Zoom’s Use of Facebook’s SDK in iOS Client
blog.zoom.us
blog.zoom.us
I've been and iOS developer for a long time. I can tell you from experience that everyone does this. I have never worked for anyone who didn't ask for their app to include some combination of Facebook, Google, Flurry, AppCenter, Segment, Intercom, Parse, or whatever other random analytics framework the PM happens to be infatuated with.
Getting mad at Zoom for using the Facebook SDK is missing the point. They and a million others are always going to be doing this. Get mad at Apple for not letting you wireshark your own iPhone. Or having no way to package open source software where you can actually see what's running. As long as you're running binary blobs that can make whatever network connections they please, people are going to take your data and send it to places you don't know about.
Yeah maybe you can pass laws about it. But is that really a great solution? Who audits that? How do you determine what's legal and what's not? We should be pushing for a platform that makes it obvious what the software you're running is up to. The random pitchfork crusade against whatever company happens to catch a bad news cycle just isn't going to get us anywhere.
If this app works without root, it must be possible to apps on iPhone to add their own certificates to the system, which are then trusted by other applications - that would already be pretty alarming. I think Android still requires certificates to be manually imported by the user. Maybe this app points you to instructions on how to do this, but the description makes it sound very automatic.
https://andydavies.me/blog/2019/12/12/capturing-and-decrypti...
It's really hard to believe this point given that... getting mad seems to have worked.
Webex, Teams, Slack are the only ones that matter.
Yeah some companies are behind the curve (not blaming you).
Zoom is getting very popular
"Top of page 21- In addition, we have a high concentration of research and development personnel in China, which could expose us to market scrutiny regarding the integrity of our solution or data security features. Any security compromise in our industry, whether actual or perceived, could harm our reputation, erode confidence in the effectiveness of our security measures, negatively affect our ability to attract new customers and hosts, cause existing customers to elect not to renew their subscriptions or subject us to third-party lawsuits, regulatory fines or other action or liability, which could harm our business."
Check any news outlet to know why, and you’re likely to also read about zoom in some article.
No.
That's all that really needs to be said about it but I'll add a couple of more lines here so no one thinks I'm lazy or posting a shallow dismissal:
- First, just because someone trusts you it doesn't mean you are free to abuse them. This should go without saying!
- Second: In Europe and I think California as well this is also illegal.
We’re all stuck inside for a while, this is the perfect time to act. One app and SDK at a time.
During covid nobody is paying attention and we have the additional problem that they're trying to use cellphone location data to enforce social distancing! Once this is in effect it will be difficult to undo because the next epidemic will be "just around the corner" ...
write a blog post?
take it twitter/HN/reddit?
hold a rally/demonstration outside Apple/Google?
call our MP?
bombard their employees with phone calls or knock on their front door where they live?
write malware?
... really I got nothing that sounds like it would work. In retrospect all of Tim Cook's privacy / security grandstanding and attitude of superiority was just that. There are no good guys in this game.
We're outgunned by the lobbying from these companies I think.
In this very thread we started from “I can tell you from experience that everyone does this.”.
Now when a PO will be asked to add facebook in its app (or wants to remove it) there is at least one prominent instance to point to showing that having the SDK is not the right move. And hopefully that “everyone does it” will become “some still do it”.
If of course in the meantime we find a working systematic solution, it’s all for the better.
Compare to a system where you fix the incentives to automatically align everyone’s interests: e.g. bottle deposits, or a small fee for plastic bags. Now people will want to do the right thing, because it is aligned with their own interests.
The same holds here: fix this one instance with enough outrage, there will be a thousand more. Instead, let’s fix the misaligned incentives between app builders and users, so their invasion of my privacy costs them as much as it does me (e.g. GDPR).
This is how you make efficient markets: align incentives. Fixing everything on a case by case basis only provides temporary relief.
[edit: note that OP never said "don't do it", they just said "it's missing the point". which I think is a fair call. this one fix is good, but it's unsustainable.]
