8 ms·
Zoom monitors activity on your computer
- threatofrain 6y agoFrom https://zoom.us/privacy https://zoom.us/privacy: > Whether you have Zoom account or not, we may collect Personal Data from or about you when you use or otherwise interact with our Products. We may gather the following categories of Personal Data about you: > - Information commonly used to identify you, such as your name, user name, physical address, email address, phone numbers, and other similar identifiers > - Information about your job, such as your title and employer > - Credit/debit card or other payment information > - Facebook profile information (when you use Facebook to log-in to our Products or to create an account for our Products) > - General information about your product and service preferences > - Information about your device, network, and internet connection, such as your IP address(es), MAC address, other device ID (UDID), device type, operating system type and version, and client version > - Information about your usage of or other interaction with our Products (“Usage Information”) > - Other information you upload, provide, or create while using the service ("Customer Content"), as further detailed in the “Customer Content” section below
- aquadrop 6y agoThese don't look that bad, but what's describe in a tweet (tracking focus app etc) is much worse, it doesn't seem to be in the privacy policy though (or they masked it?). So where's the information about focused window come from?
- neonate 6y agoYour name, physical address, email address, phone number, employment, credit card, Facebook profile, IP address, MAC address, device ID...is not that bad?
- Turing_Machine 6y agoHow are they supposed to charge you for the service without your credit card billing information? How is it supposed to work at all without your IP address?
- manigandham 6y agoThat data is either required to run or provided to them by you directly.
- neonate 6y agoI haven't provided them with most of that.
- manigandham 6y agoThen they don't have it.
- neonate 6y agoHow do you know that? These statements leave other possibilities open: It covers all Personal Data that you affirmatively provide during your interactions with us, information that we automatically collect when you interact with our Products, and information that we collect about you from third parties Whether you have Zoom account or not, we may collect Personal Data from or about you when you use or otherwise interact with our Products.
- manigandham 6y agoIt says "when you use or otherwise interact with our Products." It's not unreasonable. I'm not sure what your claim is here, because you'll find this language in every single online business. You realize Zoom sells enterprise video conferencing right? They have no use for your data otherwise.
- gray_-_wolf 6y agoI think other running programs would fall under > information that we collect about you from third parties
- manigandham 6y ago
- aquadrop 6y agoThese are technical details for normally working with the app. They charge you, so they need you name and credit card. You ask for a support, so they need your ip etc. They list what they may gather, because privacy policy should cover everything, doesn't mean they require all that info at once. I also didn't provide them many of these items.
- deathhand 6y agoThere is a feature for when doing webinars that can track focus: https://support.zoom.us/hc/en-us/articles/115000538083-Attendee-attention-tracking?mobile_site=true https://support.zoom.us/hc/en-us/articles/115000538083-Atten...
- vpzom 6y agoThat's awful.
- riteshpatel 6y agoIt only tracks if the Zoom window has focus, not via facial recognition. How is that bad?
- gsich 6y agoWhat value is that if I have multiple monitors?
- neonate 6y agoThat's shocking. How are they able to collect this?
- dahfizz 6y agoIs that a technical question? All of that information is immediately available because you typed it in when you made your account, or because of the nature of the internet. Seriously, you've given this information to any service you've ever signed up for and / or ran.
- lloeki 6y agoCould it be CYA legalese because there’s a screen sharing feature?
- blakesterz 6y agoThis is the part that is not so reassuring: Does Zoom sell Personal Data? No part of that paragraph makes me feel better, and it ends with this... " If you opt out of “sale” of your info, your Personal Data that may have been used for these activities will no longer be shared with third parties."
- deleted 6y ago[deleted]
- Nextgrid 6y ago> your name, user name, physical address, email address, phone numbers, and other similar identifiers My problem with this isn't the info they collect, it's how they would collect it, which this privacy policy doesn't seem to clarify. As it stands, this policy technically gives them the right to crawl through all my personal files or even listen using the microphone to search for and collect this information. I'm not saying they are doing this, but the policy is not reassuring. I wish there was enforced legislation (so GDPR is excluded, as regulators don't give a fuck) to curb this. There should be a legal requirement describing exactly the information collected, how is it collected, transmitted, sorted and which third-parties it is given to, if any.
