Live data from Hacker News

‘War Dialing’ tool exposes Zoom’s password problems

krebsonsecurity.com

61–70 of 247 posts

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#62
post #10

Earlier quoted context omitted.

Yeah but then it sucks for people calling in to have to punch in a 21+ character long meeting ID

> Yeah but then it sucks for people calling in to have to punch in a 21+ character long meeting ID I may be out of touch with the average biz-guy, but how many people are realistically calling in manually, over traditional phone-lines these days? Is it really a significant percentage?

My husband is a market researcher, and is now conducting market research over Zoom & other platforms. The first thing he does is have _everyone_ dial in. It's been a major help in reducing latency and dropped packets, which in turn has a majorly positive effect in getting stranger to be able to talk normally with each other. It helps prevent the "you go no you go" as latency allows people to unknowingly step over each other.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#63
post #10

Earlier quoted context omitted.

Yeah but then it sucks for people calling in to have to punch in a 21+ character long meeting ID

The telephone dial-in option should've been separate - if the user chooses to enable it then they can fall back to shorter IDs, while meetings that don't need it (or where it doesn't make sense anyway - screen shares, presentations, etc) would use longer, more secure IDs.

As we've used it at work, the phone dial-in option is the backup plan -- useful when people can't set up their computer's microphone correctly, or lose Internet access for whatever reason.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#64

Earlier quoted context omitted.

Working in global research, 40% of our ROW (rest of world) sites and vendors use landline or cell pones to join our meetings, depends on their institutional security and IT settings.

Smart phones can dial a long code in software. Only dumb phones and landlines can't

Some smartphones, using some applications, and some input devices, can dial some long codes.

Jim from sales who is dialing in from his company's oddball calendar app over Bluetooth on the infotainment system in his rental car probably can't.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#65
One positive thing about all these horrendous security flaws that have been recently discovered in Zoom, due to its popularity, is that the company seems to be taking them seriously, recently instituting a feature freeze to focus on fixing them: https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u...

As a consequence, I suspect Zoom's security is more likely than not to improve going forward... although it will surely take a long while. Security is Capital-H Hard.

Also, I cannot think of any other multi-video-conferencing solution that "just works" and has been as thoroughly stress-tested and attacked by bad actors in the wild at such a large scale. If Zoom does a decent-to-good job fixing all the security issues, it looks likely to continue to dominate its market.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#66
post #37

TLDR: With 17 digits meeting password is not needed at all. If meeting will be 17 numbers it will be the same as to protect 11 length digit number with 6 digit password. So basically that's the trade off. One could say that password is not the same as meeting ID, but usually they both sent in one email/message and lifetime and protection for them is equal. Also it's easier to input one number than 2 different.

Please don't think of this in entropy terms alone. There is a massive usability difference between the two.

I'm not sure I understand your point. The usability of clicking a link stays equal regardless of the amount of digits in the ID. Adding a password reduces the usability.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#67
post #6

Earlier quoted context omitted.

> Hey look it's Mr "it's 2020 but I still don't give a shit about mobile users". Nobody owes you their site behaving a certain way on your phone.

It's not really about entitlement. He's the one benefiting from people consuming his content, why not make it more accessible? All at the cost of some CSS rules.

> accessible

For what it's worth, his website works better with my screen-reader than most modern-style websites.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#69
post #66

Earlier quoted context omitted.

Please don't think of this in entropy terms alone. There is a massive usability difference between the two.

I'm not sure I understand your point. The usability of clicking a link stays equal regardless of the amount of digits in the ID. Adding a password reduces the usability.

Security pretty much always reduces usability - that’s the trade off.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#70
post #37

TLDR: With 17 digits meeting password is not needed at all. If meeting will be 17 numbers it will be the same as to protect 11 length digit number with 6 digit password. So basically that's the trade off. One could say that password is not the same as meeting ID, but usually they both sent in one email/message and lifetime and protection for them is equal. Also it's easier to input one number than 2 different.

If you don’t separate the access key from the secret you can’t change the secret if and when it gets compromised.
Post reply on HN