Zoom is compromised

Michael J. Oghia mike.oghia at GMAIL.COM
Fri Apr 3 06:29:33 EEST 2020


Some additional good news is that Zoom has agreed to create a transparency
report after Access Now advocated for them to create it:
https://www.accessnow.org/zoom-heeds-access-nows-call-for-transparency-reporting/

-Michael

On Fri, Apr 3, 2020 at 12:41 PM dorothy g <dgdorothydg at gmail.com> wrote:

> I agree with you we should work towards making online platforms across the
> board more secure and with greater respect for privacy but I do not see
> this discussion as zoom bashing. I use zoom all the time and will probably
> continue to do so, however once it is in 'official' use by ICANN we are
> totally justified in sharing concerns and figuring out how to protect
> ourselves.  I am deeply appreciative of those who brought these issues to
> our attention.  Thanks again!
>
> best to all
>
> On Fri, Apr 3, 2020 at 10:05 AM Niel Harper <niel.harper at ieee.org> wrote:
>
>> Zoom has privacy and security issues, let's get that out of the way.
>>
>>
>> However, other platforms like Microsoft Teams, Cisco WebEx, Citrix
>> GoToMeeting, Slack, and others also have their own issues around privacy
>> and security. WebEx does not employ end-to-end encryption by default (and
>> many users don't know this). GoToMeeting has input validation and
>> authentication issues and doesn't have any measures to alert or prevent
>> others from recording sessions, among other things. Most all of them have
>> third-party integration or API call vulnerabilities. Another issue is that
>> for functionality and ease of use reasons, many of the robust privacy and
>> security controls in these platforms are switched off by default. There are
>> also issues with underlying OS issues that can be exploited through the
>> tools.
>>
>>
>> Shouldn't the larger and more valuable discussion be about how we focus
>> our efforts on making online platforms across the board more secure and
>> privacy respecting?
>>
>>
>> This Zoom bashing is a distraction and not constructive at all.
>>
>>
>> Regards,
>>
>>
>> Niel Harper
>>
>> On Fri, Apr 3, 2020 at 10:49 AM lists at icann.guru <lists at icann.guru>
>> wrote:
>>
>>> For 95% of peoples threat models there is no actual risk here. Its
>>> fearmongering at its worst.
>>>
>>> *---*
>>> *James Gannon*
>>>
>>> On 03/04/2020 09:47:48, Michael J. Oghia <mike.oghia at gmail.com> wrote:
>>> Raoul, all;
>>>
>>> Here is the official response from Zoom:
>>> https://blog.zoom.us/wordpress/2020/04/01/facts-around-zoom-encryption-for-meetings-webinars/
>>>
>>> What do you all make of it? At the moment, I don't intend to switch
>>> services and hope this can help strengthen Zoom's security and transparency
>>> processes going forward.
>>>
>>> Stay safe and well,
>>> -Michael
>>>
>>>
>>>
>>> On Fri, Apr 3, 2020 at 5:14 AM Caleb Olumuyiwa Ogundele <
>>> muyiwacaleb at gmail.com> wrote:
>>>
>>>> Hello Dorothy and All,
>>>>
>>>> I'm a strong advocate of FOSS. However, using Linux does not always
>>>> means it's full proof from attacks.
>>>>
>>>> That said, on an advisory note to ICANN ORG, *SSAC* used to be at the
>>>> fore
>>>> front of these things and we have not seen them flag this yet. Are they
>>>> socially distancing themselves from Zoom?
>>>>
>>>> In another news, I had concerns about the report ICANN shared recently.
>>>> It contained information that suggests ICANN had access to some attendees
>>>> usage of the app. For sure I know hosts might know the programs I'm running
>>>> at the instance of that meeting.
>>>> If you read the privacy policy of zoom, it says :"*we may collect
>>>> Personal Data from or about you when you use or otherwise interact with our
>>>> Products." *
>>>> That also calls for concerns.
>>>>
>>>> Speaking of Linux and FOSS. Perhaps, now is the time for FOSS
>>>> enthusiasts to consider running all zoom meeting instances on a sandboxed
>>>> VM or flatpak.
>>>>
>>>> Now that we are locked in and it does not seem we have much
>>>> alternative. Here is a text and video guide for not so technically advanced
>>>> users who do not know how to use sandboxed VM or flatpak to help us at the
>>>> moment pending when zoom fixes it's flaws.
>>>>
>>>> https://youtu.be/JvTMA6d-LwU
>>>>
>>>> Or
>>>>
>>>>
>>>>
>>>> https://www.wordfence.com/blog/2020/04/safety-and-security-while-video-conferencing/
>>>>
>>>>
>>>> Caleb Ogundele
>>>>
>>>> ________________
>>>>
>>>> Sent with thumbs from a small screen mobile device.
>>>>
>>>> Pelase exsuce typos adn errosr.
>>>>
>>>> On Thu, Apr 2, 2020, 9:46 AM dorothy g <dgdorothydg at gmail.com> wrote:
