Live data from Hacker News

Zoom still don't understand GDPR

threatspike.com

101–110 of 267 posts

Re: Zoom still don't understand GDPR

#101
post #48

I love how when you go to enter a Zoom meeting, they bury the no-install, run-in-browser link in small type in a footer. And then, if you manage to see the link and use the browser, they withhold "Gallery View", forcing you to deal with the extremely annoying "Active Speaker View".

> And then, if you manage to see the link and use the browser, they withhold "Gallery View", forcing you to deal with the extremely annoying "Active Speaker View". Is this a browser limitation or something? I think microsoft teams has the same issue.

Jitsi supports multiple videos, I've had at least 6 people before.

We use GoToMeeting at work, and many times have 20 people with video, plus screen sharing (there's also gotowebinar which supports thousands of viewers).

With GTM I love that you can seamlessly share without disabling your video. The web browser experience is hands down better overall then everything else I've used (Zoom, MS Teams, Slack, Jitsi, WebEx). Camera views are just auto-sizing, auto-layout boxes (think: floating tiles) that fit the space you give them, and you can pick top/bottom/left/right when someone is sharing a screen.

Then things that hold GTM back: they still push their native client, and it takes two clicks every time to join with browser (it's not buried like zoom, but it's nowhere near the instant-on, zero-effort of Jitsi). The other thing driving me absolutely mad right now is they introduced a bug a few weeks ago that causes it not to remember my audio settings or name. When I host a meeting, despite telling it to "remember me" it never does -maybe this is part of the federated login my company uses, but the end result is when I click to start my meeting it tells me it's waiting for me to arrive, add takes like 4 more clicks and bouncing around login sites to get in.

My ideal:

Run in a browser, use extensions to get extra functionality if needed.

With lots of people, switch to multiplexing and/or automatically downscale video.

Support seamless pstn dial-in, and pop up a suggestion about this to users if their audio starts breaking up.

Don't stop my webcam when I start screen-sharing.

Support active speaker view, gallery (zoom-style), or GTM-style.

Remember all my preferences and make it so I rarely have to think about any settings. Or login.

Make it easy to give people permission to control/share/etc, and for recurring meetings, remember those changes for next time.

Re: Zoom still don't understand GDPR

#102
post #62

Earlier quoted context omitted.

The web version also won't allow the host to request control from what I can tell. I use it daily for remote support because new webex sucks and no one knows what jitsi is.

MS Teams has the same behaviour in web client. Is it browser-level restriction?

Google Meet has tiled view on web.

Re: Zoom still don't understand GDPR

#103

I love how when you go to enter a Zoom meeting, they bury the no-install, run-in-browser link in small type in a footer. And then, if you manage to see the link and use the browser, they withhold "Gallery View", forcing you to deal with the extremely annoying "Active Speaker View".

Btw Zoom account manager can enable this "Join from your browser" link, to show it to all participants. It's hidden by default. This is what I did in our org:

https://support.zoom.us/hc/en-us/articles/115005666383-Show-...

Re: Zoom still don't understand GDPR

#104
post #99

Earlier quoted context omitted.

Same, they were my preferred platform for secure messaging, which is bizarre when you think about the fact that this wasn't even their original purpose. I guess this was indicative of the general lack of a single defined direction the product was going in near the time of the Zoom acquisition. What a shame. Hopefully someone makes something similar.

What was the draw of Keybase? I wasn't interested when it was a "post all your website usernames here, but with crypto somehow" site, and by the time I looked in on it later, it was an unreadable startup homepage and had some kind of cryptocurrency scam attached to it. If it had a good messaging featureset that should be cloned, former Keybase users should speak up!

It had excellent chat functionality that worked well, and this was at a time in which the Signal client for Android was still quite buggy (hundreds of Bad encrypted message messages flooding group chats, messages delivered hours late and all at once, poor performance etc.) My group naturally gravitated towards Keybase as our secure messaging platform. The other killer feature was KBFS, which was a sort of shared encrypted filesystem with which you could sync files securely across all of your devices, share files publicly or with specific users or sets of users or groups in cryptographically protected ways.

The unintelligible foray into cryptocurrency with Lumens made very little sense to me, but apparently the coins I was gifted for free by Keybase are worth over 100 USD now. I'll probably hold on to them.

Re: Zoom still don't understand GDPR

#105

This is what we need app sandboxing for. No reason third-party apps should be able to read the browser's cookie database.

As an aside, the Chrome cookies database on Windows is protected using the Windows Data Protection API[1], which ties encryption keys to a specific user. In the case of the Chrome cookie database, each cookie's payload/value is encrypted using a cryptographic key generated by the DPAPI which is only accessible to that Windows user. Of course, (and as is the case with most situations like this), this does absolutely nothing to protect users against malicious or intrusive programs running with the permissions of that user.

So yeah, you're right. App sandboxing please.

[1] https://en.wikipedia.org/wiki/Data_Protection_API

Re: Zoom still don't understand GDPR

#106

Earlier quoted context omitted.

Zoom is not alone in this. Lots of crud gets left, and it differs between which OS it is.

This looks more like them actively placing a cookie into the cookie DB upon install. Doesn't appear to be simply left behind.

*uninstall

Re: Zoom still don't understand GDPR

#107
post #27

Earlier quoted context omitted.

Especially when you consider the software and design of Zoom, poor engineering culture sounds like the more realistic answer.

> "Poor engineering culture" The software and service is currently running at a scale that the vast majority of visitors to HN can barely dream of achieving. But yeah, they prioritized ease of install for the client of their software over other considerations, so that must mean they have a "poor engineering culture", whatever that's supposed to mean.

Profitable business culture, poor engineering culture. Happens all the time in companies of all sizes.

Re: Zoom still don't understand GDPR

#109
Google Meet features seem so much better suited for government and education, especially if using G Suite on top of it. It is like the same price of Zoom but includes a lot of other great features, including unlimited storage using Google Drive.

Re: Zoom still don't understand GDPR

#110
post #97

I argue Zoom does understand GDPR and the ePrivacy Directive from a legal perspective. The specific citation about the length of a cookie is a recommendation and not a law[0]. The key word is 'should'. I'm not a lawyer nor claim the ability to interpret GDPR legally, but I have seen companies that actively worked to edge case GDPR to their advantage (I was part of one). We would have lawyers and other 'GDPR experts'…

I imagine GDPR doesn't apply to Zoom, as a non-EU company. Much like China bans what it doesn't want, the onus is on the EU to set up a GFW of their own and ban Zoom (and other GDPR-non-compliant foreign websites) if they disagree with it. Otherwise, Zoom only needs to obey the laws of USA and wherever else they have offices. Disclaimer: IANAL Also: I'm not arguing for Zoom's sketchy practices but just saying that GD…

I'm pretty sure GDPR applies to any companies with dealings in the EU, or at least to that company's dealings which occur within the EU.

Disclaimer: IAANAL

Post reply on HN