HNHacker News
TopNewBestAskShowJobs

madwhitehatter

1 karma · joined March 25, 2020

submissionscomments
madwhitehatter··on Zoom admits some calls were routed through China by mistake
https://jobs.51job.com/yx/co5065032.html

Mistake? whoops

madwhitehatter··on Zoom needs to clean up its privacy act
So were the people who got all your data
madwhitehatter··on Zoom’s Use of Facebook’s SDK in iOS Client
https://www.theregister.co.uk/2020/03/27/doc_searls_zoom_pri...
madwhitehatter··on Zoom’s Use of Facebook’s SDK in iOS Client
No, they don't? There are very few companies that record your phone calls/video calls, then transcribe them into text. Then store the data for themselves. This includes any data that we shared in the session. Why can't Zoom just come out and explain why they do this? Seems pretty simple. If you asked me?
madwhitehatter··on Zoom’s Use of Facebook’s SDK in iOS Client
This is what scares most security analysts is the fact that the product was developed and stores data in a place that has incredibly sketchy laws when it comes to intellectual property.

I can't see why Zoom can't come out with a statement regarding why they are collecting all of this sensitive data.

Big corporations might be sharing stuff unwittingly with people that they don't want to share it with.

https://www.sec.gov/Archives/edgar/data/1585521/000119312519...

Top of page 21 in their SEC filing:

"In addition, we have a high concentration of research and development personnel in China, which could expose us to market scrutiny regarding the integrity of our solution or data security features. Any security compromise in our industry, whether actual or perceived, could harm our reputation, erode confidence in the effectiveness of our security measures, negatively affect our ability to attract new customers and hosts, cause existing customers to elect not to renew their subscriptions or subject us to third-party lawsuits, regulatory fines or other action or liability, which could harm our business."

madwhitehatter··on Zoom’s Use of Facebook’s SDK in iOS Client
From security perspective, Companies do not like the fact that Zoom was developed in China and the vast majority of its R&D is still in China. China has different rules on security than many other countries. Particularly surrounding intellectual property. https://www.sec.gov/Archives/edgar/data/1585521/000119312519...

"Top of page 21- In addition, we have a high concentration of research and development personnel in China, which could expose us to market scrutiny regarding the integrity of our solution or data security features. Any security compromise in our industry, whether actual or perceived, could harm our reputation, erode confidence in the effectiveness of our security measures, negatively affect our ability to attract new customers and hosts, cause existing customers to elect not to renew their subscriptions or subject us to third-party lawsuits, regulatory fines or other action or liability, which could harm our business."

madwhitehatter··on Zoom needs to clean up its privacy act
Why do they have to record calls? Transcribe the call into text then Store it. Why do they need to take copies of whiteboards and PowerPoint’s it’s does not make sense.
madwhitehatter··on Zoom needs to clean up its privacy act
They record and transcribe all calls why? Where do they store it? Why do they store it?
madwhitehatter··on Zoom needs to clean up its privacy act
This goes much deeper than add data. The collect PowerPoints and record and transcribe all calls this is. And it’s unencrypted
madwhitehatter··on Zoom needs to clean up its privacy act
Zoom was developed in China

Look at the top of page 21 of their sec submission. https://www.sec.gov/Archives/edgar/data/1585521/000119312519...

madwhitehatter··on Zoom monitors activity on your computer
https://www.infosecurity-magazine.com/news/uk-government-zoo...

https://www.sec.gov/Archives/edgar/data/1585521/000119312519...

The top of page 21 in the first set of SEC documents:

Quote " Many governments have enacted laws requiring companies to provide notice of data security incidents involving certain types of personal data. In addition, some of our customers require us to notify them of data security breaches. Security compromises experienced by our competitors, by our customers or by us may lead to public disclosures, which may lead to widespread negative publicity. In addition, we have a high concentration of research and development personnel in China, which could expose us to market scrutiny regarding the integrity of our solution or data security features. Any security compromise in our industry, whether actual or perceived, could harm our reputation, erode confidence in the effectiveness of our security measures, negatively affect our ability to attract new customers and hosts, cause existing customers to elect not to renew their subscriptions or subject us to third-party lawsuits, regulatory fines or other action or liability, which could harm our business. "

madwhitehatter··on Zoom monitors activity on your computer
The question is, why doesn't Zoom use WebRTC in favor of the plug-in. WebRTC uses the SRTP Cryptosuite which is pretty secure and can be made very secure https://wiki.freepbx.org/display/DIMG/SRTP+Cryptosuite

Zoom is unencrypted by default? So you have to physically turn encryption on. Also, it is very unclear if your data is encrypted at rest. "End to end encryption" does not necessarily mean "end-to-end encryption" as has been shown many times before

madwhitehatter··on Zoom monitors activity on your computer
https://www.forbes.com/sites/kateoflahertyuk/2020/03/25/zoom...

Still seeing loads of red flags in mainstream media. This is not a Secure business tool

madwhitehatter··on Using Zoom? Here are the privacy issues you need to be aware of
https://metro.co.uk/2020/03/25/concern-zoom-video-conferenci...
madwhitehatter··on Using Zoom? Here are the privacy issues you need to be aware of
The U.K. MOD has BANNED zoom what do they know
madwhitehatter··on Zoom monitors activity on your computer
The one thing nobody ever mentions about this is the Chinese connection. Zoom is 100% developed in China. They have a datacentre in tianjin. Even states in their financial papers. The S1 form that one of the risks is the fact the product is predominantly developed in China. By PRC citizens.

Encryption is also off by default? why is this?

The Zoom App also collects screenshots and transcriptions of shared data. This is fine if you are Facebook or Google.