- manigandham 6y agoThis is standard language to cover everything in normal use. Billing details is obvious. Profile info is provided when you signup and use the service. The system info is used to run and optimize the calls. Zoom isn't actively scraping your info, and there's 0 evidence of anything in the Tweet.
- jjoonathan 6y agoLawyerspeak: "It's just boilerplate." Translation: "Yeah, that's one of the parts where we really screw you, but you don't have a choice, lol."
- jkdrki9 6y agoWe do though. Apply our agency to providing free software solutions that don’t that. I suppose it’s easier to be a nihilist and complain though.
- ganstyles 6y agoLet me tell work that I can't collaborate remotely anymore on video because I am using my agency to refuse to use Zoom even though everyone else at the whole company does. Then they can use their agency to put me on a PIP because my choice hindered my ability to do my job. I'm sure you realize it's not as easy as you say, but I suppose it's easier to assert that situations don't have nuance because then you can make blanket statements like you did.
- manigandham 6y agoAre you ok with all the other software they use?
- manigandham 6y agoYou have a choice to not use Zoom.
- 6y ago
- kelnos 6y agoSo, all this doesn't sound great, but... the specific accusation in the tweet is that they're tracking other applications that are open. Their privacy policy does not say they do that, and the Zoom twitter account says they don't either[0]. Now, it's a matter of trust, of course (and after [1] I wouldn't blame people for a lack of trust), but to state authoritatively that Zoom tracks other open applications seems like completely unsubstantiated fear-mongering. [0] https://twitter.com/zoom_us/status/1241768006327336963 https://twitter.com/zoom_us/status/1241768006327336963 [1] https://www.schneier.com/blog/archives/2019/07/zoom_vulnerabil.html https://www.schneier.com/blog/archives/2019/07/zoom_vulnerab...
- gsich 6y agoAll points are so vague that this behaviour might be in either: - General information about your product and service preferences - Information about your device, network, and internet connection ... - Information about your usage of or other interaction with our Products - Other information you upload, provide, or create while using the service
- kelnos 6y agoSure, as I said, the privacy policy isn't great, but the tweet specifically accused Zoom of tracking and recording what other applications people are running. There seems to be no evidence of that.
- raverbashing 6y agoYes if you use the app you need to enter some information for example, profile, login to an account, etc That being said, I don't see anything surprising on the list. > such as your name, user name, physical address, email address, phone numbers, and other similar identifiers That sounds like billing information
- robin_reala 6y agoThe GDPR’s specific, granular and informed clauses for opt-in couldn’t have been more timely. I wonder how long it is before Zoom have to stop providing services to the EU?
- lghh 6y agoDownside of what may be a societal long term shift to work from home is even LESS privacy. I find that ironic, but not surprising.
- deleted 6y ago[deleted]
- maxerickson 6y agoAt least most work from home roles justify company owned equipment. I certainly avoid mixing activities (I don't have access to a company computer at home, but I don't use the work computer or network for personal stuff).
- kube-system 6y agoI'm not sure this is an example of that. It is not atypical for office buildings to have cameras/timeclocks/access control which records the movements of employees throughout the day, packet inspection and/or MITM of your network traffic, and a boss that literally looks over your shoulder.
- DyslexicAtheist 6y agoIf Zoom would be a Chinese company they'd immediately be branded threat-actor! A company that bypasses security controls on the host[1] has no place in a corporate network, covid19 crisis or not. [1] see news from ca July 2019
- kube-system 6y agoYes, governance is of material importance to privacy.
- smitty1e 6y agoGoes without saying that there is massive "pattern of life" info emitted by what you attend and with whom. No wonder it's such a great little product.
- rdxm 6y agowould have thought people learned their lesson w.r.t. this product with the first round of douchebaggery vis-a-vis the hidden http server. that said, FB still has a billion+ users...people are stupid.
- thorum 6y agoThanks for the heads up, just uninstalled.
- griphook 6y agoDoes anybody have a good alternative to zoom that does not do this?
- sahaskatta 6y agoI've been using both Uberconference and Google Meet (G Suite only). Both of these run entirely in a browser without any extensions or applications.