You know how these programs started? They started small. A few stores requiring them. Eventually, they become a law.
It isn’t. This is recycling one bottle. It doesn’t have any sustainable long lasting effect.
To stretch the metaphor, the equivalent of one store asking for deposits would be e.g. Apple requiring full disclosure of all such tracking SDKs on the App Store page, as suggested by someone else in this thread. That’s sustainable, scalable, and that’s what might eventually even lead to legislation, as you pointed out.
If California and the EU get wind of this, they may also give Facebook a gentle nudge.
That'll get Facebook to remove it fairly quickly, or at least stop triggering it in the background without user initiation.
Blaming Zoom and FB is entirely acceptable here, it is their responsibility to keep my data private.
Blaming Apple? Why, when Zoom is on the Play Store as well?
https://play.google.com/store/apps/details?id=us.zoom.videom...
>As long as you're running binary blobs that can make whatever network connections they please, people are going to take your data and send it to places you don't know about.
Surely there are open source video chat solutions already? They haven't taken off for one simple reason: video hosting is expensive. It's quite literally one of the most intensive network activities you can partake in, rivaling torrenting.
It doesn't make sense economically to offer a video hosting platform without collecting income from it. Nor does it make sense to attempt a peer-to-peer solution knowing full well that one laggy peer wrecks the experience for everyone else.
It's a very hard problem.
Blame Apple because they constantly tout the iPhone as being "privacy respecting" and "what happens on your iPhone stays on your iPhone"[0], while they
A. Apple doesn't default to "limit tracking", or at least make "limit tracking" an option on setup/iOS upgrade
B. Apple doesn't penalize developers for using Facebook's SDK with auto data collection (ie. punishment by having text like "sends data to: facebook, google, hotjar" on an app's install page)
C. Apple doesn't do any software stuff to limit and track the trackers. Having a counter for # of total days a domain name was contacted would be an eye-opener for many, and being able to toggle a "block" on the domain would be a big step forward.
Facebook meets the standard for being included in apps (respects the user resetting the usage ID), but that standard isn't the standard privacy-conscious users want. Apple can do better, but whether it be industry pressure or monetary pressure [google paying to be the default search engine], they don't actually put privacy first.
0: https://www.businessinsider.com/apples-ces-ad-las-vegas-misl...
Sorry state of Apple App security and privacy - all your apps are swarms of data collection and privacy abuses.
Apple built this world - and Apple is to blame. Zoom is to blame too. And finally individual app developers should also alert everyone on what's truly happening in their apps.
https://www.apple.com/privacy/features/
Apple sells privacy, brags about privacy - yet Privacy is abused in from the beginning in the store apps.
And preventing this from happening with SSL pinning is not a barrier for Google or Apple because they can easily bypass that.
Since they have the means to inspect the traffic at scale then they should be able to filter out apps that are violating your privacy.
Blame them. Not Apple
So I don't see how they're a "privacy respecting company" either. It's just marketing BS.
https://techcrunch.com/2020/03/24/apple-card-gets-updated-pr...
> Apple is changing the privacy policy for Apple Card with iOS to share a richer, but still anonymized set of data with Goldman Sachs in order to allow the creation of a new credit assignment model, which could expand the group of users that may be able to secure credit. > There is also a beefed up fallback method in the works that will allow users to share more personal data on an opt-in basis with Goldman Sachs if you do not at first get approved
So anonymised by default.
Opt-in, IF you want to share more personal data.
Do you also understand it's Goldman Sachs that run the credit cards, accounts, etc, they're not just randomly sharing data with Goldman Sachs?
“You can opt out of this use or your Apple relationship information by emailing our privacy team at dpo@apple.com with the subject line ‘Apple Relationship Data and Apple Card.’”
Sure, it would be nice if no company ever shared data with any other company, but that does not track in this case.
People signing up for an Apple branded Goldman Sachs credit card shouldn't be surprised or affronted by the fact Goldman Sachs gets anonymised data from Apple.
