Live data from Hacker News

Zoom still don't understand GDPR

threatspike.com

111–120 of 267 posts

Re: Zoom still don't understand GDPR

#111

Earlier quoted context omitted.

> I love how when you go to enter a Zoom meeting, they bury the no-install, run-in-browser link in small type in a footer. I wasn't even aware that was possible until now.

In my experience, that link only appears after you actively deny the opening of an external application (xdg-open alerts pop up), after 3 tries it will _finally_ appear. Quite infuriating.

True. But there is an option to show it by default. Though it is not easy to find. And only the manager of the host account can do it.

https://support.zoom.us/hc/en-us/articles/115005666383-Show-...

Re: Zoom still don't understand GDPR

#112
post #97

Earlier quoted context omitted.

I imagine GDPR doesn't apply to Zoom, as a non-EU company. Much like China bans what it doesn't want, the onus is on the EU to set up a GFW of their own and ban Zoom (and other GDPR-non-compliant foreign websites) if they disagree with it. Otherwise, Zoom only needs to obey the laws of USA and wherever else they have offices. Disclaimer: IANAL Also: I'm not arguing for Zoom's sketchy practices but just saying that GD…

I'm pretty sure GDPR applies to any companies with dealings in the EU, or at least to that company's dealings which occur within the EU. Disclaimer: IAANAL

You could say that about China as well. China's laws say that you need to censor your search results of certain things. Google and Facebook don't censor. They get banned by the GFW. Plain and simple.

The EU can do the same thing and set up their own firewall if they wish to enforce GDPR on foreign websites.

The fact that their citizens would revolt over the idea of internet censorship, is irrelevant. The point I'm trying to make is that EU saying "you can't serve X to our citizens" and China saying "you can't serve Y to our citizens" is no different and it's upto them to enforce it within their borders if they wish. The EU doesn't get to play world police any more than China's government does.

FWIW baidu.com and tencent.com are both pretty damn GDPR incompliant and the EU isn't doing anything about it. And yes there are Chinese-speaking EU nationals that use these companies' services.

Re: Zoom still don't understand GDPR

#113
post #95

Earlier quoted context omitted.

> they bury the no-install, run-in-browser link I wrote a browser extension that will transparently redirect all zoom links to user their web client: https://github.com/arkadiyt/zoom-redirector

I thought they removed the in-browser link? Does your extension still work?

According to a different comment it is hidden by default.

Re: Zoom still don't understand GDPR

#114

Earlier quoted context omitted.

> I love how when you go to enter a Zoom meeting, they bury the no-install, run-in-browser link in small type in a footer. I wasn't even aware that was possible until now.

In my experience, that link only appears after you actively deny the opening of an external application (xdg-open alerts pop up), after 3 tries it will _finally_ appear. Quite infuriating.

Have you tried disabling Javascript? The "Join from your browser" URL follows a predictable format, only a slight variation from the meeting link. If you have a meeting link that someone sent you, you can create the web client URL yourself.

Re: Zoom still don't understand GDPR

#115
post #48

I love how when you go to enter a Zoom meeting, they bury the no-install, run-in-browser link in small type in a footer. And then, if you manage to see the link and use the browser, they withhold "Gallery View", forcing you to deal with the extremely annoying "Active Speaker View".

> And then, if you manage to see the link and use the browser, they withhold "Gallery View", forcing you to deal with the extremely annoying "Active Speaker View". Is this a browser limitation or something? I think microsoft teams has the same issue.

