Live data from Hacker News

Zoom’s 90-day plan to bolster key privacy and security initiatives

blog.zoom.us

31–40 of 113 posts

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#31
post #30

Earlier quoted context omitted.

There's many reasons not to trust the CPC. (ip theft, surveillance, etc.) There's also many humanitarian concerns as well: https://www.cnn.com/2018/10/10/asia/xinjiang-china-reeducati... https://nypost.com/2019/06/01/chinese-dissidents-are-being-e... https://www.npr.org/sections/health-shots/2019/09/04/7570898...

> There's many reasons not to trust the CPC. (ip theft, surveillance, etc.) That's pretty much the summary of US attacks on our EU government as well (remember the backdoor direct attack on Belgacom?), soo... why does it make a difference? If anything, routing things through China denies our data to NSA and makes it less concentrated and useful. Similarly how spreading data over multiple cloud providers gives less po…

You ignored the humanitarian issues.

Also, please give me examples of a US or European country stealing IP, because that's the main threat w/ Zoom (spying on businesses & stealing tech)

Yes, most countries spy, China goes much much further and has no accountability because it's an authoritarian regime, not a democracy.

You can talk shit about Trump all you want, but try to call Xi Jinping a cartoon bear.

Ask Hong Kong, they'd love to have the freedoms that they once had as UK citizens.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#33
post #27
post #15

Earlier quoted context omitted.

Are you suggesting that China isn't responsible for repeated, massive state-sponsored hacks? That they aren't actively committing industrial espionage primarily through said state-sponsored hacking? If you're not saying that, then why are you pretending the fact that Zoom is sending keys THROUGH CHINA and developing the product IN CHINA is not a big deal?

> Are you suggesting that China isn't responsible for repeated, massive state-sponsored hacks? That they aren't actively committing industrial espionage primarily through said state-sponsored hacking? Nope, not at all. They're guilty of all of it and probably more. > If you're not saying that, then why are you pretending the fact that Zoom is sending keys THROUGH CHINA and developing the product IN CHINA is not a big…

Why do you think it doesn't make a difference? At a minimum, one country shares a mutual defense pact with most of Europe. The other doesn't (to say the least).

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#34
post #24

I showed Alex Stamos information two days ago that Zoom engineers had surreptitiously spied on women around the world and then assembled their webcams into a single dashboard for Zoom engineers to view. The name of this dashboard was p*ssy4all.dashboard-production.ipa.zoom.us. A quick way to prove this is to type this subdomain into securitytrails.com. It lists a dozen different IP addresses this internal product had…

Can you link? I couldn't find that on securitytrails

https://securitytrails.com/domain/pussy4all.dashboard-produc...

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#35
post #32

I can only assume CISO is Chief Information Security Officer? I hadn't seen the acronym before. Bad Zoom for not writing it out in full on the first instance.

"CISO" is a pretty standard acronym. People who don't work in cybersecurity or who don't have that background might not recognize it, but it seems like a minor detail.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#36
post #27
post #15

Earlier quoted context omitted.

Are you suggesting that China isn't responsible for repeated, massive state-sponsored hacks? That they aren't actively committing industrial espionage primarily through said state-sponsored hacking? If you're not saying that, then why are you pretending the fact that Zoom is sending keys THROUGH CHINA and developing the product IN CHINA is not a big deal?

> Are you suggesting that China isn't responsible for repeated, massive state-sponsored hacks? That they aren't actively committing industrial espionage primarily through said state-sponsored hacking? Nope, not at all. They're guilty of all of it and probably more. > If you're not saying that, then why are you pretending the fact that Zoom is sending keys THROUGH CHINA and developing the product IN CHINA is not a big…

can't reply to remarkEon directly, so here it goes.

America bugged the phone of our chancellor (germany). Trust is at an all time low. nuf said.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#37

"90 day plans" tend to be management & PR things... Real engineering is more of a "it takes as long as the job takes"...

Can you blame them? Most users and purchasers (at a lot of companies the people making purchase decisions aren't actually the users) don't really understand or care about how long real engineering takes. As long as they made a decision to pick a vendor based based on the principles of Cover Your Ass it's all that matters.

It's another primary reason why so many "enterprise" companies purchase Redhat over running CentOS.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#38
Zoom's web SDK and web client were down for nearly four days over the weekend with minimal communication, and when they brought it all back they killed a key functionality the education market needs which is the ability to join a meeting without an account: https://devforum.zoom.us/t/in-progress-web-sdk-web-client-fr...

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#39
post #28
post #26

I'm still not sure what to think of the whole debacle. Zoom could be a victim of the internet mob justice, where every inevitable misstep is blown out of proportion. Perhaps the mob is helped along by some competing interests. Or Zoom could be yet another tech company with dubious ethics (like U: or F). I doubt they are outright a PLA branch, that would be far too obvious. This isn't just idle musings - I love how Zo…

Occam’s Razor. Zoom usage went up by 8x in a few months. Usually doubling in two years is great for a public company. So that’s 6 years of great growth, compressed into a few months. It shouldn’t be surprising to see six years of security problems also compressed into those three months. I think Zoom is on track to fix these problems quickly and cement their spot as the best solution for videoconferencing.

Zoom had the same security issues with half the traffic. Acting like usage causes them is disingenuous.

Technically speaking, zoom has shown off great and remarkably stable/scalable features.

But that is orthogonal to whether they are putting people at risk (e.g. not-so-secret therapy sessions) or lying about their feature set (clearly claiming to have end to end encryption).

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#40
post #27

Earlier quoted context omitted.

> Are you suggesting that China isn't responsible for repeated, massive state-sponsored hacks? That they aren't actively committing industrial espionage primarily through said state-sponsored hacking? Nope, not at all. They're guilty of all of it and probably more. > If you're not saying that, then why are you pretending the fact that Zoom is sending keys THROUGH CHINA and developing the product IN CHINA is not a big…

Why do you think it doesn't make a difference? At a minimum, one country shares a mutual defense pact with most of Europe. The other doesn't (to say the least).

The mutual defense pact our president has repeatedly tried to weaken and or remove the US from? Yeah, that's going swimmingly.
Post reply on HN