Zoom is compromised

Michael J. Oghia mike.oghia at GMAIL.COM
Tue Apr 21 04:37:57 EEST 2020


Thank you very much Alejandro, Houssem, Joan, Alapini, and Oreoluwa for the
kind words and for sharing. I'm doing OK, and hope everyone will take
better steps to protect ourselves and our communities.

Stay safe and well,
-Michael



On Mon, Apr 20, 2020 at 2:05 PM Alejandro Acosta <
alejandroacostaalamo at gmail.com> wrote:

> Thanks Michael, nice work.
>
>
> Alejandro,
>
>
> On 4/17/20 3:13 PM, Michael J. Oghia wrote:
>
> Hi everyone,
>
> Yesterday, while I was participating in a Zoom session hosted by an
> activists' group I'm part of, our meeting was "bombed" (hijacked) by highly
> disturbing and traumatising imagery. This experience left all of us on the
> call quite shaken, but I told myself that it can be the catalyst for action
> so that we can protect ourselves going forward. As such, I compiled a short
> guide
> <https://docs.google.com/document/d/1zUV_z0XkuN2rQ5bDYFx9BBWM4rpYpO5Ker5ZWDnPr9M/edit?usp=sharing>
> on how to protect ourselves from Zoom-bombing that I want to share.
>
> Stay safe and well,
> -Michael
> __________________
>
> Michael J. Oghia | Advocacy & Engagement Manager
> Global Forum for Media Development (GFMD <https://gfmd.info>)
> Belgrade, Serbia | Twitter <https://www.twitter.com/MikeOghia> | LinkedIn
> <https://www.linkedin.com/in/mikeoghia>
>
>
> On Thu, Apr 9, 2020 at 10:48 AM Michael J. Oghia <mike.oghia at gmail.com>
> wrote:
>
>> Hi everyone,
>>
>> See this FAQ from Citizen Lab about Zoom:
>> https://citizenlab.ca/2020/04/faq-on-zoom-security-issues/
>>
>> Stay safe and well,
>> -Michael
>>
>>
>> On Mon, Apr 6, 2020 at 2:02 PM dorothy g <dgdorothydg at gmail.com> wrote:
>>
>>> Thanks Joly,  we need a few extra rows to address security concerns
>>> including secret backend permissions and access given to national security.
>>> Great matrix. I will circulate.
>>>
>>> best
>>>
>>> On Mon, Apr 6, 2020 at 11:49 AM Joly MacFie <jolynyc at gmail.com> wrote:
>>>
>>>>
>>>> Diplo have put together such a matrix. I am sure they will appreciate
>>>> any further input.
>>>>
>>>> https://www.diplomacy.edu/conference-tech-lab
>>>>
>>>>
>>>>
>>>> On Mon, Apr 6, 2020 at 7:43 AM dorothy g <dgdorothydg at gmail.com> wrote:
>>>>
>>>>> Dear Raoul,  All of the major meeting platforms have serious issues. I
>>>>> do not believe zoom is more disastrous than the others. It was not obscure,
>>>>> tens of millions of people all over the world have been using it for years
>>>>> and this is not the first time issues have come up.  I agree that we should
>>>>> watch carefully to see if they improve on the existing situation. Please
>>>>> point me to independent reviews of Jitsi before I even think about it.  I
>>>>> hope security researchers have also looked into it.  Perhaps we should look
>>>>> at Houseparty?(Joke)
>>>>>
>>>>> The fact is that capitalist competition is driving some of the public
>>>>> discussion (e.g.competition for software used in schools - general approach
>>>>> get them to use it in school and they will never leave) so it is good if we
>>>>> stick to objective facts.  Perhaps someone could create a matrix so we
>>>>> compare the issues for the various platforms : IBM, Google Open
>>>>> Meetings, ClickMeeting, Microsoft Corporation, Oracle Corporation, Citrix
>>>>> Systems, Inc. and Cisco Systems.  Kindly note that when I started
>>>>> using it zoom was distributed and free (I have never paid for zoom) and
>>>>> even touted as open source even though most people would not agree with
>>>>> that claim.   All the best and thanks in advance to the brilliant person
>>>>> who will create the matrix.
>>>>>
>>>>> best
>>>>>
>>>>> On Mon, Apr 6, 2020 at 2:36 AM Raoul Plommer <plommer at gmail.com>
>>>>> wrote:
>>>>>
>>>>>> Bruce Schneier isn't exactly flattering them either:
>>>>>>
>>>>>> https://www.schneier.com/blog/archives/2020/04/security_and_pr_1.html
>>>>>>
>>>>>> "That's what we know about Zoom's privacy and security so far. Expect
