<html><head><style>body{font-family:Helvetica,Arial;font-size:13px}</style></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;"><div id="bloop_customfont" style="font-family:Helvetica,Arial;font-size:13px; color: rgba(0,0,0,1.0); margin: 0px; line-height: auto;">The information provided on this thread (repairs by Zoom, Adobe, Apple) is interesting.</div><div id="bloop_customfont" style="font-family:Helvetica,Arial;font-size:13px; color: rgba(0,0,0,1.0); margin: 0px; line-height: auto;"><br></div><div id="bloop_customfont" style="font-family:Helvetica,Arial;font-size:13px; color: rgba(0,0,0,1.0); margin: 0px; line-height: auto;">But I was trying to make a broader point: we could suggest a bottom-up approach in defining the parameters of a collective conference tool. Providers would then be invited to make offers, commercial or otherwise.</div><div id="bloop_customfont" style="font-family:Helvetica,Arial;font-size:13px; color: rgba(0,0,0,1.0); margin: 0px; line-height: auto;"><br></div><div id="bloop_customfont" style="font-family:Helvetica,Arial;font-size:13px; color: rgba(0,0,0,1.0); margin: 0px; line-height: auto;">In essence, what I’m suggesting is </div><div id="bloop_customfont" style="font-family:Helvetica,Arial;font-size:13px; color: rgba(0,0,0,1.0); margin: 0px; line-height: auto;">- empowering the community,</div><div id="bloop_customfont" style="font-family:Helvetica,Arial;font-size:13px; color: rgba(0,0,0,1.0); margin: 0px; line-height: auto;">- creating some sense of competition among potential providers to come up with a solution to the problem defined by the community, rather than community having to adapt to their pre-defined solutions,</div><div id="bloop_customfont" style="font-family:Helvetica,Arial;font-size:13px; color: rgba(0,0,0,1.0); margin: 0px; line-height: auto;">- enabling the community, alongside ICANN leadership and/or Staff, to be part of both the definition AND the chosen solution.</div><div id="bloop_customfont" style="font-family:Helvetica,Arial;font-size:13px; color: rgba(0,0,0,1.0); margin: 0px; line-height: auto;"><br></div><div id="bloop_customfont" style="font-family:Helvetica,Arial;font-size:13px; color: rgba(0,0,0,1.0); margin: 0px; line-height: auto;">Surely we don’t need to be apologetic about being multi-stakeholder, perhaps even socially (and not only technically) innovative?</div><div id="bloop_customfont" style="font-family:Helvetica,Arial;font-size:13px; color: rgba(0,0,0,1.0); margin: 0px; line-height: auto;"><br></div><div id="bloop_customfont" style="font-family:Helvetica,Arial;font-size:13px; color: rgba(0,0,0,1.0); margin: 0px; line-height: auto;">Jean-Jacques Subrenat.</div> <br> <div id="bloop_sign_1562821804181732096" class="bloop_sign"></div> <br><p class="airmail_on">Le 11 juillet 2019 à 00:59:08, Ayden Férdeline (<a href="mailto:icann@ferdeline.com">icann@ferdeline.com</a>) a écrit:</p> <blockquote type="cite" class="clean_bq"><span><div><div></div><div>
<title></title>
<div>Apple has now released a software update for Macs to correct
the vulnerability in Zoom.</div>
<div><br></div>
<div><span style="caret-color: rgb(51, 51, 51); color: rgb(51, 51, 51); font-family: "Helvetica Neue", Helvetica, Arial, sans-serif; -webkit-text-size-adjust: 100%;">
“Apple often pushes silent signature updates to Macs to thwart
known malware — similar to an anti-malware service — but it’s rare
for Apple to take action publicly against a known or popular app.
