A Message to Our Users
blog.zoom.us
blog.zoom.us
The important part is the leaderships reaction to the situation. Compare to something like Boeing. Zoom acknowledges facts, takes responsibilty and starts fixing things. Boeings reaction to its product killing hundreds of people was “Lol user error. RTFM”. That is (apparently) what acceptable leadership can look like..
Any sw product has issues. The question is what the company does about it
> Any sw product has issues. The question is what the company does about it
See https://news.ycombinator.com/item?id=20389812, https://news.ycombinator.com/item?id=20390755
A possible scenario is that users continue to browse the user directory and join meetings with their Zoom account even after leaving a company.
You gotta figure, as soon as you starting writing a blacklist of “common” domains like gmail.com, hotmail.com, etc, your immediate thought should probably be “wait, maybe we’re doing this wrong.”
Why is it that it’s on by default for arbitrary domains (excepting the ones some poor soul has to blacklist)?
If this situation isn't a mass condemnation of the idea users care about security or privacy more than usability, I don't know what is.
[edit, formatting]
Content-Security-Policy-Report-Only: default-src blob: 'self'; script-src 'unsafe-eval' 'unsafe-inline' blob: https://*.50million.club https://*.adroll.com https://*.cloudfront.net https://*.google.com https://*.hotjar.com https://*.zoom.us https://*.zoomus.cn https://*.zopim.com https://ad.lkqd.net https://ajax.aspnetcdn.com https://apiurl.org https://appsforoffice.microsoft.com https://assets.zendesk.com https://bat.bing.com https://cdn.5bong.com https://cdn.jsdelivr.net https://cdncache-a.akamaihd.net https://code.jquery.com https://connect.facebook.net https://consent.trustarc.com https://extnetcool.com https://fp166.digitaloptout.com https://googleads.g.doubleclick.net https://intljs.rmtag.com https://pi.pardot.com https://px.ads.linkedin.com https://ruanshi2.8686c.com https://rum-static.pingdom.net https://s.dcbap.com https://s.yimg.com https://s.ytimg.com https://s3.amazonaws.com https://scout-cdn.salesloft.com https://sealserver.trustwave.com https://secure-cdn.mplxtms.com https://secure.myshopcouponmac.com https://snap.licdn.com https://sp.analytics.yahoo.com https://srvvtrk.com https://static.zdassets.com https://static2.sharepointonline.com https://tag.demandbase.com https://tpc.googlesyndication.com https://tracking.g2crowd.com https://translate.googleapis.com https://trk.techtarget.com https://unpkg.com https://www.comeet.co https://www.dropbox.com https://www.google-analytics.com https://www.googleadservices.com https://www.googletagmanager.com https://www.gstatic.com https://www.youtube.com https://d.adroll.mgr.consensu.org https://serve2.cheqzone.com https://*.ada.support 'self'; img-src https: blob: data: 'self'; style-src https: 'unsafe-inline' 'self'; font-src https: data: 'self'; connect-src * data: 'self'; media-src * blob: 'self'; frame-src https: ms-appx-web: zoommtg: zoomus: 'self'
These extensions inject their own scripts into the page which will then fail based on the CSP and send a report to the server. In an ideal world you would just 'ignore' these reports server-side instead of whitelisting the domains.
I understand the header causes logged reports, no actual policy enforcement, but still... I don't have a good read on their underlying concern here.
As for "Thousands of enterprises around the world have done exhaustive security reviews of our user, network, and data center layers and confidently selected Zoom for complete deployment."... well it can't have been that exhaustive if a couple of weeks in the sunlight have generated a shopping list full of concerns.
Kudos for half-playing by the 3F rule, though - probably their smartest move yet
Some of the biggest issues came to be due to deception and this message does not address that point. They were intentional decisions with effort put into obscuring them. One of the most egregious being the creative use of the "end to end encrypted" moniker. That was deliberately deceptive and I don't see this cookie cutter response addressing any of that.
More engineering resources and engineering fixes don't fix deception, that starts at the top. And this puts the whole message into question.
> These new, mostly consumer use cases have helped us uncover unforeseen issues with our platform. Dedicated journalists and security researchers have also helped to identify pre-existing ones.
I don't think he is saying that these issues have to do with scaling problems, but rather that the increased usage + new types of usages led to increased scrutiny and uncovered new issues. Which is correct in a way.
Obviously, they were told several issues in the past too, but then those issues were not costing them money. Now they are, so they are trying to fix them.
This isn't a scaling, usage, or whoops issue. This was intentional.
After all, users never want to uninstall our software, right? That implies they don't love our product. And of course they love our product. ;)
It's not that uninstalling isn't an important feature. It's just that at crunch time, project managers will pull people off polishing the uninstaller to put them on that virtual green-screen feature 10 out of 10 times.
