Live data from Hacker News

I'll pass on your zoom call

operand.online

21–30 of 74 posts

Re: I'll pass on your zoom call

#23
If you have to take the call, and your main concern is desktop client malware...

At a startup a few years ago, since I was the engineering dept., I had to be on a lot of enterprise sales/partnership calls, and much of the time we had to use the other company's favorite videoconferencing software.

Rather than installing those dumpster fire desktop apps on my Linux laptop that had the keys to our kingdom, I expensed an iPad that would be dedicated to random videoconf apps.

We still get violated numerous ways, but at least compartmentalized from the engineering laptop.

(I also used the iPad for passive monitoring of production at night, like a little digital photo frame in my living room, after putting away the work laptop.)

Re: I'll pass on your zoom call

#25

> Jitsi - their biggest offense in my book is their name, which is hard to say is or is not really offensive. And who can't remember not using a video conference app that didn't have an inoffensive name? If "jitsi" is offensive, who to? If not, which video conferencing app names are?

Sounds kind of like “Gypsy”, I guess.

Re: I'll pass on your zoom call

#26

Do you recall back in the day when zoom used to Root kit your computer?

Yeah I have to use Zoom for work, but I wrote a little script that installs it without the background services and privileged helper tools

https://raw.githubusercontent.com/jamesy0ung/zoom_grabber/re...

Re: I'll pass on your zoom call

#27
> If there's one [zoom call] I really need to be on, I'm going to spin up a VM on my computer so that it has no idea of the other files laying around, such as my ~/passcodes.csv`

Oh come now. You don't really think Zoom is exfiltrating unrelated files from your computer, do you? If they got caught doing this, it would be such a major scandal... why risk it? And even though the client is closed-source I do think they'd get caught. It just isn't fathomable to me.

Re: I'll pass on your zoom call

#28
post #13

When Zoom took the world by storm due to the pandemic, they're security was known to be horrible. They aquihired the keybase team who are crypto experts and this presumably had some measure of positive effect.

The advantage of Zoom was that it just worked. No more spending the first 10 minutes of a call making sure everyone is online and can see/hear you. Or at least greatly improved.

Re: I'll pass on your zoom call

#29

> If there's one [zoom call] I really need to be on, I'm going to spin up a VM on my computer so that it has no idea of the other files laying around, such as my ~/passcodes.csv` Oh come now. You don't really think Zoom is exfiltrating unrelated files from your computer, do you? If they got caught doing this, it would be such a major scandal... why risk it? And even though the client is closed-source I do think they'…

There's also security vulnerabilities. A while back there was a Firefox bug that let websites upload arbitrary files, which got used to steal SSH keys.

Re: I'll pass on your zoom call

#30

> Jitsi - their biggest offense in my book is their name, which is hard to say is or is not really offensive. And who can't remember not using a video conference app that didn't have an inoffensive name? If "jitsi" is offensive, who to? If not, which video conferencing app names are?

Sounds kind of like “Gypsy”, I guess.

I'm 3/4 Gypsy and I don't have a problem with it.
Post reply on HN