Live data from Hacker News

SpaceX bans Zoom over privacy concerns

reuters.com

151–160 of 301 posts

Re: SpaceX bans Zoom over privacy concerns

#151

Earlier quoted context omitted.

> The fact that it's through the backup servers instead of the iMessage servers makes no difference. It makes a big difference. If I print out the texts I receive, it doesn't change whether the texting program is end-to-end encrypted. The same goes for backups. An unencrypted system-level backup doesn't mean that the program being backed up is failing at security. It's bad that Apple doesn't let you encrypt your back…

What if the texting program has a built in feature to print the texts you receive and mail a copy to the company that wrote the program, and it nags you to enable this feature all the time, and most of your friends have it enabled? Because that's a lot closer to the scenario here. > An unencrypted system-level backup doesn't mean that the program being backed up is failing at security. iOS programs can choose how the…

iMessage itself bugs you to enable backups?

> iOS programs choose how their data is backed up.

Well desktop apps don't. Would you say that no desktop app that saves its key can ever qualify as end-to-end encrypted?

> And besides, iCloud is made by the same company, it's not a separate entity.

I'm not convinced that's relevant to whether the encryption is end-to-end or not.

Re: SpaceX bans Zoom over privacy concerns

#152
post #10
post #3

SpaceX is strategic national defense, so this makes sense. I expect many similar companies to follow suit.

Seems like any organization under ITAR should prefer in-house solutions in areas relating to dissemination of sensitive design notes.

Are you basically asked to rewrite your own Zoom app or are there ITA certified videoconferencing softwares ? (Any names?)

Re: SpaceX bans Zoom over privacy concerns

#153

Earlier quoted context omitted.

In my experience Google's Hangout Meetings have been at least as good or better quality and the interface is far superior in my opinion. For example it works in the browser without any plugins (even in Firefox.)

I haven't used Hangouts on a professional setting in a while. Does it finally support tile view? Another feature I find really valuable is allowing two windows. One for participant view and a separate one for shared screen.

yeah we use it. Not sure if this is still hangouts or something else underneath, but meet.google.com is the url which allows you to quickly create a session and share it. You can present your desktop using a separate tile.

Re: SpaceX bans Zoom over privacy concerns

#154

Earlier quoted context omitted.

What if the texting program has a built in feature to print the texts you receive and mail a copy to the company that wrote the program, and it nags you to enable this feature all the time, and most of your friends have it enabled? Because that's a lot closer to the scenario here. > An unencrypted system-level backup doesn't mean that the program being backed up is failing at security. iOS programs can choose how the…

iMessage itself bugs you to enable backups? > iOS programs choose how their data is backed up. Well desktop apps don't. Would you say that no desktop app that saves its key can ever qualify as end-to-end encrypted? > And besides, iCloud is made by the same company, it's not a separate entity. I'm not convinced that's relevant to whether the encryption is end-to-end or not.

> Would you say that no desktop app that saves its key can ever qualify as end-to-end encrypted?

I would say that no app can qualify as end-to-end encrypted if a large fraction of users send their data to the maker of the app in a form that can be decrypted by the maker of the app, regardless of the reason.

Re: SpaceX bans Zoom over privacy concerns

#155

Earlier quoted context omitted.

This is completely ridiculous. iMessage is encrypted by my device and remains encrypted until it gets to the recipient device. That is what end-to-end encryption means. That I may have given Apple my private key through a different message in no way affects that end-to-end encryption, because it is trivial to decide not to give Apple that key.

iCloud isn't some separate entity from iMessage. It's all Apple. And you have no option to use a different cloud backup provider. You can decide not to give your keys to Apple, but you can't decide for all your friends to not give their keys to Apple, and the result is the same: Apple can read your messages. And the marketing is so misleading that hardly anyone knows that Apple can read most iMessages.

Got any sources for that? Sounds a lot like FUD.

Re: SpaceX bans Zoom over privacy concerns

#156
post #95

That's the right thing to do. If SpaceX is important to national security, then Zoom security and privacy is so bad, that a bad actor could steal SpaceX technology. At my previous job, we used to dial in random zoom numbers and entered into random conversations of other companies. Once we landed into a Facebook call where they were talking about Libra (before it was a thing). If you turn of camera and video, the host…

Doesn’t it chime when someone enters?

It’s optional.

Re: SpaceX bans Zoom over privacy concerns

#157
post #152
post #10

Earlier quoted context omitted.

Seems like any organization under ITAR should prefer in-house solutions in areas relating to dissemination of sensitive design notes.

Are you basically asked to rewrite your own Zoom app or are there ITA certified videoconferencing softwares ? (Any names?)

Its not so much that you need to have your own, its just much more complicated to do it in the cloud. When you have to be able to prove by audit that only US persons are authorized to access the datacenter and that only US persons have accessed the datacenter then you need a provider willing to do that as well as contracts, policies, and procedures. It all needs to be audit-able and evidence based. If you need to do these things in the cloud then you need to do them in-house too. Which means that you already do the basics in-house making it attractive to do things in-house.

Take Confluence for example, if I use the cloud version I can't store any files there or have any information about certain projects. But I can run the same Confluence in-house and then we can share project details. As you point out, its not always that easy.

Re: SpaceX bans Zoom over privacy concerns

#159
post #53
post #26

Earlier quoted context omitted.

It works, but it burns through so much CPU your computer will be a gibbering mess. There's some pretty silly inefficiencies going on, for example; if you switch away to another window, they display a small video player while keeping the big one running the background. Each time you switch into screen sharing mode, they drag you back to the app again. If you draw on the screen, someone has screwed up their linear alge…

I regularly have complaints that people can't hear me over my laptop's fan when using slack video conferencing, or jokes about hair driers. Computer is a MBP16. Seems like they need to get their CPU use under control.

You could also get a headset instead of yelling at your built-in mic. As a 100% remote employee, even before Covid, the coworkers with headsets are much easier to understand, and have less background/foreground noise.

As a headset user myself, no one ever asks me to repeat myself, notices when I type, or hears anything not within an inch of my mouth. Plus, I've got a physical mute switch for instant, unambiguous mute, as-needed.

Re: SpaceX bans Zoom over privacy concerns

#160
post #4

The fact that they show end users (no pun intended) an "end-to-end encrypted" badge on the meeting window itself, and elsewhere explain how a Zoom server (not Zoom client) is what constitutes an "end" despite the whole rest of the electronic communication industry using "end-to-end" to refer exclusively to user agents, is bonkers.

The Zoom CEO and founder is chinese. He was refused a Visa to the US (8 times!).

It's not inspiring, it's scary.

https://www.bloomberg.com/news/articles/2019-04-18/u-s-refus...

Post reply on HN