Live data from Hacker News

Trolls break into meetings on Zoom

businessinsider.com

271–280 of 302 posts

Re: Trolls break into meetings on Zoom

#271

Earlier quoted context omitted.

e2e encryption for multi-party videoconferencing that works well enough to use for something like this is basically an unsolved problem at this point.

Was it not solved in FaceTime group chats? I can’t see the Apple Security Guide right now, but I know they claim that FaceTime 1-to-1 is e2e, and with their whole marketing thing being privacy, I bet they did it for group conversations too (not that it’s Enterprise ready since there’s no user management or SSO or whatever). I’ve noticed over the years that FaceTime is much more likely than other video chat software t…

Yeah, there seem to be multiple statements by Apple saying they can't access the content of FaceTime calls, without any qualification that it only applies to one-to-one calls. So it's probably a reasonable assumption that even the group ones are e2e encrypted.

How many participants can you have in a FaceTime group call?

I have also noticed that FaceTime drops the video much more often that other software.

Re: Trolls break into meetings on Zoom

#272
post #20

Earlier quoted context omitted.

That's not the only security leak in that photo.

On a couple of pictures you can see balcony doors, house layouts, ceilings, vents, etc, doors. Every now and then CNN shares photos of the houses of rich and famous. They must be taking them from some magazine. Anyway, I remember looking at Cara Delevingne's amazing home, and I noticed that apart from walls with decorations, furniture, bathtub, etc there was NO view of doors, windows, balcony doors. Basically anythin…

The woman in the bottom left corner has the right idea. A white wall! And you're right about their houses. However with everyone home and the plods out on the empty streets. Now is not the time for a B&E

Re: Trolls break into meetings on Zoom

#273
post #125
post #101

Earlier quoted context omitted.

It works, the quality is decent, and it doesn't max out 4-8 cores for a simple video call. The others don't work, are Microsoft UI dumpster fires (Skype), or consume vast amounts of CPU (anything WebRTC for some reason).

On Linux (Skylake u-i7) Zoom maxes out my CPU :-(

I found that making the window smaller greatly reduced CPU usage. It seems to be doing the video decoding on the CPU.

Re: Trolls break into meetings on Zoom

#274
post #210

Earlier quoted context omitted.

Few things that are "free" handle massive numbers of participants well. Yes, Skype for Business etc can, but those options are commercial. There's also less usable, obscure stuff that does OK.

Skype for Business is a dumpster fire. We use it at work and it's terrible at graceful degradation, even for voice.

Skype for business + outlook integration doesn't even manage to handle chat history correctly, not without glitches that lose you the history for chats ever so often. Not fit for purpose.

Re: Trolls break into meetings on Zoom

#275

Earlier quoted context omitted.

Why is it hard? Video streaming has been a thing for a couple decades. I am genuinely curious.

When you stream a Youtube or Netflix video, you can download several seconds ahead over boring old HTTP. It's a one-to-one link, you don't have to upload anything, and you don't need access the user's camera or microphone. To be competitive in videoconferencing these days, you need: * Low latency, so people don't talk over each other * Video and audio compression that doesn't get confused by dropped packets. * Setup…

>* Free of charge

It seems like, in the current use case, this one isn't as important? Institutions would pay for something that does everything else really well. Source: All the paid accounts my institution shelled out for on Zoom in our transition to remote work. So I guess n=1.

Re: Trolls break into meetings on Zoom

#276
post #199

Earlier quoted context omitted.

I'm surprised they're even allowed to use Zoom for a national cabinet meeting. Wouldn't the Gov have its own video chatting software that is self hosted?

In general (moreso focused on the EU than the Brits) I've never understood why the EU doesn't pump a billion a year, or a billion worth of dev hours a year into open source. That's an absolutely tiny, almost infitismal amount of EU budget (and even tinier for most member states their budget) and it would allow them to get out of the noose of closed source corporate support contracts and being beholden to foreign comp…

The reason the "year of the Linux desktop" hasn't happened yet and open source hasn't conquered the consumer world isn't because of the lack of money. It's because none of the projects have a goal per-se; everyone works in their corner, on their own time, mostly just scratching their own itch. Donating money to them won't solve this problem. There's also a lack of certain skill sets like user experience design, project management, branding, etc.

If the EU wants an open-source conferencing solution they have to do it in-house (whether from scratch or fork an existing solution) and treat it like a business with a clear objective and actual employees (instead of benevolent devs donating their time & effort) including positions which open source projects often deem unnecessary like UI & UX design, and so on.

Re: Trolls break into meetings on Zoom

#277
post #80

Earlier quoted context omitted.

I am out of the loop as to why Zoom is suddenly "blowing up". Even my workplace is using it now. Previously, we were using either Skype, Webex, or Jitsi. What does Zoom offer that the other three doesn't?

same. known zoom for a while... the "it just works" and "it has better quality" comments are very surprising to me and got me skeptical. are skype, slack, gotomeeting, hangouts, meet, webex, &c. all really crashing on people now? in a huge conspiracy? things i thought could be the real reason: novelty (for some/most people), popularity (someone online famous/influencer mentioned it), shadow marketing, luck. but wikip…

I've used everything on that list, except meet, in an institutional setting. 1-on-1, small groups, large groups. The only one that our institution has used that works straight out of the box 100% of the time for everyone who has access to data, is zoom.

Re: Trolls break into meetings on Zoom

#278
post #110

Earlier quoted context omitted.

Also interesting about that photo: Five of the 25 have portrait-oriented video feeds. Tbh this may make more sense for this kind of thing (shows more of the person rather than more of the space they're in) but I'm thinking about the hardware—am I correct in inferring that those five are zooming from their mobile? Do high-level UK cabinet ministers not have laptops?

I'm speculating, but they might find it more convenient to use a separate device for the video chat? Especially if you're using your laptop a lot during the video call, it's quite convenient to have the chat open elsewhere.

Microphone quality is still not a solved problem on laptops, and Windows' sound preferences UI does not make it easy to switch to a Bluetooth headset (that is, if you even have one on you).

Re: Trolls break into meetings on Zoom

#279

This is a feature not a bug, to make joining meetings frictionless. (And in videoconferencing there's little distinction between meeting ID and password anyways -- they form a single access credential.) To prevent unwanted people from joining, the host simply has to turn on the waiting room feature -- where people who have dialed in have to be explicitly accepted by the host, which can be done individually or en mass…

If the trolls are just guessing the ID then it seems to be too low-entropy to serve as an access credential.

Re: Trolls break into meetings on Zoom

#280
post #3

I attended a PhD defense yesterday that got zoom bombed. They quickly moved it to an actively managed call and the presenter did a fine job of keeping their composure and getting back on track. Now we're circulating guides about how to set up secure rooms and webinars, so I don't anticipate this will happen again. Normally I'd wave this off as a childish prank, but both the URL and loading screen prominently indicate…

In general PhD defenses are open to public, I mean, in some places it isn't even valid if it wasn't public announced (by a printed paper glued to some wall, for all it's worth) and the access is restricted to the public.

Of course different times require different actions but I think that some challenges remain for the _formal_ part of it.

Post reply on HN