The company said it pushed the update to protect users from the
risks posed by the exposed web server.“</span><br></div>
<div><span style="caret-color: rgb(51, 51, 51); color: rgb(51, 51, 51); font-family: "Helvetica Neue", Helvetica, Arial, sans-serif; -webkit-text-size-adjust: 100%;">
<br></span></div>
<div><a href="https://techcrunch.com/2019/07/10/apple-silent-update-zoom-app/">https://techcrunch.com/2019/07/10/apple-silent-update-zoom-app/</a><span style="caret-color: rgb(51, 51, 51); color: rgb(51, 51, 51); font-family: "Helvetica Neue", Helvetica, Arial, sans-serif; -webkit-text-size-adjust: 100%;"><br>
</span></div>
<div><br></div>
<div id="protonmail_mobile_signature_block">
<div>Ayden Férdeline </div>
</div>
<div><br></div>
<div><br></div>
On Wed, Jul 10, 2019 at 18:02, Paul Rosenzweig <<a href="mailto:paul.rosenzweig@REDBRANCHCONSULTING.COM" class="">paul.rosenzweig@REDBRANCHCONSULTING.COM</a>> wrote:
<blockquote class="protonmail_quote" type="cite">
<div class="WordSection1">
<p class="MsoNormal">From a different list of mine:</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">“A vulnerability in Zoom conferencing software
was published yesterday. The security concern was this could
potentially allow malicious websites access and control to Mac
cameras. This impacts only Mac users who have the Zoom application
installed on their computer. PC users and people who join
meetings by clicking through their browser are not impacted.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Zoom has released a patch that [we] will be
pushing out to … impacted users this evening. You do not need to do
anything special at this time, the patch will install automatically
and will not require a restart of your machine. If you do have Zoom
installed, and are still nervous about your camera, you can open
the Zoom application, go into video settings, and select the
checkbox next to: "Turn off my video when joining a meeting." This
will turn your camera off by default on any Zoom meetings you join.
If you want to show your video, you can do that from within any
meeting once you get there.”</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">I assume that, soon, Zoom will push this
universally to all users (including ICANN) as well</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Paul</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal"> </p>
<p class="MsoNormal"> </p>
<div>
<p class="MsoNormal">Paul Rosenzweig</p>
<p class="MsoNormal"><a href="mailto:paul.rosenzweig@redbranchconsulting.com"><span style="color:#0563C1">paul.rosenzweig@redbranchconsulting.com</span></a></p>
<p class="MsoNormal">O: +1 (202) 547-0660</p>
<p class="MsoNormal">M: +1 (202) 329-9650</p>
<p class="MsoNormal">VOIP: +1 (202) 738-1739</p>
<p class="MsoNormal"><a href="http://www.redbranchconsulting.com/"><span style="color:#0563C1">www.redbranchconsulting.com</span></a></p>
<p class="MsoNormal">My PGP Key: <a href="https://keys.mailvelope.com/pks/lookup?op=get&search=0x9A830097CA066684">
<span style="color:#0563C1">https://keys.mailvelope.com/pks/lookup?op=get&search=0x9A830097CA066684</span></a></p>
<p class="MsoNormal"> </p>
</div>
<p class="MsoNormal"> </p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b>From:</b> NCSG-Discuss
<NCSG-DISCUSS@LISTSERV.SYR.EDU> <b>On Behalf Of</b> Arsène
Tungali<br>
<b>Sent:</b> Wednesday, July 10, 2019 3:42 PM<br>
<b>To:</b> NCSG-DISCUSS@LISTSERV.SYR.EDU<br>
<b>Subject:</b> Re: Zoom Structural Vulnerability Discovered</p>
</div>
</div>
<p class="MsoNormal"> </p>
<p class="MsoNormal">Very good and informative discussion here
around Adobe and Zoom! </p>
<div>
<p class="MsoNormal"> </p>
</div>
<div>
<p class="MsoNormal">On one side, i am pretty sure ICANN has some
of the best techies as staff members and i am hoping we can
continue to trust their guts.</p>
</div>
<div>
<p class="MsoNormal"> </p>
</div>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt">On the other
side, for the techies we have as members here, please do keep us
posted for any tips on how we can stay safe while using these
