Live data from Hacker News

Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

vice.com

361–370 of 375 posts

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#361
post #67

Their desktop version is not much better. https://securityboulevard.com/2020/03/using-zoom-here-are-th...

It has been known for a while now to not touch their desktop app with even a ten feet pole. The best bet is using the web app.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#362
post #26

EVERY. SINGLE. APP. THAT. INCLUDES. THE. FACEBOOK. SDK. Even if you don't log in. The Facebook SDK sends data back. Hook your device up to an intercepting proxy and start up a few apps. 99% of them do this. I really wish Apple would put an end to this.

> I really wish Apple would put an end to this. This is what really gives lie to the whole walled garden thing. Its selling point is supposed to be in Apple preventing things like this, but here we are in reality and they don't. Meanwhile they do e.g. prevent Signal from replacing Apple's default app for SMS, which has no purpose other than to create barriers for cross-platform competitors to the default apps.

Well, the issue isn't just that Apple doesn't put an end to it, it's that Apple doesn't let users toggle this sort of thing off. I think most HNers would say the best solution is for Apple to require apps get permission to do this sort of thing, and let the user decide if they want to have data sent back to FB. There needs to be transparency and a chance to opt in or or at the least to opt out.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#363

Earlier quoted context omitted.

> It is their right to run their business as they see fit It absolutely isn't. We want to use services but we do not want to be subjected to surveillance capitalism. Privacy is more important than some business and if it can't operate without being invasive it should fail. If they insist on being hostile and tracking people despite their wishes, people will use the product anyway and they will find a way to break the…

> We want to use services but we do not want to be subjected to surveillance capitalism. Who is the “we” you are referring to? I think most people care so little about this that they don’t even bother to skim the TOS before using a service.

To add to your point (which I fully agree) (and I am surprised of the downvotes - I don't care for the karma but it looks that I didn't write it clear enough and/or people misunderstood my comment 2-3 levels up).

I am not touching the "add value" bit, I will stick to the ethics. Some businesses are (imho) scum (Facebook, Google, Zoom, every tracker, every data aggregator, etc.)

They may uphold the law or they may ignore the law. Since we should not burn their buildings down in retribution, we can sue them (or whatever the local privacy laws state), we can stop giving them money (our free/paid information). But it is up to us. Zoom clearly needs a (sic) phat penalty by EU to get their stuff straight. Then every EU user should bombard both Zoom and FB with questions on their data practices and "right to be forgotten". Then we should burry them in the sand and move to other service providers.

I am adamant on the issue of privacy and the reason for that is that these scum KNOW they are violating our rights, and the voice in their minds tells them "screw them, £€¥$ goes first".

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#364
post #26

EVERY. SINGLE. APP. THAT. INCLUDES. THE. FACEBOOK. SDK. Even if you don't log in. The Facebook SDK sends data back. Hook your device up to an intercepting proxy and start up a few apps. 99% of them do this. I really wish Apple would put an end to this.

Apple is busy deleting localStorage data from PWA users...

For those who did not read about it: https://andregarzia.com/2020/03/private-client-side-only-pwa...

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#365

Earlier quoted context omitted.

> It is their right to run their business as they see fit It absolutely isn't. We want to use services but we do not want to be subjected to surveillance capitalism. Privacy is more important than some business and if it can't operate without being invasive it should fail. If they insist on being hostile and tracking people despite their wishes, people will use the product anyway and they will find a way to break the…

> We want to use services but we do not want to be subjected to surveillance capitalism. Who is the “we” you are referring to? I think most people care so little about this that they don’t even bother to skim the TOS before using a service.

Caring about this shouldn't be necessary. When people sign up for a service, they shouldn't have to stop everything and wonder about the many, many ways their personal information could be abused. Nor should they have to scrutinize the terms of every single service out there just to know exactly how they're being exploited without being able to do anything about it. This constant paranoia about everything is not a good way to live.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#366

Earlier quoted context omitted.