- _ink_ 6y agoAn open source alternative might be Jitsi Meet https://jitsi.org/jitsi-meet/ https://jitsi.org/jitsi-meet/. I haven't tried it though.
- ourcat 6y agoGoogle Duo? https://duo.google.com/about/ https://duo.google.com/about/
- oever 6y agohttps://sip2sip.info/ https://sip2sip.info/ powered by https://sylkserver.com/ https://sylkserver.com/
- dpwm 6y agoIf you would prefer to self host, there's always FreeSWITCH [0]. It can act as a server for meetings. There is a webRTC client called Verto Communicator that seems to work quite well, or you can use SIP clients. The documentation is a bit lacking, but it's actually a very capable system for unifying voice, video and chat communications – and a whole lot more. [0] https://freeswitch.com/ https://freeswitch.com/
- EGreg 6y agoThat’s why we have been building https://qbix.com/platform https://qbix.com/platform To have an open source alternative. Want videoconferencing on your own site? You can! See here for instance. https://yang2020.app/meeting https://yang2020.app/meeting We have a harder challenge of making all the SDP offers work cross browser, but Chrome should def work. Code: https://github.com/Qbix https://github.com/Qbix (If you like it, star it lol ⭐️) Contact me if you want to learn how to use the Qbix platform. I will be teaching classes and put it online. We are following the wordpress model. My email is in https://qbix.com/about https://qbix.com/about Quick question for the networking experts here... with everyone connecting from home, what percentage are behind a LAN firewall that you need to use TURN servers? What if you avoided those servers and made peer to peer infra entirely, how many people would we lose? (Is a complete graph of everyone sending to everyone worse than an SFU once you get too many users? Isn’t it exactly the same number of streams, just in a star topology? Can’t we just nominate a few of the browsers to do what the SFU does, namely forwarding video to the others? Is the issue only with resolution?)
- kelnos 6y agowith everyone connecting from home, what percentage are behind a LAN firewall From home? Essentially 100%. that you need to use TURN servers? That's less clear. I'm not sure how many home firewalls are impenetrable by STUN as well. I worked on Twilio's WebRTC-based audio product back in 2012-2014. In the beginning we only supported STUN. We did get some customer support requests about initial connection failures (which I mostly attributed to STUN failures), but never kept track of stats on what the success/fail ratio was. We eventually added TURN support (after I left that product team), but based on how long it took us to do that, my guess would be STUN was effective for most setups. Also consider that many (most?) of our users were probably behind restrictive corporate firewalls, and I'd expect home firewalls to be more lenient.
- SahAssar 6y ago> Can’t we just nominate a few of the browsers to do what the SFU does, namely forwarding video to the others? IIRC this is basically what skype did back when it was P2P, those clients were called supernodes and would route calls for clients that could not be directly P2P. To be a supernode you needed to be internet-routable and have good bandwidth. Supernodes could be used for hole punching or to relay calls (as you talk about). See more here: https://en.wikipedia.org/wiki/Skype_protocol https://en.wikipedia.org/wiki/Skype_protocol
- Mathnerd314 6y agoEFF seems to be the source: https://www.eff.org/deeplinks/2020/03/what-you-should-know-about-online-tools-during-covid-19-crisis https://www.eff.org/deeplinks/2020/03/what-you-should-know-a... > If attendees of a meeting do not have the Zoom video window in focus during a call where the host is screen-sharing, after 30 seconds the host can see indicators next to each participant’s name indicating that the Zoom window is not active. It doesn't seem too invasive, although of course it'd still be annoying if you have two monitors etc.
- dmurray 6y agoIt seems reasonable for Zoom or any app to know whether its window has focus. That doesn't imply spying on anything else you're doing.
- bobwaycott 6y agoI think the issue is not that Zoom knows if its application window has focus, but that it reports focus state to anyone other than the user. For example: 1. Zoom knows it’s not focused on Bob’s machine, and notifies Bob that someone has begun sharing their screen. 2. Zoom knows it’s not focused on Bob’s machine and notifies Sally of this. Scenario 1 seems acceptable and helpful. Scenario 2 is invasive and unnecessary.
- ss3000 6y agoThis reminds me of read receipts in chat apps. Hate them with a passion. I usually just leave the chat itself unopened and read the notifications until I'm ready to actually reply.
