Live data from Hacker News

Zoom’s 90-day plan to bolster key privacy and security initiatives

blog.zoom.us

101–110 of 113 posts

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#102
post #32

I can only assume CISO is Chief Information Security Officer? I hadn't seen the acronym before. Bad Zoom for not writing it out in full on the first instance.

I only first encountered it a year or two ago. It's pretty difficult to keep up with management/marketing buzzwords.

In any case, anyone at the 'C' level almost by definition knows little or nothing about actual computer security.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#103

and this is why product over security always wins. there's mob mentality right now, but zoom got a TON of customers, and now is gonna have proof of end-to-end encryption in a couple of months. boom. zoom wins. honestly just don't talk on zoom about something highly secretive such as ... idk... something a government is interested in as that isn't currently secure, other than that, don't sweat it.

And don't install the Zoom app on a computer where you store secretive data, such as medical information, private keys, passwords, credit card data or anything that you don't want the government or cyber-criminals to know.

Doesn't sound as easy now.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#104

Zoom's web SDK and web client were down for nearly four days over the weekend with minimal communication, and when they brought it all back they killed a key functionality the education market needs which is the ability to join a meeting without an account: https://devforum.zoom.us/t/in-progress-web-sdk-web-client-fr...

Shouldn’t schools be using SSO with Zoom Education, or does that cost money?

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#105

Zoom's web SDK and web client were down for nearly four days over the weekend with minimal communication, and when they brought it all back they killed a key functionality the education market needs which is the ability to join a meeting without an account: https://devforum.zoom.us/t/in-progress-web-sdk-web-client-fr...

Shouldn’t schools be using SSO with Zoom Education, or does that cost money?

I believe that costs money. But quite cheap actually.

My college (~2200 students + a couple hundred faculty/staff) pays $18k/yr for Zoom Enterprise. Good value, I'd say.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#107
post #50

Earlier quoted context omitted.

Zoom had the same security issues with half the traffic. Acting like usage causes them is disingenuous. Technically speaking, zoom has shown off great and remarkably stable/scalable features. But that is orthogonal to whether they are putting people at risk (e.g. not-so-secret therapy sessions) or lying about their feature set (clearly claiming to have end to end encryption).

Devil's advocate, I guess: 8 times the users, 8 times (at least) the number of people to notice those problems. Especially when work from home is now at the center of our conversation, and journalistic outlets shift their attention to newly-popular services like Zoom and Houseparty. Regarding your last example, I'm also continually confused at the claim that Zoom has been lying about end-to-end encryption. I don't se…

They removed the e2e claim after criticism.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#109
post #98

Earlier quoted context omitted.

Hard drives are pretty cheap, particularly for a government. Store it all now, target your analysis narrowly later at your leisure.

Do you know how much data that would have to be? Scaling that seems improbable.

The NSA has built a data center in Utah specifically for this problem[1], so it's hardly beyond the realm of plausibility.

[1]: https://en.wikipedia.org/wiki/Utah_Data_Center

Post reply on HN