33 comments

[ 2.6 ms ] story [ 89.9 ms ] thread
This is really hammed up by NPR. The "FBI warning" is more or less "don't use open calls if you don't want random strangers to enter your call".

A couple days ago, more scrupulous reporters were able to explain this succintly and help people avoid it.

Yes, Zoom should amend their bug bounty policy to allow for responsible disclosure, rather than non-disclosure, but it's not like they're alone in that failing, nor most of the other failings involved in this dogpile.

I like it when vendors are held to account, but the way that this has been reported over the last few days has seemed like more of a shakedown than a genuine consumer reporting effort.

I don’t understand this bashing of a fairly good tool. There are worse tools (when it comes to privacy, especially when it comes to privacy)
Yeah it seems like Zoom is being unfairly singled out. Compared to the rest of the industry, it now appears as if Zoom is a terrible choice for security. Is this really justified? How is the competition doing?
It does not seem justified. Even now the bar is pretty low for protecting customer information in online services.

At the same time Zoom clearly has some work to do. Having a strong Infosec team with proper release controls would solve many of the problems published to date.

I think it's pretty justified because of the sheer number of grade schools and healthcare companies are on-boarding with them because of name recognition. Perceived security isn't good enough when dealing with sensitive industries like that.
But is the alternative really better? Say they’ll use Skype or WebEx instead, is the situation any better there?
It's being bashed because these are real problems that real people are encountering when using it. Just because there are worse options doesn't mean there aren't/can't be better options.
Zoom has a track record of exposing user computers to breakins on more than one occasion, false claims of secure encryption, and dark patterns in hiding the web client from users to fool them into installung the swiss cheese native client, and an arrogant attitude throughout. What more do you need?

Of course the list of mistakes is smaller than eg Microsoft's but it's also a much younger company and their attitude doesn't reflect a striving for better.

It's because people are insisting on it's use.

e.g. College Lectures giving online lectures. Employers hosting meetings.

Normally you pick software to your preference but things like social media have strong network effects. This is the battle thats being fought.

If you're going to make me use something I'm going to push back if it's not up to scratch. Otherwise I wouldn't care.

I don't think that's it, otherwise we'd see mentions of software that is up to scratch, not the far inferior solutions from Cisco, Microsoft, and Google. I don't see any of these journalists suggesting an app with true E2E-encrypted video conferencing, chat, and screen-sharing. I had to google around a bit to find one -- "Wire" apparently claims to have E2E-encryption for video, but there must be some others.
But it is being used because of the networking effect. Just to speak from higher education - do you think colleges had zero connection to zoom before this?

Anecdotal, sure, but I'm betting it's a good indicator - I work at a small, small, small, under-resourced community college in 'average' America. Zoom has been a thing on our campus for at least two years. We never really used it, because we didn't need to. Until about three weeks ago.

We chose it during our crisis planning sessions, because they were already in our space. They got in our space years ago through clever partnerships and integrations with our learning management system (online course delivery platforms). They were the 'preferred provider' according to the LMS teams, both on campus and nationally. They have automatic integration with our accessibility tools for live transcriptions/captions and interpreting. They were the suggested provider by our professional organizations related to disabilities, under-represented students, and ease-of-use technology. Therefore, we use them exclusively now.

Students never saw any of that back-end conversation, because it is literally irrelevant to their experience. But it was there, and it 100% impacted our conscious choice to move to zoom for live meetings.

If we were targeted for all of this, with a student population of <2000, I guaran-damn-tee larger institutions were.

Minor player. Gets viral. You expect all competitors to stand still?
Who cares? It's working good. Someone is always spying anyway. If you don't like that, turn off your internet.
Short sellers of Zoom stock has something to do with it, competitor lobbyists, or just new outlet opportunists looking to pile it on to get more views. Although I do agree there is some legitimate concerns, but not at this level
(comment deleted)
The ability for someone to crash your Zoom meeting was extensively discussed here yesterday, and Zoom already has all the necessary tools to prevent it, but people aren't necessarily aware of them:

https://news.ycombinator.com/item?id=22762173

But a fear-mongering article like this has no place on HN. A "dark side"? "FBI warning"? This is pure propaganda and sensationalism -- that if someone joins your unprotected Zoom meeting, they can stream whatever they want (obviously) which could include pornography.

You might as well issue an FBI warning about phones because someone can randomly dial you and say gross stuff.

I don't have a problem with HN articles about legitimate security concerns around a newly popular tool, but linking it to pornography is pure fearmongering at its worst.

This article doesn't deserve to be here.

Well, the FBI issued a warning in the public interest, not to persecute Zoom. And by the sounds of it Zoom is going to address these issues and absolutely none of this press going to hurt them in the long run.
Just today it comes out that Safari would let sites silently spy on users through the camera and microphone.

Orders of magnitude worse than anything Zoom ever did. Will it be reported with the same level of hair rending?

You’re right that that’s bad. For me it comes down not to mistakes but to intentions. I might be wrong, but it seems like it’s in Apple’s DNA to do their best to provide privacy and security, while Zoom so far seems to me to have a Facebook-like “growth at all costs” mindset. I can forgive mistakes – every tech company (and all humans) will make them – but their shenanigans with the installer, for example, seems less like a mistake than a decision made with bad intentions.

