Live data from Hacker News

Zoom sued for overstating, not disclosing privacy, security flaws

uk.reuters.com

91–100 of 166 posts

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#91

Earlier quoted context omitted.

Oh wow. ECB mode? That's horrifying.

For those that don't know much about encryption, here is an example image for why ECB mode is trash: https://i.stack.imgur.com/bXAUL.png

I would say that anyone who ever tries to encrypt some data and does the bare minimum google/stackoverflow search for how to do it would see extremely vigorous warnings not to touch ECB with a 10 foot pole.

Unfortunately, crypto libraries have a history of having a terrible UI and defaulting to ECB. Years ago I ran into this with pycrypto. I worked on a team that joked about how important it was not to do ECB and it turns out they had done ECB. https://www.dlitz.net/software/pycrypto/api/current/Crypto.C...

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#93
post #84

Earlier quoted context omitted.

So Zoom is essentially a Chinese company with a formal outer shell in the US and 81% of its revenue coming from North America?

That's an excellent business model.

It's basically what a lot of consumer goods companies are now. All the products are made and mostly designed in China, and then the US HQ does all the sales, marketing, and funneling product requirements back to China.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#95

Not surprising. Crazy how zoom in the beginning of the crisis was hailed for helping folks get together, but now with all the highlighted security concerns they are receiving a ton backlash. Hopefully they can recover and learn from this.

I've worked for a couple of companies where capacity planning was way out of whack with the sales side.

The worst case of this was when a manager came and told me we had just landed a big customer and my response was, 'Oh, fuck me'.

When your product isn't built for scale, you can sell the hell out of it to small and medium sized customers, or sit back and let organic growth bring you people by word of mouth, and they will all be happy. Invite yourself to the Big Show before your systems are ready and you're gonna have a bad time.

In this case, there is probably nothing Zoom could have done to avoid this level of scrutiny at this time. Handle that scrutiny better? Sure. But it was going to happen either way.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#97

Earlier quoted context omitted.

I’m more shocked that this massive tech industry has like one decent solution to remote video conferencing. Maybe we really have gone too far down the road of making bullshit apps, and stopped solving real problems. Shame on us.

Shame on the telcos who prevent residential customers from using the internet as intended. If everyone was given an IPV6 address block and freedom to accept outside connections from anywhere, none of this would be an issue.

>freedom to accept outside connections from anywhere

Without NAT from home gateways (like consumer routers) preventing inbound connections from the internet, security would be far more of a nightmare than it is today. Requiring that people manually forward specific ports is the best way to handle it. We would be seeing news about Blaster-like worms pretty much every week of the past 20 years, otherwise.

Also, even if it were a good idea, this still wouldn't solve the problem at all. The NAT-traversing capability of Zoom and other products is like 0.01% of the value they provide. You still need good software.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#98

Earlier quoted context omitted.

For our daily standup we use meet.google.com as it's more convenient than ZOOM. ymmv ofc

My company has been trying to find a solution since the Coronavirus hit. (We're not used to working from home) We were using Slack's built-in conferencing at first, but aside from the quality being generally bad, there was a 15 person limit, and we're ~ 17 people. I didn't want us to use Zoom with everything that's going on, so I suggested Google Meet. We tried it, and it worked, but not well—people's voices would fr…

That's odd. We haven't had problems with google meet, so we use it. Though we use zoom too, for all hands meetings for whatever reason.

Maybe it's locality to the servers, or just packet loss heavy internet in your neck of the woods. Either way, I get it.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#99

Am i the only one struggling to use Zoom properly since they introduced the latest security changes? The slack integration (write /zoom to start a meeting) was working ok-ish even though we always had problem with the meeting not starting unless the host of the meeting was logged in (gosh...why so complicated?) Now they added this waiting room, there is no sound notification to let you know that people are waiting. D…

I would think that meetings being company users only by default could side step a lot of these clunky security measures. You would only need them for external meetings. No zoom bombing or war dialing issues with that default permission set.

Re: Zoom sued for overstating, not disclosing privacy, security flaws

#100
post #84
post #80

Earlier quoted context omitted.

Unlikely IMO. "Zoom, a Silicon Valley-based company, appears to own three companies in China through which at least 700 employees are paid to develop Zoom’s software. This arrangement is ostensibly an effort at labor arbitrage: Zoom can avoid paying US wages while selling to US customers, thus increasing their profit margin. However, this arrangement may make Zoom responsive to pressure from Chinese authorities." htt…

So Zoom is essentially a Chinese company with a formal outer shell in the US and 81% of its revenue coming from North America?

Correct.
Post reply on HN