Live data from Hacker News

Zoom’s 90-day plan to bolster key privacy and security initiatives

blog.zoom.us

91–100 of 113 posts

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#91
post #2

So were they really sending data to servers in China? From what little I've heard and read about this, that is what stood out to me. Not sure they should ever be trusted again after that.

Serious hypothetical question: suppose you're able to capture all Zoom calls. If you're a foreign government, how do you scale the analysis, and what can you generally do with the information? It'd be hard to get a useful amount of trade secrets or know-how. You'll see partial schematics and design docs, but without much context. At the executive level, you could at least scale the analysis to have actual people moni…

The NSA figured this out in the 90s -- you filter based on metadata and then retrieve the corresponding data if necessary. Aside from the fact that this (in the NSA's view) allows them to sidestep the 4th amendment, it's usually much more effective than sifting through billions of records every day. That same system lives on today with XKeyScore (or whatever they've replaced it with in the past 7 years).

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#92

"90 day plans" tend to be management & PR things... Real engineering is more of a "it takes as long as the job takes"...

Eric Yuan is the real deal. He's an engineer and is taking this seriously. This isn't marketing spin.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#93
post #87

They’re in the same bed as China. I don’t trust them for anything now, this to me is just a PR management exercise. They’re still going to give away your data

Would you please stop posting unsubstantive and/or flamebait comments to HN? We're hoping for a better quality of discussion than this, and (especially) than what it leads to. Case in point: see below. https://news.ycombinator.com/newsguidelines.html

I believe the GP was referencing Zoom's encryption going through China's servers, which was on HN's recently: https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto...

There are valid criticism to be discussed about China's actions and how much Zoom should be trusted given its close relation.

There's been many criticism of the US government here and I never see anything flagged or removed, I would consider that nationalistic and provocative under the same guidelines. I just don't see why the China discussions are removed.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#94
post #87

Earlier quoted context omitted.

Would you please stop posting unsubstantive and/or flamebait comments to HN? We're hoping for a better quality of discussion than this, and (especially) than what it leads to. Case in point: see below. https://news.ycombinator.com/newsguidelines.html

I believe the GP was referencing Zoom's encryption going through China's servers, which was on HN's recently: https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto... There are valid criticism to be discussed about China's actions and how much Zoom should be trusted given its close relation. There's been many criticism of the US government here and I never see anything flagged or removed, I would consider that…

> There are valid criticism to be discussed about China's actions and how much Zoom should be trusted given its close relation

Yes, and that's why comments about it should be thoughtful and substantive—not drive-by flamebait leading to useless flamewars about NATO and Winnie the Pooh.

> There's been many criticism of the US government here and I never see anything flagged or removed

That happens often. If you never see it, that's because of a cognitive bias: we notice and weight more strongly—that is, we see—what we dislike. https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que.... People on the opposite side of this question have exactly the opposite complaint.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#95
post #30

Earlier quoted context omitted.

> There's many reasons not to trust the CPC. (ip theft, surveillance, etc.) That's pretty much the summary of US attacks on our EU government as well (remember the backdoor direct attack on Belgacom?), soo... why does it make a difference? If anything, routing things through China denies our data to NSA and makes it less concentrated and useful. Similarly how spreading data over multiple cloud providers gives less po…

You ignored the humanitarian issues. Also, please give me examples of a US or European country stealing IP, because that's the main threat w/ Zoom (spying on businesses & stealing tech) Yes, most countries spy, China goes much much further and has no accountability because it's an authoritarian regime, not a democracy. You can talk shit about Trump all you want, but try to call Xi Jinping a cartoon bear. Ask Hong Kon…

I just told you a few days ago that if you keep taking HN threads further into political, nationalistic, or ideological flamewar, we are going to have to ban you. You're still doing it.

This sort of tedious boilerplate gets certain juices flowing but it has nothing at all to do with intellectual curiosity, the purpose of this site. In fact, it drowns it out. Would you please review https://news.ycombinator.com/newsguidelines.html and take the spirit of this site more to heart? We want curious conversation here, not demon-fighting.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#96
post #94

Earlier quoted context omitted.

I believe the GP was referencing Zoom's encryption going through China's servers, which was on HN's recently: https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto... There are valid criticism to be discussed about China's actions and how much Zoom should be trusted given its close relation. There's been many criticism of the US government here and I never see anything flagged or removed, I would consider that…

> There are valid criticism to be discussed about China's actions and how much Zoom should be trusted given its close relation Yes, and that's why comments about it should be thoughtful and substantive—not drive-by flamebait leading to useless flamewars about NATO and Winnie the Pooh. > There's been many criticism of the US government here and I never see anything flagged or removed That happens often. If you never s…

[deleted]

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#97
post #95

Earlier quoted context omitted.

You ignored the humanitarian issues. Also, please give me examples of a US or European country stealing IP, because that's the main threat w/ Zoom (spying on businesses & stealing tech) Yes, most countries spy, China goes much much further and has no accountability because it's an authoritarian regime, not a democracy. You can talk shit about Trump all you want, but try to call Xi Jinping a cartoon bear. Ask Hong Kon…

I just told you a few days ago that if you keep taking HN threads further into political, nationalistic, or ideological flamewar, we are going to have to ban you. You're still doing it. This sort of tedious boilerplate gets certain juices flowing but it has nothing at all to do with intellectual curiosity, the purpose of this site. In fact, it drowns it out. Would you please review https://news.ycombinator.com/newsgu…

Understood, could you delete my account and all of my comments please as I no longer wish to participate here.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#98

Earlier quoted context omitted.

Serious hypothetical question: suppose you're able to capture all Zoom calls. If you're a foreign government, how do you scale the analysis, and what can you generally do with the information? It'd be hard to get a useful amount of trade secrets or know-how. You'll see partial schematics and design docs, but without much context. At the executive level, you could at least scale the analysis to have actual people moni…

Hard drives are pretty cheap, particularly for a government. Store it all now, target your analysis narrowly later at your leisure.

Do you know how much data that would have to be? Scaling that seems improbable.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#99

Earlier quoted context omitted.

Serious hypothetical question: suppose you're able to capture all Zoom calls. If you're a foreign government, how do you scale the analysis, and what can you generally do with the information? It'd be hard to get a useful amount of trade secrets or know-how. You'll see partial schematics and design docs, but without much context. At the executive level, you could at least scale the analysis to have actual people moni…

Hard drives are pretty cheap, particularly for a government. Store it all now, target your analysis narrowly later at your leisure.

Year-old data isn't worth very much.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#100

Earlier quoted context omitted.

Hard drives are pretty cheap, particularly for a government. Store it all now, target your analysis narrowly later at your leisure.

Year-old data isn't worth very much.

There's no reason to think they'd have to wait a year. High value targets, like SpaceX had they not banned the use of Zoom, would obviously receive priority treatment by the Chinese intelligence community. My point here is that the analysis doesn't need to be done in real time, they could store the data and review it a few hours later, or whenever they wanted.

(For that matter, there is certainly a lot of data that would be useful a year later. Some data could be valuable even many years later. Taking SpaceX as an example, it should be obvious that old data could be valuable.)

Post reply on HN