There are way too many complex dark patterns which have been exposed to excuse them as oopsies. This is a company where product managers overruled developers into creating security-breaking implementations for the sake of "usability".
It doesn't have to be malicious; the fact is that the market simply favors usability. Optimizing for the things users care about over the things they don't is the first PM guideline. This has been demonstrated over and over and over again; have users first, then worry about security and privacy.
I don't think parent did.
What you originally described (or proposed) what that it may be a simple case of accidentally overlooking a bit of tidying up during uninstall.
What I described - the problem that came to light March and then June last year - is that Zoom installed a web server on your Mac whose sole purpose was to silently re-install Zoom if you a) uninstalled zoom, and b) later clicked on a zoom link.
There is nothing about it that could be attributed to 'getting uninstaller logic wrong'.
That's a lot of stuff to forgive, within just a few weeks. I could forgive their servers buckling under the load or the trolls bombing in meetings. But everything else is less of a mistake rather than a concious decision in the basic software architecture.
Isn't this where fines balance things out? I mean, it's 2020 ... GDPR isn't a new thing. It's good they have a plan to fix things, but isn't that enough for tech startups "We're sorry :(" narrative?
They are well funded, and have plenty of resources when compared to SMEs...
People still can choose to not use the service anymore, but that choice alone isn't enough. They should pay for it, and then users can make that decision.
Exactly! Thats the point I was trying to make (sorry if that didn't came accross properly). It's not like they are facing completely new challenges. GDPR has been in place for years, yet they are breaking it. Guessing URLs to access "protected" files is also not unheard of.
I understand that it is a massive challenge to scale so fast and its good that they have plans to fix these issues, but these are mistakes that could have been easily avoided in the beginning.
The idea to enforce it was each country Data Protection Agency is the key contact for any data/security issue - doesn't matter if it's reported by the company itself, or by a consumer who denounced a breach in data protection terms.
Then the country can issue any fines, reporting to EU agencies, etc.
The problems are:
- This process isn't clear for companies, let alone consumers;
- Not all Data Protection Agencies are the same, neither have the same resources. Here, in Portugal, when GDPR was live, the director of the agency came out to the public and said it was impossible to enforce anything because they didn't have the resources to do it. He was fired.
The reality is that it's extremely hard to control so many players, and delegating it to each country, some of which underfunded, doesn't get us anywhere.
We are all software devs -- we know as well as him. He's chosen to prioritise growth over end user data privacy protection and then lying about it with marketing e.g. E2E advertised on front page.
Many of these privacy/security issues were being complained about on HN about Zoom well before Corona.
If Zoom users are data breached I personally won't feel sorry for them like some other breaches like Equifax for example. They've signed up to this to secure a bit of convenience. I will be personally discouraging it's use where I work.
I think that’s a bit unfair of a stance to take. As an example, I know someone who doesn’t want to use Zoom, but thanks to their university classes going online-only due to COVID-19, some of their professors have forced them to use Zoom for lectures, presentations, and examinations.
edit: clarity
I feel like I'm in crazy town. Isn't this the actual, living, real motto of SV? Move fast and break things.
That's a thing that exists. Why are you people hating on Zoom when they're doing what you're all (seemingly) trying to do? Have I lost my mind?
Not all of us are in SV. And some of us go to great lengths to not break things.
What does that have to do with user count?
https://blog.zoom.us/wordpress/2020/04/01/facts-around-zoom-...
Because "thousands of enterprises around the world have done exhaustive security reviews of our user, network, and data center layers and confidently selected Zoom for complete deployment" and they didnt "design the product" for these "new, mostly consumer use cases", it means that up until now they couldnt have forseen that lying about e2e encryption to sell enterprise subscriptions was an issue.
I'm pretty sure they are referring to security reviews for things like SOC2 and PCI. Which aren't exhaustive and generally consist of throwing a scanner on the network and running some sort of WASP top 10 vulnerability tester against the product. I have uncovered major flaws in products I have written that these "extensive reviews" have missed, like user enumeration by changing something in a POST request.
RFP by "who can tailor their marketing to check all the boxes" is a terrible process and leads to this marketing bloat. RFP would be much more useful if it stuck to "list only things you do your competitors doesnt; what processes come with your product that are much more efficient or innovative compared to your competition; like an sec disclosure what are three true non fluff risks to selecting your product; describe your revenue, user growth, and future ownership expectations." If a company cant answer those seriously, push them until they can, or tell them youll move on.
The important thing is that they establish enough trust to create basis for shifting liability.