Why the hell anyone would sign up for this crap is beyond me. But it's not a reason to drag Apple into the context of a thread about a company guilty of basic privacy failures -- sending personal data to a 3rd party social network the user has no connection to.
Please also understand what 'anonymised' means, it means _not reversible_ i.e. you _cannot_ tell who the user is.
So Facebook will just provide an SDK for app developers to integrate server-side that lets their app send the data to their own domain, and the server passes it on to FB. Developers will install it, because they want the analytics and ad conversion tracking. There probably isn't a great technical solution to this problem.
It‘s a little bit like blaming the person making the deal with the devil. Of course on some level they deserve blame for engaging with evil but evil presenting itself in a slick interface should also get its fair share.
However every app vendor by now should know that Facebook is hungry for data and careless use of Facebook software is to blame in them.
As is Apple (and Google) to blame for providing no privacy measures for users.
Apple doesn’t allow software like that on iOS.
[0] https://support.apple.com/en-is/guide/mdm/mdmc77c9609/1/web/...
maybe some kind of automated little snitch settings ⇄ profile converter?
It’s possible that your solution might work for some small fraction of users, some of the time, for known spying hosts. Many people still want to access Facebook and Instagram, though.
Their kids should be able to help.
There are, as you state OSS solutions [0]. But the video hosting is not akin to Torrenting. Most people are fine with 720p quality video as you're not "watching" the participants like a movie. And as you scale up the number of users the required bandwidth for each subsequent user goes down in a linear fashion due to reduced screen real estate. A conference with 8 users, from a video perspective doesn't reasonably take up more bandwidth than that of 2 given the smaller stream. I am on almost constant conference meetings with 4-12 users, many times with video and I have a full packet monitoring solution at home and can tell you it's not remotely as intensive as you've claimed here.
Most people are fine with 720p movies too.
If you want to be creeped out, go to https://www.facebook.com/off_facebook_activity/ and find out how many apps have been quietly reporting all your usage activity to Facebook.
I have 100's of websites which managed to identify my Facebook account despite me logging into Facebook only in Incognito for the past 2 years.
I have been running Facebook in the special Firefox container pretty much since it was available. I took off the WhatsApp and Instagram apps from my phone months ago. For me, the number of ads (on Instagram) and integration into Facebook made them expendable.
I don't know if Facebook really has no information or they do but are not showing it to me.
I'd like to do the same with Google but the Google container wants to force all interactions with Google into one container. I've got dedicated containers for different Gmail identities - it was very handy to have a Gmail identity while I was president of the kids' soccer club and then turn the account over to someone else.
It's a "commons" issue. I don't necessarily trust FOSS software because I am going to login to the repo and check the code (though I have once or twice), I trust it because I know thousands of people motiviated by ethics and quality vs. money have peer reviewed the code for things like this.
Similar in concept to herd immunity.
"Who audits that?" We just did. And if there was a law against that, Zoom would just have been exposed for breaking it. Any sane company will try their best to adhere to laws. Some big players like Google can afford to mess around pay a few billions in fines, but those are the exceptions, not the rule. Eventually, even they can't afford to pay the fines in the long run (Even Google bowed to GDPR or at least its getting bashed with steeper fines until they wake up).
"How do you determine what's legal and what's not?" You pass a law, read the law? This is a self-contradiction. Laws are open for interpretation but the interpretation is quite clear after a supreme court case (for the better or worse).
"We should be pushing for a platform that makes it obvious what the software you're running is up to". Oh the web of trust? Did you ever install Snitch or some other firewall on your system? Its utterly hopeless even if you are knowledgeable. There is simply not way to audit that. Who audits that? Here you CAN ask this question.
I can't for the life of me understand how you can believe that it is better for everyone, including parents and grandparents to audit their phone, instead of having researchers audit phones and report companies who break the law. This is non-nonsensical. You must either be some expert without a connection to the real world, or some elitist who thinks everyone is like him.
