<div dir="ltr"><div class="gmail_default" style=""><font face="arial, sans-serif"><span style="color:rgba(0,0,0,0.9);white-space:pre-wrap;background-color:rgb(243,246,248)"></span></font><p style="box-sizing:inherit;margin:0px;padding:0px;border:0px;vertical-align:baseline;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;line-height:1.5;color:rgba(0,0,0,0.9);white-space:pre-wrap"><font face="arial, sans-serif" style="">Zoom has privacy and security issues, let's get that out of the way. </font></p><p style="box-sizing:inherit;margin:0px;padding:0px;border:0px;vertical-align:baseline;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;line-height:1.5;color:rgba(0,0,0,0.9);white-space:pre-wrap"><font face="arial, sans-serif"><br style="box-sizing:inherit"></font></p><p style="box-sizing:inherit;margin:0px;padding:0px;border:0px;vertical-align:baseline;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;line-height:1.5;color:rgba(0,0,0,0.9);white-space:pre-wrap"><font face="arial, sans-serif">However, other platforms like Microsoft Teams, Cisco WebEx, Citrix GoToMeeting, Slack, and others also have their own issues around privacy and security. WebEx does not employ end-to-end encryption by default (and many users don't know this). GoToMeeting has input validation and authentication issues and doesn't have any measures to alert or prevent others from recording sessions, among other things. Most all of them have third-party integration or API call vulnerabilities. Another issue is that for functionality and ease of use reasons, many of the robust privacy and security controls in these platforms are switched off by default. There are also issues with underlying OS issues that can be exploited through the tools.</font></p><p style="box-sizing:inherit;margin:0px;padding:0px;border:0px;vertical-align:baseline;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;line-height:1.5;color:rgba(0,0,0,0.9);white-space:pre-wrap"><font face="arial, sans-serif"><br></font></p><p style="box-sizing:inherit;margin:0px;padding:0px;border:0px;vertical-align:baseline;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;line-height:1.5;color:rgba(0,0,0,0.9);white-space:pre-wrap"><font face="arial, sans-serif">Shouldn't the larger and more valuable discussion be about how we focus our efforts on making online platforms across the board more secure and privacy respecting?</font></p><p style="box-sizing:inherit;margin:0px;padding:0px;border:0px;vertical-align:baseline;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;line-height:1.5;color:rgba(0,0,0,0.9);white-space:pre-wrap"><font face="arial, sans-serif"><br></font></p><p style="box-sizing:inherit;margin:0px;padding:0px;border:0px;vertical-align:baseline;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;line-height:1.5;color:rgba(0,0,0,0.9);white-space:pre-wrap"><font face="arial, sans-serif">This Zoom bashing is a distraction and not constructive at all.</font></p><p style="box-sizing:inherit;margin:0px;padding:0px;border:0px;vertical-align:baseline;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;line-height:1.5;color:rgba(0,0,0,0.9);white-space:pre-wrap"><font face="arial, sans-serif"><br></font></p><p style="box-sizing:inherit;margin:0px;padding:0px;border:0px;vertical-align:baseline;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;line-height:1.5;color:rgba(0,0,0,0.9);white-space:pre-wrap"><font face="arial, sans-serif">Regards,</font></p><p style="box-sizing:inherit;margin:0px;padding:0px;border:0px;vertical-align:baseline;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;line-height:1.5;color:rgba(0,0,0,0.9);white-space:pre-wrap"><font face="arial, sans-serif"><br></font></p><p style="box-sizing:inherit;margin:0px;padding:0px;border:0px;vertical-align:baseline;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;line-height:1.5;color:rgba(0,0,0,0.9);white-space:pre-wrap"><font face="arial, sans-serif" style="">Niel Harper</font></p></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Apr 3, 2020 at 10:49 AM lists@icann.guru <lists@icann.guru> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div id="gmail-m_2455771518338999852__MailbirdStyleContent" style="font-size:10pt;font-family:Arial;color:rgb(0,0,0)">
                                        
                                        
                                            
                                        
                                        