If you don't read, comprehend, and remember Emergency Airworthiness Directives you have no business being a pilot for hundreds of people. (The instructions were a whole two steps: 1. trim to normal with electric trim switches 2. turn off the stab trim system.) Boeing is still at fault, but the pilots do share a portion of the responsibility.
https://theaircurrent.com/wp-content/uploads/2018/11/B737-MA...
Boeing was working on a fix right after the first LA crash.
> Over the next 90 days, we are committed to... Enacting a feature freeze, effectively immediately, and shifting all our engineering resources to focus on our biggest trust, safety, and privacy issues.
I see a lot of comments here claiming that this blog post is bland corporate apologia, doesn't take responsibility, doesn't change anything.
But this seems like a pretty legit turnaround. Overall, they seem to be addressing pretty much everything that's been brought up. They removed the Facebook SDK, they removed attention tracking, they've clarified their encryption policies in detail.
One commenter here is asking for more, for punishment, another demands their security team be fired. And I mean, if someone wants to try to sue Zoom for misusing the term E2EE then go for it, but obviously Zoom can't "punish itself" in a blog post, and pinning it on a few bad engineers feels like a scapegoat.
This seems to be positive steps, folks. Genuinely not sure what more you could be asking for from a regular for-profit business.
A portion of the development community loves to talk about blameless post-mortems and a blame-free culture until a tech company like Zoom does something they don't like.
Consistently does something they don't like. Most people forgive single instances, but they don't forgive patterns as much. Especially when the patterns look like they are on purpose.
Which part of the GDPR do you think would have significantly delayed development?
I really don't agree with your argument that caring about user security and privacy would have a substantial effect on development time, certainly not in respect of GDPR.
The fact we don't indicates there may be some reason security and privacy take a back-seat to usability and market adoption (and, in fact, it appears we've seen that pattern over and over again). "Engineering for security and privacy slows down product-to-market" is, admittedly, but one hypothesis.
I can't name one.
We've become such a cynical culture, once pitchforks are brandished they appear to be unsheathable, rather they grow sharper and more wild as the chorus of internet echos grow. While there is value in discouraging certain behaviors (and thus "make an example"), and encouraging new ones (some level of noise was needed to warrant a response at all), surely there must be a path to redemption, an acknowledgement of misaligned incentives in lieu of the demonization of individuals. There are too many true enemies in the world (most of them not processes not people) to harbor such disgruntlement against a platform which is by at least basic measures doing good (providing a service that is obviously loved and used by many and jobs and economic well-being to those who make and support it).
I personally have been wary of Zoom since the first reports of their apps doing shady things (and the forcefulness with which they attempt to make you use it) and don't find it provides any value over a multitude of other services. But this wariness warrants a mere "meh, I'll go elsewhere," not a crucifixion. Yet as the frothiness grows from this current story (and it's really not much of a story) it becomes more difficult to see just what sort of blood sacrifice will satiate the mob.
When you have a handful of tech companies who systematically, unashamedly and deliberately abuse people's trust and privacy, it ruins the landscape for everyone. As it stands today, our trust has been betrayed so many times that a default assumption that the other actor is malicious and will do the wrong thing is almost always correct.
It's a shame, but this seems to be the case for every industry that is consumed by greed, and almost as a rule, every successful industry will eventually be consumed by greed. It's a local minimum that our society in it's current form cannot seem to avoid.
But we have a pretty good reason, beyond that, to not trust Zoom - THEY clearly never gave a shit about security, given in a few weeks of people taking a slightly deeper look we've had pretty much every possible leak and bug and problem you can imagine crop up.
How long did it take Microsoft to go from "no-shits-are-given-security" to "security-is-core"? 2 decades, something like that?
So yeah, sure, 90 days, that's... well, maybe the beginnings of a start.
“There’s a misspelling in the HTTP headers spec, so obviously this was written by amateurs.”
“Browser X has an RCE, so obviously they don’t care about security.”
These are obviously faulty logic when stated about other scenarios, and apply here as well.
Has Zoom been found to have the same specific technical issue reoccurring over multiple releases, to the tune of “buffer overflow” or similar? If so, then that’s a trend to throw up warning flags about.
A series of bugs that share no commonality other than being bugs is, perhaps, not so much.
However, saying "it took another megacorp twenty years to fix their privacy problems, so we shouldn't trust $relativelysmallcompany for the next two decades" is not fair to $relativelysmallcompany and doesn't even consider the cultural change it probably took to get $megacorp to actually care about security and user privacy.
Personally, I don't really like Zoom. I use it, and it works okay, but there are a lot of little nitpicks I would like to see addressed- for instance, it'd be really nice to be able to adjust individual member's volume levels or be able to mute them outright as a participant instead of listening to a compressor that needs a new bearing in the background for an entire meeting because they're not using push-to-talk and the host just downloaded the client yesterday. I'm also more than willing to give a company time to fix underlying architecture problems and not demand fixes in the meantime.