Specifically on this point, I think the HN comment sorting algorithm may take account of how many votes child comments have too, so you may find that it’s the top child comment which has brought this to the top.
There’s plenty of anger to go around. Get mad all all three: Facebook for making an SDK that tracks you, Zoom for integrating it, and Apple for letting it through unencumbered.
I’d like to see Apple launch their own telemetry/events framework, that users can examine the data from, and then cut off everyone else
But you’ve just said everyone does it and we shouldn’t get mad at them - so we don’t need wireshark, because it would simply confirm that everyone does it and we shouldn’t get mad at them - right?
edit: some people won't want to give them any slack because they committed the offenses in the first place, but I think that's silly. Reward them for trying, because if this is the way they're going to respond to blowing it, they're one of the good guys.
a definite improvement in this case and so far.
PWAs could answer this problem, at least to some extent, but Apple historically has been limiting the features to protect the AppStore and the Apple Tax (v. the recent local persistence changes in ITP).
It's better than, say, Google pretending that third-party cookies make the web a safer place (yup, that happened).
(Don't get me wrong, I think ITP and Safari are great)
> Get mad at Apple for not letting you wireshark your own iPhone.
People on HN can, but an average user shouldn't have to care about that. I'm 100% up for stronger legislative measures (both tech and dark UX patterns) and more education in this area. Sounds boring, but without it we'll just keep running in circles.
This is not true and even if it was true it is an extremely lame argument. You can justify pretty much everything with this logic.
That's a tiny proportion of the user population and doesn't imply agreement or consent to the information the Facebook SDK shares. And even if it it did, it wouldn't automatically mean that it's an acceptable or good behaviour by those apps and Facebook.
Bringing widely-distributed privacy breaches to a wider audience's attention can help those users provide feedback regarding products and then allow them to select vendors who respect their values.
Regarding the issue that started this Zoom-FB dialogue I have commented a dozen (or more) times on the necessity to have a firewalled phone that a user (unfortunately the user needs to have basic knowledge of firewall admin) can decide what to allow and what to block. Your point on who audits is valid (I am a CISA and CISM of many years), and, well, nobody does. Each user will have to do his/her own work/effort to keep their family clear of these scum.
Apple gives you no way to find what your phone is doing, and no way to prevent it from doing it.
They provide company sponsored "controls" on what apps can do, which is about as useful as a factory alarm on a mid-80's car. Except with a modern twist, where they're the only ones capable of installing an alarm. (and imagine the alarm gives a free pass to apple)
The fact that they're starting in on MacOS and Little Snitch makes me think their platform isn't long for the world.
sigh. I do like arch linux.
Now almost all the packages grab identifiable info by default and some are doing things like making screen recordings. Combine that with a rotating set of product owners like described above and a lot of apps just end up making way too many calls to way too many places.
And I do think Apple could and should be doing something more here. Their developer analytics setup is a good example to lead by as it gives users a global option to opt out. They also are able to reject apps for an icon being offbrand so I’m pretty sure they could figure out something here.
What justification does Facebook have for keeping automatic event collection turned on by default in their SDKs? Why can't they enable it only when the the user has explicitly opted in (https://developers.facebook.com/docs/app-events/gdpr-complia...)? They even say, "you need to ensure that your SDK implementation meets these [GDPR] consent requirements."
That would imply they are incompetent and negligent.
Would one not expect large companies like LG to have internal security and privacy reviews of the software they publish, and know very well what they are doing?
> What justification
Their core business.
I'm surprised that you consider that unlikely/surprising. Lots of companies act in technically incompetent ways all the time
Not really.
Product Manager: I want to be able to support Facebook login for our app.
Developer: OK... [googles for how to do that] ... We can use the FB SDK for that.
PM: Cool, let's do that.
Dev: [implements it]
Nobody really does much more due diligence than that most of the time. I suppose you could argue that's negligent, but if that's the case, then pretty much every company that has an app with login functionality is probably in that boat.
