Earlier quoted context omitted.
Please don't think of this in entropy terms alone. There is a massive usability difference between the two.
Do it in base 9000 with baby names and common words. "Join us in black raven deodorant daisy mega delta leo " Also create dud rooms with prerecorded conversation.
‘War Dialing’ tool exposes Zoom’s password problems
191–200 of 247 posts
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#192Earlier quoted context omitted.
A phone number is already 10 digits. As long as you put proper break characters between the groupings it's not hard to read IMO.
They could also just generate 4 words and string them together as the password. Considerably more entropy than 10 digital and easier to communicate too.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#193Earlier quoted context omitted.
A phone number is already 10 digits. As long as you put proper break characters between the groupings it's not hard to read IMO.
They could also just generate 4 words and string them together as the password. Considerably more entropy than 10 digital and easier to communicate too.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#194Earlier quoted context omitted.
I wouldn't be shy about betting the reason they haven't done this is because they don't want the ids to be longer/have a larger character set than they have to be, because they'd take longer/be more error prone to type/say out loud. Lowest possible friction: the reason for most of their flaws thus far.
Agreed. I will add: security and convenience are always polar opposites. The most successful companies are typically the ones that can get away with being as convenient as possible for the longest.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#195Earlier quoted context omitted.
They could also just generate 4 words and string them together as the password. Considerably more entropy than 10 digital and easier to communicate too.
English-specific tho
Your memorable phrase is 'correct horse battery staple'.
Its not often that people without a common language have zoom meetings anywayRe: ‘War Dialing’ tool exposes Zoom’s password problems
#196I worked in videoconferencing for a while. When it comes to meeting identifiers, striking the right balance between ease of use and security is really hard. On the one side, maximum ease-of-use is a name or code short enough for someone to say over the phone. "Here, just jump into the videoconferencing meeting 'mikefred' or 'john10' or '39584'". That works particularly well for small meetings where it's immediate obv…
For the phone only route, it seems like you could still mostly automate it by going oldschool. Give the host an option to play the meeting code as a DTMF signal (or whatever) while the other person holds their phone near the mic.
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#197One positive thing about all these horrendous security flaws that have been recently discovered in Zoom, due to its popularity, is that the company seems to be taking them seriously, recently instituting a feature freeze to focus on fixing them: https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u... As a consequence, I suspect Zoom's security is more likely than not to improve going forward... although it wi…
> Security is Capital-H Hard. It is even harder when you try and graft the security on after the fact. Security needs to be a consideration from day 1, not once youve your minimal product. Proper security may steer architecture decisions that may be difficult or impossible which to adapt. This is especially true for internet facing services. I had a hell of a time bolting on authentication/permission to an internal A…
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#198One positive thing about all these horrendous security flaws that have been recently discovered in Zoom, due to its popularity, is that the company seems to be taking them seriously, recently instituting a feature freeze to focus on fixing them: https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u... As a consequence, I suspect Zoom's security is more likely than not to improve going forward... although it wi…
You’re kidding... right?
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#199One positive thing about all these horrendous security flaws that have been recently discovered in Zoom, due to its popularity, is that the company seems to be taking them seriously, recently instituting a feature freeze to focus on fixing them: https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u... As a consequence, I suspect Zoom's security is more likely than not to improve going forward... although it wi…
Re: ‘War Dialing’ tool exposes Zoom’s password problems
#200One positive thing about all these horrendous security flaws that have been recently discovered in Zoom, due to its popularity, is that the company seems to be taking them seriously, recently instituting a feature freeze to focus on fixing them: https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u... As a consequence, I suspect Zoom's security is more likely than not to improve going forward... although it wi…
I'm not a fan of Zoom... But the pile-on of grief is ridiculous. The "war dialing" issue is a great example. Webex has had the exact same "flaw" for a decade, with the exact same solution - set a meeting password. Other solutions like Google Meet or Skype have the "lobby" approach.
It's not always ideal though. I've organized meetings with 10+ people, want able to attend the meeting and now nobody can join the session.