news.volyx.in

Zoom iOS app sends data to Facebook even if you don’t have a Facebook account (vice.com)

1433 points by softwaredoug · 2387 days ago · 360 comments on HN

Article summary

The Zoom iOS app sends data to Facebook, including device information and location, even if the user does not have a Facebook account. This data is sent through Facebook's Graph API and includes details such as the user's device model, time zone, and phone carrier. Zoom's privacy policy does not explicitly mention this data transfer. Zoom has announced that it will remove the Facebook SDK and reconfigure the feature to address this issue.

Main themes

  • data privacy
  • regulation
  • tech industry transparency
  • user consent
  • HIPAA and GDPR compliance
  • innovation vs. regulation

What commenters say

  • Some commenters believe that Zoom's data collection and transfer to Facebook is a violation of user privacy and potentially illegal under regulations such as GDPR and CCPA.
  • Others argue that the issue is not with Zoom, but with the lack of transparency and regulation in the tech industry, which allows companies to prioritize profits over user privacy.
  • There is a disagreement about the effectiveness of regulations such as HIPAA in protecting user data, with some arguing that they are necessary to prevent companies from exploiting user data, while others believe that they stifle innovation and are too burdensome for small businesses.
  • Some commenters suggest that users should be able to choose whether or not to share their data, and that companies should be transparent about their data collection practices.
  • Others argue that the issue is not just about user choice, but about the power dynamics between companies and users, and that regulations are necessary to protect users from exploitation.
  • There is also a discussion about the potential consequences of Zoom's actions, including the potential for fines and legal action under regulations such as GDPR and CCPA.
  • Some commenters believe that the issue highlights the need for greater transparency and accountability in the tech industry, and that companies should be held responsible for their data collection and transfer practices.