Live data from Hacker News

Zoom will enable waiting rooms by default to stop Zoombombing

techcrunch.com

21–30 of 51 posts

Re: Zoom will enable waiting rooms by default to stop Zoombombing

#21
post #18
post #4

I work for a large multi-national media company, and we've been using BlueJeans for video conferencing for the last few years. It's been very reliable, but I haven't heard of very many others using BlueJeans. I'm curious if the security issues in Zoom vs its competitors more have to do with the amount of people using it and putting eyes on it.

Red Hat uses Blue Jeans for their webinars, and the OKD project uses it for the WG meetings. Not sure about internally or other projects as I don’t have experience with them nor am I an employee.

Did Red Hat use Blue Jeans before being acquired by IBM?

Re: Zoom will enable waiting rooms by default to stop Zoombombing

#22
post #2

> Starting April 5th, it will require passwords to enter calls via Meeting ID A meeting id with a password is semantically the same as a longer meeting id (or a meeting id with a character space larger than just digits). I wish they'd do that instead (make meeting ids longer) so I could continue to enter my company meetings with only a link but not have to worry about getting wardialed.

Except the search space is much, much, larger.

What is larger than what?

With the most straightforward way for "meeting id with a password" and "longer meeting id" to be the same, both methods provide the exact same expansion in search space compared to the previous implementation, and they have the exact same search space as each other.

(That method being: concatenate shortid and password to get longid)

Re: Zoom will enable waiting rooms by default to stop Zoombombing

#23
> a reasonable price to pay to keep people from being scarred by Zoombombing attacks

That's right folks. The most traumatizing thing going on in the world right now is the two weeks where our video conferences got prank called with freaky porn. The scars will heal, and we will grow stronger.

I'll see you all next Mar-Apr for Zoombombing Victim Awareness Week, where our distant gazes will still itch from the Five Nights at Freddie's Rule 34 pics that came screaming out of the aether to blitz our retinas. We will share many a fond remembrance of those dear fallen comrades of ours, whose ghosts shall tread with pixelated lips, ever-mumbling weary explanations to the kids.

Re: Zoom will enable waiting rooms by default to stop Zoombombing

#24
post #19

I see some people running meetings who can barely find the chat. I'm not sure I trust them to manage a waiting room.

Giving the benefit of doubt here, if you enter full screen mode chat opens in a different window and no longer gives you notifications. At least on linux. I honestly find this quite painful and rather surprising. I'm not sure why full screen and chat isn't equivalent to just maximizing the window (where the chat is on the right and users are above) with tabs to open and close chat (and users). New windows seems like a weird decision.

Re: Zoom will enable waiting rooms by default to stop Zoombombing

#25
post #21
post #18

Earlier quoted context omitted.

Red Hat uses Blue Jeans for their webinars, and the OKD project uses it for the WG meetings. Not sure about internally or other projects as I don’t have experience with them nor am I an employee.

Did Red Hat use Blue Jeans before being acquired by IBM?

yes

Re: Zoom will enable waiting rooms by default to stop Zoombombing

#26
post #4

I work for a large multi-national media company, and we've been using BlueJeans for video conferencing for the last few years. It's been very reliable, but I haven't heard of very many others using BlueJeans. I'm curious if the security issues in Zoom vs its competitors more have to do with the amount of people using it and putting eyes on it.

We used BlueJeans at my previous job and it was reliably awful. So many issues with it.

I'm using Jitsi now and am quite happy with it.

Re: Zoom will enable waiting rooms by default to stop Zoombombing

#27
post #2

> Starting April 5th, it will require passwords to enter calls via Meeting ID A meeting id with a password is semantically the same as a longer meeting id (or a meeting id with a character space larger than just digits). I wish they'd do that instead (make meeting ids longer) so I could continue to enter my company meetings with only a link but not have to worry about getting wardialed.

Except the search space is much, much, larger.

Don't we want the search space larger? That way it is harder to wardial? YouTube has 11 characters composed of [a-Z] and [0-9]. (26*2+10)^11 is a pretty big number. There's no reason it couldn't be longer.

Re: Zoom will enable waiting rooms by default to stop Zoombombing

#28

Waiting rooms don't help because you don't see any identifying information. My sister's call got zoombombed even with a moderated waiting room. They were trying to keep within their university's students, but they couldn't see the email addresses associated with the zoom user name in the waiting room, so a griefer got through.

For these cases required sign in might be best

Seems like User Interface design issue.

At the minimum they could show anonymized email id: abgh@univname.com

Re: Zoom will enable waiting rooms by default to stop Zoombombing

#29
post #4

I work for a large multi-national media company, and we've been using BlueJeans for video conferencing for the last few years. It's been very reliable, but I haven't heard of very many others using BlueJeans. I'm curious if the security issues in Zoom vs its competitors more have to do with the amount of people using it and putting eyes on it.

We use both Zoom and BlueJeans at work, and Zoom Just Works™ while BlueJeans has all sorts of compatibility headaches; if it's not Chrome/Windows, it's pretty much a crapshoot.

That being said, the AV quality between the two are pretty similar.

Re: Zoom will enable waiting rooms by default to stop Zoombombing

#30
post #2

> Starting April 5th, it will require passwords to enter calls via Meeting ID A meeting id with a password is semantically the same as a longer meeting id (or a meeting id with a character space larger than just digits). I wish they'd do that instead (make meeting ids longer) so I could continue to enter my company meetings with only a link but not have to worry about getting wardialed.

meeting IDs need to be numbers to make it easy to join meetings by phone. no particular reason they can't be longer though.
Post reply on HN