Live data from Hacker News

Zoom’s 90-day plan to bolster key privacy and security initiatives

blog.zoom.us

1–10 of 113 posts

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#4
post #2

So were they really sending data to servers in China? From what little I've heard and read about this, that is what stood out to me. Not sure they should ever be trusted again after that.

I think this is the Zoom response to that one: https://blog.zoom.us/wordpress/2020/04/03/response-to-resear...

As I read it they accidentally routed some data to China based servers for a month (Feb 2020) due to a config mess up during their crazy fast scaling period. This is since fixed.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#5
post #4
post #2

So were they really sending data to servers in China? From what little I've heard and read about this, that is what stood out to me. Not sure they should ever be trusted again after that.

I think this is the Zoom response to that one: https://blog.zoom.us/wordpress/2020/04/03/response-to-resear... As I read it they accidentally routed some data to China based servers for a month (Feb 2020) due to a config mess up during their crazy fast scaling period. This is since fixed.

I find this a little to convenient of an explanation and with the founder and CEO being Chinese.

"Accidentally" routing requests to China is something that should have been spotted easily by monitoring and logging. Request latency should have spiked.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#7

uh, is that an outlook-email link with someone's username in? The one linking to Alex.

Probably someone internally emailed Alex's Stanford profile to their blog content writer - the sender had email tracking enabled and the writer blindly copied the link.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#8
post #4
post #2

So were they really sending data to servers in China? From what little I've heard and read about this, that is what stood out to me. Not sure they should ever be trusted again after that.

I think this is the Zoom response to that one: https://blog.zoom.us/wordpress/2020/04/03/response-to-resear... As I read it they accidentally routed some data to China based servers for a month (Feb 2020) due to a config mess up during their crazy fast scaling period. This is since fixed.

They were making requests to IPs in China long before Feb 2020. At the time I assumed they’d been hacked, but in retrospect it seems like this was just how their organisation is distributed.

Needless to say, I have decided not to endorse their videoconferencing solution.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#9

uh, is that an outlook-email link with someone's username in? The one linking to Alex.

Yup. Looks to be their email address. Email is from PR firm Sard Verbinnen & Co.

Safelinks have the email address of the recipient of a link.
Post reply on HN