Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is there a legitimate purpose for this entitlement?

Zoom for government is authorised for FedRAMP moderate, and has authorisations from the DoD and the Air Force. Does that mean anything?



> Does that mean anything?

It means they ticked a lot of boxes.

Certifications only overlap a little bit with actual security. Most of SOC2 for example is just bureaucracy and a cash grab by enterprise SSO providers.


This post[0] from fly.io does a good job at giving examples of the boxes and bureaucracy.

[0]: https://fly.io/blog/soc2-the-screenshots-will-continue-until...


Yes, it can be used to allow an application to load user defined / compiled / etc plugins but Zoom probably doesn't need that.


I can't think of one for zoome ubless they allow filter plugins for the camera or something. One thing it is useful for is probably loading unsigned VSTs for DAWs.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: