8 ms·
I think thats fair. All of us who have written and deployed software know that a change in the onboarding/new users rate like this would be a punch in the face
by Msurrow 7y ago
I think thats fair. All of us who have written and deployed software know that a change in the onboarding/new users rate like this would be a punch in the face that would knock any SW team on its ass. And it would take anyone a few days to get back up.
The important part is the leaderships reaction to the situation. Compare to something like Boeing. Zoom acknowledges facts, takes responsibilty and starts fixing things. Boeings reaction to its product killing hundreds of people was “Lol user error. RTFM”. That is (apparently) what acceptable leadership can look like..
Any sw product has issues. The question is what the company does about it
- Nullabillity 7y agoErr, no. It would be understandable if their servers buckled under the load or something. Zoom's blatant disregard for their users' security and privacy is unacceptable regardless of whether they have 5 or 5 million users. > Any sw product has issues. The question is what the company does about it See https://news.ycombinator.com/item?id=20389812 https://news.ycombinator.com/item?id=20389812, https://news.ycombinator.com/item?id=20390755 https://news.ycombinator.com/item?id=20390755
- JohnJamesRambo 7y agoOther than Zoom stockholders, I’m unsure why this comment is being downvoted. It seems entirely factual and provides references.
- deleted 7y ago[deleted]
- xenonite 7y agoAnd more recently, Zoom Is Leaking Peoples' Email Addresses and Photos to Strangers https://news.ycombinator.com/item?id=22753675 https://news.ycombinator.com/item?id=22753675
- ninkendo 7y agoI let out an audible “wow” upon reading this. This is absolutely bone-headed and I have no idea how they thought automatically grouping members by their email domain name was a good idea. You gotta figure, as soon as you starting writing a blacklist of “common” domains like gmail.com, hotmail.com, etc, your immediate thought should probably be “wait, maybe we’re doing this wrong.”
- planb 7y agoYou’re right but I absolutely see why they are doing this. When I saw all my colleagues in the company list I immediately figured they only have the email domain and I found it extremely useful to see whom I can contact without explaining how zoom works. Privacy isn’t our most important concern right now, it’s keeping the world running, and this “feature” helped me/us (if only just a little bit) communicate more effectively.
- luckylion 7y agoI don't mean to be overly snarky, but removing authentication from all computers and servers would also help everyone (if only just a little bit) be more effective. It's still a bad idea, crisis or not.
- shadowgovt 7y agoYep. And at the other end of the spectrum, never having users is the easiest way to maintain user privacy and security.
- ninkendo 7y agoWhy wouldn’t this be an opt in feature per-organization? I’m acme co, I buy a zoom subscription for acme.com, I click a box saying “let everyone with an acme.com email address see each other”. Done. Yes, I would have to prove I own acme.com, but we have solutions for that (didn’t set out to make this joke but, the ACME protocol, for one.) Why is it that it’s on by default for arbitrary domains (excepting the ones some poor soul has to blacklist)?
- shadowgovt 7y ago... by that special definition of "unacceptable" that means "It's been wildly accepted." If this situation isn't a mass condemnation of the idea users care about security or privacy more than usability, I don't know what is.
- ornornor 7y agoTheir website headers also whitelist a lot of domains including quite a handful that are known malware distributors. See for yourself: curl -I https://zoom.us https://zoom.us
- LukeShu 7y agoAll I see is `Content-Security-Policy-Report-Only`, which doesn't actually do anything security-wise. Their site uses the default CSP settings.
- hncommenter13 7y agoI'm not expert in this stuff. Is there a reason all of these domains are specified here? [edit, formatting] Content-Security-Policy-Report-Only: default-src blob: 'self'; script-src 'unsafe-eval' 'unsafe-inline' blob: https://*.50million.club https://*.50million.club https://*.adroll.com https://*.adroll.com https://*.cloudfront.net https://*.cloudfront.net https://*.google.com https://*.google.com https://*.hotjar.com https://*.hotjar.com https://*.zoom.us https://*.zoom.us https://*.zoomus.cn https://*.zoomus.cn https://*.zopim.com https://*.zopim.com https://ad.lkqd.net https://ad.lkqd.net https://ajax.aspnetcdn.com https://ajax.aspnetcdn.com https://apiurl.org https://apiurl.org https://appsforoffice.microsoft.com https://appsforoffice.microsoft.com https://assets.zendesk.com https://assets.zendesk.com https://bat.bing.com https://bat.bing.com https://cdn.5bong.com https://cdn.5bong.com https://cdn.jsdelivr.net https://cdn.jsdelivr.net https://cdncache-a.akamaihd.net https://cdncache-a.akamaihd.net https://code.jquery.com https://code.jquery.com https://connect.facebook.net https://connect.facebook.net https://consent.trustarc.com https://consent.trustarc.com https://extnetcool.com https://extnetcool.com https://fp166.digitaloptout.com https://fp166.digitaloptout.com https://googleads.g.doubleclick.net https://googleads.g.doubleclick.net https://intljs.rmtag.com https://intljs.rmtag.com https://pi.pardot.com https://pi.pardot.com https://px.ads.linkedin.com https://px.ads.linkedin.com https://ruanshi2.8686c.com https://ruanshi2.8686c.com https://rum-static.pingdom.net https://rum-static.pingdom.net https://s.dcbap.com https://s.dcbap.com https://s.yimg.com