That said, I also agree with some of the sentiment here that it feels like there are a dozen articles per day posted about Zoom that are nothing more than hyperbole or worse, simply an aggregation of links to articles posted earlier in the week. I say this as someone who has argued against Zoom being used in my workplace and who refuses to install it on my machine (I use it through Chrome): I’ve simply started to roll my eyes each time I see a new Zoom post.

I agree with everything you wrote. The salient point for me is that it’s no longer a question of the technical merit, it’s just a political judgement against Zoom being Good or Evil.

It’s easy for technologists to forget that video-conferencing was terribly, horribly broken not because of some terribly difficult technological challenge, but because the average user simply couldn’t get it to work.

Security always involves either bootstrapping of an existing trust, or some level of ease-of-use trade off.

For example, the calculus for “I need this meeting to start on time” and “My meeting password needs more entropy against brute force attacks” necessarily comes down on the side of starting the meeting in most threat environments.

But in the end I just don’t see Zoom as the evil empire, and I’m deeply suspicious of articles which try to convince me otherwise. I’m not sure where your perception of “growth at all costs” comes from.

From what I can tell, they make one of the best conferencing products on the market in terms of quality and usability. I think the privacy and security issues are significantly overblown.

For example, why refuse to install their client software? It seems highly unobtrusive, it’s not malware, nor spyware, nor adware... it doesn’t ever nag me or get in the way, or randomly start sapping CPU or give annoying update prompts. It’s quick and simple to install and uninstall. Overall it seems nicely written.

I see the “dirty tricks” they had to pull to make their install simpler overall as reasonable hacks aimed at improving their end user experience and increasing the percentage of users who are successfully able to get into a meeting.

Again, I think we tend to underestimate how hard using computers can be for so many people. Making video conferencing accessible to quarantined populations is pretty crucial right now.

Zoom doesn’t have a monopoly position to leverage like some do to pre-install their product on billions of devices. So they need every little bit they can find to make on boarding fast and easy.

They screwed up on their marketing of end-to-end encryption and should be fined by the FCC for that. I never saw that marketing claim, but nor would I stop using their product knowing that it’s not decentralized.

> it seems like it’s in Apple’s DNA to do their best to provide privacy and security

Except when it's security from Apple itself.

I disagree, Zoom has chosen to make calls as friction free as possible because the perceived “cost” of having an insecure meeting is low. This increases the cost by creating bad PR. This has the potential to force Zoom to change their defaults to secure meetings rather than having something more friction free. The average user is not going to know about the need to secure their connection. Sometimes sensationalist articles can be a good thing even if they are manipulative.
I don't think the 'bad' PR is going to be very costly at all.

More like free advertising.

A massive proportion have heard of Zoom this week compared to last because of the PR. Pretty much an ideal free viral marketing campaign!

> Zoom already has all the necessary tools to prevent it

How about:

- A good UI which encourages users to do the correct thing - Systems to detect and block war dialers

> Zoom already has all the necessary tools to prevent it, but people aren't necessarily aware of them

Why should they have to? I don't get why Zoom doesn't just make the meeting ID longer.

This has been a better study of media behavior than investigation of zoom.

Apparently there isn't enough going on in the world so every outlet feels the need to repeat previously disclosed information with less detail and more pearl clutching. At least npr was decent enough to link to some of the better sources.

Meanwhile we still get another few potential RCEs in Windows every month and the same editors are like "whatcha gonna do, bill gates amirite."

Too bad they used such a gross clickbait headline
It's attacking the 'new' leader. Windows had its moment in the sun, in terms of shitty practices. I remember when Bill Gates's philanthropy was attacked because he did such shitty things at microsoft. Hell, M$ is still an appropriate abbreviation of that company in some places.

Now it's zoom, last year it was facebook, next year it will be someone else. Don't know what value this comment adds, just an observation.

So far, those open AA meetings had all their access tokens advertised on the web - as open AA meetings do. Yes, there's a "WarDialing" app that can find Zoom calls, but I've seen no reports of calls that had passwords set being accessed or bombed. I don't follow the big media that much, but looking at the other links on the page, NPR seems to be in major "Hair's On Fire" mode - is that typical? I guess that's how to get clicks.
Generally NPR is slower and cleaner in their reporting (except when it comes to fair coverage of political candidates). This is disappointing.
Schools seem to be moving away from it in droves, warranted or not. My 5 year has a whole-class zoom today and if someone nefarious dropped by it would be seriously bad news. The teacher said this is the last one though before they move to MS Teams. Yes, they could just lock it down, but that is onerous for a big group (I am guessing, haven't tried it), and also the teacher wouldn't feel confident about it without experience. Which they won't get because DC public schools has already sent out a memo recommending to discontinue usage.
It just takes a couple of checkboxes on the host's end. Reading comprehension and identifying shapes. A teacher who can't do that isn't much of a teacher.
Is William S. Sessions coming for all of us now?