14 ms·
Following pushback, Zoom says it won't use customer data to train AI models
- harha_ 3y agoI've never used Zoom. Never had to, but everyone keeps talking about it. Weird how I've dodged it.
- farts_mckensy 3y agoThe answer has always been fairly simple. Allow users the choice to opt in if they'd like to. Transparency is key.
- eigenvalue 3y agoAll they had to do was offer users a 10% discount to agree to it explicitly, and enough would have agreed out of millions of users to generate tons of training data. They were both greedy and stupid here and ended up shooting themselves in the foot.
- esafak 3y agoOnly if every participant in the call consents.
- brucethemoose2 3y agoZoom is just disappointed the ToS change went viral, and that their reputation is privacy friendly enough for that to even matter. I wonder if Teams would face similar uproar, assuming that bit isn't already in the ToS.
- JohnFen 3y ago> I wonder if Teams would face similar uproar, Maybe, but Teams is very good at ignoring uproars. While I assume that there are people who feel differently, everybody I know already loathes Teams and only uses it when their employer forces them to anyway.
- chefandy 3y agoYeah— the scale of uproar MS would need to budge on something that affects their core business goals probably dwarfs the number of teams users aware enough to care by 100 to 1.
- mrguyorama 3y agoThe only thing that would get O365 out of companies would be if Microsoft started having a Hunger Games for CEOs
- chefandy 3y agoAnd now that Balmer is gone, MS Sustenance Pro Executive Marketplace Edition will never get internal traction.
- codeflo 3y agoWhile that’s true, isn’t part of that due to Microsoft having enterprise-friendly licensing nailed down? I’d think that doing the equivalent of industrial espionage would remove Microsoft’s offerings from some industries extremely fast. (Corporate legal departments do read licensing terms!)
- mlinhares 3y agoIf by "enterprise-friendly licensing nailed down" you mean "it's free if you buy something else". People use it only because someone up the chain sees it's included in Office and they're like "we're not paying for something else if we get this for free". I hope Slack and others bring MS to court to stop this, this is exactly what happened during the browser wars.
- bradley13 3y agoI use Teams a lot, because it is (here, at least) pretty much the only such app that everyone knows. Meeting across groups or companies? Teams. Aside from the usual (and understandable) MS hate, I don't see the problem. Features and performance? Nothing else is better, most are worse. Cisco is a mess, Skype is horrible, Zoom lies about their security, etc, etc
- bongoman37 3y agoMicrosoft culturally is extremely averse to using customer data for doing these kind of things. I was once talking to a Microsoft exec and he said that once the idea of using contextual ads in Hotmail was brought up (similar to Gmail), and it was shot down hard. The idea of using customer data (even non-paying ones) in this fashion was anathema. Microsoft makes its money from massive enterprise contracts which might be threatened by someone using your data to benefit your competitor in any way.
- dgb23 3y agoGitHub is owned by MS?
- rolph 3y agosince 2018 https://en.wikipedia.org/wiki/GitHub https://en.wikipedia.org/wiki/GitHub https://fourweekmba.com/who-owns-github/ https://fourweekmba.com/who-owns-github/
- JohnFen 3y agoThis. It throws the idea that MS is extremely averse to using customer data for these sorts of things into great doubt, doesn't it?
- costcofries 3y agoTeams will use your O365 enterprise data to power it's AI 'copilot' offering, it's literally what its customers are asking for.
- mrweasel 3y agoGreat, but they already lost user trust. Many will never install or use Zoom again.
- freedomben 3y agoEh, people have short memories. There was a major scandal back in the day where (forgive me if my memory is not super accurate, it's been a while) they were basically starting a long-running daemon process as root and binding it to a port where it would listen for instructions, so even when you closed Zoom it was still actually running. There were other big security (encryption IIRC?) issues that they had. Huge privacy and security scandals, so bad that they ended up acquihiring Keybase (still sad at that loss personally). But still it didn't matter, nobody remembers or cares (except me, I refuse to install their native app. The day they fully block browser access will be a bad day).