https://s.yimg.com https://s.ytimg.com https://s.ytimg.com https://s3.amazonaws.com https://s3.amazonaws.com https://scout-cdn.salesloft.com https://scout-cdn.salesloft.com https://sealserver.trustwave.com https://sealserver.trustwave.com https://secure-cdn.mplxtms.com https://secure-cdn.mplxtms.com https://secure.myshopcouponmac.com https://secure.myshopcouponmac.com https://snap.licdn.com https://snap.licdn.com https://sp.analytics.yahoo.com https://sp.analytics.yahoo.com https://srvvtrk.com https://srvvtrk.com https://static.zdassets.com https://static.zdassets.com https://static2.sharepointonline.com https://static2.sharepointonline.com https://tag.demandbase.com https://tag.demandbase.com https://tpc.googlesyndication.com https://tpc.googlesyndication.com https://tracking.g2crowd.com https://tracking.g2crowd.com https://translate.googleapis.com https://translate.googleapis.com https://trk.techtarget.com https://trk.techtarget.com https://unpkg.com https://unpkg.com https://www.comeet.co https://www.comeet.co https://www.dropbox.com https://www.dropbox.com https://www.google-analytics.com https://www.google-analytics.com https://www.googleadservices.com https://www.googleadservices.com https://www.googletagmanager.com https://www.googletagmanager.com https://www.gstatic.com https://www.gstatic.com https://www.youtube.com https://www.youtube.com https://d.adroll.mgr.consensu.org https://d.adroll.mgr.consensu.org https://serve2.cheqzone.com https://serve2.cheqzone.com https://*.ada.support https://*.ada.support 'self'; img-src https: blob: data: 'self'; style-src https: 'unsafe-inline' 'self'; font-src https: data: 'self'; connect-src * data: 'self'; media-src * blob: 'self'; frame-src https: ms-appx-web: zoommtg: zoomus: 'self'
- cookie_monsta 7y agoPoint taken, but none of the issues raised over the last few days had anything to do with scaling problems. The humblebrag of "we were just a little company and then we got hugged to death" doesn't sit right when a lot of the issues fall into the same category: prioritising ease of use and onboarding over security. As for "Thousands of enterprises around the world have done exhaustive security reviews of our user, network, and data center layers and confidently selected Zoom for complete deployment."... well it can't have been that exhaustive if a couple of weeks in the sunlight have generated a shopping list full of concerns. Kudos for half-playing by the 3F rule, though - probably their smartest move yet
- close04 7y agoThe statement admits that they fell short of the privacy and security goals but go on explaining how it's not their fault. It makes it look like either the issues are non-issues, or they're someone else's issues, or "we'll do these generic things that don't address in any way how those issues came to be". Which is a big thing to mention if you care about transparency and earning back the trust. Some of the biggest issues came to be due to deception and this message does not address that point. They were intentional decisions with effort put into obscuring them. One of the most egregious being the creative use of the "end to end encrypted" moniker. That was deliberately deceptive and I don't see this cookie cutter response addressing any of that. More engineering resources and engineering fixes don't fix deception, that starts at the top. And this puts the whole message into question.
- deleted 7y ago[deleted]
- abdullahkhalids 7y agoHe says: > These new, mostly consumer use cases have helped us uncover unforeseen issues with our platform. Dedicated journalists and security researchers have also helped to identify pre-existing ones. I don't think he is saying that these issues have to do with scaling problems, but rather that the increased usage + new types of usages led to increased scrutiny and uncovered new issues. Which is correct in a way. Obviously, they were told several issues in the past too, but then those issues were not costing them money. Now they are, so they are trying to fix them.
- moooo99 7y agoI don't know if I'd accept this. Zoom deliberately bypassed macOS security measures and ignored other basic principles for security. Additionally, they ignored privacy regulations like the GDPR by sharing data with facebook without user consent. That's a lot of stuff to forgive, within just a few weeks. I could forgive their servers buckling under the load or the trolls bombing in meetings. But everything else is less of a mistake rather than a concious decision in the basic software architecture.
- gjs278 7y agooh no!!!! not ignoring the GDPR!?!? oh nooo!!!!!!!!
- libertine 7y ago>That's a lot of stuff to forgive Isn't this where fines balance things out? I mean, it's 2020 ... GDPR isn't a new thing. It's good they have a plan to fix things, but isn't that enough for tech startups "We're sorry :(" narrative? They are well funded, and have plenty of resources when compared to SMEs... People still can choose to not use the service anymore, but that choice alone isn't enough. They should pay for it, and then users can make that decision.
- moooo99 7y ago> Isn't this where fines balance things out? I mean, it's 2020 ... GDPR isn't a new thing. Exactly! Thats the point I was trying to make (sorry if that didn't came accross properly). It's not like they are facing completely new challenges. GDPR has been in place for years, yet they are breaking it. Guessing URLs to access "protected" files is also not unheard of. I understand that it is a massive challenge to scale so fast and its good that they have plans to fix these issues, but these are mistakes that could have been easily avoided in the beginning.