I would want to be given the benefit of time to fix problems, wouldn't you?
> It's a local minimum that our society in it's current form cannot seem to avoid.
It can't avoid it because it is the result of incentives, not specific players. This is why it's so ineffective to brandish hostility towards individuals or even companies: others, up to and including yourself, would do the same things if put in the same positions, because that is what would be best for you (and there are plenty of rationalizations you can come up with to show why it's net good).
To eradicate this kind of thing we cannot be relegated to impotent rage with mob-issued pitchforks at industries or companies or the individuals who operate them, or play the victim card and blame the industry for "betraying our trust." The "why" of this is not an "industry consumed with greed," it is a fundamental result of technological breakthroughs in an economic environment such as ours. When you have bad incentives you will continually get bad actors, and playing whack-a-mole with them will be a fruitless exercise. We have to recognize the systems as a society, not the players, if we are to have any hope of true reformation.
So a change in the system is required to fix the root cause, but I think some amount of pitchfork waving and torch igniting is not out of the order. The excuse of "everyone would do it with these incentives" is not an excuse for this behavior. And I say that fully admitting that I'm part of the system (although a different industry), and yes of course I'd do (and am doing) the same given the choice.
Perhaps the pitchforks show the individual the error of their way, and the society will change once enough individuals decide to make the change?
A) It misses the bigger picture and thus doesn't address the underlying cause, thus it will continue to happen over and over.
and
B) It feeds an outrage culture that permeates far too much of our online conversation that requires more nuance and careful dissection, which paired w/ the first leads to division and us vs them mentalities when more than ever we mentalities are needed.
Perhaps I'm overly sensitive to that second one because I'm more focused on systems and because outrage culture, which itself is bourn of other misaligned incentives, is a large problem underlying other issues that I've tended to notice more in my circumstantial isolation. So in a sense I'm being hypocritical when I plead for a more measured and forgiving response as I'm addressing individuals not the systems that caused them to react in this way. Mostly I'm just thinking out loud, as are we all (we're thinking at each other rather than with each other, another issue, related to outrage culture).
Anyway, as I'm in danger of severely incoherent rambling here I'll circle back to say I cautiously agree with you that some measure of pitchfork waving is warranted. But when the CEO makes a response like this, at least on its face an earnest effort to right past wrongs, can't we at least give them a chance to do so? Otherwise the pitchforks lose their meaning as it begins to look like they were out just to be out, and we're more concerned with persecution than actual redemption or resolution.
I’d be much more willing to cut them some slack if this was their first offense, or if their previous mea culpas had showed evidence of change. Today, it feels like “This time for sure!”
It doesn't seem like anything they did warrants "Blood Sacrifice", and it doesn't seem like anything they did was criminal negligence. Security incompetence? Yes certainly, but lets be real, 99% of companies would fail under the same security scrutiny if the company suddenly had 190 million more users using their same product over night. Aren't you at least glad their CEO cares enough to address these issues? Its not like Facebook drastically addressed their users privacy issues, even with intense scrutiny over the last few years. The situation with Zoom could be much much worse. They definitely have some more work to do, and we should keep holding them accountable, but since I am forced to use Zoom for work, I'm glad they're even pretending to take these issues seriously.
I don't think Zoom has done anything malicious. I think they just built their software quickly and just made it work.
Now that it's under a lot of scrutiny they're paying a bit of PR price. But they'd probably do it all over again since they are now seeing hundreds of millions of users.
There are two issues with that argument. First, they put in EXTRA effort to break the security of their users. The feature of 'upon de-installation, install a daemon on the system that silently re-installs the app whenever a zoom link is clicked' is MORE work than not doing that, for example. Second, they are 8 years old, have 2500 employees and a revenue of over 600 million. I work at a 30 ppl startup and I would not at all be surprised of we invested more hours in security in 2019 than Zoom did...
This drives me nuts. Disclosure: I'm currently working in a security role. My company is great, and if someone on my team says "we shouldn't do this", the reaction is to meet and decide how to replace an idea with something that serves the business request and our (and our users') security needs. I love it.
But I also know I'm being spoiled here. More common in my experience is:
Software engineer: We need to do a thing.
Security team: No! We can't do thing at all. It would ruin us.
Engineer's manager: We've already started and our CEO promised it to a customer. Do your job and figure out how to secure it.
Just saying, cut that group a little slack until we know that someone actually didn't do their jobs.
Anyway, I agree with your last sentence; at what point is something "good enough". Lately I feel like the "good enough" in a significant amount of corporations isn't acceptable. I'm in healthcare and the absolute lack of security in my day to day is absolutely amazing.
