Zoom is compromised

Raoul Plommer plommer at GMAIL.COM
Tue Mar 31 12:54:48 EEST 2020


https://theintercept.com/2020/03/31/zoom-meeting-encryption/  Yeah, it's
not E2E either, despite false advertising.

-Raoul

On Sat, 28 Mar 2020 at 16:55, Raoul Plommer <plommer at gmail.com> wrote:

> I'm glad the FB-SDK is now removed. I think that was compromising
> everyone's personal data and if it wasn't mentioned in their privacy
> policy, like the Vice article suggests, I definitely consider Zoom to have
> compromised all of their users' trust by feeding it to Facebook, without
> asking any permissions.
>
> -Raoul
>
> On Sat, 28 Mar 2020 at 13:52, Bruna Martins dos Santos <
> bruna.mrtns at gmail.com> wrote:
>
>> Hello all,
>>
>> Hope this email finds everyone well!
>>
>> On that same note, Access Now sent a letter to the company asking them
>> for more disclosure when it comes to their transparency reports:
>>
>> *"Access Now argues that Zoom needs to publish a transparency report so
>> that the public can be informed about how the company handles and protects
>> user data. “The growing demand for your services makes Zoom a target for
>> third parties, from law enforcement to malicious hackers, seeking personal
>> data and sensitive information,” wrote Isedua Oribhabor, Access Now’s US
>> policy analyst, and Peter Micek, Access Now’s general counsel, in the
>> letter to Zoom. “Meanwhile, as people gather online, these assemblies will
>> draw scrutiny from authorities looking to control the flow of information.
>> This is why disclosing only privacy policies is not enough — it is
>> necessary for Zoom to also disclose its policies and procedures protecting
>> the data and accounts of everyone interacting with its services through a
>> regular transparency report."*
>>
>> As seen on:
>> https://www.theverge.com/2020/3/19/21186152/zoom-transparency-report-access-now-advocacy-group
>>
>> Lesser on the control of the data that Zoom possibly shares on us and
>> more on the self protection side,  Karisma
>> <https://twitter.com/Karisma/status/1242569633619677187> Foundation, a
>> civil society organization from the LAC region tweeted about possible tips
>> to lessen any possible risks Zoom might offer us - most of them already in
>> use in ICANN calls. And this is the translated list of their
>> recommendations:
>>
>> - Host of the call can restrict the use of the sharing screen feature
>> only to him. You can do this in the call administrator settings - Sharing
>> screen -> Advanced sharing settings;
>> - Disable other people from entering before the host, disable “Join
>> Before Host” feature;
>> - Enable the co-host feature for someone else to help moderate the call;
>> - Disable file transfer to avoid malicious links or documents to be sent;
>> and
>> - Disable “Allow Removed Participants to Register” so you can prevent
>> unwanted intrusions.
>>
>> Best,
>> B
>>
>> Le sam. 28 mars 2020 à 13:34, Carlos Afonso <
>> 0000103799ed46a9-dmarc-request at listserv.syr.edu> a écrit :
>>
>>> I absolutely agree with you on the bigger problems we face right now. I
>>> think this pandemic will redefine the world community, and we are not sure
>>> what this redefinition will be.
>>>
>>> We may "redive" into the Dark Ages, or emerge as a society in which
>>> stupidities like the "minimum State" gibberish and the neoliberal mantras
>>> will be extinguished forever.
>>>
>>> fraternal regards
>>>
>>> --c.a.
>>>
>>> On 28/03/2020 12:39, James Gannon wrote:
>>> > I think the community has bigger problems right now tbh, your profiled
>>> by FB on the vast majority of the websites on the internet right now,
>>> nothing is going to change that.
>>> >
>>> > I have to admit that I find the crying wolf at the moment by a lot of
>>> folks (And not targeting folks on this list but the general chatter about
>>> this on twitter etc) is particularly ignorant of the current situation that
>>> people are in, Zoom has proven to be a lifesaver in many situations, both
>>> private, educational and professional and if anything should be lauded for
>>> its work to remain scalable and stable, rather than slated for providing a
>>> user requested feature (FB Live integration allow people who are not tech
>>> savvy to be able to see loved ones or participate in education).
>>> >
>>> > Compromised does have a specific meaning within the security
>>> community, that the app has been modified or changed by a third party not