                                        For 95% of peoples threat models there is no actual risk here. Its fearmongering at its worst.<br><div><br></div><div><span style="font-size:8pt"><b>---</b></span><div><span style="font-size:8pt"><b>James Gannon</b></span></div></div><blockquote type="cite" style="border-left-style:solid;border-width:1px;margin-top:20px;margin-left:0px;padding-left:10px">
                        <p style="color:rgb(170,170,170);margin-top:10px">On 03/04/2020 09:47:48, Michael J. Oghia <<a href="mailto:mike.oghia@gmail.com" target="_blank">mike.oghia@gmail.com</a>> wrote:</p><div style="font-family:Arial,Helvetica,sans-serif"><div dir="ltr">Raoul, all;<div><br></div><div>Here is the official response from Zoom: <a href="https://blog.zoom.us/wordpress/2020/04/01/facts-around-zoom-encryption-for-meetings-webinars/" target="_blank">https://blog.zoom.us/wordpress/2020/04/01/facts-around-zoom-encryption-for-meetings-webinars/</a></div><div><br></div><div>What do you all make of it? At the moment, I don't intend to switch services and hope this can help strengthen Zoom's security and transparency processes going forward.</div><div><br clear="all"><div><div dir="ltr"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><span style="font-family:arial,helvetica,sans-serif">Stay safe and well,</span></div><div dir="ltr"><span style="font-family:arial,helvetica,sans-serif">-Michael</span><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><br></div></div></div>
</div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Apr 3, 2020 at 5:14 AM Caleb Olumuyiwa Ogundele <<a href="mailto:muyiwacaleb@gmail.com" target="_blank">muyiwacaleb@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="auto">Hello Dorothy and All, <div dir="auto"><br></div><div dir="auto">I'm a strong advocate of FOSS. However, using Linux does not always means it's full proof from attacks. </div><div dir="auto"><br></div><div dir="auto">That said, on an advisory note to ICANN ORG, <b style="background-color:rgb(239,154,154)">SSAC</b> used to be at the fore </div><div dir="auto">front of these things and we have not seen them flag this yet. Are they socially distancing themselves from Zoom? </div><div dir="auto"><br></div><div dir="auto">In another news, I had concerns about the report ICANN shared recently. It contained information that suggests ICANN had access to some attendees usage of the app. For sure I know hosts might know the programs I'm running at the instance of that meeting. </div><div dir="auto">If you read the privacy policy of zoom, it says :"<b>we may collect Personal Data from or about you when you use or otherwise interact with our Products." </b></div><div dir="auto">That also calls for concerns. </div><div dir="auto"><br></div><div dir="auto">Speaking of Linux and FOSS. Perhaps, now is the time for FOSS enthusiasts to consider running all zoom meeting instances on a sandboxed VM or flatpak. </div><div dir="auto"><br></div><div dir="auto">Now that we are locked in and it does not seem we have much alternative. Here is a text and video guide for not so technically advanced users who do not know how to use sandboxed VM or flatpak to help us at the moment pending when zoom fixes it's flaws. </div><div dir="auto"><br></div><div dir="auto"><a href="https://youtu.be/JvTMA6d-LwU" rel="noreferrer" target="_blank">https://youtu.be/JvTMA6d-LwU</a><br></div><div dir="auto"><br></div><div dir="auto">Or</div><div dir="auto"><br></div><div dir="auto"><br></div><div dir="auto"><a href="https://www.wordfence.com/blog/2020/04/safety-and-security-while-video-conferencing/" rel="noreferrer" target="_blank">https://www.wordfence.com/blog/2020/04/safety-and-security-while-video-conferencing/</a><br></div><div dir="auto"><br></div><div dir="auto"><br></div><div dir="auto"><div dir="auto">Caleb Ogundele<br><br>________________<br><br>Sent with thumbs from a small screen mobile device. <br><br>Pelase exsuce typos adn errosr.