Zoom is compromised

Michael J. Oghia mike.oghia at GMAIL.COM
Thu Apr 9 03:48:35 EEST 2020


Hi everyone,

See this FAQ from Citizen Lab about Zoom:
https://citizenlab.ca/2020/04/faq-on-zoom-security-issues/

Stay safe and well,
-Michael


On Mon, Apr 6, 2020 at 2:02 PM dorothy g <dgdorothydg at gmail.com> wrote:

> Thanks Joly,  we need a few extra rows to address security concerns
> including secret backend permissions and access given to national security.
> Great matrix. I will circulate.
>
> best
>
> On Mon, Apr 6, 2020 at 11:49 AM Joly MacFie <jolynyc at gmail.com> wrote:
>
>>
>> Diplo have put together such a matrix. I am sure they will appreciate any
>> further input.
>>
>> https://www.diplomacy.edu/conference-tech-lab
>>
>>
>>
>> On Mon, Apr 6, 2020 at 7:43 AM dorothy g <dgdorothydg at gmail.com> wrote:
>>
>>> Dear Raoul,  All of the major meeting platforms have serious issues. I
>>> do not believe zoom is more disastrous than the others. It was not obscure,
>>> tens of millions of people all over the world have been using it for years
>>> and this is not the first time issues have come up.  I agree that we should
>>> watch carefully to see if they improve on the existing situation. Please
>>> point me to independent reviews of Jitsi before I even think about it.  I
>>> hope security researchers have also looked into it.  Perhaps we should look
>>> at Houseparty?(Joke)
>>>
>>> The fact is that capitalist competition is driving some of the public
>>> discussion (e.g.competition for software used in schools - general approach
>>> get them to use it in school and they will never leave) so it is good if we
>>> stick to objective facts.  Perhaps someone could create a matrix so we
>>> compare the issues for the various platforms : IBM, Google Open
>>> Meetings, ClickMeeting, Microsoft Corporation, Oracle Corporation, Citrix
>>> Systems, Inc. and Cisco Systems.  Kindly note that when I started using
>>> it zoom was distributed and free (I have never paid for zoom) and even
>>> touted as open source even though most people would not agree with that
>>> claim.   All the best and thanks in advance to the brilliant person who
>>> will create the matrix.
>>>
>>> best
>>>
>>> On Mon, Apr 6, 2020 at 2:36 AM Raoul Plommer <plommer at gmail.com> wrote:
>>>
>>>> Bruce Schneier isn't exactly flattering them either:
>>>>
>>>> https://www.schneier.com/blog/archives/2020/04/security_and_pr_1.html
>>>>
>>>> "That's what we know about Zoom's privacy and security so far. Expect
>>>> more revelations in the weeks and months to come. The New York Attorney
>>>> General is investigating
>>>> <https://www.nytimes.com/2020/03/30/technology/new-york-attorney-general-zoom-privacy.html>
>>>>  the company. Security researchers are combing through the software,
>>>> looking for other things Zoom is doing and not telling anyone about. There
>>>> are more stories waiting to be discovered.
>>>>
>>>> Zoom is a security and privacy disaster
>>>> <https://www.theguardian.com/technology/2020/apr/02/zoom-technology-security-coronavirus-video-conferencing>,
>>>> but until now had managed to avoid public accountability because it was
>>>> relatively obscure. Now that it's in the spotlight, it's all coming out.
>>>> (Their 4/1 response to all of this is here
>>>> <https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-users/>.)
>>>> On 4/2, the company said
>>>> <https://www.theguardian.com/technology/2020/apr/02/zoom-says-engineers-will-focus-on-security-and-safety-issues>
>>>>  it would freeze all feature development and focus on security and
>>>> privacy. Let's see if that's anything more than a PR move.
>>>>
>>>> In the meantime, you should either lock Zoom down as best you can, or
>>>> -- better yet -- abandon the platform altogether. Jitsi
>>>> <https://jitsi.org/> is a distributed, free, and open-source
>>>> alternative. Start your meeting here <https://meet.jit.si/>."
>>>>
>>>> -Raoul
>>>>
>>>> On Sun, 5 Apr 2020 at 21:07, Raoul Plommer <plommer at gmail.com> wrote:
>>>>
>>>>>
>>>>> https://theintercept.com/2020/04/03/zooms-encryption-is-not-suited-for-secrets-and-has-surprising-links-to-china-researchers-discover/
>>>>>
>>>>> " In addition to promptly fixing several security issues that were
>>>>> reported, the company removed an “attendee attention tracker” feature, a
>>>>> privacy nightmare which let meeting hosts track whether participants had
>>>>> the Zoom window — or some other app’s window — in focus during a meeting.
>>>>> It has also invested in new training materials to teach users about the
>>>>> security features like setting passwords on meetings to avoid
>>>>> Zoom-bombing
>>>>> <https://www.fbi.gov/contact-us/field-offices/boston/news/press-releases/fbi-warns-of-teleconferencing-and-online-classroom-hijacking-during-covid-19-pandemic>,
>>>>> the phenomenon where people disrupt unprotected Zoom meetings."
>>>>>
>>>>> I'm glad they're fixing the faults but some of these seem like it's
>>>>> going to take quite a while. I'm no security expert, but some people that I
>>>>> know have been very concerned over these revelations during the past week.
>>>>> If there was no "bashing", they probably wouldn't have treated these issues
>>>>> as priority.
>>>>>
>>>>> -Raoul
>>>>>
>>>>> On Fri, 3 Apr 2020 at 11:48, Carlos Afonso <
>>>>> 0000103799ed46a9-dmarc-request at listserv.syr.edu> wrote:
>>>>>
>>>>>>
>>>>>> https://www.theguardian.com/technology/2020/apr/02/zoom-technology-security-coronavirus-video-conferencing
>>>>>>
>>>>>> frt rgds
>>>>>>
>>>>>> --c.a.
>>>>>>
>>>>>> =====================
>>>>>>
>>>>>> On 27/03/2020 18:53, Raoul Plommer wrote:
>>>>>> > FYI:
>>>>>> >
>>>>>> >
>>>>>> https://www.theguardian.com/technology/2020/mar/27/trolls-zoom-privacy-settings-covid-19-lockdown
>>>>>> >
>>>>>>
>>>>>> --
>>>>>>
>>>>>> Carlos A. Afonso
>>>>>> [emails são pessoais exceto quando explicitamente indicado em
>>>>>> contrário]
>>>>>> [emails are personal unless explicitly indicated otherwise]
>>>>>>
>>>>>> Instituto Nupef - https://nupef.org.br
>>>>>> ISOC-BR - https://isoc.org.br
>>>>>>
>>>>>
>>>
>>> --
>>> Dorothy Gordon
>>>
>>
>
> --
> Dorothy Gordon
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20200409/b3b323ea/attachment.htm>


More information about the Ncsg-discuss mailing list