Live data from Hacker News

Zoom sued for overstating, not disclosing privacy, security flaws

uk.reuters.com

81–90 of 166 posts

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#81
post #76
post #11

Earlier quoted context omitted.

Interesting that shareholders are the one to fill a lawsuit.

They aren't. The lawsuit is really being filed by lawyers hoping to get a windfall. They don't even need to have much of a case, at worst Zoom will pay their fees and more for the nuisance to go away. However, they do need to pretend for the court that this more than just a lawyer led money grab and that they actually represent the interest of a plaintiff. Enters Michael Drieu. If you read the complaint [1] you'll se…

> Enters Michael Drieu. If you read the complaint [1] you'll see Michael Drieu claim damages of ... $300. He's basically enabling a shakedown out of either malice or stupidity but not greed.

Those are pretty strong statements for an 11 minute old account.

Dang, you can go ahead and scold me for insinuations of shilling. I just can't help myself.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#82
post #66
post #57

Earlier quoted context omitted.

Why is having engineers in China cause for suspicion? Lots of tech companies have engineers in China. Eg Microsoft.

But if Microsoft has teams in China, Russia work on MS Teams, I will be very concerned. The same goes with Slack, that many companies now rely on to keep business going.

I'm very sure that Microsoft (and plenty of other companies including Apple) has teams in China, Russia and other countries to develop and update proper localizations for those apps.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#83
post #57

Earlier quoted context omitted.

Why is having engineers in China cause for suspicion? Lots of tech companies have engineers in China. Eg Microsoft.

Because the CCP has no qualms about threatening an employee’s family to insert a backdoor or exfiltrate information, for one. The decoupling has begun. Sentiment in the US toward China has never been as negative as it is now, from both sides of the aisle. I wouldn’t be surprised if we even see sanctions against China after the dust settles on this COVID fiasco.

You would have to start by decoupling investments in China and Wall Street and many politicians will not allow that to happen.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#84
post #80
post #50

Don't know what is going on at Zoom, but I suspected at least part of it sneaky. For example, about 3 or 4 weeks ago I heard about this company, and learned that it has R&D in China per its SEC filing at IPO. However, checked its website, the career section led me to https://jobs.lever.co/zoom , and there was ONLY one opening at China per the website (I remember it was a position at marketing department). Then I sear…

Unlikely IMO. "Zoom, a Silicon Valley-based company, appears to own three companies in China through which at least 700 employees are paid to develop Zoom’s software. This arrangement is ostensibly an effort at labor arbitrage: Zoom can avoid paying US wages while selling to US customers, thus increasing their profit margin. However, this arrangement may make Zoom responsive to pressure from Chinese authorities." htt…

So Zoom is essentially a Chinese company with a formal outer shell in the US and 81% of its revenue coming from North America?

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#85

Earlier quoted context omitted.

For those that don't know much about encryption, here is an example image for why ECB mode is trash: https://i.stack.imgur.com/bXAUL.png

Images are uniquely bad for ECB mode since they almost definitionally will have repeated material. ECB mode is bad and shouldn't be used. But it isn't like somebody listening to your zoom traffic can transparently see penguins.

Isn't an h264 stream even worse given that unlike a random image it has a very well defined repeating structure? The risk isn't that someone will look at zoom traffic directly and see the content Matrix-style. The risk is that it should become possible to just completely decode the encryption given what you know about the plaintext. In that context the penguin image is a great illustration.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#86
post #64
post #57

Earlier quoted context omitted.

Why is having engineers in China cause for suspicion? Lots of tech companies have engineers in China. Eg Microsoft.

What alerted me at that time was the discrepancy between their HR site at U.S of the Chinese opening (only one), and their job postings in Chinese job sites.

I doubt it is a complicated conspiracy. Someone probably pushed the wrong button on the HR site.

I’d guess the one opening you saw was coming out of a US manager’s budget, and the manager wanted some physical presence in China to help work with teams that are based there.

It’s not surprising that they wouldn’t target China-based positions in fluent Chinese language offices at their US based English language site.

Also, I’ve been using Zoom at work for years. They’re more popular with younger firms (“anything but Cisco”, maybe?).

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#87
post #47

Earlier quoted context omitted.

Is there a simple way for those of us who hold index funds to check if we are shareholders?

yes: if you hold an index fund which holds zoom, you are not a shareholder, the fund managers are.

That doesn’t mean you weren’t damaged financially by their misconduct.

It probably doesn’t matter much for a small company like Zoom, but I imagine it would for MFAANG and friends.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#89
post #84
post #80

Earlier quoted context omitted.

Unlikely IMO. "Zoom, a Silicon Valley-based company, appears to own three companies in China through which at least 700 employees are paid to develop Zoom’s software. This arrangement is ostensibly an effort at labor arbitrage: Zoom can avoid paying US wages while selling to US customers, thus increasing their profit margin. However, this arrangement may make Zoom responsive to pressure from Chinese authorities." htt…

So Zoom is essentially a Chinese company with a formal outer shell in the US and 81% of its revenue coming from North America?

That's an excellent business model.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#90
post #57

Earlier quoted context omitted.

Why is having engineers in China cause for suspicion? Lots of tech companies have engineers in China. Eg Microsoft.

Because the CCP has no qualms about threatening an employee’s family to insert a backdoor or exfiltrate information, for one. The decoupling has begun. Sentiment in the US toward China has never been as negative as it is now, from both sides of the aisle. I wouldn’t be surprised if we even see sanctions against China after the dust settles on this COVID fiasco.

Enforcing US IP protections isn't a partisan issue. I think it's crazy that people are trusting zoom for their critical communications (like design review meetings and screen sharing schematics/process diagrams!) when there's a non-zero chance that the CCP/PLA has the infrastructure to:

    cat '$COMPANY/zoom-chat.log' | grep '$TRADE_SECRET' | local_industry_boost.bash 
inb4 the whataboutism: yes, the US Government has (and might continue to) participated in state sponsored industrial espionage. But if I'm an American company, I'm not going to care about that.

I've worked for at least one company that outright refused to do business in China or with certain companies that had oversized presence in mainland China because of experiences with this kind of problem. I know of some engineers that were arrested upon entry to the USA because they stole company IP and founded a company in China that used it. I know of another company that had network hardware compromised by an employee over there and was used to attempt to penetrate US networks (and if you wanna get spooked, they weren't alerted by their stateside infosec team, but federal authorities). I don't know why people treat me like a conspiracy theorist for bringing this up about Zoom routing data through China and using less-than-best-practice security.

Post reply on HN