Live data from Hacker News

‘War Dialing’ tool exposes Zoom’s password problems

krebsonsecurity.com

101–110 of 247 posts

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#101

They’re explaining how seriously they take security using Wordpress.

I know that WordPress doesn't have the greatest security record, but it seems unfair to judge an organization for using WP.

Many, many respectable businesses use WordPress for their brochureware or corporate blogs. In my experience, it's not a security nightmare if it's well maintained.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#102

I worked in videoconferencing for a while. When it comes to meeting identifiers, striking the right balance between ease of use and security is really hard. On the one side, maximum ease-of-use is a name or code short enough for someone to say over the phone. "Here, just jump into the videoconferencing meeting 'mikefred' or 'john10' or '39584'". That works particularly well for small meetings where it's immediate obv…

What about a long, unique identifier for the baseline, and the ability to generate temporary, single (or `n`) use, short identifiers that can be used when speaking the id?

Clicking a long I'd link takes practically training, and entering a short ID would only require training the salespeople how to generate one (would should only be a few clicks tops).

This way, a conference is secure by default and easy for people to join by link, and is still easily accessable by code for when needed.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#105
post #97

Earlier quoted context omitted.

Security pretty much always reduces usability - that’s the trade off.

I've been thinking about security and usability for a while. IMO a big part of use-ability issues are related to interfaces people have to interact with. This is mainly concerning authentication and crypto related processes. I generally like the idea of smartcards, or having some physical thing you carry around which is used to authenticate with systems.

Two factor auth - some physical thing you carry around with you to authenticate with systems - is the very definition of decreasing usability in order to increase security.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#106
post #65

One positive thing about all these horrendous security flaws that have been recently discovered in Zoom, due to its popularity, is that the company seems to be taking them seriously, recently instituting a feature freeze to focus on fixing them: https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u... As a consequence, I suspect Zoom's security is more likely than not to improve going forward... although it wi…

Pro: A worldwide, motivated, unpaid volunteer team is doing their thorough security audit, privacy review and QA testing for them.

Con: After the product was released :)

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#107

It's 1985 all over again: I'm in my bedroom running a ProDOS wardialer on my 300/1200 baud AppleModem; I have found zero computers, but it is fun watching the numbers flick past, hoping that I, too, can discover a WOPR and start global thermonuclear war.

Yeah but this time, it’s an easy as guessing a world leaders zoom meeting, and tricking them into believing something preposterous

Supposedly Captain Crunch got on the phone with Nixon, so it isn't that far off.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#108
post #91

It's 1985 all over again: I'm in my bedroom running a ProDOS wardialer on my 300/1200 baud AppleModem; I have found zero computers, but it is fun watching the numbers flick past, hoping that I, too, can discover a WOPR and start global thermonuclear war.

>It's 1985 all over again i think it is even earlier than that: >Each Zoom conference call is assigned a Meeting ID that consists of 9 to 11 digits. 8 char passwd and 16 digit credit cards came way before 1985. Never mind, i have committed in memory our daily scrum 9 digit pin code :) Very convenient. And if somebody else were to dial in uninvited into our scrum ... well, it is at their own peril as it carries (espec…

Most Unix systems had 8 character password limits well into the 90's (a limitation of the original DES-based crypt.)
Post reply on HN