I always wondered why teleconferencing systems don't incorporate a workflow where people connecting in need an approval from the organizer before actually entering the meeting.
‘War Dialing’ tool exposes Zoom’s password problems
71–80 of 247 posts
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#72Earlier quoted context omitted.
Please don't think of this in entropy terms alone. There is a massive usability difference between the two.
I'm not sure I understand your point. The usability of clicking a link stays equal regardless of the amount of digits in the ID. Adding a password reduces the usability.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#73TLDR: With 17 digits meeting password is not needed at all. If meeting will be 17 numbers it will be the same as to protect 11 length digit number with 6 digit password. So basically that's the trade off. One could say that password is not the same as meeting ID, but usually they both sent in one email/message and lifetime and protection for them is equal. Also it's easier to input one number than 2 different.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#74Re: ‘War Dialing’ tool exposes Zoom’s password problems
#75This chart suggests that one of the companies they found was an aerospace company: https://krebsonsecurity.com/wp-content/uploads/2020/04/zward...
I wonder if this is related to the news yesterday that SpaceX has banned the use of Zoom.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#76Not a good idea to use 9 to 11 digit long IDs with no password requirement by default; they should have used at least 128-bit random ids, i.e. 21 character long base64-encoded strings.
Yeah but then it sucks for people calling in to have to punch in a 21+ character long meeting ID
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#77Earlier quoted context omitted.
Yeah but this time, it’s an easy as guessing a world leaders zoom meeting, and tricking them into believing something preposterous
Modern Version: "Shall we play a game?" "Love to" "‼To play Global Thermonuclear War, you must first update your flash player. Click here‼️"
"Shall we play a game of Global Thermonuclear War?"
"Sure!"
"Updating Steam client... It seems you're connecting from a new device! Please check the 2FA code sent to your email... Downloading more updates... Here are some popups about unrelated games... Please register an account with MS Game Live!... Downloading patches... [error in wopr.dll]"
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#78TLDR: With 17 digits meeting password is not needed at all. If meeting will be 17 numbers it will be the same as to protect 11 length digit number with 6 digit password. So basically that's the trade off. One could say that password is not the same as meeting ID, but usually they both sent in one email/message and lifetime and protection for them is equal. Also it's easier to input one number than 2 different.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#79Earlier quoted context omitted.
Please don't think of this in entropy terms alone. There is a massive usability difference between the two.
I'm not sure I understand your point. The usability of clicking a link stays equal regardless of the amount of digits in the ID. Adding a password reduces the usability.
The situations and use-cases behind meeting-software are such that you can't rely on this.
There are many situations where you want to transcribe the information. For example, dialing in as voice-only with a private phone based on an e-mail on your work-laptop.
Or perhaps a conference room at a client-site where the client-guy has their corporate-approved presentation laptop, but he can't find the e-mail/chat message with it. Meanwhile you've got it up on-screen, but your device is not approved for any kind of internet connection in this part of the labs, and even your phone has no signal. (Yes, I've been there.)
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#80I feel a little bit sorry for the Zoom devs. All of a sudden there are a _lot_ of eyes on Zoom. Every design decision and mistake are under a big microscope, while also presumably having to deal with some major scaling.
I don't feel sorry for them.
Also: this crisis is giving them vast amounts of marketing for free.
I'm based in Sweden. I was just vaguely aware of Zoom until a few days ago - now I suddenly hear of them all of the time from Late Night hosts on Youtube.