I think every company that does this is negligent. Audit your dependencies, people!
I think for small teams this is a near impossible task. For big corporations it should be doable and expected. They actually have some leverage to push the other big companies to track less. Something a small company simply can't do.
This is not some surprising behaviour hidden in some random dependency.
This is the Facebook SDK, from Facebook, and everybody knows what their business is.
Ignorance is a bliss. Talk to some people that still use fb after their scandal and you'll get "who cares, everyone is tracking users and selling data anyway" as an answer.
> Would one not expect large companies like LG to have internal security and privacy
can't tell if this is sarcasm because this is exactly what they are. an OEM is just packaging stuff and always bigger than it's parts (in this case meaning the knowhow of their otherwise bright and knowledgeable engineers is lost in the organization as a whole). the biggest companies are always the dumbest places where no matter how bright you may be the management layers above make sure that this gets cancelled out (I've worked at Samsung, Nokia and Ericsson and it was the case in all these places). Doubt LG would be any different.
Also, that just linking the SDK in your app deanonimzes the user to Facebook is very, very clear in its documentation. It's not like Zoom didn't notice until someone told them. They made a decision, and now they're changing it because they were called out.
Do you really think they prepared a PR statement to respond to harsh criticism and just decided to toss in there the list of information sent without crafting the order of the items?
Yes, because it's in alphabetical order.
You don't have to craft anything for it to be in alphabetical order.
You just put it in alphabetical order.
The sorts of people who are going to read that list and understand any of it are the sorts of people for whom the order doesn't matter one iota — they will see the information.
For the majority of people, putting it at the top of the list would, equally, not matter one iota — they won't know what it means.
> You don't have to craft anything for it to be in alphabetical order.
> You just put it in alphabetical order.
Again, if you get to choose the names, you get to choose the order.
Seriously, what is more likely, someone decided to nefariously re-order the list, possibly while laughing maniacally, or the list was just pulled and presented in alphabetical order?
HN commenters are just determined to turn everyone in to evil not-so-geniuses, refusing to recognise that almost everyone involved in this at Zoom are just like everyone else on HN.
They found a thing that did what they needed, an official SDK no less, and used it. They found out (in zoom's case via public crucifixion) that it was doing something nefarious they didn't like, and stopped using it.
But no, if HN is to be believed, they were collaborating with Facebook in some evil diabolical plan to take over the world via advertising.
And you can still set your preferred order by naming and wording. Had they dropped "iOS" from everything, "Advertiser ID" would be at the top. I don't think they would've lost a lot of clarity with e.g. "Device Disk Space Available" instead of "iOS Device Disk Space Available". Or, if prefixes are their thing, why not call it "Zoom Application Bundle Identifier"?
Alphabetical order means nothing if you control the strings that are used for sorting.
https://developer.apple.com/documentation/adsupport/asidenti...
You are thinking of “identifierForVendor”:
https://developer.apple.com/documentation/uikit/uidevice/162...
In the company I worked for, they read the code, you have access to it, and stripped that parts. It's not much work but its a pain.
The best approach is to use just the HTTP APIs and ignore the SDK. Your team will better understand how Facebook works, your app will be lighter and you are free from nasty surprises that a 3rd party may add to your app without your knowledge.
Now you need to log in via Facebook with a separate browser window, and thanks to the HTTP change, you need to click on a browser dialog to launch a meeting from a link. So, they've either changed their policy to err more towards the privacy side and haven't found all the cases yet, or, more likely, still have the same attitude except when the tech world starts screaming at them.
I really can't fault Zoom here. They used an existing tool provided by a company that is, allegedly, reputable.
Though, thinking about it more perhaps Zoom should get some more scrutiny here because this isn't the first time Facebook has said eff it to user privacy. Distrust of Facebook should be the default.
There are probably thousands of other apps that have the same problem.
