Live data from Hacker News

‘War Dialing’ tool exposes Zoom’s password problems

krebsonsecurity.com

241–247 of 247 posts

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#241

Earlier quoted context omitted.

I think you overestimate the reliability of the alternatives. Zoom focused all their early engineering muscle on reliability. When we build new products, we don't have infinite resources to attack every front simultaneously. We have finite resources to prove a concept, and we incur debt in just about every other dimension. Now that everyone is using them (precisely because of reliability) the emphasis becomes other t…

That last statement, I'm there with you on. Tech debt is necessary, it could even be renamed "tech leverage," because that's what a lot of it is. My thing is that there are tons of potential ways to mitigate zoombombing, even incrementally, and that they haven't or chose not to indicates it's because there were cost barriers to doing it. It has the tech debt smell, and it's what I've seen in other orgs.

> My thing is that there are tons of potential ways to mitigate zoombombing

Someone call the feds quickly, that sounds like a very serious crime.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#242

Earlier quoted context omitted.

s/users/ips/

Yes, that's brilliant. That should work well when most of your customers are behind corporate NAT access points.

Thanks. Yeah, your customers aren't the ones who are going to get IP banned by wardialing.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#243
post #186

Earlier quoted context omitted.

A phone number is already 10 digits. As long as you put proper break characters between the groupings it's not hard to read IMO.

They could also just generate 4 words and string them together as the password. Considerably more entropy than 10 digital and easier to communicate too.

Kind of like the what3words approach to GIS

[1] https://what3words.com/about-us/

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#244

Earlier quoted context omitted.

IMO, when it comes to security, the fact that other people have made the same mistake makes a design flaw more egregious, not less.

It’s not an egregious flaw, any more than the telephone numbering system is. It’s a design decision to improve usability that is generating a lot of noise during an extraordinary period. Usability is the zoom priority, and the reason why people who already own more secure, no cost, solutions like Teams, Skype or Google Meet buy Zoom.

People often forgot that its a Security-Usabilty scale, with perfect security on one side and perfect usability on the other. An unplugged computer is perfectly secure, while a computer wide open is perfectly usable. But neither is usually preferable.

As with most things, its a trade off.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#246

Earlier quoted context omitted.

Yes, that's brilliant. That should work well when most of your customers are behind corporate NAT access points.

Thanks. Yeah, your customers aren't the ones who are going to get IP banned by wardialing.

Right, because in one case you'll see thousands of different meeting connection requests for different meetings from one IP, and in the other you'll see thousands of different meeting connection requests for different meetings from one IP.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#247
post #165

Earlier quoted context omitted.

Meet has a 10-letters ID for meetings over HTTP and a 9-numbers ID (like zoom) for phoning in. It sounds complicated but in practice every Meet invitation has a single-tap phone link that dials the correct number and input the conference ID after a pause, all encoded in the link. It works flawlessly and so it doesn’t matter if that number is different from the concernce URL you click on a computer.

You are assuming a cell phone that calls in. But lots of people dial in manually from an actual telephone.

Do you have any statistics on "actual phone" usage? I'd imagine it's very low these days.
Post reply on HN