Zoom Structural Vulnerability Discovered

Ayden Férdeline icann at FERDELINE.COM
Wed Jul 10 14:57:42 EEST 2019


I do not want to be seen as offering Adobe too much praise, but I do think it is important to consider the severity between the vulnerabilities we were made aware of in Adobe Connect versus those we now know of in Zoom. With Adobe Connect, the (fixed) vulnerability was that the chat box could be read by anyone. Given we operate in the open, and we save the chat messages anyway, this did not seem a massive issue to me. Nonetheless, Adobe promptly fixed this issue. The situation in Zoom, however, struck me as more severe: a Mac's webcam can be activated without one's knowledge, and this situation was not resolved immediately. The security researcher gave them 90 days before going public with his concerns.

Best wishes, Ayden Férdeline

‐‐‐‐‐‐‐ Original Message ‐‐‐‐‐‐‐
On Wednesday, 10 July 2019 20:42, Arsène Tungali <arsenebaguma at GMAIL.COM> wrote:

> Very good and informative discussion here around Adobe and Zoom!
>
> On one side, i am pretty sure ICANN has some of the best techies as staff members and i am hoping we can continue to trust their guts.
>
> On the other side, for the techies we have as members here, please do keep us posted for any tips on how we can stay safe while using these platforms whenever there is any breach found.
>
> Sent from my iPhone
>
> On 10 Jul 2019, at 16:01, Schaefer, Brett <Brett.Schaefer at heritage.org> wrote:
>
>> The most recent Risky Business podcast discusses this Zoom issue. You might find it an interesting listen.
>>
>> __________
>>
>> ---------------------------------------------------------------
>> Brett Schaefer
>> Jay Kingham Senior Research Fellow in International Regulatory Affairs
>> Margaret Thatcher Center for Freedom Davis Institute for National Security and Foreign Policy
>> The Heritage Foundation
>> 214 Massachusetts Avenue, NE
>> Washington, DC 20002
>> 202-608-6097
>> [heritage.org](http://heritage.org/)
>>
>> On Jul 10, 2019, at 9:54 AM, Alan Levin <alan at afridns.org> wrote:
>>
>> On Wed, Jul 10, 2019 at 3:21 PM Jean-Jacques Subrenat <jjs at dyalog.net> wrote:
>>
>>> Then, a recommendation to Chairs of ACs and SOs: ICANN Board and CEO could be requested to set up a specifications sheet for a desirable conferencing tool, based on needs expressed by the multi-stakeholder community, and publish that as a tender. Offers received could then be reviewed not only by Staff, but in consultation with ACs and SOs.
>>> This would get us closer to what we, collectively, consider as the appropriate tool for the numerous conference calls held throughout ICANN.
>>
>> Agreed...
>>
>> I'm an open (systems) person and I have seen so many ICANN/ISOC decisions supporting "closed" and prorietary systems. I always shudder at the Zoom/Adobe options in this regard...
>> At ISOC-ZA and ISPA we use https://jitsi.org/
>>
>>  - works brilliantly...
>>
>> Unfortunately open systems companies don't respond to tenders...
>> I suggest such a tender is written to support the use of open systems rather than the "provision of a closed software solution"
>>
>> hth
>>
>> aL
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20190710/13b5a0f9/attachment.htm>


More information about the Ncsg-discuss mailing list