Live data from Hacker News

Zoom terms now allow training AI on user content with no opt out

explore.zoom.us

431–440 of 538 posts

Re: Zoom terms now allow training AI on user content with no opt out

#431

Earlier quoted context omitted.

I am yet to find a modern video chat that isn't draining the battery of any laptop. From old Xeons, to fairly recent Ryzen and even M1/2 Macs. It's a bit puzzling, actually. I don't think Skype and TeamSpeak had the same effect on computers back in the day. Just how much local processing are they doing these days? It's crazy

It's most likely due to the fact they are all electron apps rather than they are doing "something".

Video encoding and decoding is expensive! Especially as cameras improve and users' expectations of quality increase.

Re: Zoom terms now allow training AI on user content with no opt out

#432
post #398

This is not new. These terms were quietly updated on 1st April 2023. Looks like very few people noticed it until now. https://web.archive.org/web/20230401045359/https://explore.z...

I am really puzzled how are they able to "quietly" update the terms without notifying their users? Everybody was joking about the emails (We have updated our terms...) raining from every company when GDPR et al. got introduced. What changed?

You really ought to read “No Filter” by Sarah Frier. She talks about exactly this, except with Apple and iTunes in 2001. Apple’s biggest change wasn’t “digitizing music”, it was enabling a system that allows arbitrary changes to terms and conditions for services they offered. Apparently if you presented a digital copy of a TOS and users clicked one button, it was legally binding. Other companies caught on and started doing it, and well that’s how Zoom is able to do this - people don’t bother to read what they’re agreeing to so legally it’s the user’s fault if the software does something they don’t like.

Re: Zoom terms now allow training AI on user content with no opt out

#433

Earlier quoted context omitted.

It's most likely due to the fact they are all electron apps rather than they are doing "something".

Hardware decoding is also an issue.. as in, not being used. Old webcams used to do h.264 encoding in hardware. Encoding has since now moved to the CPU which may or may not be fine.. the next issue becomes the codec chosen.. most stuff all has h.264 decoding in hardware.. but it's not being used anymore.. instead they're trying to use vp09 or h.265 or av1 which in many cases requires CPU-based software encoding and de…

Bandwidth is the limiting factor in a lot of circumstances, and networks are very challenging to manage. Especially with an increasing number of users on mobile connections, reducing network usage can be the right call.

But performance matters, too, of course. It's tricky to balance them.

Re: Zoom terms now allow training AI on user content with no opt out

#434
post #121

Earlier quoted context omitted.

Why setup a separate broadcast when listeners can just join the meeting room?

Yes, I know it's more comfortable that way, but if you have to decide between giving all your data from all your meetings to a random US company and a slight annoyance whenever you do conferences with more than 500(!) participants, the choice is pretty simple to me. Giving all the data to zoom probably means also giving it to most US law enforcement agencies (should they request it), that would be a big no no for me.

You say "just more comfortable" but if you have two streams and one of them is on a channel you know to be unreliable (Jitsi) it's pretty guaranteed the unreliable stream is going to be down a significant percentage of the time. If you're a company with 500 people this isn't a comfort question, you're wasting probably hundreds of hours of your employees' time.

Re: Zoom terms now allow training AI on user content with no opt out

#435

Tangentially related, but a number of telehealth operations with hospitals/therapists/etc... use Zoom -- I suspect because their clients can connect without an app or an account over a browser. When you join a Zoom session over the browser, you don't sign a TOS. And I assume that actual licensed medical establishments are under their own TOS provisions that are compatible with HIPPA requirements. Training on voice-to…

IANAL but “Zoom for Healthcare” is a business associate under HIPAA and treated as an extension of the provider with some added restrictions.

Covered entities (including the EMR and hospital itself) can use protected health information for quality improvement without patient consent and deidentified data freely.

Where this gets messy is that deidentification isn’t always perfect even if you think you’re doing it right (especially if via software) and reidentification risk is a real problem.

To my understanding business associates can train on deidentified transcripts all they want as the contracts generally limit use to what a covered entity would be allowed to do (I haven’t seen Zoom’s). I know that most health AI companies from chatbots to image analysis do this. Now if their model leaks data that’s subsequently reidentified this is a big problem.

Most institutions therefore have policies more stringent than HIPAA and treat software deidentified data as PHI. Stanford for example won’t allow disclosure of models trained on deidentified patient data, including on credentialed access sources like physionet, unless each sample was manually verified which isn’t feasible on the scale required for DL.

Edit: Zoom’s BAA: https://explore.zoom.us/docs/en-us/baa.html

“Limitations on Use and Disclosure. Zoom shall not Use and/or Disclose the Protected Health Information except as otherwise limited in this Agreement or by application of 42 C.F.R. Part 2 with respect to Part 2 Patient Identifying Information, for the proper management and administration of Zoom…”

“Management, Administration, and Legal Responsibilities. Except as otherwise limited in this BAA, Zoom may Use and Disclose Protected Health Information for the proper management and administration of Zoom…”

Not sure if “proper management and administration” has a specific legal definition or would include product development.

