Zoom is compromised

Alejandro Acosta alejandroacostaalamo at GMAIL.COM
Mon Apr 20 07:05:16 EEST 2020


Thanks Michael, nice work.


Alejandro,


On 4/17/20 3:13 PM, Michael J. Oghia wrote:
> Hi everyone,
>
> Yesterday, while I was participating in a Zoom session hosted by an
> activists' group I'm part of, our meeting was "bombed" (hijacked) by
> highly disturbing and traumatising imagery. This experience left all
> of us on the call quite shaken, but I told myself that it can be the
> catalyst for action so that we can protect ourselves going forward. As
> such, I compiled a short guide
> <https://docs.google.com/document/d/1zUV_z0XkuN2rQ5bDYFx9BBWM4rpYpO5Ker5ZWDnPr9M/edit?usp=sharing>
> on how to protect ourselves from Zoom-bombing that I want to share.
>
> Stay safe and well,
> -Michael
> __________________
>
> Michael J. Oghia | Advocacy & Engagement Manager 
> Global Forum for Media Development (GFMD <https://gfmd.info>)
> Belgrade, Serbia | Twitter
> <https://www.twitter.com/MikeOghia> | LinkedIn
> <https://www.linkedin.com/in/mikeoghia>
>
>
> On Thu, Apr 9, 2020 at 10:48 AM Michael J. Oghia <mike.oghia at gmail.com
> <mailto:mike.oghia at gmail.com>> wrote:
>
>     Hi everyone, 
>
>     See this FAQ from Citizen Lab about
>     Zoom: https://citizenlab.ca/2020/04/faq-on-zoom-security-issues/
>
>     Stay safe and well,
>     -Michael
>
>
>     On Mon, Apr 6, 2020 at 2:02 PM dorothy g <dgdorothydg at gmail.com
>     <mailto:dgdorothydg at gmail.com>> wrote:
>
>         Thanks Joly,  we need a few extra rows to address security
>         concerns including secret backend permissions and access given
>         to national security. Great matrix. I will circulate.
>
>         best
>
>         On Mon, Apr 6, 2020 at 11:49 AM Joly MacFie <jolynyc at gmail.com
>         <mailto:jolynyc at gmail.com>> wrote:
>
>
>             Diplo have put together such a matrix. I am sure they will
>             appreciate any further input.
>
>             https://www.diplomacy.edu/conference-tech-lab 
>
>              
>
>             On Mon, Apr 6, 2020 at 7:43 AM dorothy g
>             <dgdorothydg at gmail.com <mailto:dgdorothydg at gmail.com>> wrote:
>
>                 Dear Raoul,  All of the major meeting platforms have
>                 serious issues. I do not believe zoom is more
>                 disastrous than the others. It was not obscure, tens
>                 of millions of people all over the world have been
>                 using it for years and this is not the first time
>                 issues have come up.  I agree that we should watch
>                 carefully to see if they improve on the existing
>                 situation. Please point me to independent reviews of
>                 Jitsi before I even think about it.  I hope security
>                 researchers have also looked into it.  Perhaps we
>                 should look at Houseparty?(Joke)
>
>                 The fact is that capitalist competition is driving
>                 some of the public discussion (e.g.competition for
>                 software used in schools - general approach get them
>                 to use it in school and they will never leave) so it
>                 is good if we stick to objective facts.  Perhaps
>                 someone could create a matrix so we compare the issues
>                 for the various platforms : IBM, Google Open Meetings,
>                 ClickMeeting, Microsoft Corporation, Oracle
>                 Corporation, Citrix Systems, Inc. and Cisco Systems.
>                  Kindly note that when I started using it zoom was
>                 distributed and free (I have never paid for zoom) and
>                 even touted as open source even though most people
>                 would not agree with that claim.   All the best and
>                 thanks in advance to the brilliant person who will
>                 create the matrix.
>
>                 best
>
>                 On Mon, Apr 6, 2020 at 2:36 AM Raoul Plommer
>                 <plommer at gmail.com <mailto:plommer at gmail.com>> wrote:
>
>                     Bruce Schneier isn't exactly flattering them either:
>
>                     https://www.schneier.com/blog/archives/2020/04/security_and_pr_1.html
>
>
>                     "That's what we know about Zoom's privacy and
>                     security so far. Expect more revelations in the
>                     weeks and months to come. The New York Attorney
>                     General is investigating
>                     <https://www.nytimes.com/2020/03/30/technology/new-york-attorney-general-zoom-privacy.html> the
>                     company. Security researchers are combing through
>                     the software, looking for other things Zoom is
>                     doing and not telling anyone about. There are more
>                     stories waiting to be discovered.
>
>                     Zoom is a security and privacy disaster
