like Google and Microsoft wouldn't exhibit much worse privacy concerns, and the other major competitor, Cisco, was the architect of China's great firewall. Zoom works pretty great. I have been on very large conference calls almost daily over a year and they've been pretty flawless. They also sign HIPAA BAAs which is great for the industry I'm in.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#148

Looking back, there isn't actually any evidence that Zoom is not, as they put it, "encrypted from end point to end point". But it is clear that Zoom itself is kind of confused about the whole thing. I don't think that Zoom is all that good with technical stuff... To have any assurance that a video conferencing system is actually secure e2e you would have to have access to the verified source code of the client progra…

Security audits are done all the time, for which access to the source is given. In Zoom’s case, going through an audit from a reputable firm, may just be the answer of getting the public’s confidence back. And of course it’s fairly extreme to claim you should not use any video conference system for any sensitive discussions; security is not black and white, and each situation deserves an appropriate level of security…

>There are a lot of situations where I would prefer “mostly” secure communication, rather than no communication at all.

We are not talking about "mostly" here for the video conference case. We are talking about a situation where most providers have access to the data of their users without very much work. If you are actually willing to confirm the identity of your correspondent using verified binaries you can get end to end protected communications ... if someone claims that they have something easier then they are lying. You can't beat the law of logic. The fact that anyone is even suggesting that Zoom could of been e2ee in any way that mattered is kind of depressing. I think we have some education to do.

Security audits are pointless unless you can confirm that the software that was audited is the software actually running on your device.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#149

Earlier quoted context omitted.

In this sense yes, absolutely. China is known for doing grotesque humanitarian violations. In another sense such as starting a war to deflect from problems at home, theres one champ and that is our democratic country. Either one doesn’t mean the other is doing something legitimate and is waranted shielding from criticism

"Starting a war to deflect from problems at home", what the heck would you call the invasion of Tibet then? And while not literally a war, what purpose do you think the bellicose suppression of the fact of Taiwanese independence both domestically and abroad serves? Some people seem so obsessed with the country they live in, they can't see the rest of the world properly. An over focus on domestic politics distorts eve…

Not exactly, Tibet is a different type of thing, it’s more like chinas’s expansion rather than Xi wanting to deflect attention from his own problems. American wars weren’t for any purpose or even any benefit for the US and lots of money was wasted and stolen through military industrial complex.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#150

Earlier quoted context omitted.

In this sense yes, absolutely. China is known for doing grotesque humanitarian violations. In another sense such as starting a war to deflect from problems at home, theres one champ and that is our democratic country. Either one doesn’t mean the other is doing something legitimate and is waranted shielding from criticism

The US does not start wars to distract from problems at home. That’s conspiracy horse manure. Whether you want to believe it or not, every president that has ever started a conflict or US involvement in an existing conflict has felt the action justified on foreign policy reasons. Those reasons might be something you object with, or even downright stupid in hindsight. But only in Hollywood is it ever a smoke screen fo…

I don’t see the humor in what you’re saying.
Post reply on HN