It's past time for us to get serious and apply HIPAA-style protection to the storage and transmission of PII, without exemptions. Companies like Facebook will complain loudly that they won't be able to survive, but that is not our problem. If we pass legislation with teeth, they will need to change their business model. That would be the point.

They're not sending your name and address. They're sending the IDFA, device ID, of your device to Facebook. The fact that Facebook can link that device ID to your identity is on YOU. You logged into Facebook in their app to make that connection.

This is simply false. Facebook creates phantom profiles to track users that don't even have a Facebook account.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#367

Earlier quoted context omitted.

Why do comments suggesting that data collection is paid for by Facebook/google get downvoted? Serious question. This wasn’t my comment but I think it’s true and I’ve said the same previously and was downvoted too. Is it because it’s obvious and well known? Did I miss the memo too? If Facebook is encouraging the capture and transmission of this data and paying for it, does this mean that Facebook has indemnified Zoom?

Those comments are downvoted because there is no evidence that anyone is paying for data from Zoom. IMO, speculation without support should be downvoted.

Companies ultimately respond to monetary incentives. So directly or indirectly, they are giving your data to Facebook because it gets them paid.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#368
post #234

Earlier quoted context omitted.

Terrible take. They use it to apply many security and privacy policies! Just not the one we're talking about now. Difficult to figure out how to actually do this, especially so without a crazy UX. They should figure out the default apps thing. Though I don't know what you'd need for SMS, there's not much system integration there besides Siri (which I think supports plugins) and maybe sms: links?

> They use it to apply many security and privacy policies! Have you read the guidelines? Many words requiring you to use and not discourage users from using Apple's in-app purchasing system (which they get a large cut of), prohibiting you from trying to compete with the App Store or similar, prohibiting app-alternatives they don't control (like remote desktop into a cloud server), requiring "Sign in with Apple" if yo…

The App Store having additional restrictions doesn't have anything to do with the privacy aspect of the walled gardens being a "lie". You can go on a tirade about the app store's limitations if you want, but that's not relevant.

Your proposed solution would not work, obviously, because how do you define what services an app is allowed to connect to? How do you know it's connecting to Facebook's servers? Just hope they always use facebook.com?

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#369
post #368

Earlier quoted context omitted.

> They use it to apply many security and privacy policies! Have you read the guidelines? Many words requiring you to use and not discourage users from using Apple's in-app purchasing system (which they get a large cut of), prohibiting you from trying to compete with the App Store or similar, prohibiting app-alternatives they don't control (like remote desktop into a cloud server), requiring "Sign in with Apple" if yo…

The App Store having additional restrictions doesn't have anything to do with the privacy aspect of the walled gardens being a "lie". You can go on a tirade about the app store's limitations if you want, but that's not relevant. Your proposed solution would not work, obviously, because how do you define what services an app is allowed to connect to? How do you know it's connecting to Facebook's servers? Just hope the…

> that's not relevant.

It's the true motive for the "walled garden" -- it explains why it continues to exist even though the stated reasons why it exists don't pan out in practice.

> Your proposed solution would not work, obviously, because how do you define what services an app is allowed to connect to?

Why is it allowed to connect to any services for no reason? If the app makes a network connection the developer should have to justify it by something other than enabling collection of user data.

> How do you know it's connecting to Facebook's servers? Just hope they always use facebook.com?

I feel confident that Apple has the resources to determine whether the servers every application using the Facebook SDK is contacting belong to Facebook.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#370

Earlier quoted context omitted.

What about a Unique Advertiser Identifier? What about a UAI with a name, phone number, phone model, GPS coordinates, and software version?

Had a briefing with our company lawyer a while back and any information can be considered PII when paired with other information. Eg that you bought 7 foo’s is not PII, but that you bought 7 foo’s on Tuesday might be if that can then be looked up in the purchase history and you were the only one who bought 7 on Tuesday.

Does it have to be uniquely identifying to be PII? Or is there some minimum threshold for k-anonymity?
Post reply on HN