</div></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Apr 2, 2020, 9:46 AM dorothy g <<a href="mailto:dgdorothydg@gmail.com" rel="noreferrer noreferrer noreferrer" target="_blank">dgdorothydg@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div class="gmail_default" style="font-size:10pt">Stick with Linux!</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Apr 2, 2020 at 8:16 AM Joly MacFie <<a href="mailto:jolynyc@gmail.com" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">jolynyc@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div class="gmail_default" style="font-size:10pt">I agree with this commenter.</div><div class="gmail_default" style="font-size:10pt"><a href="https://arstechnica.com/information-technology/2020/04/unpatched-zoom-bug-lets-attackers-steal-windows-credentials-with-no-warning/?comments=1&post=38771635#comment-38771635" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">https://arstechnica.com/information-technology/2020/04/unpatched-zoom-bug-lets-attackers-steal-windows-credentials-with-no-warning/?comments=1&post=38771635#comment-38771635</a><br></div><div class="gmail_default" style="font-size:10pt"><br></div><div class="gmail_default" style="font-size:10pt"><i><span style="color:rgb(0,0,0);font-family:opensans;font-size:14px">This is evidently a Microsoft Windows flaw.</span><br style="box-sizing:inherit;color:rgb(0,0,0);font-family:opensans;font-size:14px"><br style="box-sizing:inherit;color:rgb(0,0,0);font-family:opensans;font-size:14px"><span style="color:rgb(0,0,0);font-family:opensans;font-size:14px">It appears to be reported along the same lines as: the Tech Industry built insecure products, so let's train users to not click links.</span><br style="box-sizing:inherit;color:rgb(0,0,0);font-family:opensans;font-size:14px"><br style="box-sizing:inherit;color:rgb(0,0,0);font-family:opensans;font-size:14px"><span style="color:rgb(0,0,0);font-family:opensans;font-size:14px">Fix Windows so it doesn't send credentials to random SMB servers on the internet that bear no relation to the host's domain, and using an insecure protocol to boot.</span><br style="box-sizing:inherit;color:rgb(0,0,0);font-family:opensans;font-size:14px"><br style="box-sizing:inherit;color:rgb(0,0,0);font-family:opensans;font-size:14px"><span style="color:rgb(0,0,0);font-family:opensans;font-size:14px">Sheesh!</span>  </i><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Apr 1, 2020 at 9:35 PM Raoul Plommer <<a href="mailto:plommer@gmail.com" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">plommer@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div>

<a href="https://arstechnica.com/information-technology/2020/04/unpatched-zoom-bug-lets-attackers-steal-windows-credentials-with-no-warning/" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">https://arstechnica.com/information-technology/2020/04/unpatched-zoom-bug-lets-attackers-steal-windows-credentials-with-no-warning/</a>

<br><br></div><div>This discovery was made yesterday, so it's not an April fool's day prank..</div><div><br></div><div>-Raoul<br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, 31 Mar 2020 at 17:41, Remmy Nweke <<a href="mailto:remmyn@gmail.com" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">remmyn@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr">Very instructive. Thanks<br clear="all"><div><div dir="ltr"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr">____<div>REMMY NWEKE, <span style="font-size:8pt">mNGE</span>,  </div><div>Lead Consulting Strategist/Group Executive Editor, <br><span style="background-color:rgb(255,0,0)">DigitalSENSE Africa Media</span> <span>[<i>Multiple-award winning medium</i>]<br></span>(<a href="http://www.digitalsenseafrica.com.ng/businessnews" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">DigitalSENSE Business News</a>; <a href="http://www.itrealms.com.ng" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">ITREALMS</a>, <a href="http://www.naijaagronet.com.ng" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">NaijaAgroNet</a>)</div><div>Block F1, Shop 133 Moyosore Aboderin Plaza, Bolade Junction, Oshodi-Lagos<br>M: 234-8033592762, 8023122558, 8051000475, T: <a href="http://www.twitter.com/ITRealms" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">@ITRealms<br></a><div>Author: <a href="https://www.facebook.com/adecadeofictreportageinnigeria%E2%80%8E" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">A Decade of ICT Reportage in Nigeria</a></div><div><br></div><div><b><span style="color:rgb(255,0,0)">2020 <a href="http://www.digitalsenseafrica.com.ng" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">Nigeria DigitalSENSE Forum on IG4D & Nigeria IPv6 Roundtable</a></span></b> </div><div>JOIN us!!