Live data from Hacker News

Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

vice.com

81–90 of 375 posts

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#81
post #63

Earlier quoted context omitted.

I never heard this before. Can you explain how it protects insurance companies?

Insurance companies have incentives to get better data than their competitors, so they can offer less expensive coverage to lower risk people and leave the competing insurance companies with all the higher risk people. Until the competitors do the same thing. Then you're all just offering less expensive coverage to most of your customers and making less money. (That also tends to cause trouble for higher risk patient…

Wikipedia claims:

It was created primarily to modernize the flow of healthcare information, stipulate how Personally Identifiable Information maintained by the healthcare and healthcare insurance industries should be protected from fraud and theft, and address limitations on healthcare insurance coverage.

Is the protected from fraud and theft part somehow incorrect?

https://en.wikipedia.org/wiki/Health_Insurance_Portability_a...

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#82
post #2

> There is nothing in the privacy policy that addresses [that data is being sent to Facebook] > The Zoom app notifies Facebook when the user opens the app, details on the user's device such as the model, the time zone and city they are connecting from, which phone carrier they are using, and a unique advertiser identifier created by the user's device which companies can use to target a user with advertisements So Zoo…

It's past time for us to get serious and apply HIPAA-style protection to the storage and transmission of PII, without exemptions. Companies like Facebook will complain loudly that they won't be able to survive, but that is not our problem. If we pass legislation with teeth, they will need to change their business model. That would be the point.

I disagree with this — more regulation will make it harder to innovate.

For example, I’ve met several founders who wanted to enable tele-medicine years ago but decided against it because “the lawyers cost more than the engineers”, and walking-on-eggshells destroys morale & iteration speed.

I’m not arguing to de-regulate heath data — my point is that we should selectively apply regulation.

It’s likely a great thing to regulate self-driving cars. But please keep the lawyers away from my niche online forums, 3rd-party clients for social apps, blogs, video games, calculators etc...

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#83
post #26

EVERY. SINGLE. APP. THAT. INCLUDES. THE. FACEBOOK. SDK. Even if you don't log in. The Facebook SDK sends data back. Hook your device up to an intercepting proxy and start up a few apps. 99% of them do this. I really wish Apple would put an end to this.

This is equivalent to including Google Analytics or any 3P analytics platform.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#84
post #13

Reminder: The NextDNS iOS app allows you to monitor and block these types of requests from all of your apps, via their DNS logging/filtering. (You can also configure the retention on the DNS logging, so as to not cause more toxic waste data.) I can't recommend it enough. Until/unless we get something like Little Snitch for the phone (are you listening, Apple?!), this is the next best thing.

On the NextDNS website:

> "Try it now for free. No sign up required."

> I click the button

> "Sign In. Don't have an account? Sign up."

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#85
post #13

Reminder: The NextDNS iOS app allows you to monitor and block these types of requests from all of your apps, via their DNS logging/filtering. (You can also configure the retention on the DNS logging, so as to not cause more toxic waste data.) I can't recommend it enough. Until/unless we get something like Little Snitch for the phone (are you listening, Apple?!), this is the next best thing.

How does its blocking compare to Blockada?

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#86
post #82

Earlier quoted context omitted.

It's past time for us to get serious and apply HIPAA-style protection to the storage and transmission of PII, without exemptions. Companies like Facebook will complain loudly that they won't be able to survive, but that is not our problem. If we pass legislation with teeth, they will need to change their business model. That would be the point.

I disagree with this — more regulation will make it harder to innovate. For example, I’ve met several founders who wanted to enable tele-medicine years ago but decided against it because “the lawyers cost more than the engineers”, and walking-on-eggshells destroys morale & iteration speed. I’m not arguing to de-regulate heath data — my point is that we should selectively apply regulation. It’s likely a great thing to…

If a company can't 'innovate' without sharing users' data with third parties or treating it recklessly through lax security (or uploading database dumps to publicly-accessible S3 buckets) then that company doesn't deserve to be in business.

It doesn't take a suite of lawyers to enforce that, either. Health care is gigantic mess of bullshit in the US especially, because of the multiple different 'stakeholders' - customers, insurance companies, brokers, "networks", hospitals, doctors, etc., and every mistake is a gigantic lawsuit waiting to happen. It's a disaster however you cut it.

As for personal data for some arbitrary startup, any argument that "innovation" depends on being able to be careless or cavalier with that data is just ridiculous. Be careful with it. Store it properly. Only collect what you need, and delete the rest. Expunge data you no longer need. Never send it to any third party without asking the user, and provide clear information about where and with whom the data is processed and stored at rest.

There, now you're being careful with user data and you can still "innovate" decent products, as long as your business model isn't user-hostile from the start.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#87

Earlier quoted context omitted.

It's past time for us to get serious and apply HIPAA-style protection to the storage and transmission of PII, without exemptions. Companies like Facebook will complain loudly that they won't be able to survive, but that is not our problem. If we pass legislation with teeth, they will need to change their business model. That would be the point.

Zoom has allegedly HIPAA-compliant BAAs with users in the health space. If any PHI data is making it over to Facebook without a similar agreement from Facebook, Zoom is in for some trouble.

IP address, telephone number, city and other identifying information is ALL considered PII.

I work with (adjacent industry) HIPAA protected data, which is considered PII by virtue of knowing Bob Smith is in the system. If they're under a BAA and sending that information to Facebook they're in violation.

If one of my sub-processors did this my lawyer would be livid. But hey, it's Silicon Valley, don't harsh their buzz man.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#88

Earlier quoted context omitted.

Similar to how we have organizations which can certify whether produce is organic or not, we need organizations which can certify whether apps and websites are certified ad tracking free.

This is an interesting point. Either the government would then need businesses to disclose their "rating" (similar to movies) or businesses could opt in to show a seal (like Fairtrade bananas). The problem is, if there aren't enough (popular) sites with the seal, then the value of this declaration is lost.

Yeah. For many people I interact with Facebook, and to a lesser extent Google, are the internet. So they’d never see the seal unless Google put the sites in their top three results and didn’t scrape the relevant info.

Or someone posted a meme with the seal in it on Facebook.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#89
post #84
post #13

Reminder: The NextDNS iOS app allows you to monitor and block these types of requests from all of your apps, via their DNS logging/filtering. (You can also configure the retention on the DNS logging, so as to not cause more toxic waste data.) I can't recommend it enough. Until/unless we get something like Little Snitch for the phone (are you listening, Apple?!), this is the next best thing.

On the NextDNS website: > "Try it now for free. No sign up required. " > I click the button > "Sign In. Don't have an account? Sign up."

That's odd, I just tried it and that didn't happen for me at all.

Re: Zoom iOS app sends data to Facebook even if you don’t have a Facebook account

#90
post #2

> There is nothing in the privacy policy that addresses [that data is being sent to Facebook] > The Zoom app notifies Facebook when the user opens the app, details on the user's device such as the model, the time zone and city they are connecting from, which phone carrier they are using, and a unique advertiser identifier created by the user's device which companies can use to target a user with advertisements So Zoo…

You think Zoom is doing it for fun? This is a revenue source right?

Why do comments suggesting that data collection is paid for by Facebook/google get downvoted?

Serious question. This wasn’t my comment but I think it’s true and I’ve said the same previously and was downvoted too. Is it because it’s obvious and well known? Did I miss the memo too?

If Facebook is encouraging the capture and transmission of this data and paying for it, does this mean that Facebook has indemnified Zoom?

Post reply on HN