However, it's the Project Managers and Product Owners that are not aware and they say "do it because that's what the customer wants!" and you can argue. You really do so at your own peril if you don't have others on the team to back you up.
People on the team knew, they just either didn’t care or were ignored when they voiced concerns.
"It's good that they removed it, and it goes to show just how important it is to inspect your application's wire traffic as part of your development and testing processes. Otherwise you'll have no idea what's happening until someone makes a blog post about it."
That sounds like a pretty accurate description of how software is built. (No, I'm not being flippant.)
> ... and hope it's not doing anything their users don't like?
I expect most don't think too much about it, not out of malice, but because their product manager told them "I want FB login" and to do that, they either spend an afternoon using the FB SDK, or spend a week figuring out how it works, implementing it from scratch themselves, and debugging the inevitable interop issues with whatever oauth2 (or whatever) library they've picked. It's really a no-brainer... few developers can take the week-long route and then justify that to their manager. They'll get fired.
As an example, 2 weeks ago I had to implement Instabug's SDK for one of our app brands, and created a no-op fake library [0] in order not to shop any Instabug code to the other 5+ apps.
Simply because our PM was afraid of possibly sending stuff to them while not having added them to the privacy policy.
[0]: https://medium.com/@orhanobut/no-op-versions-for-dev-tools-b...
https://blog.zoom.us/wordpress/2020/03/27/zoom-use-of-facebo...
Please take care and be safe.
You are right on! To focus on our service stability and security are our top 2 priorities. We will work as hard as we can to keep improving. Thank you for your great support!
But the where matters as much at the what; sending it to FB means that they add it to their profile of your users.
Uploading all of this data to Facebook just so you don't have to run a Matomo instance (or whatever controlled analytics platform you use) is either laziness or disregard for your users. There's a reason the analytics are free and sacrificing your users for something this small is exactly what is wrong with the modern software ecosystem.
So they don't know what they're doing? Really? How does that defense go in criminal trials?
They took prompt action because they were attacked so much over this.
https://blog.zoom.us/wordpress/2020/03/27/zoom-use-of-facebo...
Most apps shouldn’t need wildcard access, and the mobile device could include a warning when an app does this teaching users that they should be careful with the app.
This way at least when you installed Zoom for example, it would say something like:
“Zoom is requesting network access to:
- zoom.us - analytics.tracker.example.com - facebook.com “
And then at everyone would know. It still doesn’t solve the underlaying problem, but it would probably make companies more reluctant to add third party analytics and sdks.
But there probably is some sort of good similar solution based on guidelines. If apple were to start defining policies on data collection and opt outs and say that apps needed to follow them or be rejected it would put a lot of pressure companies like Facebook to adhere to these guidelines in their sdks.
I don’t know if apple has the appetite for this as it would cause a whole lot of rewriting of a whole lot of code but they are in a great position to do this.
"Zoom Removes Code That Sends Data to Facebook when you first open the app"
as per the article:
"Motherboard downloaded the update and verified that it does not send data to Facebook upon opening."
It's a bit naive to just assume that just because they don't send the data right away, that it's not getting sent at some point later on.
Since they removed the Facebook SDK entirely, whatever mechanism Facebook used to collect the info doesn’t exist any more. Instead of being able to collect the data at all times, wouldn’t FB only have a vector to do so through web login? At that point, I assume they could do fingerprinting in the browser to collect some info, but at least the cannot do it on the system level any more.
It still seems like this is a big improvement. Though, I imagine most folks will have at least one other app using the FB SDK, so it’s not like the root cause is fixed.
Specifically, SFSafariViewController does not share cookies or other data with Safari anymore. Some bad actors got caught with their hands in the cookie jar, literally, and out that sharing went.
Someone's lying here.
> releasing a program without even hooking it up to a network monitor for five minutes
How many times have you seen anyone do that? Unfortunately that is the reality - my personal take is to simply try to avoid vendor libraries at all costs, but it's hard to sell.
