Zoom Structural Vulnerability Discovered
Ayden Férdeline
icann at FERDELINE.COM
Wed Jul 10 17:58:13 EEST 2019
Apple has now released a software update for Macs to correct the vulnerability in Zoom.
“Apple often pushes silent signature updates to Macs to thwart known malware — similar to an anti-malware service — but it’s rare for Apple to take action publicly against a known or popular app. The company said it pushed the update to protect users from the risks posed by the exposed web server.“
https://techcrunch.com/2019/07/10/apple-silent-update-zoom-app/
Ayden Férdeline
On Wed, Jul 10, 2019 at 18:02, Paul Rosenzweig <paul.rosenzweig at REDBRANCHCONSULTING.COM> wrote:
> From a different list of mine:
>
> “A vulnerability in Zoom conferencing software was published yesterday. The security concern was this could potentially allow malicious websites access and control to Mac cameras. This impacts only Mac users who have the Zoom application installed on their computer. PC users and people who join meetings by clicking through their browser are not impacted.
>
> Zoom has released a patch that [we] will be pushing out to … impacted users this evening. You do not need to do anything special at this time, the patch will install automatically and will not require a restart of your machine. If you do have Zoom installed, and are still nervous about your camera, you can open the Zoom application, go into video settings, and select the checkbox next to: "Turn off my video when joining a meeting." This will turn your camera off by default on any Zoom meetings you join. If you want to show your video, you can do that from within any meeting once you get there.”
>
> I assume that, soon, Zoom will push this universally to all users (including ICANN) as well
>
> Paul
>
> Paul Rosenzweig
>
> paul.rosenzweig at redbranchconsulting.com
>
> O: +1 (202) 547-0660
>
> M: +1 (202) 329-9650
>
> VOIP: +1 (202) 738-1739
>
> [www.redbranchconsulting.com](http://www.redbranchconsulting.com/)
>
> My PGP Key: https://keys.mailvelope.com/pks/lookup?op=get&search=0x9A830097CA066684
>
> From: NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU> On Behalf Of Arsène Tungali
> Sent: Wednesday, July 10, 2019 3:42 PM
> To: NCSG-DISCUSS at LISTSERV.SYR.EDU
> Subject: Re: Zoom Structural Vulnerability Discovered
>
> Very good and informative discussion here around Adobe and Zoom!
>
> On one side, i am pretty sure ICANN has some of the best techies as staff members and i am hoping we can continue to trust their guts.
>
> On the other side, for the techies we have as members here, please do keep us posted for any tips on how we can stay safe while using these platforms whenever there is any breach found.
>
> Sent from my iPhone
>
> On 10 Jul 2019, at 16:01, Schaefer, Brett <Brett.Schaefer at heritage.org> wrote:
>
>> The most recent Risky Business podcast discusses this Zoom issue. You might find it an interesting listen.
>>
>> __________
>>
>> ---------------------------------------------------------------
>>
>> Brett Schaefer
>> Jay Kingham Senior Research Fellow in International Regulatory Affairs
>> Margaret Thatcher Center for Freedom Davis Institute for National Security and Foreign Policy
>> The Heritage Foundation
>> 214 Massachusetts Avenue, NE
>> Washington, DC 20002
>> 202-608-6097
>> [heritage.org](http://heritage.org/)
>>
>> On Jul 10, 2019, at 9:54 AM, Alan Levin <alan at afridns.org> wrote:
>>
>> On Wed, Jul 10, 2019 at 3:21 PM Jean-Jacques Subrenat <jjs at dyalog.net> wrote:
>>
>>> Then, a recommendation to Chairs of ACs and SOs: ICANN Board and CEO could be requested to set up a specifications sheet for a desirable conferencing tool, based on needs expressed by the multi-stakeholder community, and publish that as a tender. Offers received could then be reviewed not only by Staff, but in consultation with ACs and SOs.
>>>
>>> This would get us closer to what we, collectively, consider as the appropriate tool for the numerous conference calls held throughout ICANN.
>>
>> Agreed...
>>
>> I'm an open (systems) person and I have seen so many ICANN/ISOC decisions supporting "closed" and prorietary systems. I always shudder at the Zoom/Adobe options in this regard...
>>
>> At ISOC-ZA and ISPA we use https://jitsi.org/
>>
>> - works brilliantly...
>>
>> Unfortunately open systems companies don't respond to tenders...
>>
>> I suggest such a tender is written to support the use of open systems rather than the "provision of a closed software solution"
>>
>> hth
>>
>> aL
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20190710/a8d1c689/attachment.htm>
More information about the Ncsg-discuss
mailing list