>>>>
>>>>> Stick with Linux!
>>>>>
>>>>> On Thu, Apr 2, 2020 at 8:16 AM Joly MacFie <jolynyc at gmail.com> wrote:
>>>>>
>>>>>> I agree with this commenter.
>>>>>>
>>>>>> https://arstechnica.com/information-technology/2020/04/unpatched-zoom-bug-lets-attackers-steal-windows-credentials-with-no-warning/?comments=1&post=38771635#comment-38771635
>>>>>>
>>>>>>
>>>>>>
>>>>>>
>>>>>>
>>>>>>
>>>>>>
>>>>>> *This is evidently a Microsoft Windows flaw.It appears to be reported
>>>>>> along the same lines as: the Tech Industry built insecure products, so
>>>>>> let's train users to not click links.Fix Windows so it doesn't send
>>>>>> credentials to random SMB servers on the internet that bear no relation to
>>>>>> the host's domain, and using an insecure protocol to boot.Sheesh!  *
>>>>>>
>>>>>> On Wed, Apr 1, 2020 at 9:35 PM Raoul Plommer <plommer at gmail.com>
>>>>>> wrote:
>>>>>>
>>>>>>>
>>>>>>> https://arstechnica.com/information-technology/2020/04/unpatched-zoom-bug-lets-attackers-steal-windows-credentials-with-no-warning/
>>>>>>>
>>>>>>> This discovery was made yesterday, so it's not an April fool's day
>>>>>>> prank..
>>>>>>>
>>>>>>> -Raoul
>>>>>>>
>>>>>>> On Tue, 31 Mar 2020 at 17:41, Remmy Nweke <remmyn at gmail.com> wrote:
>>>>>>>
>>>>>>>> Very instructive. Thanks
>>>>>>>> ____
>>>>>>>> REMMY NWEKE, mNGE,
>>>>>>>> Lead Consulting Strategist/Group Executive Editor,
>>>>>>>> DigitalSENSE Africa Media [*Multiple-award winning medium*]
>>>>>>>> (DigitalSENSE Business News
>>>>>>>> <http://www.digitalsenseafrica.com.ng/businessnews>; ITREALMS
>>>>>>>> <http://www.itrealms.com.ng>, NaijaAgroNet
>>>>>>>> <http://www.naijaagronet.com.ng>)
>>>>>>>> Block F1, Shop 133 Moyosore Aboderin Plaza, Bolade Junction,
>>>>>>>> Oshodi-Lagos
>>>>>>>> M: 234-8033592762, 8023122558, 8051000475, T: @ITRealms
>>>>>>>> <http://www.twitter.com/ITRealms>
>>>>>>>> Author: A Decade of ICT Reportage in Nigeria
>>>>>>>> <https://www.facebook.com/adecadeofictreportageinnigeria%E2%80%8E>
>>>>>>>>
>>>>>>>> *2020 Nigeria DigitalSENSE Forum on IG4D & Nigeria IPv6 Roundtable
>>>>>>>> <http://www.digitalsenseafrica.com.ng>*
>>>>>>>> JOIN us!!
>>>>>>>>
>>>>>>>> *Vice President, African Civil Society on the Information Society
>>>>>>>> (ACSIS <http://www.acsis-scasi.org/en/>)
>>>>>>>> _________________________________________________________________
>>>>>>>> *Confidentiality Notice:* The information in this document and
>>>>>>>> attachments are confidential and may also be privileged information. It is
>>>>>>>> intended only for the use of the named recipient. Remmy Nweke does not
>>>>>>>> accept legal responsibility for the contents of this e-mail. If you are not
>>>>>>>> the intended recipient, please notify me immediately, then delete this
>>>>>>>> document and do not disclose the contents of this document to any other
>>>>>>>> person, nor make any copies. Violators may face court persecution.
>>>>>>>>
>>>>>>>>
>>>>>>>>
>>>>>>>> On Sat, Mar 28, 2020 at 12:03 AM Raoul Plommer <plommer at gmail.com>
>>>>>>>> wrote:
>>>>>>>>
>>>>>>>>>
>>>>>>>>> https://www.vice.com/en_us/article/k7e599/zoom-ios-app-sends-data-to-facebook-even-if-you-dont-have-a-facebook-account
>>>>>>>>>
>>>>>>>>>
>>>>>>>>> "The Zoom app notifies Facebook when the user opens the app,
>>>>>>>>> details on the user's device such as the model, the time zone and city they
>>>>>>>>> are connecting from, which phone carrier they are using, and a unique
>>>>>>>>> advertiser identifier
>>>>>>>>> <https://konsole.zendesk.com/hc/en-us/articles/115013349668-Identify-Android-AdIDs-Apple-IDFAs-and-Safari-IDs> created
>>>>>>>>> by the user's device which companies can use to target a user
>>>>>>>>> with advertisements
>>>>>>>>> <https://www.singular.net/mobile-tutorial-series-idfa-apple-identifier-advertisers/>
>>>>>>>>> "
>>>>>>>>>
>>>>>>>>> -Raoul
>>>>>>>>>
>>>>>>>>>
>>>>>>>>>
>>>>>>>>> On Fri, 27 Mar 2020 at 17:53, Raoul Plommer <plommer at gmail.com>
>>>>>>>>> wrote:
>>>>>>>>>
>>>>>>>>>> FYI:
>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>> https://www.theguardian.com/technology/2020/mar/27/trolls-zoom-privacy-settings-covid-19-lockdown
>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>
>>>>>
>>>>> --
>>>>> Dorothy Gordon
>>>>>
>>>>
>>
>> --
>> *Niel Harper*
>> Barbados: +(246) 424 3809
>> London: +44 207 193 9826
>> Mobile: +(246) 243 3818
>> Email: niel.harper at ieee.org
>> Website: http://nielharper.com
>>
>
>
> --
> Dorothy Gordon
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20200403/b7a9e412/attachment.htm>


More information about the Ncsg-discuss mailing list