Most things are operated in an honor system.
Take npm as another example, in a large corporation, any commercial product that relies on third-party npm packages will have to survive a long legal audit process.
That's exactly the point. Zoom says they care deeply about privacy, but their actions demonstrate they don't. Doesn't matter how common it is, or the reasons why it happened, it's proof positive that their statement is untruthful.
If the defense is the practice being common then there isn't anything special about Zoom regarding user privacy, is it.
centralized location tracking in an infectious crisis (either mandatory or mass voluntary) will normalize to 'good'
sleazy third-party phone home from apps considered key to surviving under lockdown, apparently not ok now! good
the bad news is we'll normalize some bad practices, but the good news is we'll make pragmatic compromises using actual information -- with covid taking up moral panic cycles, privacy is a place we can be rational
also no business feels totally secure RN and people will do anything to win & keep business -- even zoom
On the Web, it's recommended to use a generic OAuth library instead of integrating Facebook JS SDK. On mobile, this is almost impossible though as Facebook doesn't implement the OAuth PKCE flow.
[1] - https://media.ccc.de/v/35c3-9941-how_facebook_tracks_you_on_...
I am very sorry that so many bad publicity happens right now, but as far I know even bad publicity is good in the end.
> Motherboard downloaded the update and verified that it does not send data to Facebook upon opening.
Edit: Fixing mental hiccup, nothing to see here.
Don’t mind me, just fixing that mistake.
It sounds like this they're just no longer flat out using the Facebook SDK (which provides a slightly more "native" / "nicer" login flow for apps when used). They're going to do what most (at least, from personal experience) apps do and just show a webview with a redirect back into the app, which doesn't call out to Facebook at all.
EDIT: That is, it doesn't call out to Facebook at all until you start the login flow, which is just opening a browser view to the oauth2 flows..
For me this would be much stranger at a tiny company.
So clearly the mic itself is not muted - the software is still listening.
Not sure how I felt about that given all the recent Zoom privacy revelations.
There seem to be some legitimate concerns about privacy worth discussing further but I'm not sure this is one of them.
So Zoom is basically lying here
Come on, the developers who takes the responsibility to use the SDK were aware of it, ok maybe the CEO of Zoom or the market guy was not but the tech team is. They are not stupid.
You should have just apologise and assume your fault, that would be the courageous position, not denying it.
Tbh I am ok with Zoom sending my data to FB (I mean, in my case I've insta/messenger anyway) but not ok for Zoom taking everyone as naïve people with this lying statement.
I can't see why Zoom can't come out with a statement regarding why they are collecting all of this sensitive data.
Big corporations might be sharing stuff unwittingly with people that they don't want to share it with.
https://www.sec.gov/Archives/edgar/data/1585521/000119312519...
Top of page 21 in their SEC filing:
"In addition, we have a high concentration of research and development personnel in China, which could expose us to market scrutiny regarding the integrity of our solution or data security features. Any security compromise in our industry, whether actual or perceived, could harm our reputation, erode confidence in the effectiveness of our security measures, negatively affect our ability to attract new customers and hosts, cause existing customers to elect not to renew their subscriptions or subject us to third-party lawsuits, regulatory fines or other action or liability, which could harm our business."
Also scary. I have never ever logged in to Facebook on my iPhone except via the Facebook app and it was the first time I've installed Zoom. When I went into the Zoom app and picked login via Facebook, somehow it knew who I was and asked if I wanted to login as me. How is this possible? Is iOS sharing cookies across apps? I feel like maybe I need to reset my phone. WTF
I also feel like the best solution for this case is to somehow login via the facebook app. I know that used to be an option but it seems facebook deprecated it. My argument would be (a) I don't have to worry Zoom (or any other app) is getting my Facebook credentials (b) If actually do want to login via Facebook it's almost guaranteed I have the app installed.
No, I'm not a paid shill, just a really tired and stressed out guy who gets almost all of his social interaction through Zoom.