Live data from Hacker News

Zoom’s 90-day plan to bolster key privacy and security initiatives

blog.zoom.us

41–50 of 113 posts

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#41
post #27

Earlier quoted context omitted.

> Are you suggesting that China isn't responsible for repeated, massive state-sponsored hacks? That they aren't actively committing industrial espionage primarily through said state-sponsored hacking? Nope, not at all. They're guilty of all of it and probably more. > If you're not saying that, then why are you pretending the fact that Zoom is sending keys THROUGH CHINA and developing the product IN CHINA is not a big…

Why do you think it doesn't make a difference? At a minimum, one country shares a mutual defense pact with most of Europe. The other doesn't (to say the least).

After agressive sanctions from US government for EU, the targeted EU travel ban and current presidents rhetoric, I have zero trust in any kind of mutual defense or military assistance coming from US in the time of crisis.

Remember, people of Italy are currently being helped by Chinese doctors while US president ignores and belittles the problem.

The talks between France and Germany about creating an independent defense pact also reflect the complete lack of trust into what NATO has become. So much was lost in so few years.

And that also ignores all the nasty surveillance stuff they've been doing these last few years - where the Five Eyes pact was used to surveil our own citizens by our own government by piping data through US. If there's one thing I'm sure of is that China won't share their spying data with my own government ;P

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#43

Zoom's web SDK and web client were down for nearly four days over the weekend with minimal communication, and when they brought it all back they killed a key functionality the education market needs which is the ability to join a meeting without an account: https://devforum.zoom.us/t/in-progress-web-sdk-web-client-fr...

Why is the need for an account a showstopper?

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#44
post #27

Earlier quoted context omitted.

> Are you suggesting that China isn't responsible for repeated, massive state-sponsored hacks? That they aren't actively committing industrial espionage primarily through said state-sponsored hacking? Nope, not at all. They're guilty of all of it and probably more. > If you're not saying that, then why are you pretending the fact that Zoom is sending keys THROUGH CHINA and developing the product IN CHINA is not a big…

Why do you think it doesn't make a difference? At a minimum, one country shares a mutual defense pact with most of Europe. The other doesn't (to say the least).

Don't feed the troll, this person is a Winnie the Pooh shill.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#45
post #13

They’re in the same bed as China. I don’t trust them for anything now, this to me is just a PR management exercise. They’re still going to give away your data

China, the best bogeyman to discredit anyone you don't like. Is that the 2020s version of a "commie"?

[flagged]

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#46

I showed Alex Stamos information two days ago that Zoom engineers had surreptitiously spied on women around the world and then assembled their webcams into a single dashboard for Zoom engineers to view. The name of this dashboard was p*ssy4all.dashboard-production.ipa.zoom.us. A quick way to prove this is to type this subdomain into securitytrails.com. It lists a dozen different IP addresses this internal product had…

I don't see anything for that domain...

I do, in that link provided in an edit, after getting around google recaptcha (wow securitytrails.com has a shitty website...)

Edit: here's a screenshot: https://twitter.com/danehrlich11/status/1247206209876353025/...

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#47

Zoom's web SDK and web client were down for nearly four days over the weekend with minimal communication, and when they brought it all back they killed a key functionality the education market needs which is the ability to join a meeting without an account: https://devforum.zoom.us/t/in-progress-web-sdk-web-client-fr...

Actually this isn't true anymore, they have since added the _option_ to not require an account when using the web client. The Web SDK still works like before and also doesn't require an account.

But I agree, the way it was handled was harrowing.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#48
post #2

So were they really sending data to servers in China? From what little I've heard and read about this, that is what stood out to me. Not sure they should ever be trusted again after that.

Serious hypothetical question: suppose you're able to capture all Zoom calls. If you're a foreign government, how do you scale the analysis, and what can you generally do with the information?

It'd be hard to get a useful amount of trade secrets or know-how. You'll see partial schematics and design docs, but without much context. At the executive level, you could at least scale the analysis to have actual people monitoring the calls. You could get broad strategy (e.g. launch a mid-range 5G phone in 2021 Q1) and enough financial information to make some well-informed trades.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#49

Zoom's web SDK and web client were down for nearly four days over the weekend with minimal communication, and when they brought it all back they killed a key functionality the education market needs which is the ability to join a meeting without an account: https://devforum.zoom.us/t/in-progress-web-sdk-web-client-fr...

You can still activate this functionality in the settings, it now only deactivated by default due to the public outcry over Zoombombing etc.

Amusing that many of the changes lowered accessibility significantly (e.g. my grandmother wasn't able to join the meeting anymore after passwords became default). I still don't get it. Skype was way worse in my opinion and nobody ever cared about it.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#50
post #28

Earlier quoted context omitted.

Occam’s Razor. Zoom usage went up by 8x in a few months. Usually doubling in two years is great for a public company. So that’s 6 years of great growth, compressed into a few months. It shouldn’t be surprising to see six years of security problems also compressed into those three months. I think Zoom is on track to fix these problems quickly and cement their spot as the best solution for videoconferencing.

Zoom had the same security issues with half the traffic. Acting like usage causes them is disingenuous. Technically speaking, zoom has shown off great and remarkably stable/scalable features. But that is orthogonal to whether they are putting people at risk (e.g. not-so-secret therapy sessions) or lying about their feature set (clearly claiming to have end to end encryption).

Devil's advocate, I guess: 8 times the users, 8 times (at least) the number of people to notice those problems.

Especially when work from home is now at the center of our conversation, and journalistic outlets shift their attention to newly-popular services like Zoom and Houseparty.

Regarding your last example, I'm also continually confused at the claim that Zoom has been lying about end-to-end encryption. I don't see any place where they ever claimed to encrypt anything end-to-end except for chats, and only after enabling the feature:

https://support.zoom.us/hc/en-us/articles/207599823-End-To-E...

https://support.zoom.us/hc/en-us/articles/201362723-Encrypti...

When I'm in a Zoom meeting, it says that my connection is encrypted (the green E lock thing). It does not say "end-to-end." So I always assumed that just meant that the transport layer is encrypted.

Post reply on HN