- Nextgrid 7y agoThe problem is that the GDPR is a joke, it's almost like they passed the law under duress but aren't actually interested in enforcing it (maybe because whoever is in charge is actually benefiting from the current situation?)
- hc91 7y agoAbsolutely not. They have LIED about end-to-end encryption knowing very well that their product did not support that. That is premeditation, not making a mistake. Also their atroicious history regarding their privacy practices makes me think that they are now reacting in this way only because they got caught, not due to a genuine desire to be better.
- s_dev 7y ago>Any sw product has issues. The question is what the company does about it We are all software devs -- we know as well as him. He's chosen to prioritise growth over end user data privacy protection and then lying about it with marketing e.g. E2E advertised on front page. Many of these privacy/security issues were being complained about on HN about Zoom well before Corona. If Zoom users are data breached I personally won't feel sorry for them like some other breaches like Equifax for example. They've signed up to this to secure a bit of convenience. I will be personally discouraging it's use where I work.
- arm 7y ago“If Zoom users are data breached I personally won't feel sorry for them like some other breaches like Equifax for example. They've signed up to this to secure a bit of convenience.” I think that’s a bit unfair of a stance to take. As an example, I know someone who doesn’t want to use Zoom, but thanks to their university classes going online-only due to COVID-19, some of their professors have forced them to use Zoom for lectures, presentations, and examinations.
- A4ET8a8uTh0 7y agoThat. I am personally in that boat and I in my class I had no choice, but to use Zoom for it. The problem with "you don't want it, don't use it" mantra is, it is ignoring cases like mine. In law, those tend to be characterized as contracts of adhesion. edit: clarity
- zimpenfish 7y agoSame. $WORK moved from Whereby to Zoom (to handle more people in the weekly video meeting) which means I have to use Zoom - but I'm only using the iOS version and without signing up for an account.
- Loughla 7y ago>He's chosen to prioritise growth over end user data privacy protection and then lying about it with marketing I feel like I'm in crazy town. Isn't this the actual, living, real motto of SV? Move fast and break things. That's a thing that exists. Why are you people hating on Zoom when they're doing what you're all (seemingly) trying to do? Have I lost my mind?
- sneak 7y agoZoom were and are outright lying about being e2e encrypted. What does that have to do with user count? https://daringfireball.net/linked/2020/03/31/zoom-e2e https://daringfireball.net/linked/2020/03/31/zoom-e2e
- basch 7y ago"While we never intended to deceive any of our customers, we recognize that there is a discrepancy between the commonly accepted definition of end-to-end encryption and how we were using it." https://blog.zoom.us/wordpress/2020/04/01/facts-around-zoom-encryption-for-meetings-webinars/ https://blog.zoom.us/wordpress/2020/04/01/facts-around-zoom-... Because "thousands of enterprises around the world have done exhaustive security reviews of our user, network, and data center layers and confidently selected Zoom for complete deployment" and they didnt "design the product" for these "new, mostly consumer use cases", it means that up until now they couldnt have forseen that lying about e2e encryption to sell enterprise subscriptions was an issue.
- redbeard0x0a 7y ago> enterprises around the world have done exhaustive security reviews I'm pretty sure they are referring to security reviews for things like SOC2 and PCI. Which aren't exhaustive and generally consist of throwing a scanner on the network and running some sort of WASP top 10 vulnerability tester against the product. I have uncovered major flaws in products I have written that these "extensive reviews" have missed, like user enumeration by changing something in a POST request.
- basch 7y agoIt's very likely that a bunch of companies RFP process is a feature checklist and to get the "encrypted" box checked they needed that lie, or their product was out of the running. RFP by "who can tailor their marketing to check all the boxes" is a terrible process and leads to this marketing bloat. RFP would be much more useful if it stuck to "list only things you do your competitors doesnt; what processes come with your product that are much more efficient or innovative compared to your competition; like an sec disclosure what are three true non fluff risks to selecting your product; describe your revenue, user growth, and future ownership expectations." If a company cant answer those seriously, push them until they can, or tell them youll move on.
- scarface74 7y agoWell, think of all the man hours they spent creating “features” like installing a backdoor on MacOS that allowed them to reinstall Zoom after the user explicitly uninstalled it.
- WalterBright 7y ago> LOL user error. RTFM If you don't read, comprehend, and remember Emergency Airworthiness Directives you have no business being a pilot for hundreds of people. (The instructions were a whole two steps: 1. trim to normal with electric trim switches 2. turn off the stab trim system.) Boeing is still at fault, but the pilots do share a portion of the responsibility. https://theaircurrent.com/wp-content/uploads/2018/11/B737-MAX-AD-1107.pdf https://theaircurrent.com/wp-content/uploads/2018/11/B737-MA... Boeing was working on a fix right after the first LA crash.
- just_myles 7y agoI'm in complete agreement here. Their response is appropriate given the challenges that they face. No team ever thinks they are going to get that kind of migration to their platform the way zoom has received. Good for them.