Live data from Hacker News

Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

vice.com

321–330 of 375 posts

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#321
post #2

> There is nothing in the privacy policy that addresses [that data is being sent to Facebook] > The Zoom app notifies Facebook when the user opens the app, details on the user's device such as the model, the time zone and city they are connecting from, which phone carrier they are using, and a unique advertiser identifier created by the user's device which companies can use to target a user with advertisements So Zoo…

My opinion about this is that many apps and websites don't have a real product offering. FB, Dropbox, Twitter and others are more of a service offering than a product offering and hence everything is rooted around services and tracking services and, finally, just plain old tracking.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#322
post #320

Earlier quoted context omitted.

It is Zoom’s responsibility to list Facebook here: https://zoom.us/subprocessors Not sure why Vice called out the omission from the privacy policy – I’ve never seen one that actually lists all companies out by name. The GDPR mandates a list of subprocessors, though!

Listing this on their webpage doesn’t solve the spying problem. “Well, at least they told us about it” is absolutely no solution to “so many of our tools are spying on us”.

It is their right to run their business as they see fit, and it is our right to not use them. It is the deception we do not allow (any more) with GDPR.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#323
post #2

> There is nothing in the privacy policy that addresses [that data is being sent to Facebook] > The Zoom app notifies Facebook when the user opens the app, details on the user's device such as the model, the time zone and city they are connecting from, which phone carrier they are using, and a unique advertiser identifier created by the user's device which companies can use to target a user with advertisements So Zoo…

My opinion about this is that many apps and websites don't have a real product offering. FB, Dropbox, Twitter and others are more of a service offering than a product offering and hence everything is rooted around services and tracking services and, finally, just plain old tracking.

I don't see how is selling a service different then selling a product ? If clients want it => pay for it.

The real point that privacy advocates REFUSE to talk about is that FREE service wins over 99% market share over PAID service. So people does not want to pay for Facebook (greed) and Facebook does not want to make people pay (market share first in Silicon Valley mindset).

Well money for its thousand engineers has to be found ¯\_(ツ)_/¯

Now that the actors have collectively chosen the combo free services in exchange for private data, a small minority wants free service in exchange of nothing. How does it work, Freemium, government subsidies ?

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#324
post #320

Earlier quoted context omitted.

Listing this on their webpage doesn’t solve the spying problem. “Well, at least they told us about it” is absolutely no solution to “so many of our tools are spying on us”.

It is their right to run their business as they see fit, and it is our right to not use them. It is the deception we do not allow (any more) with GDPR.

Most present societies and thus governments do not believe that people should get to run their businesses however they see fit.

There are a thousand different ways in which companies are not presently allowed to be operated, even if the owner sees fit to do so: worker safety, discrimination, collusion, et c.

I’m not saying these things are good or bad, or that there should be more or less of them. I’m saying that Zoom’s (and Facebook’s) spying is a problem, remains a problem, and is not solved by them putting some text on their webpage.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#325
post #99
post #86

Earlier quoted context omitted.

If a company can't 'innovate' without sharing users' data with third parties or treating it recklessly through lax security (or uploading database dumps to publicly-accessible S3 buckets) then that company doesn't deserve to be in business. It doesn't take a suite of lawyers to enforce that, either. Health care is gigantic mess of bullshit in the US especially, because of the multiple different 'stakeholders' - custo…

I think you've missed your parents point. The problem they point out is that well intentioned businesspeople who want to provide you a useful service and store your data correctly are priced out. If you want to deal with medical data of any kind, you need a lawyer. Full stop. It doesn't matter how good your intentions are, or how many "best practice" blog posts you follow. You need to hire a lawyer, and lawyers are i…

>The problem they point out is that well intentioned businesspeople who want to provide you a useful service and store your data correctly are priced out.

I think pricing out the odd well-intentioned business person is a good tradeoff for avoiding the "move-fast and break things" snake-oil salesmen.

>Said another way: regulation always adds cost and barriers to entry.

And saves money and harm when things go bad.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#326
post #82

Earlier quoted context omitted.

It's past time for us to get serious and apply HIPAA-style protection to the storage and transmission of PII, without exemptions. Companies like Facebook will complain loudly that they won't be able to survive, but that is not our problem. If we pass legislation with teeth, they will need to change their business model. That would be the point.

