<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=utf-8"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:Helvetica;
        panose-1:2 11 6 4 2 2 2 2 2 4;}
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p.msonormal0, li.msonormal0, div.msonormal0
        {mso-style-name:msonormal;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
p.8e96fa11-c06d-4965-8817-8ff46765e27f, li.8e96fa11-c06d-4965-8817-8ff46765e27f, div.8e96fa11-c06d-4965-8817-8ff46765e27f
        {mso-style-name:8e96fa11-c06d-4965-8817-8ff46765e27f;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
span.EmailStyle20
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link=blue vlink=purple><div class=WordSection1><p class=MsoNormal>From a different list of mine:<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>“A vulnerability in Zoom conferencing software was published yesterday. The security concern was this could potentially allow malicious websites access and control to Mac cameras. This impacts only Mac users who have the Zoom application installed on their computer.  PC users and people who join meetings by clicking through their browser are not impacted.<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>Zoom has released a patch that [we] will be pushing out to … impacted users this evening. You do not need to do anything special at this time, the patch will install automatically and will not require a restart of your machine. If you do have Zoom installed, and are still nervous about your camera, you can open the Zoom application, go into video settings, and select the checkbox next to: "Turn off my video when joining a meeting." This will turn your camera off by default on any Zoom meetings you join. If you want to show your video, you can do that from within any meeting once you get there.”<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>I assume that, soon, Zoom will push this universally to all users (including ICANN) as well<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>Paul<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><o:p> </o:p></p><div><p class=MsoNormal>Paul Rosenzweig<o:p></o:p></p><p class=MsoNormal><a href="mailto:paul.rosenzweig@redbranchconsulting.com"><span style='color:#0563C1'>paul.rosenzweig@redbranchconsulting.com</span></a><o:p></o:p></p><p class=MsoNormal>O: +1 (202) 547-0660<o:p></o:p></p><p class=MsoNormal>M: +1 (202) 329-9650<o:p></o:p></p><p class=MsoNormal>VOIP: +1 (202) 738-1739<o:p></o:p></p><p class=MsoNormal><a href="http://www.redbranchconsulting.com/"><span style='color:#0563C1'>www.redbranchconsulting.com</span></a><o:p></o:p></p><p class=MsoNormal>My PGP Key: <a href="https://keys.mailvelope.com/pks/lookup?op=get&search=0x9A830097CA066684"><span style='color:#0563C1'>https://keys.mailvelope.com/pks/lookup?op=get&search=0x9A830097CA066684</span></a><o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p></div><p class=MsoNormal><o:p> </o:p></p><div><div style='border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in'><p class=MsoNormal><b>From:</b> NCSG-Discuss <NCSG-DISCUSS@LISTSERV.SYR.EDU> <b>On Behalf Of </b>Arsène Tungali<br><b>Sent:</b> Wednesday, July 10, 2019 3:42 PM<br><b>To:</b> NCSG-DISCUSS@LISTSERV.SYR.EDU<br><b>Subject:</b> Re: Zoom Structural Vulnerability Discovered<o:p></o:p></p></div></div><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>Very good and informative discussion here around Adobe and Zoom! <o:p></o:p></p><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>On one side, i am pretty sure ICANN has some of the best techies as staff members and i am hoping we can continue to trust their guts.<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal style='margin-bottom:12.0pt'>On the other side, for the techies we have as members here, please do keep us posted for any tips on how we can stay safe while using these platforms whenever there is any breach found.<o:p></o:p></p><div id=AppleMailSignature><p class=MsoNormal>Sent from my iPhone<o:p></o:p></p></div><div><p class=MsoNormal style='margin-bottom:12.0pt'><br>On 10 Jul 2019, at 16:01, Schaefer, Brett <<a href="mailto:Brett.Schaefer@heritage.org">Brett.Schaefer@heritage.org</a>> wrote:<o:p></o:p></p></div><blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'><div><p class=8e96fa11-c06d-4965-8817-8ff46765e27f style='margin-bottom:12.0pt'>The most recent Risky Business podcast discusses this Zoom issue. You might find it an interesting listen. <o:p></o:p></p><div id=AppleMailSignature><p class=MsoNormal>__________<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div class=MsoNormal><hr size=2 width=160 style='width:120.0pt' noshade style='color:#58595B' align=left></div><p class=MsoNormal><b><span style='font-size:10.0pt;color:#004B8D'>Brett</span></b> <b><span style='font-size:10.0pt;color:#004B8D'>Schaefer</span></b><i><span style='font-size:10.0pt;color:#58595B'><br>Jay Kingham Senior Research Fellow in International Regulatory Affairs<br>Margaret Thatcher Center for Freedom Davis Institute for National Security and Foreign Policy</span></i><br><span style='font-size:10.0pt;color:#58595B'>The Heritage Foundation<br>214 Massachusetts Avenue, NE<br>Washington, DC 20002<br>202-608-6097</span><br><span style='font-size:10.0pt;color:#004B8D'><a href="http://heritage.org/"><span style='color:#004B8D;text-decoration:none'>heritage.org</span></a><o:p></o:p></span></p><div><p class=MsoNormal style='margin-bottom:12.0pt'>On Jul 10, 2019, at 9:54 AM, Alan Levin <<a href="mailto:alan@afridns.org">alan@afridns.org</a>> wrote:<o:p></o:p></p></div><div><div><div><p class=MsoNormal>On Wed, Jul 10, 2019 at 3:21 PM Jean-Jacques Subrenat <<a href="mailto:jjs@dyalog.net">jjs@dyalog.net</a>> wrote:<o:p></o:p></p></div><div><blockquote style='border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in'><div><div id="gmail-m_-8124010385389413219bloop_customfont"><p class=MsoNormal><span style='font-size:10.0pt;font-family:"Helvetica",sans-serif;color:black'>Then, a recommendation to Chairs of ACs and SOs: ICANN Board and CEO could be requested to set up a specifications sheet for a desirable conferencing tool, based on needs expressed by the multi-stakeholder community, and publish that as a tender. Offers received could then be reviewed not only by Staff, but in consultation with ACs and SOs.<o:p></o:p></span></p></div><div id="gmail-m_-8124010385389413219bloop_customfont"><p class=MsoNormal><span style='font-size:10.0pt;font-family:"Helvetica",sans-serif;color:black'>This would get us closer to what we, collectively, consider as the appropriate tool for the numerous conference calls held throughout ICANN.<o:p></o:p></span></p></div></div></blockquote><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>Agreed... <o:p></o:p></p></div><div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>I'm an open (systems) person and I have seen so many ICANN/ISOC decisions supporting "closed" and prorietary systems. I always shudder at the Zoom/Adobe options in this regard...<o:p></o:p></p></div><div><p class=MsoNormal>At ISOC-ZA and ISPA we use <a href="https://jitsi.org/" target="_blank">https://jitsi.org/</a> <o:p></o:p></p><p class=MsoNormal> - works brilliantly... <o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>Unfortunately open systems companies don't respond to tenders... <o:p></o:p></p></div><div><p class=MsoNormal>I suggest such a tender is written to support the use of open systems rather than the "provision of a closed software solution" <o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>hth<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>aL <o:p></o:p></p></div></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal> <o:p></o:p></p></div></div></div></div></div></blockquote></div></div></body></html>