>>> associated with the creators, which is not the case here, and is merely a
>>> tabloid style headline. Which we have enough of on other topics right now.
>>> >
>>> > -----Original Message-----
>>> > From: NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU> On Behalf Of
>>> Carlos Afonso
>>> > Sent: Saturday 28 March 2020 15:32
>>> > To: NCSG-DISCUSS at LISTSERV.SYR.EDU
>>> > Subject: Re: Zoom is compromised
>>> >
>>> > There are different meanings for "compromise"... but anyway, the joint
>>> big-time *unauthorized* profiling Zoom-Facebook is the central problem. Not
>>> sure if the relationship stopped because of the removal of the SDK.
>>> >
>>> > To be sure, the community should seek alternatives.
>>> >
>>> > fraternal regards
>>> >
>>> > --c.a.
>>> >
>>> > On 28/03/2020 12:05, James Gannon wrote:
>>> >> Its not compromised however, its using the Facebook SDK (And has now
>>> been removed) to enable the FB live integration, while yes there may be a
>>> feature here that people were not aware of, its not "compromised" in any
>>> way.
>>> >>
>>> >> -----Original Message-----
>>> >> From: NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU> On Behalf Of
>>> Carlos
>>> >> Afonso
>>> >> Sent: Saturday 28 March 2020 14:54
>>> >> To: NCSG-DISCUSS at LISTSERV.SYR.EDU
>>> >> Subject: Re: Zoom is compromised
>>> >>
>>> >> Dear Farell, I think you did not read the second message from Raoul:
>>> >>
>>> >> ====
>>> >>
>>> https://www.vice.com/en_us/article/k7e599/zoom-ios-app-sends-data-to-f
>>> >> acebook-even-if-you-dont-have-a-facebook-account
>>> >>
>>> >> "The Zoom app notifies Facebook when the user opens the app, details
>>> >> on the user's device such as the model, the time zone and city they
>>> >> are connecting from, which phone carrier they are using, and a unique
>>> >> advertiser identifier
>>> >> <
>>> https://konsole.zendesk.com/hc/en-us/articles/115013349668-Identify-A
>>> >> ndroid-AdIDs-Apple-IDFAs-and-Safari-IDs>
>>> >> created
>>> >> by the user's device which companies can use to target a user with
>>> >> advertisements
>>> >> <
>>> https://www.singular.net/mobile-tutorial-series-idfa-apple-identifier
>>> >> -advertisers/>
>>> >> "
>>> >> -Raoul
>>> >>
>>> >> ====
>>> >>
>>> >> This is far more serious than hacking vulnerabilities known in the
>>> standard configuration of Zoom.
>>> >>
>>> >> fraternal regards
>>> >>
>>> >> --c.a.
>>> >>
>>> >> On 28/03/2020 08:37, Farell FOLLY wrote:
>>> >>> Dear Raoul,
>>> >>>
>>> >>> Thanks for sharing this. However, I don’t think the word
>>> “compromised” is the right one to use here, unless I don’t understand what
>>> you would like to mean. What is described in the link you shared as well as
>>> in your second e-mail is something about privacy setting of the apps….that
>>> the user could prevent in many ways. Indeed, anytime you use your browser
>>> or anything that connect you to the internet, if you do not properly set up
>>> your privacy and cookie setting, it always send some data about your
>>> device, your operating system and your location. This situation is even
>>> worse when you accept cookies on a 3rd party website without reading it in
>>> details… A “yes” on a website most of the time means: “yes propagate all my
>>> date to all your thousand partners”.
>>> >>>
>>> >>>
>>> >>>
>>> >>>
>>> >>>
>>> >>>
>>> >>> @__f_f__
>>> >>>
>>> >>> Best Regards
>>> >>> ____________________________________
>>> >>>
>>> >>> (Ekue) Farell FOLLY
>>> >>> GNSO Councillor
>>> >>> linkedin.com/in/farellf
>>> >>>
>>> >>>
>>> >>>
>>> >>>
>>> >>>
>>> >>>
>>> >>>> On 27 Mar 2020, at 22:53, Raoul Plommer <plommer at gmail.com> wrote:
>>> >>>>
>>> >>>> FYI:
>>> >>>>
>>> >>>>
>>> https://www.theguardian.com/technology/2020/mar/27/trolls-zoom-priva
>>> >>>> c
>>> >>>> y-settings-covid-19-lockdown
>>> >>>> <
>>> https://www.theguardian.com/technology/2020/mar/27/trolls-zoom-priv
>>> >>>> a
>>> >>>> cy-settings-covid-19-lockdown>
>>> >>>
>>> >>>
>>> >>
>>> >
>>>
>>> --
>>>
>>> Carlos A. Afonso
>>> [emails são pessoais exceto quando explicitamente indicado em contrário]
>>> [emails are personal unless explicitly indicated otherwise]
>>>
>>> Instituto Nupef - https://nupef.org.br
>>> ISOC-BR - https://isoc.org.br
>>>
>>
>>
>> --
>> *Bruna Martins dos Santos *
>>
>> Skype ID: bruna.martinsantos
>> @boomartins
>>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20200331/06af695b/attachment.htm>


More information about the Ncsg-discuss mailing list