Zoom is compromised
Raoul Plommer
plommer at GMAIL.COM
Sun Apr 5 20:35:23 EEST 2020
Bruce Schneier isn't exactly flattering them either:
https://www.schneier.com/blog/archives/2020/04/security_and_pr_1.html
"That's what we know about Zoom's privacy and security so far. Expect more
revelations in the weeks and months to come. The New York Attorney General
is investigating
<https://www.nytimes.com/2020/03/30/technology/new-york-attorney-general-zoom-privacy.html>
the company. Security researchers are combing through the software,
looking for other things Zoom is doing and not telling anyone about. There
are more stories waiting to be discovered.
Zoom is a security and privacy disaster
<https://www.theguardian.com/technology/2020/apr/02/zoom-technology-security-coronavirus-video-conferencing>,
but until now had managed to avoid public accountability because it was
relatively obscure. Now that it's in the spotlight, it's all coming out.
(Their 4/1 response to all of this is here
<https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-users/>.) On
4/2, the company said
<https://www.theguardian.com/technology/2020/apr/02/zoom-says-engineers-will-focus-on-security-and-safety-issues>
it would freeze all feature development and focus on security and privacy.
Let's see if that's anything more than a PR move.
In the meantime, you should either lock Zoom down as best you can, or --
better yet -- abandon the platform altogether. Jitsi <https://jitsi.org/> is
a distributed, free, and open-source alternative. Start your meeting here
<https://meet.jit.si/>."
-Raoul
On Sun, 5 Apr 2020 at 21:07, Raoul Plommer <plommer at gmail.com> wrote:
>
> https://theintercept.com/2020/04/03/zooms-encryption-is-not-suited-for-secrets-and-has-surprising-links-to-china-researchers-discover/
>
> " In addition to promptly fixing several security issues that were
> reported, the company removed an “attendee attention tracker” feature, a
> privacy nightmare which let meeting hosts track whether participants had
> the Zoom window — or some other app’s window — in focus during a meeting.
> It has also invested in new training materials to teach users about the
> security features like setting passwords on meetings to avoid Zoom-bombing
> <https://www.fbi.gov/contact-us/field-offices/boston/news/press-releases/fbi-warns-of-teleconferencing-and-online-classroom-hijacking-during-covid-19-pandemic>,
> the phenomenon where people disrupt unprotected Zoom meetings."
>
> I'm glad they're fixing the faults but some of these seem like it's going
> to take quite a while. I'm no security expert, but some people that I know
> have been very concerned over these revelations during the past week. If
> there was no "bashing", they probably wouldn't have treated these issues as
> priority.
>
> -Raoul
>
> On Fri, 3 Apr 2020 at 11:48, Carlos Afonso <
> 0000103799ed46a9-dmarc-request at listserv.syr.edu> wrote:
>
>>
>> https://www.theguardian.com/technology/2020/apr/02/zoom-technology-security-coronavirus-video-conferencing
>>
>> frt rgds
>>
>> --c.a.
>>
>> =====================
>>
>> On 27/03/2020 18:53, Raoul Plommer wrote:
>> > FYI:
>> >
>> >
>> https://www.theguardian.com/technology/2020/mar/27/trolls-zoom-privacy-settings-covid-19-lockdown
>> >
>>
>> --
>>
>> Carlos A. Afonso
>> [emails são pessoais exceto quando explicitamente indicado em contrário]
>> [emails are personal unless explicitly indicated otherwise]
>>
>> Instituto Nupef - https://nupef.org.br
>> ISOC-BR - https://isoc.org.br
>>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20200405/a06a51fc/attachment.htm>
More information about the Ncsg-discuss
mailing list