- eur0pa 3y agoI don't trust their words
- quijoteuniv 3y agoIs again disappointing that big companies just try to push this policies in the hope they will go unnoticed. What kind of person think this is ok? Is just a money grabbing exec? We need to be better than this
- ihsw 3y ago[dead]
- Sunspark 3y agoWhy should I believe that they're telling the truth? What's to stop any unethical company from doing it anyway, and not telling anyone? There is no such thing as a training model auditor.
- consumer451 3y agoThe upside is too high to trust them, leaving aside any geopolitical stuff, it's just a juicy business. New Zoom Subscription Tier: Virtual agent with perfectly fine tuned domain-specific knowledge performs 99% as well as your sales/support person. 24/7/365 $400 per month
- f1shy 3y agoYou just shouldn’t!
- lq9AJ8yrfs 3y agoThere are model risk analysis services among big-4 and boutique firms, and these fit into conventional audit processes as domain-experts. Similar services be bought apart from audit services as risk consulting from the same firms or alternately the familiar names in management consulting.
- deleted 3y ago[deleted]
- gaogao 3y agoTheir consent order with the FTC also contains a prohibition against privacy misrepresentations, so it would probably get audited during their biennial assessments. For some unethical company that doesn't get regularly audited, yeah they'd probably get away with it unless it got leaked. > Finally, the company must obtain biennial assessments of its security program by an independent third party, which the FTC has authority to approve, and notify the Commission if it experiences a data breach. https://www.ftc.gov/news-events/news/press-releases/2020/11/ftc-requires-zoom-enhance-its-security-practices-part-settlement https://www.ftc.gov/news-events/news/press-releases/2020/11/...
- tornato7 3y agoToo late, it took me an hour to spin up a self-hosted Jitsi instance and I have no reason to switch back.
- itake 3y agoWhat do you host jitsi on?
- tornato7 3y agoA NUC in my garage
- rabbitofdeath 3y agoThis. I saw the post and had a mildly customized Jitsi running on my docker host on Hetzner within 2 hours. I'm amazed at the performance and stability of the Jitsi.
- screamingninja 3y agoAny insights or lessons learned would be greatly helpful. Several people I know, myself included, are about to go down this route.
- tornato7 3y agoI used the Docker instructions on their website. Just follow it very closely and make sure the right ports are opened. Then work on configuring it. You can adjust the video quality up to 1440p in the config.js - this quality blows away Zoom.
- rvz 3y agoToo late. Now are you willing to abandon the rest of the other companies using your information to train their AI models? (Looking at Google, Microsoft (GitHub), Meta, Instagram, etc) Now should be the time to self-host then. Whether if it is a GitLab, or Gitea instance for Git, or a typical Mastodon server with a single user that controls the instance for full ownership.
- EGreg 3y agoOh do I have something to say about this! How are you going to serve your content? What is the best tool out there — OwnCloud?
- bhhaskin 3y agoHow can they do training in the first place if everything is E2E...?
- cced 3y agoE2E means everything between two ends is encrypted. Once it gets on their end, they can do what they please.
- traek 3y agoThis isn’t what E2E means for communication software. E2E means only the participants have the keys. Signal is a good example of this, the message is encrypted from the sender to the receiver and Signal themselves cannot decrypt it. Separately, most Zoom meetings are not E2EE. That’s why features like live transcription work.
- JonChesterfield 3y agoOnly the participants do have the keys. You, the other people on the meeting, the company running Zoom, at least one government. It's still usefully encrypted to stop (at least some) other companies/countries benefiting from the information. I think zoom probably have a defence against the fraud accusation that no reasonable person would believe end to end encrypted meant zoom doesn't have the data as that's the whole point of the service existing.
- greiskul 3y agoZoom has not committed any fraud. They clearly state that by default their meetings are encrypted, but not end to end encrypted. And that you can turn on end to end encryption, but that it causes a bunch of features to be disabled. I think this is a great balance between being able to add features that are impossible with E2EE, but allowing privacy concious users to choose if they need stronger encryption. https://support.zoom.us/hc/en-us/articles/360048660871-End-to-end-E2EE-encryption-for-meetings https://support.zoom.us/hc/en-us/articles/360048660871-End-t...