>>>>>> more revelations in the weeks and months to come. The New York Attorney
>>>>>> General is investigating
>>>>>> <https://www.nytimes.com/2020/03/30/technology/new-york-attorney-general-zoom-privacy.html>
>>>>>>  the company. Security researchers are combing through the software,
>>>>>> looking for other things Zoom is doing and not telling anyone about. There
>>>>>> are more stories waiting to be discovered.
>>>>>>
>>>>>> Zoom is a security and privacy disaster
>>>>>> <https://www.theguardian.com/technology/2020/apr/02/zoom-technology-security-coronavirus-video-conferencing>,
>>>>>> but until now had managed to avoid public accountability because it was
>>>>>> relatively obscure. Now that it's in the spotlight, it's all coming out.
>>>>>> (Their 4/1 response to all of this is here
>>>>>> <https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-users/>.)
>>>>>> On 4/2, the company said
>>>>>> <https://www.theguardian.com/technology/2020/apr/02/zoom-says-engineers-will-focus-on-security-and-safety-issues>
>>>>>>  it would freeze all feature development and focus on security and
>>>>>> privacy. Let's see if that's anything more than a PR move.
>>>>>>
>>>>>> In the meantime, you should either lock Zoom down as best you can, or
>>>>>> -- better yet -- abandon the platform altogether. Jitsi
>>>>>> <https://jitsi.org/> is a distributed, free, and open-source
>>>>>> alternative. Start your meeting here <https://meet.jit.si/>."
>>>>>>
>>>>>> -Raoul
>>>>>>
>>>>>> On Sun, 5 Apr 2020 at 21:07, Raoul Plommer <plommer at gmail.com> wrote:
>>>>>>
>>>>>>>
>>>>>>> https://theintercept.com/2020/04/03/zooms-encryption-is-not-suited-for-secrets-and-has-surprising-links-to-china-researchers-discover/
>>>>>>>
>>>>>>> " In addition to promptly fixing several security issues that were
>>>>>>> reported, the company removed an “attendee attention tracker” feature, a
>>>>>>> privacy nightmare which let meeting hosts track whether participants had
>>>>>>> the Zoom window — or some other app’s window — in focus during a meeting.
>>>>>>> It has also invested in new training materials to teach users about the
>>>>>>> security features like setting passwords on meetings to avoid
>>>>>>> Zoom-bombing
>>>>>>> <https://www.fbi.gov/contact-us/field-offices/boston/news/press-releases/fbi-warns-of-teleconferencing-and-online-classroom-hijacking-during-covid-19-pandemic>,
>>>>>>> the phenomenon where people disrupt unprotected Zoom meetings."
>>>>>>>
>>>>>>> I'm glad they're fixing the faults but some of these seem like it's
>>>>>>> going to take quite a while. I'm no security expert, but some people that I
>>>>>>> know have been very concerned over these revelations during the past week.
>>>>>>> If there was no "bashing", they probably wouldn't have treated these issues
>>>>>>> as priority.
>>>>>>>
>>>>>>> -Raoul
>>>>>>>
>>>>>>> On Fri, 3 Apr 2020 at 11:48, Carlos Afonso <
>>>>>>> 0000103799ed46a9-dmarc-request at listserv.syr.edu> wrote:
>>>>>>>
>>>>>>>>
>>>>>>>> https://www.theguardian.com/technology/2020/apr/02/zoom-technology-security-coronavirus-video-conferencing
>>>>>>>>
>>>>>>>> frt rgds
>>>>>>>>
>>>>>>>> --c.a.
>>>>>>>>
>>>>>>>> =====================
>>>>>>>>
>>>>>>>> On 27/03/2020 18:53, Raoul Plommer wrote:
>>>>>>>> > FYI:
>>>>>>>> >
>>>>>>>> >
>>>>>>>> https://www.theguardian.com/technology/2020/mar/27/trolls-zoom-privacy-settings-covid-19-lockdown
>>>>>>>> >
>>>>>>>>
>>>>>>>> --
>>>>>>>>
>>>>>>>> Carlos A. Afonso
>>>>>>>> [emails são pessoais exceto quando explicitamente indicado em
>>>>>>>> contrário]
>>>>>>>> [emails are personal unless explicitly indicated otherwise]
>>>>>>>>
>>>>>>>> Instituto Nupef - https://nupef.org.br
>>>>>>>> ISOC-BR - https://isoc.org.br
>>>>>>>>
>>>>>>>
>>>>>
>>>>> --
>>>>> Dorothy Gordon
>>>>>
>>>>
>>>
>>> --
>>> Dorothy Gordon
>>>
>>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20200421/cce9b60c/attachment.htm>


More information about the Ncsg-discuss mailing list