Gentoo Archives: gentoo-dev

From: Ulrich Mueller <ulm@g.o>
To: Alessandro Barbieri <lssndrbarbieri@×××××.com>
Cc: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] zoom concerns
Date: Thu, 02 Apr 2020 11:55:22
Message-Id: ulfneyue7@gentoo.org
In Reply to: [gentoo-dev] zoom concerns by Alessandro Barbieri
1 >>>>> On Thu, 02 Apr 2020, Alessandro Barbieri wrote:
2
3 > I have concerns about the inclusion of zoom in ::gentoo. For me it's
4 > more like a malware.
5
6 Gentoo is about choice. If users want to use Zoom (or have to, because
7 their employer schedules a meeting using that platform) then it is not
8 our call to stop them.
9
10 > From the hacker news feed you'll find out that:
11
12 > [1] zero day vulnerability found
13 > [2] passwords are truncated to 32 bit
14 > [3] previously sent data to facebook
15 > [4] end to end traffic isn't encrypted
16 > [5] signed binary run unsigned script
17
18 > 1 https://techcrunch.com/2020/04/01/zoom-doom/?guccounter=1
19 > 2 https://news.ycombinator.com/item?id=22749706
20 > 3 https://www.vice.com/en_us/article/z3b745/zoom-removes-code-that-sends-data-to-facebook
21 > 4 https://theintercept.com/2020/03/31/zoom-meeting-encryption/
22 > 5 https://news.ycombinator.com/item?id=22746764
23
24 Right, and I (as its Gentoo maintainer) won't recommend Zoom to anyone,
25 nor use it myself unless I am forced to.
26
27 However, if we would remove the package from the Gentoo repo, users
28 would inevitably install it from one of the overlays listed at
29 https://gpo.zugaina.org/net-im/zoom-bin (there are even more, named
30 net-im/zoom or app-office/zoom), which vary in quality. Most of them
31 install bundled libraries which are old and vulnerable, e.g. Qt 5.9.6.
32
33 I believe that the number of overlays (more than a dozen) containing the
34 package shows that there is demand for it. In the main tree we have at
35 least a chance to address bug reports.
36
37 Ulrich

Attachments

File name MIME type
signature.asc application/pgp-signature