platforms whenever there is any breach found.</p>
<div id="AppleMailSignature">
<p class="MsoNormal">Sent from my iPhone</p>
</div>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><br>
On 10 Jul 2019, at 16:01, Schaefer, Brett <<a href="mailto:Brett.Schaefer@heritage.org">Brett.Schaefer@heritage.org</a>>
wrote:</p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<p class="8e96fa11-c06d-4965-8817-8ff46765e27f" style="margin-bottom:12.0pt">The most recent Risky Business podcast
discusses this Zoom issue. You might find it an interesting
listen. </p>
<div id="AppleMailSignature">
<p class="MsoNormal">__________</p>
</div>
<div>
<p class="MsoNormal"> </p>
</div>
<div class="MsoNormal">
<hr size="2" width="160" style="width:120.0pt" noshade="noshade" align="left"></div>
<p class="MsoNormal"><b><span style="font-size:10.0pt;color:#004B8D">Brett</span></b> <b><span style="font-size:10.0pt;color:#004B8D">Schaefer</span></b><i><span style="font-size:10.0pt;color:#58595B"><br>
Jay Kingham Senior Research Fellow in International Regulatory
Affairs<br>
Margaret Thatcher Center for Freedom Davis Institute for National
Security and Foreign Policy</span></i><br>
<span style="font-size:10.0pt;color:#58595B">The Heritage
Foundation<br>
214 Massachusetts Avenue, NE<br>
Washington, DC 20002<br>
202-608-6097</span><br>
<span style="font-size:10.0pt;color:#004B8D"><a href="http://heritage.org/"><span style="color:#004B8D;text-decoration:none">heritage.org</span></a></span></p>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt">On Jul 10, 2019,
at 9:54 AM, Alan Levin <<a href="mailto:alan@afridns.org">alan@afridns.org</a>> wrote:</p>
</div>
<div>
<div>
<div>
<p class="MsoNormal">On Wed, Jul 10, 2019 at 3:21 PM Jean-Jacques
Subrenat <<a href="mailto:jjs@dyalog.net">jjs@dyalog.net</a>>
wrote:</p>
</div>
<div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<div id="gmail-m_-8124010385389413219bloop_customfont">
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Helvetica",sans-serif;color:black">
Then, a recommendation to Chairs of ACs and SOs: ICANN Board and
CEO could be requested to set up a specifications sheet for a
desirable conferencing tool, based on needs expressed by the
multi-stakeholder community, and publish that as a tender. Offers
received could then be reviewed not only by Staff, but in
consultation with ACs and SOs.</span></p>
</div>
<div id="gmail-m_-8124010385389413219bloop_customfont">
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Helvetica",sans-serif;color:black">
This would get us closer to what we, collectively, consider as the
appropriate tool for the numerous conference calls held throughout
ICANN.</span></p>
</div>
</div>
</blockquote>
<div>
<p class="MsoNormal"> </p>
</div>
<div>
<p class="MsoNormal">Agreed... </p>
</div>
<div>
<div>
<p class="MsoNormal"> </p>
</div>
<div>
<p class="MsoNormal">I'm an open (systems) person and I have seen
so many ICANN/ISOC decisions supporting "closed" and prorietary
systems. I always shudder at the Zoom/Adobe options in this
regard...</p>
</div>
<div>
<p class="MsoNormal">At ISOC-ZA and ISPA we use <a href="https://jitsi.org/">https://jitsi.org/</a></p>
<p class="MsoNormal"> - works brilliantly... </p>
</div>
<div>
<p class="MsoNormal"> </p>
</div>
<div>
<p class="MsoNormal">Unfortunately open systems companies don't
respond to tenders... </p>
</div>
<div>
<p class="MsoNormal">I suggest such a tender is written to support
the use of open systems rather than the "provision of a closed
software solution" </p>
</div>
<div>
<p class="MsoNormal"> </p>
</div>
<div>
<p class="MsoNormal">hth</p>
</div>
<div>
<p class="MsoNormal"> </p>
</div>
<div>
<p class="MsoNormal">aL </p>
</div>
</div>
<div>
<p class="MsoNormal"> </p>
</div>
<div>
<p class="MsoNormal"> </p>
</div>
<div>
<p class="MsoNormal"> </p>
</div>
<div>
<p class="MsoNormal"> </p>
</div>
<div>
<p class="MsoNormal"> </p>
</div>
<div>
<p class="MsoNormal"> </p>
</div>
</div>
</div>
</div>
</div>
</blockquote>
</div>
</div>
</blockquote>
<div><br></div>
<div><br></div>
</div></div></span></blockquote></body></html>