Earlier quoted context omitted.
Generating a random 6-digit passcode for each meeting by default? Not hard at all. Rate-limiting incorrect password attempts could take a bit longer to implement, but still not a particularly difficult problem to solve.
I never understood "presenter will let you in" security. It's based on someone letting me in if they recognize my recorded name and that I work there? Surely that wont backfire in a world where everyone post every detail about every day of their life online. I mean who even uses LinkedIn anyway?
‘War Dialing’ tool exposes Zoom’s password problems
171–180 of 247 posts
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#172Earlier quoted context omitted.
I'm not a fan of Zoom... But the pile-on of grief is ridiculous. The "war dialing" issue is a great example. Webex has had the exact same "flaw" for a decade, with the exact same solution - set a meeting password. Other solutions like Google Meet or Skype have the "lobby" approach.
IMO, when it comes to security, the fact that other people have made the same mistake makes a design flaw more egregious, not less.
Usability is the zoom priority, and the reason why people who already own more secure, no cost, solutions like Teams, Skype or Google Meet buy Zoom.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#173Earlier quoted context omitted.
I'm not a fan of Zoom... But the pile-on of grief is ridiculous. The "war dialing" issue is a great example. Webex has had the exact same "flaw" for a decade, with the exact same solution - set a meeting password. Other solutions like Google Meet or Skype have the "lobby" approach.
Isn't it easily fixed by making IDs slightly higher entropy, and also rate limiting retries? Something like a Youtube ID which is 11-char in Base62, which is short enough but has so much entropy that even know with billions of videos, entering a random ID will most likely not work. You should also always have some reasonable rate limit of any sort of API query, if someone is querying rooms at 10qps or more, there's c…
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#174Earlier quoted context omitted.
"A problem is a problem regardless if is as of yet undiscovered." Instead of thinking that a product has 'some number of bugs, which when fixed, is perfect' - consider that there are maybe 'infinity' problems. In any given context, those problems are likely to cause differing levels of concern, in different ways, and that in different contexts they may be more likely discovered than not. For example - Mac is generall…
I feel like security is a realm where that quote is demonstrably untrue. A "hole" in your system is exactly zero problem until the moment someone exploits it.
Mostly all we can do is triage and it mostly works.
But I'm all for a more sound approach.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#175Earlier quoted context omitted.
Isn't it easily fixed by making IDs slightly higher entropy, and also rate limiting retries? Something like a Youtube ID which is 11-char in Base62, which is short enough but has so much entropy that even know with billions of videos, entering a random ID will most likely not work. You should also always have some reasonable rate limit of any sort of API query, if someone is querying rooms at 10qps or more, there's c…
I wouldn't be shy about betting the reason they haven't done this is because they don't want the ids to be longer/have a larger character set than they have to be, because they'd take longer/be more error prone to type/say out loud. Lowest possible friction: the reason for most of their flaws thus far.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#176Earlier quoted context omitted.
IMO, when it comes to security, the fact that other people have made the same mistake makes a design flaw more egregious, not less.
It’s not an egregious flaw, any more than the telephone numbering system is. It’s a design decision to improve usability that is generating a lot of noise during an extraordinary period. Usability is the zoom priority, and the reason why people who already own more secure, no cost, solutions like Teams, Skype or Google Meet buy Zoom.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#177Earlier quoted context omitted.
I'm not sure about "just works", but I am sure about "works" in the sense that is head and shoulders above every other video chat app I've used when it comes to audio and video quality, especially for large numbers of participants, audio sharing, document camera sharing, multiple participants sharing simultaneously, and there are plenty more. I've never used the web version, but it wouldn't surprise me if it's not th…
Yeah, the only other video app I've used that approaches the call quality is Slack. I've not tried to use that with more than a handful of people though.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#178Earlier quoted context omitted.
Hangouts is going to be discontinued. Hangouts meet is limited to 720p and sharing screen is limited to f cking 5 FPS. Repeat with me, three times: Hangouts s cks for on-line presentations Hangouts s cks for on-line presentations Hangouts s cks for on-line presentations
Aside from the fact that you're wrong, I think you need to take a break from the internet. You seem stressed.
Google Delays Hangouts Shutdown Until June 2020
https://www.extremetech.com/internet/297037-google-delays-ha...
WebRTC Internals in Chrome with frame rate capped at 5 FPS while screen sharing:
https://www.reddit.com/r/chromeos/comments/absxt2/chromebox_...
Screen Share through Hangouts/Meet with high FPS? R: Nope
https://www.reddit.com/r/chromeos/comments/fo60me/screen_sha...
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#179One positive thing about all these horrendous security flaws that have been recently discovered in Zoom, due to its popularity, is that the company seems to be taking them seriously, recently instituting a feature freeze to focus on fixing them: https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u... As a consequence, I suspect Zoom's security is more likely than not to improve going forward... although it wi…
You are saying because they had lax security, now they will have good security.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#180Earlier quoted context omitted.
> Becoming one of the top names in video conferencing and displacing dozens of established players virtually overnight? Sign me up. What!? That's small thinking. You could be so many greater things than that if you're willing to compromise peoples security and personal information.
I know you're being sarcastic but there are a ton of companies that have a terrible security track record and yet are quite large...