I agree with you on that last bit. While it's important to have your compliance ducks in a row, a lot of shops seem to feel like "we've checked all the audit checkboxes so we're secure now!" No. All that stuff is nice, but having a documented process for deciding who gets root on your database servers is not the same as actually securing your database servers.
1. Instead of saying "no", saying "not that way, but let's figure this out together".
2. Evaluating risk and modeling threats: "this is who we're protecting ourselves from, and here's what happens if we fail." If a bored teenager on their couch hacked our website, it would be embarrassing because someone without a lot of resources would be able to make changes to our display system, even if no real harm was done. If North Korea hacked our user database, it would suck and be bad for our users, but in practice not too many people are going to get angry at us for being attacked by a hostile nation's government as long as we were doing the right things.
(Note: that's grossly simplified, and it's not like we're "heh we don't protect against nation states".)
Still, would like their WebRTC UI improved. The use case I'm in requires gallery view & the web ui lacks that, so I ended up having webrtc streaming me out while using Zoom in Windows Sandbox to view (Sandbox isn't able to use my webcam). "easy to use" wouldn't describe my experience
Internet jerk trolls who feel they aren’t jerk trolls because they feel they occupy some moral high ground.
“I’m not a jerk troll cause they’re bad bad!”
FTA: "On March 27th, we took action to remove the Facebook SDK in our iOS client and have reconfigured it to prevent it from collecting unnecessary device information from our users."
I don't consider a public company worth umpteen billion dollars to be a regular for-profit business. They had the resources to address these issues before the public attacked them for it, and chose not to. With the same team in charge, why would I expect them to be proactive on similar issues in the future?
Sometimes engineers are clueless, but it is unlikely that all of them are clueless. It's unlikely, unless the company is small, that there's a single engineer that's responsible for something.
However, a single person can be clueless and do incredible damage. Such persons are often called 'managers'.
Zoom had privacy and user invading issues years back. They didn't learn their lesson back then with the MacOS installers, and continued to assure us they are taking the "right steps".
My company have stopped using Zoom and we'll never go back.
> “Zoom takes its users’ privacy, security, and trust extremely seriously,” the spokesman said
https://www.theguardian.com/technology/2020/apr/02/zoom-tech...
I'm honestly curious, what could CEO say differently?
Plus blaming all the issues on consumer use cases is hilarious. That might work for like a company that makes fiber lines for commercial deployments or something However, it's like they forgot that their core video might be B2B, but the client is almost always B2C and always has been. The fact that you are forced to use the Zoom client/plugins to attend a Zoom meeting may make the business case enterprise, but they have always been taking these horrible stances on the client and harming normal people who can't choose to use something else.
That's what he could have said.
Most venture startups are focusing only on the first part. Slow-Growth focus ones on the second.
Once you get used to one model, is hard to switch to another.
This has nothing to do with delivering fast.
So that plays out as "we can never truly trust Zoom to do things right". Sounds exactly like how I feel.
Unless Yuan wants to finally say up front "I actively worsened security and threw away user trust in order to maximize our growth at the expense of everyone that installed our client" it's inpossible to take anything else he says at face value.
If their position is now that the Zoom software was designed for corporate users, e.g., that you're expected to only run it on your own VPN where you can guarantee there's no malicious network traffic, then it should have "NOT FOR CONSUMER USE" plastered all over it.
To me, this reads exactly like "Lol user error", except there's no "M" to "RTF" that ever said, for example, that its local web server stayed running after uninstallation and could take control of your camera, or that "E2E" in the Zoom docs doesn't mean the same thing as it means to the rest of the industry.
There's no responsibility being taken here. Taking responsibility would be "We fired all our 'security' people who told us we had best-of-breed security, and hired some actual security experts to re-architect our system to provide actual security for our users." What they did here is indistinguishable from "We're sorry we got caught!" except in verbosity.
And I'm honestly surprised that it is not totally watered down, it's not just PR speak and user blaming, but makes some clear points. The base defense is bad - that it was for less users and contexts before changes nothing - but it at least includes the "we will focus on that now, honestly". That's not bad already.
Maybe the only way to get useful code that starts off secure is to start it open source? That way, even if it takes "forever", there's no profit motive or need to rush into adoption...
I'm trusting for-profit software less and less and less by the decade.
But they don't have the traction of the videochat-as-a-service options because those options have financial incentive to set up servers, configure them, solve those parts of the puzzle for users, make onboarding frictionless, etc.
I'm afraid I don't think open source would be a panacea for this problem, because if there's one thing we've observed from the world of open-source and online software, it's that most users adopting an open-source solution have to become their own sysadmin too, and a lot of otherwise-competent hackers are profoundly bad at the ever-moving arms race that is "hosting a secure software service online." Distributing the security maintenance burden doesn't make it easier to solve.
