Zoom's terms of service now include training GenAI with no ability to opt out

Check sections:
- 10.2 Service Generated Data; Consent to Use
- 10.4 Customer License Grant
- 16.2 Ownership of Zoom Property

Edit: included other sections of ToS

https://explore.zoom.us/en/terms/

Zoom Terms of Service | Zoom

Read: Terms of Service – Zoom

Zoom

@jmsdnns Not remotely a fan of Zoom, but FWIW, that section of the TOS is specifically about ancillary data that Zoom generates based on usage and not user generated data:

“…telemetry data, product usage data, diagnostic data, and similar content…”

Unless I’m misreading it, this part of the TOS seems to be more for training “hey, it looks like you call Suzan around this time every week” and not “we’re going to steal your conversations and use them for data generation” data.

@bkbkbk @jmsdnns that is how I interpret this as well. Still might be the thin end of the wedge but they don't appear to be stealing camera and audio data (yet) for GenAI. 🤔
@lyonsinbeta @bkbkbk edited to include the other sections of the ToS
@jmsdnns @lyonsinbeta Yeah, the 10.4 bit looks nasty. It’s all standard boilerplate “we have the right to use your stuff for providing the service” stuff right up until the AI mention.
@lyonsinbeta @bkbkbk @jmsdnns
Totally. I mean Reddit is already looking to monetize all the conversations it is storing as AI training material, I think every company that claims to own our conversations is going to reassert their right to profit off all of our data.
@bkbkbk you are correct. i will edit the toot to include a call to section 10.4
@bkbkbk @jmsdnns I’m not a lawyer, but I read sections 10.2 and 10.4 together to mean that Zoom (or anyone really, if they like) can use anything you send or receive (audio, video, chat messages, files etc.) as well as anything that Zoom might make of that (like auto-generated subtitles) in practically any way they like, including machine learning.

@jmsdnns  

This might get them uninstalled from a lot of folks' machines

@jmsdnns time to stay with alternatives.
@jmsdnns Their security and privacy were terrible until, under massive public pressure, they fixed it. And then everyone kept using it because I guess they were magically no longer a shitty company looking to squeeze money out of their users every which way... and now, here we are. Just use Jitsi, for goodness' sake - why everyone hasn't switched to the perfectly capable, libre, self-hostable alternative is beyond me.
@jmsdnns @anomalocaris I’d like a list of right-on hippy alternatives. Jitsi and Mastodon are a start.
@jmsdnns @anomalocaris oh, and hosting your own blog. I’m cooling on giving other people my data.

@davehodg @jmsdnns @anomalocaris >hosting your own blog

#writefreely is a single binary multi-user blog platform. I quite like it. Here's an explainer (which is itself hosted by my WF instance):

https://awadwatt.com/tezoatlipoca/what-to-know-about-writefreely-the-faq

with the caveat that I offer no guarantee of service, i can spin you a trial account to play around with.

What To Know About WriteFreely: The FAQ

Its been a week 9 months (10/20) or so since I've set up my #WriteFreely instance. Here's how I did it I quite like it as a blogging ...

Third Spruce Tree On The Left
@anomalocaris @jmsdnns @tezoatlipoca I’m self-hosting Wordpress for now. I have the source and database. That’ll do for now.
@davehodg I'm going to very unhelpfully suggest just picking up HTML, then CSS and a tiny bit of basic PHP and just coding your own - a webpage is an easy and fun thing to build, you can even just copy a basic template and tinker with it to suit your needs (a good way to learn HTML). All the interactivity that WordPress offers, that's a lot more work, but who needs all that newfangled Web 2.0 gimmickry anyway?
@anomalocaris There are many useful plugins.
@davehodg But it can never be as much fun as navigating the Byzantine outer reaches of PHP!
@jmsdnns enshittification really is the word of the decade, isn’t it?
@jmsdnns Trust? 😀 AI? 😵‍💫😳🤣
@jmsdnns Use Jitsi meet.

@robertlogger @jmsdnns OK, new one on me. Jitsi is open source (Apache licence), and they seem to make it easy to run your own server; but there is a commercial company, 8x8 Inc, which owns the name ('Jitsi') and supplies a commercially supported service.

Looks interesting, definitely worth trying.

https://github.com/jitsi/jitsi-meet

GitHub - jitsi/jitsi-meet: Jitsi Meet - Secure, Simple and Scalable Video Conferences that you use as a standalone app or embed in your web application.