>                     <https://www.theguardian.com/technology/2020/apr/02/zoom-technology-security-coronavirus-video-conferencing>,
>                     but until now had managed to avoid public
>                     accountability because it was relatively obscure.
>                     Now that it's in the spotlight, it's all coming
>                     out. (Their 4/1 response to all of this is here
>                     <https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-users/>.)
>                     On 4/2, the company said
>                     <https://www.theguardian.com/technology/2020/apr/02/zoom-says-engineers-will-focus-on-security-and-safety-issues> it
>                     would freeze all feature development and focus on
>                     security and privacy. Let's see if that's anything
>                     more than a PR move.
>
>                     In the meantime, you should either lock Zoom down
>                     as best you can, or -- better yet -- abandon the
>                     platform altogether. Jitsi <https://jitsi.org/> is
>                     a distributed, free, and open-source alternative.
>                     Start your meeting here <https://meet.jit.si/>."
>
>                     -Raoul
>
>
>                     On Sun, 5 Apr 2020 at 21:07, Raoul Plommer
>                     <plommer at gmail.com <mailto:plommer at gmail.com>> wrote:
>
>                         https://theintercept.com/2020/04/03/zooms-encryption-is-not-suited-for-secrets-and-has-surprising-links-to-china-researchers-discover/
>
>                         " In addition to promptly fixing several
>                         security issues that were reported, the
>                         company removed an “attendee attention
>                         tracker” feature, a privacy nightmare which
>                         let meeting hosts track whether participants
>                         had the Zoom window — or some other app’s
>                         window — in focus during a meeting. It has
>                         also invested in new training materials to
>                         teach users about the security features like
>                         setting passwords on meetings to avoid
>                         Zoom-bombing
>                         <https://www.fbi.gov/contact-us/field-offices/boston/news/press-releases/fbi-warns-of-teleconferencing-and-online-classroom-hijacking-during-covid-19-pandemic>,
>                         the phenomenon where people disrupt
>                         unprotected Zoom meetings."
>
>                         I'm glad they're fixing the faults but some of
>                         these seem like it's going to take quite a
>                         while. I'm no security expert, but some people
>                         that I know have been very concerned over
>                         these revelations during the past week. If
>                         there was no "bashing", they probably wouldn't
>                         have treated these issues as priority.
>
>                         -Raoul
>
>                         On Fri, 3 Apr 2020 at 11:48, Carlos Afonso
>                         <0000103799ed46a9-dmarc-request at listserv.syr.edu
>                         <mailto:0000103799ed46a9-dmarc-request at listserv.syr.edu>>
>                         wrote:
>
>                             https://www.theguardian.com/technology/2020/apr/02/zoom-technology-security-coronavirus-video-conferencing
>
>                             frt rgds
>
>                             --c.a.
>
>                             =====================
>
>                             On 27/03/2020 18:53, Raoul Plommer wrote:
>                             > FYI:
>                             >
>                             >
>                             https://www.theguardian.com/technology/2020/mar/27/trolls-zoom-privacy-settings-covid-19-lockdown
>                             >
>
>                             -- 
>
>                             Carlos A. Afonso
>                             [emails são pessoais exceto quando
>                             explicitamente indicado em contrário]
>                             [emails are personal unless explicitly
>                             indicated otherwise]
>
>                             Instituto Nupef - https://nupef.org.br
>                             ISOC-BR - https://isoc.org.br
>
>
>
>                 -- 
>                 Dorothy Gordon
>
>
>
>         -- 
>         Dorothy Gordon
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20200420/ac61f942/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: pEpkey.asc
Type: application/pgp-keys
Size: 1782 bytes
Desc: not available
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20200420/ac61f942/attachment.key>


More information about the Ncsg-discuss mailing list