Live data from Hacker News

‘War Dialing’ tool exposes Zoom’s password problems

krebsonsecurity.com

191–200 of 247 posts

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#191

Earlier quoted context omitted.

Please don't think of this in entropy terms alone. There is a massive usability difference between the two.

Do it in base 9000 with baby names and common words. "Join us in black raven deodorant daisy mega delta leo " Also create dud rooms with prerecorded conversation.

[deleted]

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#192
post #186

Earlier quoted context omitted.

A phone number is already 10 digits. As long as you put proper break characters between the groupings it's not hard to read IMO.

They could also just generate 4 words and string them together as the password. Considerably more entropy than 10 digital and easier to communicate too.

English-specific tho

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#193
post #186

Earlier quoted context omitted.

A phone number is already 10 digits. As long as you put proper break characters between the groupings it's not hard to read IMO.

They could also just generate 4 words and string them together as the password. Considerably more entropy than 10 digital and easier to communicate too.

You need the ability to enter the code on a numeric keypad when dialing in from an office phone. Compatibility with "ancient" enterprise practices is also important.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#194

Earlier quoted context omitted.

I wouldn't be shy about betting the reason they haven't done this is because they don't want the ids to be longer/have a larger character set than they have to be, because they'd take longer/be more error prone to type/say out loud. Lowest possible friction: the reason for most of their flaws thus far.

Agreed. I will add: security and convenience are always polar opposites. The most successful companies are typically the ones that can get away with being as convenient as possible for the longest.

I would disagree about "always" polar opposites. For example SSO/iDP like Okta add a ton of security but also makes it easier while more secure for employees to log in to their multitude of company apps.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#195
post #192
post #186

Earlier quoted context omitted.

They could also just generate 4 words and string them together as the password. Considerably more entropy than 10 digital and easier to communicate too.

English-specific tho

Not hard to do it for any language. And they're cheap to make.

    Your memorable phrase is 'correct horse battery staple'.
    
         
Its not often that people without a common language have zoom meetings anyway

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#196

I worked in videoconferencing for a while. When it comes to meeting identifiers, striking the right balance between ease of use and security is really hard. On the one side, maximum ease-of-use is a name or code short enough for someone to say over the phone. "Here, just jump into the videoconferencing meeting 'mikefred' or 'john10' or '39584'". That works particularly well for small meetings where it's immediate obv…

For the phone only route, it seems like you could still mostly automate it by going oldschool. Give the host an option to play the meeting code as a DTMF signal (or whatever) while the other person holds their phone near the mic.

DTMF signal played over what exactly? The phone option is for when you aren't at a computer (driving, conference, etc..).

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#197
post #65

One positive thing about all these horrendous security flaws that have been recently discovered in Zoom, due to its popularity, is that the company seems to be taking them seriously, recently instituting a feature freeze to focus on fixing them: https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u... As a consequence, I suspect Zoom's security is more likely than not to improve going forward... although it wi…

> Security is Capital-H Hard. It is even harder when you try and graft the security on after the fact. Security needs to be a consideration from day 1, not once youve your minimal product. Proper security may steer architecture decisions that may be difficult or impossible which to adapt. This is especially true for internet facing services. I had a hell of a time bolting on authentication/permission to an internal A…

Yeah... graft it on after you've lunged to make a sort of OK product and they're locked in but the vulnerabilities you're exposing them to aren't worth moving off the platform. The capitalist sweet spot

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#198
post #65

One positive thing about all these horrendous security flaws that have been recently discovered in Zoom, due to its popularity, is that the company seems to be taking them seriously, recently instituting a feature freeze to focus on fixing them: https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u... As a consequence, I suspect Zoom's security is more likely than not to improve going forward... although it wi…

>horrendous security flaws

You’re kidding... right?

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#199
post #65

One positive thing about all these horrendous security flaws that have been recently discovered in Zoom, due to its popularity, is that the company seems to be taking them seriously, recently instituting a feature freeze to focus on fixing them: https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u... As a consequence, I suspect Zoom's security is more likely than not to improve going forward... although it wi…

Yes now Google meet uses random alphanumeric meeting ids this helps for sure you needed to find the.balance between security and accessibility.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#200
post #65

One positive thing about all these horrendous security flaws that have been recently discovered in Zoom, due to its popularity, is that the company seems to be taking them seriously, recently instituting a feature freeze to focus on fixing them: https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-u... As a consequence, I suspect Zoom's security is more likely than not to improve going forward... although it wi…

I'm not a fan of Zoom... But the pile-on of grief is ridiculous. The "war dialing" issue is a great example. Webex has had the exact same "flaw" for a decade, with the exact same solution - set a meeting password. Other solutions like Google Meet or Skype have the "lobby" approach.

Zoom in fact also allows you to enable a "waiting room" for all meetings owned by your account.

It's not always ideal though. I've organized meetings with 10+ people, want able to attend the meeting and now nobody can join the session.

Post reply on HN