Jitsi Meet - Secure, Simple and Scalable Video Conferences that you use as a standalone app or embed in your web application. - jitsi/jitsi-meet

GitHub
@simon_brooke @jmsdnns That's the problem with opensource, they don't have big money to make advertisements.
@robertlogger @simon_brooke @jmsdnns
Jitsi is nice but does all the video processing on the users' PCs so poor connection or slow machine runs into problems, especially for larger groups.
@DavidPenington @robertlogger @simon_brooke @jmsdnns
but that's good, because it gives you an excuse to turn the camera off if you're having a bad humaning day.
@robertlogger @jmsdnns Which is why we need to publicise it more (which was what I was trying to do).
@jmsdnns I tried reading section10.2 but I am bad at understanding legalese. What data is recorded? It says telemetry, product usage data, etc. But what are some examples of that? Is video and audio being recorded?
@jmsdnns Many medical providers use Zoom for tele-health. They claim to be HIPPA compliant, so I hope they’re not collecting any data, even meta data from those.
@richbruchal @jmsdnns Forgive me for being pedantic, but it’s HIPAA. 😉
@jmsdnns And section 10.4 (“Customer license grant”, which involves “customer content” as well)
@jmsdnns the only reason any of us use zoom instead of jitsi or BBB or jami is the same reason why they don't want us to work from home -- they are scared about the consequences of workers who realize we actually don't need the management layer and are capable of self-organizing
@jmsdnns Sounds like Zoom wants to win the BigBrother-Award for a second time.

@jmsdnns Wait, why is Zoom all of a sudden going evil?

They were supposed to bring balance to the video call ecosystem...

@AT1ST @jmsdnns from a security/privacy perspective Zoom has always been evil or incompetent depending on how willing you were to grant them the benefit of doubt.

@ATM @jmsdnns Relative to other video software, I can grant that the robodialing issue being patched with automatic passwords that are included in the links is an issue, as to some extent the fact that you could run unpatched software for a video call...but both of those at least had an UI/UX benefit that (To me) justified them.

This doesn't even have that.

@AT1ST @jmsdnns Zoom had numerous short comings besides Zoombombing, such as misrepresenting using E2EE before being called out on it and around 2019 leaving an unsecured web service running on MacOS even after uninstalling Zoom (https://www.theverge.com/2019/7/10/20689644/apple-zoom-web-server-automatic-removal-silent-update-webcam-vulnerability)
Apple is silently removing Zoom’s web server software from Macs

After all of the drama over Zoom’s use of a hidden web server on Macs, Apple itself has decided to step in, TechCrunch reports. Zoom is issuing a silent update — meaning your Mac will get it without any interaction on your part — to remove the web server from any Mac that has Zoom’s software installed.

The Verge
@ATM @jmsdnns Fair enough - my experience primarily came from work in 2020 when doing remote work briefly while I broke my ankle shortly before the pandemic had everyone switch to remote work with Zoom for video calls at my company.
@AT1ST @jmsdnns yes, the pandemic changed work rules & broke formerly taboo practices for many organizations. Work from home was only the start with cascading implications of increased VPN capacity requirements, BYOD, PC supply shortages, etc.

@jmsdnns

Another example of @pluralistic "enshitification" is the Studio54 insider line wait Bluesky.

https://mastodon.social/deck/@ramsey@phpc.social/110843651374881440

@jmsdnns 10.4 is more horrifying as it includes customer content not 'just' metadata.
@jmsdnns i see Jitsi mentioned here as an alternative. But it's free, which raises a red flag for me - I've seen other "free" services do a bait-and-switch to suddenly be "use our great AI for a fee" ... and you just know that AI was fed on our "free"-ly provided data 😕

@deborahh @jmsdnns Jitsi is free in that it is an open source project, so you *can* host it yourself and control ALL the data.

However that is not free, setting up cloud servers costs $, and there is time and effort involved in configuring it properly.

I think the main org that funds jitsi dev will also set up and run it for you, but I don't know anything about that.

@mlippert @jmsdnns oh, so it's for someone who has tech savvy and server access. Not public?

@deborahh @jmsdnns
I believe so. I think there's a free public version they host, but I don't think it's for general use, more for test out how it works.
See https://jitsi.org/

#jitsi

Free Video Conferencing Software for Web & Mobile | Jitsi

Learn more about Jitsi, a free open-source video conferencing software for web & mobile. Make a call, launch on your own servers, integrate into your app, and more.

Jitsi

@deborahh @jmsdnns You’re right to be worried, given the advertising ecosystem that spawns so many “free” products where we are the product.

But Jitsi is an open source, free alternative to commercial systems. Its whole reason to be is to provide encrypted, private, no-personal-data-required communication. Jitsi Meet is a trusted platform in the infosec community. No ads.

https://jitsi.org/

https://en.wikipedia.org/wiki/Jitsi

Free Video Conferencing Software for Web & Mobile | Jitsi

Learn more about Jitsi, a free open-source video conferencing software for web & mobile. Make a call, launch on your own servers, integrate into your app, and more.

Jitsi
@jmsdnns this is especially concerning when you consider that the military relies heavily on zoom, both formally and informally. It should worry everyone that, even if nothing classified is discussed, that likenesses of our military members could be used in generative AI models.

@jmsdnns Can Zoom still be HIPAA compliant with this TOS?

#HIPAA #zoom

@mlippert excellent question
@jmsdnns Some of my family is in healthcare and this matters to them. No idea how to find out the answer though.
@mlippert i meant it sincerely. i am not a lawyer, but your concern is important and valid