Zoom settles US class action privacy lawsuit for $86m
bbc.com
bbc.com
That is not enough for the damage to my reputation and that of my business. I recommended them to others for privacy important things and showed the advertised 'e2e' that was advertised approved by us gov.
I also used it with several other security professionals to work in tandem on hacked servers. Passwords were not obfuscated do to our belief in the e2e.
Shouldn't we get an opt-out of the class action email?
On the other hand the lawyers get a nice $21m payout.
You can read the original complaint here:
...because courts approve unreasonably low settlements.
(I've had my jab, it's ok).
Lots of people these days are operating primarily on fear; when you are in that sort of pattern-matching mode, any new or unknown situation will by default be evaluated as a potential threat.
Perhaps we should stop creating so many "heads I win, tails you lose" situations for huge swaths of the population. That might have something to do with an overall culture of fear, uncertainty, and doubt in general.
(insert silly Donnie Darko fear/love chalkboard gif here.)
I am not a lawyer and this isn’t legal advice, but you typically get directions on opting out as part of the class action notice you receive: https://www.classaction.org/learn/class-action-opt-out
Many people are probably familiar with receiving notifications about being eligible to receive some token payment as settlement for some lawsuit they never knew existed, if they follow steps X, Y and Z. But how many people know they can follow steps A, B and C and file an objection instead.
It's like changing defaults, opting out of advertising, using an ad blocker, running a PiHole, etc. If you do nothing, you get ads and a crappy experience. That's the default. To get a better experience you have to take action.
The default here is you ignore the notice and get nothing or you respond and get maybe a token payment, the lawyers get large payments and the company gets off the hook, limits their liability and avoids any admission of wrongdoing. If you want a better experience, you have to take action and file an objection.
https://www.classaction.org/blog/class-action-faqs-how-to-ob...
But I also recall a recent comment (I think from a saas founder?) - where they don't claim E2E with thier service as it's using webrtc(?) that needs to decrypt at the relay (stun/turn?) server - then re-encrypt to deliver.
(Which is how I will be preferring ro deliver with webrtc so to avoid direct p2p and ipaddy leaking (trading a user to user privacy for trust in the server relay - good for my situation, not what I'd suggest for most other)
anyhow - that kind of thing would get tricky, is the soft wiregaurd? that is used to peek at the traffic - would (could) show encrypted stuff leaving my box - and give me a false sense of security if zoom was decrypting in the middle - I guess I'd need to find if the data was going p2p somehow. (still learning to be security professional)
we need some way to codify parts of your comment into law, and into people's understanding of the need to have encryption for data others get to play with. - There is a tinge of this in the hippa.
Granted it only concerns US users so this figure is not strictly correct, but it shows privacy in a global service is a central problem that cannot be litigated for in a specific jurisdiction.
Zoom made over $600M in profits in 2020 alone.[1]
This awards members of the class at most $25 - which might materially mean something to an individual (unlikely), but is virtually nothing; furthermore as an accounting line item for Zoom, this is literally not worth batting an eye at. Yes there will be knock on effects of "better training" and scrutiny of messaging/security both internally and externally, but it will effect practically 0 change to their overall bottom line or revenue/profit projections, and there is obviously no legal precedent set or oversight changes that will aid end users moving forward. yay.
What does all of that cost? $21M[2] to law firms. I won't go into the insanity and inanity of billable hours and the profit machine of law in this country, but that point is simply to underscore that those legal firms are the second winners in this. Despite their position and goal - ostensibly and in name only - of aiding the members of the class in seeking a just and fair reward for wrongdoing and bad faith by Zoom.
Meanwhile, as others have commented, reputations and contracts have been burned and sullied, and doubtless money lost along with that, but our legal system is not interested in trying to attach responsibility or reparation to those effects (because they can't necessarily be proven as fault of Zoom).
So the ultrarich get ultraricher.
[1]https://www.sec.gov/ix?doc=/Archives/edgar/data/1585521/0001... [2]https://www.reuters.com/article/zoom-settlement-idUSKBN2F30W...
What personal data was shared? Was the sharing of data the problem, or the T&C's weren't clear on it? The article doesn't mention it.
What are the implications for other companies that share user data to advertising partners?
>What are the implications for other companies that share user data to advertising partners?
If they ask the user and the use says it's OK, then I don't think there would be much of an issue.
Looking at you, TechCrunch.
Certainly. And they know it's an issue. And they know next to no body will sit there an un-check those options. Such dark patterns are replete in this industry. They know, if given the choice, very few people would opt-in. They know this and it continues every day.
$86m/$2.6 billion = 0.033. If I earn $100k per year, that's like a fine of $3300.
Most businesses are structured such that failing isn't disastrous (creditors cannot chase after the owners), whereas a human experiencing financial failure is an extreme life setback.