</div><div><br></div><div>*Vice President, <a href="http://www.acsis-scasi.org/en/" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">African Civil Society on the Information Society (ACSIS</a>)</div><div>_________________________________________________________________<br><span style="font-size:8pt">*Confidentiality Notice:* The information in this document and attachments are confidential and may also be privileged information. It is intended only for the use of the named recipient. Remmy Nweke does not accept legal responsibility for the contents of this e-mail. If you are not the intended recipient, please notify me immediately, then delete this document and do not disclose the contents of this document to any other person, nor make any copies. Violators may face court persecution.<br></span><br></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Sat, Mar 28, 2020 at 12:03 AM Raoul Plommer <<a href="mailto:plommer@gmail.com" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">plommer@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><a href="https://www.vice.com/en_us/article/k7e599/zoom-ios-app-sends-data-to-facebook-even-if-you-dont-have-a-facebook-account" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">https://www.vice.com/en_us/article/k7e599/zoom-ios-app-sends-data-to-facebook-even-if-you-dont-have-a-facebook-account</a> <br><br><span style="color:rgb(0,0,0);font-family:Lora,Georgia,serif;font-size:18px">"The Zoom app notifies Facebook when the user opens the app, details on the user's device such as the model, the time zone and city they are connecting from, which phone carrier they are using, and a </span><a href="https://konsole.zendesk.com/hc/en-us/articles/115013349668-Identify-Android-AdIDs-Apple-IDFAs-and-Safari-IDs" style="box-sizing:inherit;color:rgb(0,0,0);font-family:Lora,Georgia,serif;font-size:18px" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">unique advertiser identifier</a><span style="color:rgb(0,0,0);font-family:Lora,Georgia,serif;font-size:18px"> created by the user's device which companies can use to </span><a href="https://www.singular.net/mobile-tutorial-series-idfa-apple-identifier-advertisers/" style="box-sizing:inherit;color:rgb(0,0,0);font-family:Lora,Georgia,serif;font-size:18px" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">target a user with advertisements</a>"<div><br></div><div>-Raoul<br><br>  <br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, 27 Mar 2020 at 17:53, Raoul Plommer <<a href="mailto:plommer@gmail.com" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">plommer@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr">FYI:<div><br></div><div><a href="https://www.theguardian.com/technology/2020/mar/27/trolls-zoom-privacy-settings-covid-19-lockdown" rel="noreferrer noreferrer noreferrer noreferrer" target="_blank">https://www.theguardian.com/technology/2020/mar/27/trolls-zoom-privacy-settings-covid-19-lockdown</a>  <br></div></div>
</blockquote></div>
</blockquote></div>
</blockquote></div>
</blockquote></div>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr"><div dir="ltr">Dorothy Gordon</div></div>
</blockquote></div>
</blockquote></div>
</div></blockquote>
                                        
                                        </div></blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr"><b>Niel Harper</b><br><div>Barbados: +(246) 424 3809<br></div><div>London: +44 207 193 9826<br></div><div>Mobile: +(246) 243 3818<br>Email: <a href="mailto:niel.harper@ieee.org" style="color:rgb(17,85,204)" target="_blank">niel.harper@ieee.org</a></div><div>Website: <a href="http://nielharper.com/" target="_blank">http://nielharper.com</a></div></div></div>