- croes 3y ago*Insert I don't believe you meme*
- deleted 3y ago[deleted]
- TradingPlaces 3y agoThis is the company that thought it was OK to install an always-on web server on my Mac. Apple pushed a special fix, just to remove it. I already have zero trust in them, and this does not change that. https://infosecwriteups.com/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5 https://infosecwriteups.com/zoom-zero-day-4-million-webcams-...
- deleted 3y ago[deleted]
- A4ET8a8uTh0 3y agoThe recent messaging offensive from its CEO tried to cast previous change as a lapse in process, but refused to elaborate further when pressed on more subtle points. All in all, it does smell like bs, but I am glad there is a clearly a level of scrutiny companies appear to face lately.
- lazzlazzlazz 3y agoDoes Zoom store video or audio data from calls? This is really the key question. If anything is stored, they can't be trusted.
- avrionov 3y agoIf you record your video call, Zoom will store it for you. Otherwise, it shouldn't be stored. Also if video streaming protocol like HLS or MPEG-DASH is used, this will store the stream in video chunks, which are deleted later.
- Exuma 3y ago[flagged]
- kepano 3y agoIf your data is stored in a database that a company can freely read and access (i.e. not end-to-end encrypted), the company will eventually update their ToS so they can use your data for AI training — the incentives are too strong to resist
- sandworm101 3y agoThen it is time to take control by seeing such databases with false information. We could probably design data specifically to attract an AI system looking for well-documented data. I wonder how images of Steven Colbert uploaded to imgur it would take to convince the AI that he actually was.
- nwoli 3y agoI don’t think this is a possible approach. It would basically mean needing to feed in so much noise that a human wouldn’t be able discern reality from fiction given no priors. Modern ML is too smart
- BiteCode_dev 3y agoAKA encryption.
- proser 3y agoGiven how easy it is to keep an average human from discerning reality (see the last decade of boomers/gen xers on Facebook as an example) and the massive potential to create slight variations with LLMs, I don't think a Stephenson-style misinformation propagation campaign is that far outside the bounds of possibility. That's a lot of compute power to waste on it, but I would guess that that's what bot networks are going to be used for in the future (or already are, right now, if they're done mining bitcoin).
- sandworm101 3y agoThat's why I said president of canada. A non-intelligent AI would not find any priors indicating who was the president. There isn't one. So a few thousand images in the database, against zero information to the contrary, might be enough.
- isykt 3y agoThe pushback must be constant, or they will wear us down.
- johncessna 3y ago"Following Pushback, Zoom Says It Won't Use Customer Data to Train AI Models" Yet...
- ChrisArchitect 3y agoWhere did Zoom say this? There's no link to like a blog post or social post or something?
- ChrisArchitect 3y agoAh, they updated the previous blog post (https://blog.zoom.us/zooms-term-service-ai/ https://blog.zoom.us/zooms-term-service-ai/): Editor’s note: This blog post was edited on August 11, 2023, to include the most up-to-date information on our terms of service. Following feedback received regarding Zoom’s recently updated terms of service Zoom has updated our terms of service and the below blog post to make it clear that Zoom does not use any of your audio, video, chat, screen sharing, attachments, or other communications like customer content (such as poll results, whiteboard, and reactions) to train Zoom’s or third-party artificial intelligence models. It’s important to us at Zoom to empower our customers with innovative and secure communication solutions. We’ve updated our terms of service (in section 10) to further confirm that Zoom does not use any of your audio, video, chat, screen-sharing, attachments, or other communications like customer content (such as poll results, whiteboard, and reactions) to train Zoom’s or third-party artificial intelligence models. In addition, we have updated our in-product notices to reflect this.
- ChrisArchitect 3y agoEither way this is old news from days ago also, posted in various forms
- dylan604 3y agowow, you just did a whole thing there by yourself
- butlike 3y agoWhy is this bad? Honestly, I don't understand why you wouldn't want the most accurate AI models available. The LLM is only as good as the data set it's trained on, and the more I read about LLM's and the advent of AI evolving from them, the more I'm starting to think if we don't jump both feet into the pool, then we'll never get to the promised land of: "AI model, spin me up a T-shirt company that's scaled to 10mm users a month, and spin it down after 6mo. if sales don't increase by n% month-over-month" or "AI model, get me [A,B,C, ...n] groceries so I can throw a housewarming party on Friday. I can only accept the delivery Tuesday or Thursday. I don't care which store(s) those ingredients come from or how the internals are orchestrated." What's the threat model here, specifically? What nefarious things would happen by using customer data? Most companies exist to make money, which honestly, is a pretty benign objective, all things considered.