I disagree with this — more regulation will make it harder to innovate. For example, I’ve met several founders who wanted to enable tele-medicine years ago but decided against it because “the lawyers cost more than the engineers”, and walking-on-eggshells destroys morale & iteration speed. I’m not arguing to de-regulate heath data — my point is that we should selectively apply regulation. It’s likely a great thing to…

>more regulation will make it harder to innovate.

I'm seeing prominent VCs espousing this all over social media the past few weeks. Apparently there are even some advising Jared Kushner.

Don't let a good crisis go to waste.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#327

Earlier quoted context omitted.

If they are it's against Apple's rules. Not sure what they are using to fingerprint anyways, given Apple has blocked access to the older system values that were being used.

> Not sure what they are using to fingerprint anyways >> The Zoom app notifies Facebook when the user opens the app, details on the user's device such as the model, the time zone and city they are connecting from, which phone carrier they are using, __and a unique advertiser identifier__ created by the user's device which companies can use to target a user with advertisements

There are two identifiers: Identifier for Advertisers (IDFA) and Identifier for Vendors (IDFV).

IDFA is the same across all apps on a device. However, it can be reset by the user or disabled (in which case it returns all 0s). Also, apps have to disclose (to Apple) that they use the IDFA - not sure if that's visible to the user in the App Store anywhere.

IDFV is unique per vendor - that is, each app has a different ID, but two apps from the same developer will have the same ID. I believe this is also reset when resetting the device.

The FBSDK doesn't require developers to enable the IDFA, so the unique identifier in the phone home request is either the IDFV (effectively unique) or just a UUID that the FBSDK generates and stores on launch.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#328

Earlier quoted context omitted.

I worded that poorly. How about this: If you don't own, manage, solicit or control any servers having access to PHI or PII you don't have any risk of being liable. Put all of that on the client, do your best to protect it but ultimately make it the clients responsibility. I still haven't seen any lawsuits or regulation targeting software in that sense, apart from DRM.

There is no distinction between client vs server when it comes to the law. The same organization created and operates both and is liable as a data processor in both situations. This is again the difference between engineer vs policymaker.

Do you have a source to back that up?

As far as I understand it, Microsoft has no responsibility for PIIs e-mails going through the Outlook e-mail client. Maybe the US is different, but at least in Europe, the GDPR is clear that software vendors have no responsibility in data being processed locally when it's deployed and run by others.

Oracle has no liability for the data stored in their database.

If you have no way of touching the data, your servers (self-managed or otherwise) aren't touching data in any form, you have no legal liabilities wrt data (apart from agreements of course).

Or am I missing something?

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#329
post #320

Earlier quoted context omitted.

Listing this on their webpage doesn’t solve the spying problem. “Well, at least they told us about it” is absolutely no solution to “so many of our tools are spying on us”.

It is their right to run their business as they see fit, and it is our right to not use them. It is the deception we do not allow (any more) with GDPR.

> It is their right to run their business as they see fit

It absolutely isn't. We want to use services but we do not want to be subjected to surveillance capitalism. Privacy is more important than some business and if it can't operate without being invasive it should fail. If they insist on being hostile and tracking people despite their wishes, people will use the product anyway and they will find a way to break the tracking. They will delete the surveillance code, use network filters, send fake data, whatever it takes to stop the surveillance.

> It is the deception we do not allow (any more) with GDPR.

That law also says users have the right to object to what the service is doing with their data and that they must stop doing it if the objection is valid. Almost all data collection taking place today is objectionable, especially those related to marketing and advertisements.

Collecting data on people is not a god-given right. It is a privilege and it can be revoked. People trusted companies with that power because they thought companies would act in their best interests but they were exploited instead. Now it's time to take it away.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#330

Earlier quoted context omitted.

One thing i'll note here as to a potential reason why they do this I just recently attempted to set up Facebook adverts for an app I developed. When it came time for me to set the metric up I obviously chose "App Installs" as my metric to track. To do this, Facebook told me I needed to install the Facebook SDK in my app to attribute an adverts conversion. I didn't end up running the ad, but I can see why companies po…

It is Zoom’s responsibility to list Facebook here: https://zoom.us/subprocessors Not sure why Vice called out the omission from the privacy policy – I’ve never seen one that actually lists all companies out by name. The GDPR mandates a list of subprocessors, though!

GitHub’s privacy policy is exceptional. Particularly the section on sub-processors[1] where they list out every company, don’t have any sort of CYA language that covers others that might not be listed, and make a commitment to update that page every time the sub-processors or the sub-processor’s function changes.

[1] https://help.github.com/en/github/site-policy/github-subproc...

Post reply on HN