[1] Just one example: https://github.com/jitsi/docker-jitsi-meet/blob/master/CHANG...
[1] Just one example: https://github.com/jitsi/docker-jitsi-meet/blob/master/CHANG...
Apart from that, the bug you mentioned was found and fixed by the community, and someone scanned all servers and notified the server operators. I'd say that this is about the most professional response to a vulnerability I've ever seen.
I expected the devs in the link to get caught saying something like "Yolo! Move fast and break things!"
Instead they had a pretty reasonable response considering the circumstances.
You don't have to use the app stores you don't like to use the service, they don't actually seek or store personal data, they don't use any data they do have for marketing, the use of those services falls under an identified GPDR exception, the other services they rely on for the service also have GPDR obligations with respect to any data they should collect, etc.
But even after all that, the devs realized they aren't professional lawyers. So what do they do? Ignore it all? No, they hire some. What did those lawyers say? Looks good, looks compliant.
So you've hired counsel, they say, "Good job, green light." Then someone on GitHub says, "But I have a different legal theory than the people you specifically hired to tell you how the law works!"
What do you tell someone in that situation? Fire your counsel and instead rely on advice from random strangers on the internet? Or... there are a lot of people with crazy theories on the internet.
I thought it was big of emcho to, even seeming pretty confident Alvar was mistaken, still put him in touch with his legal team. Because, I'm not a professional GPDR expert, maybe the random internet stranger is right this time? But if Alvar's right, GitHub isn't really equipped to figure that out. This has to be a conversation with lawyers.
Backing up a step...
Zoom rolls their own crypto, routes calls through China, and has a mysterious 10 char hard limit on passwords. They're also massively more popular.
Zoom's CEO has been admirably up front about how they're fixing some of these issues, but I'm not sure why a speculative GPDR complaint about a much less common service should get the same prominent media coverage.
Anyone who has published an app to any of the app stores, recognizes the valuable information than services like crashlytics provide and the hundreds of ways an app can crash on the user devices.
You may be don't like how it is, but as the parent said, that's not an app issue neither github issues is the place to discuss it.
Now, it seems lately others have been getting better, but I'm not really sure what the source of that is; when I've been pulled into Zoom calls over the last five years, they've been absolutely rock-solid.
Their security architecture is ???, and their excuse for its use of servers in PRC to move encryption secrets makes no sense, and honestly gives me the impression that at some level, somebody working on Zoom made that decision with the conscious intention to make secrets available to the PLA.
[1]: This was several years ago, competition these days may be more on par with Zoom. [2]: I imagine windows is becoming more stable these days. Again, my comment may be unfair to modern windows.
This is not something possible (or at least anywhere near as likely) with browser-based conferencing. And zoom really only seems to offer this as a last-ditch option, the vast majority of users I'm certain ending up installing the software.
It's something which I think has received far too little attention amongst the recent security focus over zoom. How traffic is routed is a bit of a red herring if you ask me. The galling thing is how the web community put a lot of effort into figuring out a sensible security model for apps' access to webcams and microphones, and the first thing popular services do is lead people to completely circumvent that and grant permanent high level privileges with seemingly little thought.
To me, these look like things that could be used for local escalation or MITM attacks. This is not good but frankly, for most of Zooms use cases, it's not an issue. The only frightening thing is the turbojpeg.dll one. A POC that leads to an RCE or even a crash would be devastating for Zoom, especially considering the amount of edu setups that don't enforce passwords even now.
IDK, for me and the edu organization I'm responsible for Zoom has been a great offering (especially considering the pricing they were able to offer by default for edu and after very little negotiation) but we are actively looking at teams as a successor for the next semester. Zoom has had 3 killer features over teams (virtual background, easy dial-in, no effort guests) and all of them have gone away now with the recent teams changes. If teams finally gets customer skype calling figured out Zoom will most likely be done in the edu field because that's quite a big part of switching to teams for an all out integrated comms solution, especially since you can't use your office 365 account for consumer skype.
Others, like perhaps an RCE, are not being seen. This is for a lot of reasons.
* Many are being found by whitehats/ researchers, so by the time they're made public an attacker is already playing catch-up - it can take days or weeks to build a good exploit chain, so starting from "A patch is out" or "The vuln is disclosed" is not encouraging.
* In general, exploitation of vulnerabilities is actually quite rare. Patching practices, mitigation strategies, etc, have radically improved over the last decade. It isn't that the attackers can't do it, but the majority of attacks will just phish you, install malware, and try to make money the simplest way possible.
Does that mean you accept that risk of vulnerable software? These are not strong mitigating factors and are mostly about risk profiling and motivation. So that decision is up to you.
And for a sister comment noting their usage of app analytics; all three services that they use are GDPR-compliant, and you can install a "libre" version via F-Droid for Android.
Very, very minor issues in comparison to Zoom's privacy & security issues.