Zoom Structural Vulnerability Discovered
Paul Rosenzweig
paul.rosenzweig at REDBRANCHCONSULTING.COM
Wed Jul 10 17:02:42 EEST 2019
>From a different list of mine:
“A vulnerability in Zoom conferencing software was published yesterday. The security concern was this could potentially allow malicious websites access and control to Mac cameras. This impacts only Mac users who have the Zoom application installed on their computer. PC users and people who join meetings by clicking through their browser are not impacted.
Zoom has released a patch that [we] will be pushing out to … impacted users this evening. You do not need to do anything special at this time, the patch will install automatically and will not require a restart of your machine. If you do have Zoom installed, and are still nervous about your camera, you can open the Zoom application, go into video settings, and select the checkbox next to: "Turn off my video when joining a meeting." This will turn your camera off by default on any Zoom meetings you join. If you want to show your video, you can do that from within any meeting once you get there.”
I assume that, soon, Zoom will push this universally to all users (including ICANN) as well
Paul
Paul Rosenzweig
<mailto:paul.rosenzweig at redbranchconsulting.com> paul.rosenzweig at redbranchconsulting.com
O: +1 (202) 547-0660
M: +1 (202) 329-9650
VOIP: +1 (202) 738-1739
<http://www.redbranchconsulting.com/> www.redbranchconsulting.com
My PGP Key: <https://keys.mailvelope.com/pks/lookup?op=get&search=0x9A830097CA066684> https://keys.mailvelope.com/pks/lookup?op=get&search=0x9A830097CA066684
From: NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU> On Behalf Of Arsène Tungali
Sent: Wednesday, July 10, 2019 3:42 PM
To: NCSG-DISCUSS at LISTSERV.SYR.EDU
Subject: Re: Zoom Structural Vulnerability Discovered
Very good and informative discussion here around Adobe and Zoom!
On one side, i am pretty sure ICANN has some of the best techies as staff members and i am hoping we can continue to trust their guts.
On the other side, for the techies we have as members here, please do keep us posted for any tips on how we can stay safe while using these platforms whenever there is any breach found.
Sent from my iPhone
On 10 Jul 2019, at 16:01, Schaefer, Brett <Brett.Schaefer at heritage.org <mailto:Brett.Schaefer at heritage.org> > wrote:
The most recent Risky Business podcast discusses this Zoom issue. You might find it an interesting listen.
__________
_____
Brett Schaefer
Jay Kingham Senior Research Fellow in International Regulatory Affairs
Margaret Thatcher Center for Freedom Davis Institute for National Security and Foreign Policy
The Heritage Foundation
214 Massachusetts Avenue, NE
Washington, DC 20002
202-608-6097
<http://heritage.org/> heritage.org
On Jul 10, 2019, at 9:54 AM, Alan Levin <alan at afridns.org <mailto:alan at afridns.org> > wrote:
On Wed, Jul 10, 2019 at 3:21 PM Jean-Jacques Subrenat <jjs at dyalog.net <mailto:jjs at dyalog.net> > wrote:
Then, a recommendation to Chairs of ACs and SOs: ICANN Board and CEO could be requested to set up a specifications sheet for a desirable conferencing tool, based on needs expressed by the multi-stakeholder community, and publish that as a tender. Offers received could then be reviewed not only by Staff, but in consultation with ACs and SOs.
This would get us closer to what we, collectively, consider as the appropriate tool for the numerous conference calls held throughout ICANN.
Agreed...
I'm an open (systems) person and I have seen so many ICANN/ISOC decisions supporting "closed" and prorietary systems. I always shudder at the Zoom/Adobe options in this regard...
At ISOC-ZA and ISPA we use https://jitsi.org/
- works brilliantly...
Unfortunately open systems companies don't respond to tenders...
I suggest such a tender is written to support the use of open systems rather than the "provision of a closed software solution"
hth
aL
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20190710/f1407b50/attachment.htm>
More information about the Ncsg-discuss
mailing list