- dx034 6y agoIt can be helpful for certain scenarios. And others don't have to enable it. For companies, at least in the enterprise plan you can also disable it company-wide (according to reports by others). So companies can simply opt out for everyone.
- eddyg 6y ago
- systemvoltage 6y agoI also heard that Zoom has a lot of CCP influence in terms of its investment mix, CEO is Chinese (take it with a grain of salt) and generally, there is nervousness around the chinese influence and surveillance.
- dasil003 6y agoSpeculation based on racial profiling, aside from the obvious fairness issues, is actively damaging to the privacy cause in the US because it frames the issue in nationalist terms. This diverts attention from the more insidious threat of American government spying on American citizens, slowly boiling the frog of our privacy and paving the way for a future repressive regime and police state.
- digitalboss 6y agovia Zoom Support Reply: https://twitter.com/zoom_us/status/1241768006327336963 https://twitter.com/zoom_us/status/1241768006327336963 "Hi, attention tracking feature is off by default - once enabled, hosts can tell if participants have the App open and active when the screen-sharing feature is in use. It does not track any aspects of your audio/video or other applications on your window." Points to this article: https://support.zoom.us/hc/en-us/articles/115000538083-Attendee-attention-tracking https://support.zoom.us/hc/en-us/articles/115000538083-Atten...
- matsemann 6y agoThe twitter thread in the OP says "collects data on the programs running" without backing anything up. Seems like FUD from the face of it. Yes, the privacy may not be perfect (according to EFF admins can see time spent by others in the organization on meetings etc.), and zoom can notify the meeting organizer about participants not having the window in focus. But that's it? Not exactly the gravity touted in the linked twitter thread, saying "If you manage the calls, you can monitor what programs users on the call are running as well". No proof of that... Kinda scared by how much a single tweet can make something blow up, without a shred of evidence backing the claims up.
- IggleSniggle 6y agoThe more interesting aspect to me from the EFF article was that admins can also see your geolocation, who you are meeting with and when, etc. Basically, if Zoom is your platform for communicating, your Zoom admin knows a LOT of metadata about your people that they might not be aware is knowable.
- robin_reala 6y agoAll of which doesn’t say whether it’s the host or the attendee that gets to determine whether this feature is on or off.
- thinkingemote 6y agois the feature to be enabled by the host? Or by each individual participant?
- magwa101 6y agoYeah, hello, delete it.
- skc 6y agoNow is probably the worst possible time to reveal this news. Because right now, people have much more pressing matters and need to communicate.
- thinkingemote 6y agoNow is the time to be on our guard, much more than in times of peace and quiet.
- anonu 6y agoThat's messed up. Our zoom usage at the company has skyrocketed these past few weeks. I was marveling at how smooth and seamless the process was. Though I was a bit peeved zoom always steers you to the installed app instead of keeping it in the browser. Now I know why...
- deleted 6y ago[deleted]
- scarface74 6y agoIs anyone surprised? https://www.zdnet.com/article/zoom-defends-use-of-local-web-server-on-macs-after-security-report/ https://www.zdnet.com/article/zoom-defends-use-of-local-web-...
- valuearb 6y agoDidn't Apple shut that down?
- scarface74 6y agoYes. And people on HN complained that it is yet another example of Apple “locking down” the Mac for killing an app that secretly installed a backdoor and let an app reinstall itself.
- discreditable 6y agoWhen someone sends you a zoom invite, cancel the download, then click the having problems link to download again. Cancel it again. It will show you a link to join by browser. A few other meeting apps have dark patterns like this. One of my favorite things about Hangouts Meet is it's web first.
- chadlavi 6y agoThanks for this! I've just been refusing to use it
- tympan 6y agoDiscord seems to be better than most others
- ilikepi 6y agoI tested "Join by Browser" recently. On macOS (Mojave), it only seemed to work in Chrome, and the video resolution of the other person was poor, but it did work. Also, I did not need to click a "Having problems" link before the "Join by browser" link to appear, so maybe this feature is being deployed more widely now. Since you mentioned Google Meet, I recently tried that with a group of 6-7 people, and it only lasted about 10 minutes before multiple participants (myself included) started having issues. It seems like it needs more time to bake, but since we're talking about Google, it's probably unlikely to ever receive that time before they kill it and reinvent it a year later.
