Zoom freezes feature development to fix security and privacy issues
techcrunch.com
techcrunch.com
I mean, sure, fine, it scaled quickly. That's not what people are mad at. We could tolerate technical issues inherent with that growth of scale. But these issues are fundamental and were issues with both 5 people and 5 billion and given that some of the choices, e.g. the installer, were deliberately designed, that statement holds no water with me.
So when the product owner asked the developers to add the ability to log in with Facebook, they looked at the technical documentation of the Facebook SDK, but probably not much thought went into how Facebook would channel through data even for non-facebook users. And if the technical staff did not communicate this to the PO they might not have been technically savvy enough to consider this a problem/threat.
I don't want to defend Zoom, I've actually also been pushing against using it in our company. But I also don't agree with the idea that every bad thing that comes out of Zoom was done with malicious intentions. I think it speaks more about software development in general. Don't forget that every website with Google Analytics, Facebook Pixel, Facebook Like buttons, Twitter embeds have basically been doing the same thing for years.
I am really impressed that the tool has remained stable and performant.
(This doesn't mean there's not things they got to fix regarding security and privacy; both things can be true, I'm still impressed with the technical quality -- AND wish/hope they use what is apparently some high-quality engineering ability in a more pro-user way).
"The company is far from done. Don’t forget that it claimed that calls are end-to-end encrypted even though they’re not at all. More importantly, the fact that Zoom is fixing issues as quickly as it can isn’t enough. Something is wrong at Zoom — there’s a corporate culture issue that leads to all those missteps. It’ll take much longer than 90 days."
Seems like this type of terrible and wide spread news about a companies only product would turn around just about any corporate culture in way less than 90 days. This was some majorly bad news and it was everywhere for weeks, I'd assume things are very different there now.
If the same software could be used without the security concerns then I don't see how competitors at their current level would remain anything but a side note.
I have brought up Jitsi, no one cares, perceived as worthless fringe. Enterprise client already has MS Teams licenses, again no one cares, only used when Zoom is no option. Internally we got Slack, cannot even do 1:1 calls without issues. We also have Pexip, it has crappy UI/UX and several disconnects if sessions > 30mins. Hangouts is Google so enterprise clients are often not getting into that.
Competitors, take note. Get the basics right - don't concern yourself with fluff - and customers will flock to you.
- keep this private
- keep this secure
- use hardware acceleration to not melt my laptop
- make it easy to setup and use
They’ve got 1/4.
They got 1/1.
So your point stands: the real world has proven that 95% of people only care about that single point.
"do i click run or save"
"yes or no to this question i dont understand, [and despite clicking hundreds of times in my life, ive never actually read it]" (UAC)
IMO they did take note and that's why we are seeing the deluge of articles about Zoom.
> “ Freeze feature development and spend the next 30 days on a top-to-bottom review of Zoom’s approach to security and privacy, followed by an update of how the company is re-allocating resources based on that review.
Unless they were already working on it, I don't see how they'll get E2E encryption hammered out in 90 days.
No new backgrounds!
if you told me they planned to offer this feature within a year, i would bet money against it happening.
>To be clear, in a meeting where all of the participants are using Zoom clients, and the meeting is not being recorded, we encrypt all video, audio, screen sharing, and chat content at the sending client, and do not decrypt it at any point before it reaches the receiving clients.
https://blog.zoom.us/wordpress/2020/04/01/facts-around-zoom-...
The part after the caret is a quote from them.