We could get there if, hypothetically, companies cared enough about security to demand that all the software running on (at least) the client machines and (ideally) the service-provider's servers was open-source so they could trust the security model via an audit by their own eyeballs. Then closed-source operations would lose out in the marketplace to open-source outfits because enterprise would only do business with the open-source ones.
They demonstrably do not care that much.
What percent of the internet user base runs their own email server? What percent of even news.yc readers do?
But here's the operative question: were they wrong to set their priorities the way they did? In this crisis, they're wildly popular, and part of that popularity comes from optimizing for usability and advertising to close the deals that got their product in front of enough people to be a "household name" when everyone suddenly needed videoconferencing.
If people want security, GChat is built on top of Google's infrastructure, has almost no outstanding security issues, and years of engineering behind making it a quality product. And users don't care enough about security for that to be the tool people are reaching for right now.
Business is an art, and that art is the art of making tradeoffs to meet users halfway. And time and again, the product that thinks users need to be met halfway at "it's secure" gets trounced by the ones who meet users halfway at "It's usable."
> We fired all our 'security' people who told us we had best-of-breed security
Why, in a crisis, would you start by firing the people who already know the inside of your application, warts and all?
And if you aren't, there are plenty of alternatives. But unlike Google, they often don't have a security or privacy model to speak of because they haven't taken the lumps Google has in the past for messing up.
Yes. Let me ask this the other way, in a different context.
Say your company builds rapid-assembly prefab building components. You have built the business on being supposedly greener than the competition, by using natural materials where possible. All of a sudden there is a massive surge in demand, and you find out that certain cost-cutting optimisations that used to be merely mildly beneficial, actually provide a marketing edge.
Does it matter that your fire-proofing is a naturally occurring material? Namely, asbestos?
2) Are we talking about 1990 (when the public actually cared, legal torts were likely, and it was a huge hassle to sell a property that was known to have asbestos) or 1890 (when in spite of evidence that asbestos may pose a health risk, industry was full-speed-ahead on it because, hey, everything poses a health risk, and lung cancer was of lower concern to the public than dying in a fire)?
Based on what we know (not much) it's equally likely that their actual security experts completely understood the current situation, but marketing or high-level C-suite people came up with all of this.
I can completely picture the conversation between security engineers and marketing about whether they can use the term "End-to-end encryption" because I've had very similar conversations before about (mis)use of technical terminology.
How far do you go if you're unable to convince them to change the terms? What if you escalate all the way up to the CEO and they don't agree.. then what? Do you refuse to leave the CEO's office until they concede? Quit your job in protest? (What do you suppose that would accomplish?)
Or was it closer to Manager: Can't we do something. Dev: Sure (with an evil grin), we can do something Manager: Great!!
The form of responsibility taking you're demanding is actually just business as usual, reactionary scapegoating.
I can only agree, from what I have seen on previous security vulnerabilities it often seemed to fall either into straight out negligence or intentional ignorance because it's easier "that way".
I believe security had never and will never bee a top priority for zoom. At least while they can get away with it, which they currently seem to be able to do.
Also I have seen it more then once that a Team originally had good intentions into making good secure software (but not necessarily enough expertise) but due to frequent changes in priorities or wrong time estimates they end up with a software which "works" but internally is broken with a promise from management that if they produce something like that soon then they will get to fix security issues in a view month. But then they never get that time and shitty security becomes the norm. Following that people with security expertise get demotivated and move on (either literally by changing the job or metaphorically by just accepting writing not so secure software).
To me it just comes across as an attempt to deliberately confuse the issue.
> Dedicated journalists and security researchers have also helped to identify pre-existing ones.
Sure, you could translate that as "more eyeballs have uncovered our sloppy security" if you'd like, but it doesn't strike me as dishonest.
As an attempt to mislead or imply that there are no problems here, this is pretty much a failure, and thus not at all cunning.
"If Linux had as many users as Windows 95, it would be just as buggy!"
Never thought I'd see it flipped around like this.
> For the past several weeks, supporting this influx of users has been a tremendous undertaking and our sole focus. We have strived to provide you with uninterrupted service and the same user-friendly experience that has made Zoom the video-conferencing platform of choice for enterprises around the world, while also ensuring platform safety, privacy, and security. However, we recognize that we have fallen short of the community’s – and our own – privacy and security expectations.
Now, putting this into context as a software development team. Let's say your security/privacy team says "we really need to patch this CVE we found" and your infrastructure team says "we really need to re-architect this one area so we can handle more users". Given that Zoom has likely just doubled its user base (which means more revenue), where do you think management is going to spend its time?
