Live data from Hacker News

Zoom still don't understand GDPR

threatspike.com

201–210 of 267 posts

Re: Zoom still don't understand GDPR

#201

“Zoom cookies are firstly written when the user connects to the website zoom.us and accepts the cookies options.” That was the moment Zoom received your consent to store data transmitted by cookies. Adding a few more cookies to the pile, regardless of expiration date, doesn’t change the agreement. Rummaging round the cookie bin on uninstall is a nice find and deserves a raised eyebrow but this doesn’t really have any…

> According to the ePrivacy Directive, they should not last longer than 12 months. ( Quick search about cookies)

The ePD text says nothing about a 12 month cookie expiration and also ePD != GDPR

Re: Zoom still don't understand GDPR

#202

It's unfortunate that they bought and destroyed Keybase [1] in a bid to improve their security and even still there seems to be no improvement. Guess even the best folks can't make an impact if company culture prevents it. [1] https://github.com/keybase/client/graphs/commit-activity

> https://github.com/keybase/client/graphs/commit-activity Thats an awesome graph. Pretty hard to hide or fake activity on an opensource project. Also it shows how quickly engineering was pulled off projects... Usually it would be a matter of "finish the PR/feature/bug you're on", which might be days or weeks. Yet here everyone is pulled off over ~3 days.

The activity declined over the course of almost 2 months.

Re: Zoom still don't understand GDPR

#204

“Zoom cookies are firstly written when the user connects to the website zoom.us and accepts the cookies options.” That was the moment Zoom received your consent to store data transmitted by cookies. Adding a few more cookies to the pile, regardless of expiration date, doesn’t change the agreement. Rummaging round the cookie bin on uninstall is a nice find and deserves a raised eyebrow but this doesn’t really have any…

> According to the ePrivacy Directive, they should not last longer than 12 months. ( Quick search about cookies)

You'll note they don't reference or explain that.

The ePrivacy Directive is a directive to member states to create legislation or regulation. It doesn't have the force of law and it certainly isn't the GDPR.

The OP is right - there is nothing here that indicates that Zoom misunderstands the GDPR. Indeed the author of the post seems to misunderstand it, or include it as an attempt to grab attention.

Re: Zoom still don't understand GDPR

#205

Earlier quoted context omitted.

The moment that a string of text appears on your screen, it is passed through between many different functions (and even pieces of hardware, with textures being stored on the GPU VRAM) and has unencrypted copies laying all around in memory as the application is running. Any part of the space in which these copies exist being compromised will mean that your encryption is useless in the end.

You have to draw the line somewhere. Otherwise we'd be saying that HTTPS/TLS is not secure since the webpage is rendered to your monitor unencrypted. I agree with the parent quote: > I’ve found statements like these to not contribute very much towards solving any practical security problems.

But HTTP/TLS indeed is not secure from the point of your local machine. Its entire point is protection of data in transit.

Re: Zoom still don't understand GDPR

#206
post #95

Earlier quoted context omitted.

I thought they removed the in-browser link? Does your extension still work?

The in-browser link is hidden till you click the button to launch the zoom client app. Then, the link appears.

> The in-browser link is hidden till you click the button to launch the zoom client app. Then, the link appears.

As someone who doesn't use Zoom, this gobsmacked me.

Re: Zoom still don't understand GDPR

#207

I love how when you go to enter a Zoom meeting, they bury the no-install, run-in-browser link in small type in a footer. And then, if you manage to see the link and use the browser, they withhold "Gallery View", forcing you to deal with the extremely annoying "Active Speaker View".

It makes sense for them as a business to convert visitors to users to customers - nothing wrong with that for me.

Sadly, we live in a world where our expecations are a bit screwed. We're used to so many things being free, ranging from music streaming to programming libraries to nearly every service. We've become acustom to the world where so many things are free to use that people get annoyed when products make the free things not as enjoyable as the paid service. Or sometimes even when someone provides a paid service.

Re: Zoom still don't understand GDPR

#208
post #167

I love how when you go to enter a Zoom meeting, they bury the no-install, run-in-browser link in small type in a footer. And then, if you manage to see the link and use the browser, they withhold "Gallery View", forcing you to deal with the extremely annoying "Active Speaker View".

every teleconferencing app does this. Teams will not show you a browser link until you download the web client. webex will actively download a .exe (on my mac?) before showing the browser link. When I see stuff like this, I think "market opportunity" but the status quo must be pretty profitable.

webex (1).exe

webex (2).exe

webex (3).exe

...

After a Windows update webex kept crashing and bringing my laptop down with it, so I started using the web app. My Downloads folder ended up with quite a few webex downloads. Now I have a script to clean them out each night.

Re: Zoom still don't understand GDPR

#209

Why people still uses zoom? Something like Google Meet or Microsoft Teams are better.

Because it's frictionless. It's very easy to set up a Zoom meeting with anyone in the world. When I tried MS Teams, my impression was that it required a fair amount of advance configuration. This is no problem if you're meeting the same people repeatedly and they work for the same employer as you. Indeed, as the name of the software suggests, it's good for "teams". But for me, anyway, this hasn't been my typical use…

It's the dropbox argument all over again. "I don't understand why people just won't use !"

I've never used Teams, but my girlfriend was trying to walk her mum through getting it setup for work. It was a very long phone call. When I tried Zoom with my parents it took a grand total of about 2 minutes from the moment they get the link to being in the call, most of the time spent figuring out audio.

Also, fuck Microsoft. From the complete destruction of Skype, the crappy Skype-rebranded Lync, to the shitshow that is their "Microsoft Store" and the whole xbox gaming ecosystem, if I ever have a choice between a Microsoft and non-Microsoft application that does the same thing, I'm never going with the Microsoft one.

Re: Zoom still don't understand GDPR

#210

Earlier quoted context omitted.

Chicken-and-egg etc. People will know what Jitsi is when you use it with them. It's so simple, why not have them use it? Why do they have to know it already?

When Teams breaks, it's Teams's fault. When Jitsi breaks, it's your fault.

Been using jit.si for months with extended family (up to ~7 connections), not broken yet.
Post reply on HN