Edit 2: My non-expert reading of this legal article suggests they can. https://www.morganlewis.com/-/media/files/publication/outsid...

“But how should a business associate interpret these rules when effective management of its business requires data mining? What if data mining of customer data is necessary in order to develop the next iteration of the business associate’s product or service? … These uses of big data are not strictly necessary in order for the business associate to provide the contracted service to a HIPAA-covered entity, but they may very well be critical to management and administration of the business associate’s enterprise and providing value to customers through improved products and services.

In the absence of interpretive guidance from the OCR on the meaning of ‘management and administration’, a business associate must rely almost entirely on the plain meaning of those terms, which are open to interpretation.”

Re: Zoom terms now allow training AI on user content with no opt out

#436

This is not new. These terms were quietly updated on 1st April 2023. Looks like very few people noticed it until now. https://web.archive.org/web/20230401045359/https://explore.z...

It's settled, then. I'll move on to using a different video chat service... They're a dime-a-dozen. Good job tanking your reputation and business, zoom!

I'm sure they'll miss your business, but this change will hardly impact their bottom line. Most users will continue to use it, even if they're aware of and are concerned by this, as the cost and inconvenience of switching is too high.

Re: Zoom terms now allow training AI on user content with no opt out

#437
post #427

Earlier quoted context omitted.

> solely for the limited purpose of operating and enabling the Service to work as intended for You and for no other purposes. To me (a former corporate lawyer) the "for You" qualifier would limit their ability to use content to train an AI for use by anyone other than "You". Is there an argument? Yes. But by that argument, they would also be allowed to "publicly perform" my videoconf calls for some flimsy reasons tha…

"You" is a defined term in Jitsi's Terms of Service. >...any legal entity or business, such entity or business (collectively, “You” or “Your”)

In case this is meant to imply that perhaps my business and your business are both part of the same "You", they are not. They are each a party to a separate contract with Jitsi; we are not all party to one huge contract with each other (which would hypothetically allow Jitsi to do anything with our content for the purpose of helping them serve all of us).

Re: Zoom terms now allow training AI on user content with no opt out

#438

Tangentially related, but a number of telehealth operations with hospitals/therapists/etc... use Zoom -- I suspect because their clients can connect without an app or an account over a browser. When you join a Zoom session over the browser, you don't sign a TOS. And I assume that actual licensed medical establishments are under their own TOS provisions that are compatible with HIPPA requirements. Training on voice-to…

IANAL, but I did health tech for 10 years and had my fair share of interactions with lawyers asking questions about stuff I built.

HIPAA applies to the provider. Patient have no responsibility to ensure the tech used by their care provider is secure or that their medical records don't wind up on Twitter. HIPAA dictates that the care providers ensure that happens by placing both civil and sometimes criminal liability on the provider for not going to great lengths here.

In practice, this means lawyers working with the care providers have companies sign legal contracts ensuring the business associate is in compliance with HIPAA, and are following all of the same rules as HIPAA (search: HIPAA BAA).

Additionally, you can be in compliance with HIPAA and still fax someone's medical records.

Re: Zoom terms now allow training AI on user content with no opt out

#439
This seems a subtle shift in general with AI is people feel entitled to treat it as an end in itself or a black box. The agreement says they can use "User Content" for:

> the purpose of product and service development, marketing, analytics, quality assurance, machine learning, artificial intelligence, training, testing, improvement of the Services, Software

So notice most of these are somehow qualified to the service they are providing you, but the AI part stands alone. If it was to improve the service to me, that would be pretty reasonable, but here it says they can use it for AI as an end unto itself.

Something about the inscrutability of modern AI (nobody knows how it really works, what the limits of its capabilities are etc.) seems to lend itself to this kind of open ended vagueness. If they just wrote "we can use your user generated content for anything we like" it would almost amount to the same thing but people would be outraged. But when they say "it's for AI" everyone nods their head as if it's somehow different to that.

Re: Zoom terms now allow training AI on user content with no opt out

#440

Tangentially related, but a number of telehealth operations with hospitals/therapists/etc... use Zoom -- I suspect because their clients can connect without an app or an account over a browser. When you join a Zoom session over the browser, you don't sign a TOS. And I assume that actual licensed medical establishments are under their own TOS provisions that are compatible with HIPPA requirements. Training on voice-to…

IANAL, but I did health tech for 10 years and had my fair share of interactions with lawyers asking questions about stuff I built. HIPAA applies to the provider. Patient have no responsibility to ensure the tech used by their care provider is secure or that their medical records don't wind up on Twitter. HIPAA dictates that the care providers ensure that happens by placing both civil and sometimes criminal liability…

I don’t think the question is about Zoom’s safeguards which are audited, and as you say almost certainly stronger than HIPAA requirements, but rather whether they can use the stored PHI for product development where the law appears ambiguous.
Post reply on HN