This is coupled with the fact that a company with a ridiculous influx of users is going to be a higher value target. Security/privacy isn't going to move the needle in terms of revenue, but infrastructure is. It's a matter of contention of focus.
That is such a dishonest way of framing it. No one was really concerned whether they would "sell" data. The issue was with the exorbitant amount of data they collect and its analysis for commercial purposes, be it ads (which doesn't involve selling data), targeted pricing or providing access to corporate admins.
MS did a terrible job with Skype and Lync. No doubt they were expecting to be able to bind it to exchange server and then create a coupling that embedded into an effective monopoly, creating yet another bad user experience that somehow becomes "the norm".
Hopefully at some point MS will compete by improving their products and we will have a better WFH experience.
I can't help but feel this sudden Zoom "panic" is coming from large (and incompetent) tech companies who are not happy with an upstart.
> (think, for example, Google Ads and Google Analytics).
> There’s no need to think about those, because both are widely known for compromising personal privacy
No need to think about google. Not sure about that one. Surely there should be more of a panic about google/facebook? Why the sudden zoom moral panic?
Presumably, as an enterprise solution they have major enterprise customers that may have a corporate policy disallowing facebook and google use.
I would be surprised if much of the rest of the world didn't see a difference between "includes the facebook SDK" and "collects your data, bundles it, and sells it". Especially since such a huge percentage of apps include the facebook SDK. There's been specific research on apps that "overcollect" information and its found that typical users will only pay a few cents more for correctly permissioned apps.
However small or big, a company shouldn't be selling data without user consent, shouldn't use terms end-to-end encryption while make otherwise claims.
This behaviour should be punishable
The use of "end to end encryption" designation was no confusion, it was deception - it is implausible that this could have been done accidentally or as a result of a misunderstanding without engineers warning managers that this is not how zoom works and being overridden in their objections to communicate it as such.
They also double down on data collection. Disclosure does not establish consent and "we do not sell data" is a red herring because data can still be shared with third parties for business purposes against the interests of the users without being overtly sold (not to mention with governments under various "compelled cooperation" arrangements) and the entire policy can be subject to retroactive change without recourse.
The fact that they were targeting organizations with IT support is irrelevant except maybe to discredit the people within those organizations who greenlighted Zoom.
The saddest part is that it is unlikely any of the competing corporate offers are any better in any of those respect, but then they are not being actively pumped these days.
True, but I am still happy to see it. It shows that they got burned and that they noticed and felt the burn. It remains to be seen how they follow up — I will be watching closely.
Remember when Twitter was incredibly unstable? That was fine when it had only ten thousand users. They had to fix it fast when it had a million. But the thing is: that seems to be viable software practice (rush on features, forget about the robustness and the corner cases) because it keeps working.
Give me a break..
Oh, I missed that one. https://support.zoom.us/hc/en-us/articles/115000538083-Atten...
Professor uses Wacom and Inkscape to draw a picture, which is incrementally transmitted to students' computers. Students, those who have Wacom, may interact. Or just watch. Transmission happens every time the svg file is saved. Transmission requires a RabbitMQ server, which can be easily set up. Basically, a class needs one person who knows Linux, to set up the server.
It is intended for scientific collaboration or teaching in small groups of people. I am now using it for teaching my QFT class, although it only has 5 students. In principle, it should scale, but I have not tried it for large groups...
Drawing with Wacom in Inkscape is a pleasure, once you get used to it. In some sense, it is more convenient than using a physical blackboard. Although, some training is needed...
This is not meant to be snarky. They are literally living by the move fast and break things motto. Growth at the expense of everything else to win the market first, fix it second.
How are they not the golden child of SV right now?
This is just a symptom of ycombinator becoming a more widely known social network. All the malaises of social networks like pointless discussions about morality without any concrete solutions are coming along with that.
The correct response to many moral issues is not to create concrete solutions, but simply to stop people from doing bad things.
Frankly I think it's absurd to expect privacy and security while not paying for anything.
How about this one: I go to the library and borrow some books. This costs me nothing. The library publishes my name, birthdate, and reading list on their website. Is that okay?
Yes how is that even a question?
> How about this one: I go to the library and borrow some books. This costs me nothing. The library publishes my name, birthdate, and reading list on their website. Is that okay?
Your library is funded through your tax dollars. You are paying for it.
It seems to me whether or not you can get something for nothing is rather orthogonal to the question of whether it's absurd to expect privacy while not paying for anything.
Are privacy and security less important than food safety? As I posted the question my immediate thought was, as yours, obviously, but the more I think about it the less I am sure. A single security breach in a critical information service could potentially have profound far-reaching effects possibly worse than a local case of food poisoning.
