TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Zoom still don't understand GDPR

451 pointsby andrewnicolaldeover 4 years ago

31 comments

1vuio0pswjnm7over 4 years ago
I love how when you go to enter a Zoom meeting, they bury the no-install, run-in-browser link in small type in a footer. And then, if you manage to see the link and use the browser, they withhold "Gallery View", forcing you to deal with the extremely annoying "Active Speaker View".
评论 #24300677 未加载
评论 #24301674 未加载
评论 #24300678 未加载
评论 #24301937 未加载
评论 #24300684 未加载
评论 #24300872 未加载
评论 #24300505 未加载
评论 #24304858 未加载
评论 #24303197 未加载
评论 #24301160 未加载
评论 #24300439 未加载
评论 #24302480 未加载
评论 #24303109 未加载
评论 #24302027 未加载
评论 #24302041 未加载
DenseCometover 4 years ago
It&#x27;s unfortunate that they bought and destroyed Keybase [1] in a bid to improve their security and even still there seems to be no improvement. Guess even the best folks can&#x27;t make an impact if company culture prevents it.<p>[1] <a href="https:&#x2F;&#x2F;github.com&#x2F;keybase&#x2F;client&#x2F;graphs&#x2F;commit-activity" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;keybase&#x2F;client&#x2F;graphs&#x2F;commit-activity</a>
评论 #24300669 未加载
评论 #24303320 未加载
评论 #24300705 未加载
评论 #24300744 未加载
评论 #24300638 未加载
评论 #24303937 未加载
评论 #24303274 未加载
saagarjhaover 4 years ago
C&#x27;mon, what does it take for Zoom to understand that when people uninstall software they don&#x27;t want parts of it to stick around forever?
评论 #24300462 未加载
评论 #24300529 未加载
评论 #24300431 未加载
评论 #24300765 未加载
评论 #24301149 未加载
评论 #24300478 未加载
评论 #24300466 未加载
laurent92over 4 years ago
Why do you guys not use <a href="https:&#x2F;&#x2F;whereby.com" rel="nofollow">https:&#x2F;&#x2F;whereby.com</a> (formerly appear.in), it’s free for 4 people, in-browser only, no-login, WebRTC, allows sharing the screen alongside faces.<p>But they made the 5+ rooms $9 per month, which is way too expensive. There are not enough competitors for WebRTC conf tools, it should be quite simple and $4-5 a month (WebRTC doesn’t incur data costs on the servers since the data is peer-to-peer).
评论 #24302361 未加载
评论 #24302818 未加载
评论 #24303044 未加载
评论 #24302148 未加载
评论 #24302153 未加载
morpheuskafkaover 4 years ago
This is what we need app sandboxing for. No reason third-party apps should be able to read the browser&#x27;s cookie database.
评论 #24301691 未加载
评论 #24303098 未加载
s_devover 4 years ago
It is difficult to get a man to understand something when his salary depends upon his not understanding it. -- Upton Sinclair
edoceoover 4 years ago
Brief: adds cookies to Chrome on the UNinstall process. Includes a funny &quot;everlogin&quot; one that lasts 10yr
评论 #24300457 未加载
jjluomaover 4 years ago
At least zoom has privacy statement &#x2F; policy page available on their web site unlike threatspike.com
评论 #24301188 未加载
评论 #24300822 未加载
nojvekover 4 years ago
Have you seen Zoom’s stock price? Wall Street don’t give a shit about security unless the company goes under due to a massive fine.<p>Let’s accept the fact that US govt doesn’t give a shit about little privacy&#x2F;security like this. EU will sometimes strike a big hammer but even that is sporadic.<p>Zoom has built momentum on “dark growth hacks” and they’re reaping the rewards. This is standard Silicon Valley.
nedsmaover 4 years ago
Zoom is a joke on Linux. You enter a meeting, it goes automatically into full screen mode and when you put in windowed mode, the window can get lost. Then you need to reconnect the session.
irjustinover 4 years ago
I argue Zoom does understand GDPR and the ePrivacy Directive from a legal perspective.<p>The specific citation about the length of a cookie is a recommendation and not a law[0]. The key word is &#x27;should&#x27;.<p>I&#x27;m not a lawyer nor claim the ability to interpret GDPR legally, but I have seen companies that actively worked to edge case GDPR to their advantage (I was part of one). We would have lawyers and other &#x27;GDPR experts&#x27; tell us what was possible and what wasn&#x27;t then simply extend into the grey area.<p>Here, I reject the Halon&#x27;s Razor[1].<p>[0] <a href="https:&#x2F;&#x2F;gdpr.eu&#x2F;cookies&#x2F;#:~:text=All%20persistent%20cookies%20have%20an,you%20do%20not%20take%20action" rel="nofollow">https:&#x2F;&#x2F;gdpr.eu&#x2F;cookies&#x2F;#:~:text=All%20persistent%20cookies%...</a>.<p>[1] <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Hanlon%27s_razor" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Hanlon%27s_razor</a>
评论 #24300913 未加载
评论 #24301589 未加载
chromedevover 4 years ago
Google Meet features seem so much better suited for government and education, especially if using G Suite on top of it. It is like the same price of Zoom but includes a lot of other great features, including unlimited storage using Google Drive.
JumpCrisscrossover 4 years ago
Does anyone expect any consequences? It’s not like any EU member would ban Zoom in the middle of the pandemic.
评论 #24303297 未加载
