Live data from Hacker News

Jitsi privacy flaw enables one-click stealth audio and video capture

zimzi.substack.com

11–20 of 37 posts

Re: Jitsi privacy flaw enables one-click stealth audio and video capture

#12

Maybe my Mac is set to be paranoid, but can you share video without being asked to give the mic and camera permission to operate? I chat with jitsi all the time and have to give jitsi explicit permission to use the mic/camera each time.

If you’re using jitsi already, won’t you have already given those permissions?

Re: Jitsi privacy flaw enables one-click stealth audio and video capture

#14
This is clearly a major vulnerability and not a feature, it's a permissions/credentials hijack.

The user has given permission for audio and videos recording to the jitsi domain during a previous meeting, and the domain is using those permissions to start an unsolicited meeting initiated by a 3rd party, who is given access to the video and audio of the victim.

Re: Jitsi privacy flaw enables one-click stealth audio and video capture

#15
post #10

Can someone describe the feature that this is used for? I struggle to think of any valid reason for automatic joining with audio/video like that.

I would say it's to reduce friction - only grant permission once, rather than every time you join a jitsi meeting.

It's not so much about the permissions (which is a browser issue) but about the config.prejoinConfig.enabled flag: usually when joining a meeting, you get an interstitial page which let's you check your webcam image and sound settings before hitting join to enter the call. This setting (passed as a request param) skips that screen.

I'm not a fan, either. I'm used to the interstitial page from other services, and in fact would not expect to join a call and stream data before hitting "join".

Jitsi is used in many custom solutions (which may have their own UI for getting user opt-in, like a customer hitting "Next step" in a registration wizard), I expect that's why they added it.

Re: Jitsi privacy flaw enables one-click stealth audio and video capture

#16

Maybe my Mac is set to be paranoid, but can you share video without being asked to give the mic and camera permission to operate? I chat with jitsi all the time and have to give jitsi explicit permission to use the mic/camera each time.

Probably 99% of people clicks "yes, always"

Re: Jitsi privacy flaw enables one-click stealth audio and video capture

#18

Can someone describe the feature that this is used for? I struggle to think of any valid reason for automatic joining with audio/video like that.

Matrix embedded Jitsi as their voice/video calling solution for a while, probably still does depending on what client you use. Automatically joining the call when you click the call button just makes sense from a UX perspective.

That said, I can't think of a reason why you'd want to permit it outside of very specific containers. Useful for integration, but outright bad design for a public instance.

Re: Jitsi privacy flaw enables one-click stealth audio and video capture

#19
This attack/feature hinges on the

config.prejoinConfig.enabled=false

config (which implicitly decides weather or not a prejoin dialog is shown)

but this makes me wonder

1. why can you set that config in a URL? Allowing users to set it for them-self seems fine, but allowing rooms or URL to use it seems ... off.

2. how many other sites have this attack surface (e.g. MS Teams) just more obscure

3. actually the moment the attacker controls JS probably *all* other video conference systems have the feature, through potentially needing a lot of additional work. In which case maybe just being straightforward and open about it is fine? But the cost of such an attack is just a very bit too low compared to other conference systems.

Re: Jitsi privacy flaw enables one-click stealth audio and video capture

#20

Maybe my Mac is set to be paranoid, but can you share video without being asked to give the mic and camera permission to operate? I chat with jitsi all the time and have to give jitsi explicit permission to use the mic/camera each time.

> but can you share video without being asked to give the mic and camera permission to operate?

yes it's a browser setting to "remember mic/camera permission for given site"

to which extend this "remember" is there by default, can be disabled through system config/MDA etc. is probably very

lastly iff that is a default for Safari on Mac I wouldn't be surprised if that was not only placed their to protect your safety but to annoy you and push you to use Mac, it would fit into a sad list of similar things done by Apple to push people to go through their app store. But then more safe is still more better for many users.

Post reply on HN