Security and Privacy Implications of Zoom
schneier.com
Security and Privacy Implications of Zoom
1–10 of 12 posts
Re: Security and Privacy Implications of Zoom
#2They traded a bit of security in favor of useability? Fair enough. They failed to recognise AES-EDC can be attacked by very motivated cryptanalysts? Alright.
They gathered a little bit more data than they claim they did? Well, who is not doing that?
I think they proved they can be agile. They fixed a bunch of sec issues in few days, while growing their user base like 30x, in a shutdown period! How many companies would be able to do that?
I am sure they will work in fixing all of those quickly. E2EE will take a bit of time. Right. In the meantime, Zoom is working pretty darn well for talking with 10+ family and friends while everybody is contained. Do we need E2EE for that? probably not, but that is my choice.
Re: Security and Privacy Implications of Zoom
#3Re: Security and Privacy Implications of Zoom
#4Calling it a disaster.. I find the security community a bit tough against Zoom. They traded a bit of security in favor of useability? Fair enough. They failed to recognise AES-EDC can be attacked by very motivated cryptanalysts? Alright. They gathered a little bit more data than they claim they did? Well, who is not doing that? I think they proved they can be agile. They fixed a bunch of sec issues in few days, while…
Re: Security and Privacy Implications of Zoom
#5Calling it a disaster.. I find the security community a bit tough against Zoom. They traded a bit of security in favor of useability? Fair enough. They failed to recognise AES-EDC can be attacked by very motivated cryptanalysts? Alright. They gathered a little bit more data than they claim they did? Well, who is not doing that? I think they proved they can be agile. They fixed a bunch of sec issues in few days, while…
No, that's not "fair enough".
> They failed to recognise AES-EDC can be attacked by very motivated cryptanalysts? Alright.
No "motivated cryptanalysts" have put time into looking at yet.
> They gathered a little bit more data than they claim they did? Well, who is not doing that?
People who care about your privacy?
> I think they proved they can be agile.
They proved they could fix things that they lied or were clearly shady as soon as the media got wind of it?
> Do we need E2EE for that? probably not, but that is my choice.
It is your choice, but you have the right to make an informed choice. Zoom lied and prevented people from doing this.
Re: Security and Privacy Implications of Zoom
#6Calling it a disaster.. I find the security community a bit tough against Zoom. They traded a bit of security in favor of useability? Fair enough. They failed to recognise AES-EDC can be attacked by very motivated cryptanalysts? Alright. They gathered a little bit more data than they claim they did? Well, who is not doing that? I think they proved they can be agile. They fixed a bunch of sec issues in few days, while…
See what I mean?
Re: Security and Privacy Implications of Zoom
#7The crypto part is really bad, because it seems potentially malicious even.
Has anyone done crypto analysis on the pwd= query parameter? Knowing their security skills I'm wondering if that is crackable...
Re: Security and Privacy Implications of Zoom
#8Just one last thing: The UNC thing..yeah lots of apps habe that issue and it is an issue only if you have a home pc and disable windows firewall or if you are an enterprise user and your network does not block outbound SMB (in which case you have a whole host of problems). Pretty sure Skype and other clients(including irc,jabber,etc...) Do it, it actually makes a lot of sense when talking about corporate meetings, I believe it's windows that sends your creds to the attacker, the client just makes it clickable.
Re: Security and Privacy Implications of Zoom
#9Re: Security and Privacy Implications of Zoom
#10Calling it a disaster.. I find the security community a bit tough against Zoom. They traded a bit of security in favor of useability? Fair enough. They failed to recognise AES-EDC can be attacked by very motivated cryptanalysts? Alright. They gathered a little bit more data than they claim they did? Well, who is not doing that? I think they proved they can be agile. They fixed a bunch of sec issues in few days, while…
That's AES-ECB, and it can be viewed by bored amateurs.