Live data from Hacker News

Zoom still don't understand GDPR

threatspike.com

141–150 of 267 posts

Re: Zoom still don't understand GDPR

#141

Earlier quoted context omitted.

Profitable business culture, poor engineering culture. Happens all the time in companies of all sizes.

In other words: a) malice, and b) a business problem, not a tech problem.

Absolutely would call this a tech culture problem. Just like e.g. not writing tests because management doesn't want to spend time on that. Doesn't mean that individual developers are to blame for this kind of decision, but it speaks for the overall culture of the tech org. Yes, often driven by business objectives.

Re: Zoom still don't understand GDPR

#142
“Zoom cookies are firstly written when the user connects to the website zoom.us and accepts the cookies options.”

That was the moment Zoom received your consent to store data transmitted by cookies. Adding a few more cookies to the pile, regardless of expiration date, doesn’t change the agreement.

Rummaging round the cookie bin on uninstall is a nice find and deserves a raised eyebrow but this doesn’t really have anything to do with GDPR.

Re: Zoom still don't understand GDPR

#143

I love how when you go to enter a Zoom meeting, they bury the no-install, run-in-browser link in small type in a footer. And then, if you manage to see the link and use the browser, they withhold "Gallery View", forcing you to deal with the extremely annoying "Active Speaker View".

Holy shit - you can run Zoom in the browser???

Re: Zoom still don't understand GDPR

#144
post #84

Earlier quoted context omitted.

Yeah this was so sad, but I'm happy the guys that made it got paid. Even they would have known this was the end for Keybase. Hopefully when their non-compete clauses end the developers will make another product the same.

> Yeah this was so sad, but I'm happy the guys that made it got paid. I don't really sympathize with this. You build something, get a ton of people to use it, advocate for it, get their friends to use it... I think after that, you have a responsibility to those users, and selling to a company like Zoom and then peaceing out on further work does not fulfill that responsibility.

The choice is entirely with the consumer to decide to use non free software. Don’t be shocked when you are hurt

Re: Zoom still don't understand GDPR

#145
post #138

Why do you guys not use https://whereby.com (formerly appear.in), it’s free for 4 people, in-browser only, no-login, WebRTC, allows sharing the screen alongside faces. But they made the 5+ rooms $9 per month, which is way too expensive. There are not enough competitors for WebRTC conf tools, it should be quite simple and $4-5 a month (WebRTC doesn’t incur data costs on the servers since the data is peer-to-peer).

> WebRTC doesn’t incur data costs on the servers since the data is peer-to-peer There are probably some operators that do pure p2p, but vast majority use some kind of bridge past certain number of users (& TURN might also be used for p2p). Usually this is to limit the amount of bandwidth participant needs. Another alternatives are https://meet.jit.si & https://8x8.vc/ . I cannot remember what was the current limit of…

8x8 has intrigued me, but I'm a bit confused as to what happened. Did 8x8 buy the Jitsi brand from Atlassian? And what's the benefit of 8x8 vs Jitsi pure? I might be a customer if 8x8 is a compelling alternative to Zoom without some of the downsides of Jitsi (generally less reliable).

Re: Zoom still don't understand GDPR

#146
post #97

I argue Zoom does understand GDPR and the ePrivacy Directive from a legal perspective. The specific citation about the length of a cookie is a recommendation and not a law[0]. The key word is 'should'. I'm not a lawyer nor claim the ability to interpret GDPR legally, but I have seen companies that actively worked to edge case GDPR to their advantage (I was part of one). We would have lawyers and other 'GDPR experts'…

I imagine GDPR doesn't apply to Zoom, as a non-EU company. Much like China bans what it doesn't want, the onus is on the EU to set up a GFW of their own and ban Zoom (and other GDPR-non-compliant foreign websites) if they disagree with it. Otherwise, Zoom only needs to obey the laws of USA and wherever else they have offices. Disclaimer: IANAL Also: I'm not arguing for Zoom's sketchy practices but just saying that GD…

> The EU isn't the world police.

That’s not how the world works. Non US citizens have been arrested in the US for breaking US law when they aren’t in the US. Hell the US has tried to extradite people to the US who have never been to America.

Re: Zoom still don't understand GDPR

#147

This is what we need app sandboxing for. No reason third-party apps should be able to read the browser's cookie database.

As an aside, the Chrome cookies database on Windows is protected using the Windows Data Protection API[1], which ties encryption keys to a specific user. In the case of the Chrome cookie database, each cookie's payload/value is encrypted using a cryptographic key generated by the DPAPI which is only accessible to that Windows user. Of course, (and as is the case with most situations like this), this does absolutely n…

I thought the rule was: If you can see it plaintext on the screen, it's not safe.

Re: Zoom still don't understand GDPR

#148

Earlier quoted context omitted.

As far as I can find online, it's american street language; I only know it from US shows and Eminem (and other rap) songs. Maybe here it's used to indicate that "zoom be stupid".

Perhaps. I'm American but live in the UK, and I have observed how people in the UK use "don't" as opposed to "doesn't" when the thing being referred to is an organisation, I suppose with the idea of it being an organisation comprised of many people (i.e. "they don't") as opposed to an inanimate non-human entity ("it doesn't"). Still incorrect to my understanding of how English works.

Perhaps it’s built into a different perception of what a company is. In America, I get the feeling people think more of companies (large companies) as human beings with rights (but no responsibilities), and that’s far less than the general view in the UK where the view is often they are parasites with valueless shareholders.

I wonder if a company with a well known single owner (amazon/bezos, spacex/musk) is also thought of as a group Or a person subconsciously.

Two countries separated by a common language

Re: Zoom still don't understand GDPR

#149
post #59

Earlier quoted context omitted.

> they bury the no-install, run-in-browser link I wrote a browser extension that will transparently redirect all zoom links to user their web client: https://github.com/arkadiyt/zoom-redirector

love this extension. we recommend it for everyone at work as the zoom client is banned.

What do you then do about the horrible performance of zoom in chrome?

For me, the sound becomes unintelligible as soon as someone shares his screen.

Re: Zoom still don't understand GDPR

#150

Earlier quoted context omitted.

Would you call Cisco and Dell principally Indian companies?

Why not, if that’s where a majority of the teams making engineering decisions are?

How about GitLab then? The CEO is Dutch, working (AIUI) in SF, and the engineering team are all remote. The company is incorporated in the Netherlands, US, UK, and a load of other countries. Does that make them principally a Dutch, American, or ??? company?
Post reply on HN