Corporations lose one day of revenue and continue with business as usual.
In a year with like 300% revenue growth, I feel like Zoom can probably just treat this fine as cost of doing business. I mean, I pay a lot more than $3k in taxes per year!
What if you were making only $25k/year the previous year, and the speeding ticket enabled you to get the job that's making $100k/year?
A wealthy man get's a $625 red light violation, and it's dinner conversation.
A poor man get the same punishment, and it could be the last straw.
I don't think Zoom is profiting from breeching privacy; I think they profit from providing video-meeting software. I think penalizing undesirable behavior that doesn't produce profit will motivate Zoom to take that undesirable behavior very seriously.
Many moons ago, lawyers used to crash the carpool lanes in Washington, DC for about that price given the time they would save and the amount they could bill. The firms just started paying the fines. It wasn't until the penalty started having points and could cost you your drivers license that the behavior stopped.
They are. "Move fast and break things"-strategy is a decision for higher growth at the cost of privacy, security and stability for customers.
I mean, I think it's worthwhile to compare and see how you'd think about this, right? $3k fine seems high in the abstract to me. Then again, if it's viewed as a kind of tax for going from $25k/year in annual income to $100k/year – eh, doesn't sound like much. What do you think?
> Hundreds of people would be laid off for a screwup this big, whole business units shut down.
I am actually curious to see if that's the case – are there any reports of such shutdowns/layoffs?
Entire companies are created and grown based on these dark patterns, which, because the law moves slowly, are not yet fully illegal in a open and shut kind of way.
The punishment doesn't deter enough, because Zoom has been making a ton more money off this and will continue to do so.
It's a bit like Ford's: "Don't ask me how I made my first million", that first million being the hardest part (once you have 999 million, getting to 1 billion is trivial).
If breaking the law is a net benefit for companies, then the only companies you'll be left with in a competitive space are the ones that break the law. So the fines have to be _huge_ to make any meaningful difference.
OTOH the laws that Uber ignores (and then later forces to change) are often a cause of stagnation, and no company would work to get them changed _before_ setting up shop, because even if they succeed then they've just paid the price of admission for all their competitors, too. So I guess I don't have a real solution to offer.
A more logical comparison is profits (net income) to salary, which is the money they keep (like salary). Zoom had net income of $672M in FY2021.
Which means if you earned $100k, that'd be a fine of $12,800.
That's a pretty big fine if you ask me. That's not a slap on the wrist -- that's going to be behavior-changing for most people.
Where do you think my salary goes? Things are pretty expensive.
So when the court is considering fines, they don't go and look at a 3 million dollar fine and go "that's a good fine", they look at the revenue instead and go "the fine can be as much as 400M"
Maybe we can, but that would be stupid.
You are always free to opt out of a class action if you'd prefer what you think you can recover directly.
What value to society do small per-user judgements bring?
They tend to be a negligible percentage of revenue, involve the company denying wrongdoing, and giving an amount valuing a gumball and a mcdonalds meal to people. Really what is the point?
But what percentage of profit? And far more importantly, are they large enough to serve as a disincentive for others to do the same thing in the future? I'd suggest that the popularity of binding arbitration clauses is evidence that the fines are noticeable.
(Note that I refer to class actions in general, not Zoom specifically.)
Considering that 100% of the popular social networks were built on these practices, no. They risk fines of hundreds of millions, maaaaybe billions at most, and they make tens of billions.
They impose some cost on unlawful behavior where the alternative, were they prohibited, would usually be no cost; plaintiff’s attorneys would seek more if the EV of going to trial was enough greater to compensate for the risks, so if you ban the low $/user settlements z you aren't getting bigger settlements, you are get fewer class actions filed even with meritorious claims.
Class actions largely exist for diffuse harms where low per-class-member damages make it not worth individual direct action lawsuits, so banning small per-member awards is effectively eliminating recovery in most of the space class actions exist to serve, outside of suicide-bomber litigants (that is, litigants who are willing to take a negative EV to make sure that a wrongdoer pays.)
I really think that we need some sort of standard definition for what this actually means. Pretty much everything claims E2EE these days just as long as there is some sort of encryption used somewhere in their system. Many (most?) are not doing something that would mean that only the end users would have access to the content, even in the face of assertive actions by the provider. Many get the technical details right but fail to properly inform the user about any critical actions required on the part of the user to make that possible.
Providers of such things should be expected to explicitly state who you need to trust and under what circumstances.
If they're using these third party services they should absolutely have that listed in their privacy policy, but even if the end result is the same, the intention is completely different between the two.
The courts are public and law can be made from new interpretations and context (precedent). Coinbase, Kraken, etc have forced arbitration. Can this be overturned when a new interpretation (say securities law) could be made by a court in the open, vs arbitration which is private?
https://www.tweaktown.com/news/80791/clubhouse-data-hacked-3...