Your food sample analogy is similar to a "free trial". No company offers permanent free trials (at least not without a paid alternative, such as Spotify), just as no supermarket _only_ hands out free samples without also selling that same product in their stores.
If you want a privacy-focused product to win, you either need to find an audience who wants it and focus there, or, you need to do great on all the other fronts that lead to acquisition and keep the privacy stuff an internal priority, not a banner feature.
Excerpt from their previous release above, only a few hours earlier.
Glad to hear they are starting to make improvements but waiting for public backlash to fix issues is a bad sign.
Think through this situation — 90,000 schools suddenly using Zoom, children doing their classes. What is most important: option 1) it just works option 2) it’s 100% secure
Imagine you were a member of Zoom's team, would you not be justified in feeling proud right now?
It has nothing to do with scaling. The problem is the numerous anti-privacy and anti-safety measures that they actively partook in. Those were no "features missed out" due to rapid development. Those were anti-user features purposefully developed in. This is what people are complaining about; and this is what the zoom manifesto is shamefully trying to brush off as if they were related to rapid development or to rapid scaling. If I was a member of the zoom team (who hadn't actively participated in these features), I would be extremely ashamed of my company for spoiling our success with these damaging practices.
The windows changelog[1] doesn't talk about a version released on April 1st, like the press release says[2].
So is the only way to mitigate that issue for non-techie users is to deactivate the chat feature for all conversations?
[1] https://support.zoom.us/hc/en-us/articles/201361953-New-Upda...
[2] https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u...
Interesting that he would point out the failure of thousands of IT departments around the world.
With everything that's come out since (not just the iOS client issue), I'm wondering how deep that questionnaire goes with regards to security concerns.
People need transparency.
They didn’t even bother to build up a reputation; hard to see how they’re going to build respect for people’s privacy and security into their culture now.
Then there's the issue that Zoom is now suddenly responsible for the complete lack of security awareness of teachers and middle managers who have never before held online classes, and are publicly posting meeting credentials so that everyone can join.
All, of course, while the while world is free loading (yes, "you are the product, hurr durr"; great contribution).
And they obviously have the business and engineering talent to make a good product (it's better than their competition, I'll grant).
But how much of their market share came because of some nefarious business and technical practices?
Forgive and forget, 'cause "correction"?
Sounds like folks at Zoom take privacy and security related feedback pretty seriously.
Sounds pretty creepy. I assume participants have to opt into this?
First, some background: our platform was built primarily for enterprise customers – large institutions with full IT support
These new, mostly consumer use cases have helped us uncover unforeseen issues with our platform
Never ever gonna use zoom.. I got rid of it a long time ago when I found out about the malware...
And this wasn't anything but an acknowledgement that they're not qualified to produce the software they're distributing. They still don't even know what they don't know.
I posit that Zoom has been right place, right price. Simple as that. The software is demonstrably hot trash. Not just at client endpoints but structurally.
I’m not sure exactly what your critique about Wordpress is. Is it that they’re using Wordpress, like 30% of the other websites in the world? Or is it that they didn’t bother removing it from the URL? Start keeping an eye out for “/wp-content/“ in the path of images or downloads on websites. You’ll be amazed.
Nothing about that message came across as sincere.
Also one of the biggest core issues (their installer) was widely reported and condemned last year (or was it the year before?) so these aren't all new issues coming to light. In fact blaming the visibility of these problems to an influx of new users (re COVID-19) is just dishonest.
Thankfully most (in fact all) places I've worked, it's not the CEO who decides which video conferencing (et al) solution people use, he delegates that responsibility to his CTO or equivalent. Who has almost always then delegated that decision to me :)
I believe using HN (for whatever reason) is a skill in its own right. If you want to use it as a tool for escaping your own echo-chamber, it takes some more thought to get right. Once you do, it works a significant percentage of the time, which is kind of impressive for a simple marketing platform of the Y Combinator (which is just a bunch of people with money and a bunch of people wanting that money to build or expand their business).
I’m usually the first to roll my eyes at such mobs but this case is different. When you have a company that has a documented past of privacy and security violations and then releases a letter saying “sorry about the new reported problems but you wouldn’t have known about it if we weren’t so popular lately,” you can hardly blame us for getting ranty. It just demonstrates that fixing those problems was never a priority and thus that press release is really just meaningless platitudes.
As for other people’s comments, if others took it too far (I haven’t read the majority other other comments since I came to this early and haven’t ventured outside of my thread since, so you’ll have to excuse my if ignorance here) then perhaps you should be taking that up with them rather than me?
In any case, I don’t appreciate being lumped as part of a “mob mentality”! My own opinions are my own and not the product others.