[deleted]

Re: Zoom still don't understand GDPR

#116
post #97

I argue Zoom does understand GDPR and the ePrivacy Directive from a legal perspective. The specific citation about the length of a cookie is a recommendation and not a law[0]. The key word is 'should'. I'm not a lawyer nor claim the ability to interpret GDPR legally, but I have seen companies that actively worked to edge case GDPR to their advantage (I was part of one). We would have lawyers and other 'GDPR experts'…

I imagine GDPR doesn't apply to Zoom, as a non-EU company. Much like China bans what it doesn't want, the onus is on the EU to set up a GFW of their own and ban Zoom (and other GDPR-non-compliant foreign websites) if they disagree with it. Otherwise, Zoom only needs to obey the laws of USA and wherever else they have offices. Disclaimer: IANAL Also: I'm not arguing for Zoom's sketchy practices but just saying that GD…

Any company that has an operating entity in an EU country must comply or risk being fined by regulators.

If the target is big enough, EU regulators will ask for help from other countries.

Zoom operates offices in a few EU countries[0] so they'll definitely have some sort of entity(ies) setup - regulation pressure can be applied.

[0] https://zoom.us/contact

Re: Zoom still don't understand GDPR

#117
I'm sure Zoom would be doing privacy-iffy things even if in full compliance with the GDPRAnd the possibility they might be surveying other cookies, and uploading them elsewhere, would be a giant concern if verified.

But the specific complaint here, about a cookie with an expiration longer-than-12-months, seems pretty silly.

It's not stored on some remote machine - it's stored locally, transparently. The user – and their own software – can control this easily & completely. If there's a good rationale for expiring cookies earlier, a browser can easily do it directly - it needn't involve regulators, or ineffectually hoping every one of thousands of different companies/websites do something the laws of one place ask.

Re: Zoom still don't understand GDPR

#118

*doesn't

It caught me off guard too. The company is UK-based so it's probably a British colloquialism.

As far as I can find online, it's american street language; I only know it from US shows and Eminem (and other rap) songs. Maybe here it's used to indicate that "zoom be stupid".

Re: Zoom still don't understand GDPR

#119
post #97

Earlier quoted context omitted.

I imagine GDPR doesn't apply to Zoom, as a non-EU company. Much like China bans what it doesn't want, the onus is on the EU to set up a GFW of their own and ban Zoom (and other GDPR-non-compliant foreign websites) if they disagree with it. Otherwise, Zoom only needs to obey the laws of USA and wherever else they have offices. Disclaimer: IANAL Also: I'm not arguing for Zoom's sketchy practices but just saying that GD…

Any company that has an operating entity in an EU country must comply or risk being fined by regulators. If the target is big enough, EU regulators will ask for help from other countries. Zoom operates offices in a few EU countries[0] so they'll definitely have some sort of entity(ies) setup - regulation pressure can be applied. [0] https://zoom.us/contact

You're right, I checked and Zoom does have offices in Paris and Amsterdam.

I suppose then they have the choice of doing Google's playbook in China and just close their EU offices if they wanted, instead of complying. I mean, China wanting censorship and EU wanting GDPR aren't any different. Without arguing for or against either, China's censorship and GDPR are both local laws and foreign-based companies with no local offices don't need to comply. Foreign companies may be blocked, that's all.

Not that I'm advocating for Zoom violating privacy, but I'm not in support of EU unilaterally setting rules for the world or their right to police EU laws outside their borders. They should set up a GFW if they don't like certain things being sent into their country borders over the web, but they can't tell me what to do if I haven't set foot in their jurisdiction. (Neither can Iran, Russia, or North Korea, so why does EU get a pass to police you? If Kim Jong Un sent you a fine for $1 million would you pay it?)

Re: Zoom still don't understand GDPR

#120

Earlier quoted context omitted.

It caught me off guard too. The company is UK-based so it's probably a British colloquialism.

As far as I can find online, it's american street language; I only know it from US shows and Eminem (and other rap) songs. Maybe here it's used to indicate that "zoom be stupid".

Perhaps. I'm American but live in the UK, and I have observed how people in the UK use "don't" as opposed to "doesn't" when the thing being referred to is an organisation, I suppose with the idea of it being an organisation comprised of many people (i.e. "they don't") as opposed to an inanimate non-human entity ("it doesn't").

Still incorrect to my understanding of how English works.

Post reply on HN