johnchristopherover 4 years ago
Why is an uninstaller allow to access a browser&#x27;s files on the first place and then modify it? There&#x27;s a name for that category of software.
评论 #24305861 未加载
andrewnicolaldeover 4 years ago
Disclaimer: I used to work at ThreatSpike Labs but left before this article was written and before any of the findings on this article were discovered.
评论 #24300500 未加载
评论 #24300386 未加载
m3kw9over 4 years ago
It seem Zoom is so big that a small bone to pick on can yield clicks for them.
评论 #24301043 未加载
IvanSologubover 4 years ago
Read between the lines: a company established on the territory of a state where there is no concept of &quot;private property&quot; does not understand that it is impossible to collect personal data.
评论 #24305678 未加载
daffyover 4 years ago
If you have run the native programme (for me it keeps breaking up in the browser), run it from a dedicated unpriviledged user, without installing it on the system. (Run .&#x2F;opt&#x2F;zoom&#x2F;ZoomLauncher.) If you have to log in (I couldn&#x27;t change the input device without logging in), when your browser tries to open the not installed programme, copy the link and give it as a command-line argument to ZoomLauncher.<p>Looking forward to a working alternative.
azepoiover 4 years ago
I really don&#x27;t like how Zoom forces the download of an executable, how doesn&#x27;t this trip the antimalware? What a bad practice.
评论 #24303246 未加载
setzer22over 4 years ago
I find the name of the <i>NPS_0487a3ac_throttle</i> cookie suspicious enough, but the article does not comment on it. Is this a common practice? Throttling the website for users who uninstalled your application?
gojomoover 4 years ago
I&#x27;m sure Zoom would be doing privacy-iffy things even if in full compliance with the GDPRAnd the possibility they might be surveying other cookies, and uploading them elsewhere, would be a giant concern if verified.<p>But the specific complaint here, about a cookie with an expiration longer-than-12-months, seems pretty silly.<p>It&#x27;s not stored on some remote machine - it&#x27;s stored locally, transparently. The user – and their own software – can control this easily &amp; completely. If there&#x27;s a good rationale for expiring cookies earlier, a browser can easily do it directly - it needn&#x27;t involve regulators, or ineffectually hoping every one of thousands of different companies&#x2F;websites do something the laws of one place ask.
whereistimboover 4 years ago
Why people still uses zoom? Something like Google Meet or Microsoft Teams are better.
评论 #24303486 未加载
评论 #24303634 未加载
评论 #24304116 未加载
评论 #24303291 未加载
chrisjudice09over 4 years ago
This is excellent work by threatspike and we should commend&#x2F;support efforts like this that help keep us informed of the sneaky and intrusive actions of certain pieces of software
ubermonkeyover 4 years ago
My bet is that Zoom <i>understand</i> the GDPR just fine, and don&#x27;t care.<p>They have repeatedly shown that they will do whatever they want, and then act contrite later if they&#x27;re caught out. They are not trustworthy, and I won&#x27;t run their software on any nonsandboxed environment AT ALL. There&#x27;s utterly no reason to.
tomschwihaover 4 years ago
The author is referring to the ePrivacy directive - its not the same as the GDPR.<p>Does he mean the ePrivacy regulation?<p>The ePrivacy regulation (not directive) is no binding law yet.
Kiroover 4 years ago
Maybe it&#x27;s obvious but how does this break GDPR?
评论 #24303186 未加载
评论 #24303528 未加载
aminozuurover 4 years ago
*doesn&#x27;t
评论 #24303499 未加载
评论 #24301711 未加载
评论 #24303253 未加载
xtatover 4 years ago
Zoom is terrible, but when you deep dive into GDPR it&#x27;s pretty clear that nobody understands it.
TedDoesntTalkover 4 years ago
As an American company, are they subject to GDPR regulations?
评论 #24301987 未加载
awinter-pyover 4 years ago
wow as with everything that&#x27;s come out about them it feels like they&#x27;re trying to get the job done but with limited platform support and badly<p>it&#x27;s not absurd for a product manager to want your desktop zoom app to inherit your browser login<p>though as a user if I saw this behavior I would have a few wtfs. But as a user I would <i>never ever</i> install zoom on a laptop<p>my takeaway from this isn&#x27;t GDPR implications, it&#x27;s that desktop OSes need to get serious about permissions, especially filesystem walkabouts
评论 #24306424 未加载
评论 #24300537 未加载
robflahertyover 4 years ago
“Zoom cookies are firstly written when the user connects to the website zoom.us and accepts the cookies options.”<p>That was the moment Zoom received your consent to store data transmitted by cookies. Adding a few more cookies to the pile, regardless of expiration date, doesn’t change the agreement.<p>Rummaging round the cookie bin on uninstall is a nice find and deserves a raised eyebrow but this doesn’t really have anything to do with GDPR.
评论 #24303498 未加载
评论 #24302807 未加载