- saltcured 6y agoThere is an account preference option for the one scheduling new meetings whether the join with browser link is present in meeting landing pages. At least, that's how it works with our university license...
- colatkinson 6y agoWe've been using Google Meet at my work for daily "standups." Typically 4-6 people, lasting 15-30 mins. Been very smooth sailing, even using Firefox. Out of curiosity, what kind of issues were you running into?
- jfolkins 6y agoSuper timely. Even on my linux box I noticed yesterday that zoom, even though I had "closed" the application, was still running `ps -ef | grep zoom` so I killed it. After reading this, I've deleted it too. Super weird.
- flyinghamster 6y agoI saw a tray icon after I closed it out when I ran it this morning, on Xubuntu with the Cinnamon desktop. I right-clicked it and selected Exit, and it did indeed exit. ETA: Checking the dpkg file listing shows that everything goes into /opt/zoom except a /usr/bin/zoom symlink to /opt/zoom/ZoomLauncher.
- hackeerTwo 6y agoTrue, I used zoom about a month ago and it's still running a process in the background.
- tripzilch 6y agoUm, why haven't you killed it?
- williesleg 6y agoYeah and my phone watches everything I do too. Data is the new oil and we're all sheeple.
- yadongwen 6y agoIs it related to screen sharing? They allow sharing a specific window. Without knowing about other processes you may not share the window. You have to specifically allow it in System Preference on Mac though.
- DyslexicAtheist 6y agothis isn't the first time zoom got caught red-handed[1]. Last year they were called out for installing a local web server in order to disable security controls to get around the deprecated NPAPI[2] ... this is literally what malware does. About the same time this story broke I interviewed for a Paris based AppSec company and their CTO asked me to install Zoom. It was really awkward because I had to ask: "Is this a trick question??" Seriously I wouldn't touch Zoom with a 20 foot stick! [1] https://medium.com/bugbountywriteup/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5 https://medium.com/bugbountywriteup/zoom-zero-day-4-million-... [2] https://en.wikipedia.org/wiki/NPAPI https://en.wikipedia.org/wiki/NPAPI
- barbs 6y agoDoes https://jitsi.org/ https://jitsi.org/ solve these problems?
- EastSmith 6y agoPretty low move by Zoom. Again. There is nothing in their interface letting users know they've been monitored. Nothing.
- fulldecent2 6y agoI don't use Zoom. But I'll assume it's the same as Google Meet and so now I'll complain about Google Meet. 1. When the call quality is less than 100%, it is difficult to attribute this blame to the other person, my equipment, my connection, or the service provider. A heartbeat signal could fix this. 2. When somebody else is presenting, I can't point on THEIR screen. I have fumble through "higher, higher, too high, it's on the bar, do you see the bar?, yes, click on that one, you're right it doesn't really look like a pencil does it?"
- yuva123 6y agoHello all I am taking cless via zoom meeting someone come and type fuck you how can find who is he can you help me in this how can find id and ip address
- jvanveen 6y agoWorking on a webbased foss sip/WebRTC/p2p conferencing solution(WIP): https://github.com/garage11/ca11 https://github.com/garage11/ca11
- lostmsu 6y agoI made a simple sandboxed WebView wrapper for Windows, that should address the privacy issue and remove the annoying need to deal with constant "download the app" nagging: https://losttech.software/Downloads/FuZoom/ https://losttech.software/Downloads/FuZoom/
- change_yourself 6y agoTruly, I was passing an online interview on programming position, and almost in the end of the process I had remembered that I could be asked on the design patterns, I opened browser, came to the site with patterns' descriptions and... the interviewer's last questions was: "I think that's all... But I have yet one question on the design patterns."
- madwhitehatter 6y agohttps://www.forbes.com/sites/kateoflahertyuk/2020/03/25/zooms-a-lifeline-during-covid-19-this-is-why-its-also-a-privacy-risk/#195e68d328ba https://www.forbes.com/sites/kateoflahertyuk/2020/03/25/zoom... Still seeing loads of red flags in mainstream media. This is not a Secure business tool