- tspike 3y agoI'd rather live in a world that preserves the fundamental right to privacy than one that can automatically organize my housewarming party.
- butlike 3y agoWhy is privacy important in this context, if the data is being fed into an impartial robot? The robot doesn't care if you have liaisons over webcam with your lover, or whatever else. An employee can blackmail another person, but the model simply has no reason to, or am I misinterpreting the "whys" of needing privacy here?
- david_shaw 3y ago> The robot doesn't care if you have liaisons over webcam with your lover, or whatever else. The concern isn't judgement from the AI, but that products from the model trained on your data could expose sensitive information. Since it's never quite clear exactly how the data could be used in situations like this, there's a chance that very sensitive data could be parroted back to people who were not the intended audience.
- 3y ago
- shtopointo 3y agoIt's wild they needed "customer pushback" to know not to do that. Something's fishy here...
- smileysteve 3y agoWhy? I'm sure their customers and investors, since Chat GTP, have been saying "You need to implement some AI Features, google and Microsoft are moving here, why aren't you?" and the company thinks, okay, you want AI Features, for it to be accurate, we need to look at real data. But no customers want AI trained on their data.
- shaunxcode 3y ago"Says" is doing a LOT of work there.
- amilich 3y agoHave been working on a list of AI companies that train on user data: https://github.com/skiff-org/skiff-org.github.io/blob/main/blogs/aitraining.md https://github.com/skiff-org/skiff-org.github.io/blob/main/b.... Will update the Zoom section but still suspect.
- nerdponx 3y agoWhat differentiates "AI" from "ML" or other predictive modeling that finds its way into an application? I fit a regression on some customer data last week, am I training an AI on customer data? Is it a matter of intent? Of being public-facing? Of being specifically a generative model?
- deleted 3y ago[deleted]
- simsla 3y agoFor me, the main issue is the potential of POI/confidential information being leaked. I think it's fine using "usage data", but the contents of a private conversation should be considered to be... private. LLMs and generative image models have shown the ability to leak/reproduce training data. That's a big deal.
- amilich 3y agoThe original thinking was generative. That is a good distinction to add. I do think regression/analysis doesn't have many of the same issues, ex. no one would have an issue if Zoom said "we're going to analyze how many minutes users spend on Zoom by time of day"
- nwoli 3y agoThey obviously do statistical analysis of user data still which I’d argue is in the “AI on user data” bucket. So no I don’t think that applies
- shadowgovt 3y agoThat's unfortunate. I was looking forward to the next generation of audio and video denoising solutions.
- 1-6 3y agoStreaming Data vs Batch Data. You can't expect to train AI models without some sort of storage mechanism to train on. If they made a 'ninja edit' to their TOS, does this mean they've also backtracked on their data collection?
- theptip 3y agoIs this actually true? Can’t you do online training in real-time, at least in principle? As audio comes in, for a micro batch of current calls on the local node, do STT, next token prediction, and calculate your loss. Transmit the loss update back to the centralized model. Google posted about Federated Learning years ago: https://ai.googleblog.com/2017/04/federated-learning-collaborative.html https://ai.googleblog.com/2017/04/federated-learning-collabo..., not sure how widely it has caught on though.
- tpoacher 3y agoTo be clear, I dont mind zoom using data from their service to train "their AI models", particularly where these are transparent and specific. I was more concerned about the wording, which implied they would give themselves the right to use the data to train "AI models" more generally. I have few problems with them building a better noise cancelling solution for their platform, but lots of problems with them selling it for improving third party surveillance and fingerprinting.
- theptip 3y agoIf you discuss proprietary information you should be very concerned about Zoom training their models on that. Especially when they pivot into generative AI (which is the obvious use case if you have that much conversation data flowing through your system). LLMs can regurgitate training data unpredictably so you really can’t have any enterprise data flowing through such a system. I guess my point is that “their AI models” will very likely include more than noise cancelling before too long. It’s too juicy a dataset to ignore.
