[deleted]
‘War Dialing’ tool exposes Zoom’s password problems
61–70 of 247 posts
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#62Earlier quoted context omitted.
Yeah but then it sucks for people calling in to have to punch in a 21+ character long meeting ID
> Yeah but then it sucks for people calling in to have to punch in a 21+ character long meeting ID I may be out of touch with the average biz-guy, but how many people are realistically calling in manually, over traditional phone-lines these days? Is it really a significant percentage?
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#63Earlier quoted context omitted.
Yeah but then it sucks for people calling in to have to punch in a 21+ character long meeting ID
The telephone dial-in option should've been separate - if the user chooses to enable it then they can fall back to shorter IDs, while meetings that don't need it (or where it doesn't make sense anyway - screen shares, presentations, etc) would use longer, more secure IDs.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#64Earlier quoted context omitted.
Working in global research, 40% of our ROW (rest of world) sites and vendors use landline or cell pones to join our meetings, depends on their institutional security and IT settings.
Smart phones can dial a long code in software. Only dumb phones and landlines can't
Jim from sales who is dialing in from his company's oddball calendar app over Bluetooth on the infotainment system in his rental car probably can't.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#65As a consequence, I suspect Zoom's security is more likely than not to improve going forward... although it will surely take a long while. Security is Capital-H Hard.
Also, I cannot think of any other multi-video-conferencing solution that "just works" and has been as thoroughly stress-tested and attacked by bad actors in the wild at such a large scale. If Zoom does a decent-to-good job fixing all the security issues, it looks likely to continue to dominate its market.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#66TLDR: With 17 digits meeting password is not needed at all. If meeting will be 17 numbers it will be the same as to protect 11 length digit number with 6 digit password. So basically that's the trade off. One could say that password is not the same as meeting ID, but usually they both sent in one email/message and lifetime and protection for them is equal. Also it's easier to input one number than 2 different.
Please don't think of this in entropy terms alone. There is a massive usability difference between the two.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#67Earlier quoted context omitted.
> Hey look it's Mr "it's 2020 but I still don't give a shit about mobile users". Nobody owes you their site behaving a certain way on your phone.
It's not really about entitlement. He's the one benefiting from people consuming his content, why not make it more accessible? All at the cost of some CSS rules.
For what it's worth, his website works better with my screen-reader than most modern-style websites.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#68Re: ‘War Dialing’ tool exposes Zoom’s password problems
#69Earlier quoted context omitted.
Please don't think of this in entropy terms alone. There is a massive usability difference between the two.
I'm not sure I understand your point. The usability of clicking a link stays equal regardless of the amount of digits in the ID. Adding a password reduces the usability.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#70TLDR: With 17 digits meeting password is not needed at all. If meeting will be 17 numbers it will be the same as to protect 11 length digit number with 6 digit password. So basically that's the trade off. One could say that password is not the same as meeting ID, but usually they both sent in one email/message and lifetime and protection for them is equal. Also it's easier to input one number than 2 different.