- tpoacher 3y agoYes. That's pretty much what I mean by "specific and transparent". Provide me with clear uses, and the ability to withdraw or restrict my data contribution in the event of the company deciding to "expand" to other AI "solutions", and I'll feel respected as a user and allow that specific use of my data for training. But reply with vagueness giving them a carte-blanche to use my data on anything under the sun, and I'm just gonna look somewhere else and encourage others to do the same.
- RadixDLT 3y agotoo late, it aready used user data.
- mlsu 3y agoZoom definitely has several AI models (as does teams, google chat, etc.) They do automatic captioning/transcription of meetings, so there is a model for that; they do automatic background blur/cutout, so there is a model for that; they are probably working on a "meeting summarization" product for that. Those are features that people love and use all the time. I would be curious to know how anyone expects Zoom to improve on these features without collecting data from real users on the platform.
- JohnFen 3y agoThe real issue isn't that they may use customer data for these things. It's that they may use customer data without getting consent first.
- rolph 3y agoi see nothing indicating collection of data wont happen. i see nothing indicating data wont be provided to third parties. i see nothing indicating third parties will be prevented from using aquired data to train AI i see nothing indicating zoom will not aquire trained models from third parties that use Zoom harvested data in training.
- villgax 3y agoScrew zoom for such blatant tactics & asking their employees to work from office. How blind or horrible does your product have to be that not even your employees would use it to get work done lol
- bastardoperator 3y agoI still think it's odd that Zoom is forcing people back into the office. The only thing I'm hearing is that they don't truly believe in their product. Given that stance, they're saying this today, when push comes to shove, they'll do it. I think the reality is they don't have the tech in place today to do it, but are working towards it.
- systemvoltage 3y agoOk, what if they change their mind just like they did now? Also what if they break the law? Who is monitoring that? If detected, who is enforcing it?
- dang 3y agoRelated: Zoom's TOS Permit Training AI on User Content Without Opt-Out - https://news.ycombinator.com/item?id=37038494 https://news.ycombinator.com/item?id=37038494 - Aug 2023 (35 comments) How Zoom’s terms of service and practices apply to AI features - https://news.ycombinator.com/item?id=37037196 https://news.ycombinator.com/item?id=37037196 - Aug 2023 (177 comments) Ask HN: Zoom alternatives which preserve privacy and are easy to use? - https://news.ycombinator.com/item?id=37035248 https://news.ycombinator.com/item?id=37035248 - Aug 2023 (16 comments) Not Using Zoom - https://news.ycombinator.com/item?id=37034145 https://news.ycombinator.com/item?id=37034145 - Aug 2023 (194 comments) Zoom terms now allow training AI on user content with no opt out - https://news.ycombinator.com/item?id=37021160 https://news.ycombinator.com/item?id=37021160 - Aug 2023 (510 comments)
- ironmagma 3y agoOK, now roll back RTO and then they’ll be a respectable company again.
- scoofy 3y agoSo what's the deal with something like employers requiring use of this. Is there any limit to what terms you must agree to to be employed somewhere? It seems pretty weird that if your office used Zoom, that you would need to agree to all these terms that aren't part of your employment contract to actually be employed.
- jkaplowitz 3y agoUnder US law, there aren’t many relevant governmentally imposed limits on this kind of thing, no. This would be a case either for collective bargaining (unionism) regarding this aspect of working conditions, or for advocating some of the worker rights that have been legislatively recognized in regions like Europe.
- palata 3y agoNext up: Slack uses customer data to train AI models. Companies are happily exposing all their data to those services, I don't understand why anybody would pretend to be surprised of the results.
- deleted 3y ago[deleted]
- littlestymaar 3y agoZoom said: “we won't use your data to train AI without your consent”, but given that they require your consent to join a zoom call you can see what to do with such a statement.
- sharts 3y agoThey're lying.
- fortyseven 3y agoThe cynic in me says they'll just pass the data to a brand new company that'll spin off of them. I'll always assume you're trying to do it, now. I have even less reason to trust them than I previously did.
- gumballindie 3y agoI never quite understood everyone’s obsession with zoom, but i suspect we wont be hearing about zoom for long.