Live data from Hacker News

Dutch journalist gatecrashes EU defence video conference

bbc.co.uk

31–40 of 94 posts

Re: Dutch journalist gatecrashes EU defence video conference

#31
This is profoundly depressing. The fact that an EU defence conference is being held... on Zoom, is truly a microcosm of what has been the strategic policy of the EU for the past 20-30 years. We have sold off our independence, out advantages economic and otherwise, for pennies. For minuscule short-term gains, we have sold off our industry, our tech, to a hostile and totalitarian government. Well when I say "we" I mean private enterprise, but also the governments who were supposed to be raking in (though as one German economist said, government and private enterprise are pretty much one and the same).

It will come soon a time (in fact, it's pretty much here already) where China calls the shots over us. "Obey, or no microchips for you. In fact, no manufacturing of any kind." Thoroughly depressing.

Re: Dutch journalist gatecrashes EU defence video conference

#32
post #31

This is profoundly depressing. The fact that an EU defence conference is being held... on Zoom, is truly a microcosm of what has been the strategic policy of the EU for the past 20-30 years. We have sold off our independence, out advantages economic and otherwise, for pennies . For minuscule short-term gains, we have sold off our industry, our tech, to a hostile and totalitarian government. Well when I say "we" I mea…

The Zoom security debate has been hashed to death on HN lately, but Webex for example patched some RCEs only a couple weeks ago. I’m not fully convinced Zoom is objectively less secure than all the other alternatives these days. They just get a lot more attention for it.

Besides, if the EU defence conference had an open URL or weak password that issue would apply regardless of Zoom, Webex, etc.

Re: Dutch journalist gatecrashes EU defence video conference

#33
post #17
post #7

Not sure how confidential that conference was but I'd imagine these use at least a 2FA dongle to authenticate. This is surprising.

Had the laptop had a 15 inch screen it would likely have shown the entire URL including the full PIN code. Also visible in the screen are bookmarks to Netflix and what looks like barber shop music. Also a Gmail tab open. Did now know defense ministers were using Gmail on official hardware...

Everyone and their mother uses Google services for their personal and/or confidential stuff, going from blind faith or just never thinking about it. After all it is good old Google, not some large surveillance capitalist.. Oh wait.

Re: Dutch journalist gatecrashes EU defence video conference

#34
post #32
post #31

This is profoundly depressing. The fact that an EU defence conference is being held... on Zoom, is truly a microcosm of what has been the strategic policy of the EU for the past 20-30 years. We have sold off our independence, out advantages economic and otherwise, for pennies . For minuscule short-term gains, we have sold off our industry, our tech, to a hostile and totalitarian government. Well when I say "we" I mea…

The Zoom security debate has been hashed to death on HN lately, but Webex for example patched some RCEs only a couple weeks ago. I’m not fully convinced Zoom is objectively less secure than all the other alternatives these days. They just get a lot more attention for it. Besides, if the EU defence conference had an open URL or weak password that issue would apply regardless of Zoom, Webex, etc.

The point of GP is that Zoom is american software, regardless of any particular issue related to the app itself. Which IMO, is a very crucial point.

A EU security conference should use EU software, and as little foreign stuff as possible. Otherwise, it's just theater (and it currently really is just that!).

Re: Dutch journalist gatecrashes EU defence video conference

#35
post #31

This is profoundly depressing. The fact that an EU defence conference is being held... on Zoom, is truly a microcosm of what has been the strategic policy of the EU for the past 20-30 years. We have sold off our independence, out advantages economic and otherwise, for pennies . For minuscule short-term gains, we have sold off our industry, our tech, to a hostile and totalitarian government. Well when I say "we" I mea…

It is not that simple. The minute China does it - they stand alone. The whole premise of outsourcing manufacturing to China will die. No one will trust them to do it. In my opinion they won’t do it

Re: Dutch journalist gatecrashes EU defence video conference

#36
post #31

This is profoundly depressing. The fact that an EU defence conference is being held... on Zoom, is truly a microcosm of what has been the strategic policy of the EU for the past 20-30 years. We have sold off our independence, out advantages economic and otherwise, for pennies . For minuscule short-term gains, we have sold off our industry, our tech, to a hostile and totalitarian government. Well when I say "we" I mea…

thats not zoom, its Pexip

https://www.pexip.com/

Re: Dutch journalist gatecrashes EU defence video conference

#37

According to a screenshot that the journalist posted on Twitter, it appears like the video conference session is browser-based, and the pin and username are in the browser URL in plaintext . So then if you can see anyone's screen, or any clear photo of it, you can easily join the conference. Seems like very poor security design if that's so https://pbs.twimg.com/media/EnRlaFeWMAQzyIS?format=jpg The software URL forma…

this should require something more than a URL, even a skype meeting would be more secure.

Re: Dutch journalist gatecrashes EU defence video conference

#38
post #34
post #32

Earlier quoted context omitted.

The Zoom security debate has been hashed to death on HN lately, but Webex for example patched some RCEs only a couple weeks ago. I’m not fully convinced Zoom is objectively less secure than all the other alternatives these days. They just get a lot more attention for it. Besides, if the EU defence conference had an open URL or weak password that issue would apply regardless of Zoom, Webex, etc.

The point of GP is that Zoom is american software, regardless of any particular issue related to the app itself. Which IMO, is a very crucial point. A EU security conference should use EU software, and as little foreign stuff as possible. Otherwise, it's just theater (and it currently really is just that!).

All of Zoom’s security team is based in the US to be fair. I don’t really agree in general that the X-conference should use X-software.

Re: Dutch journalist gatecrashes EU defence video conference

#39

If he joined the video conference to watch and listen, but just sent a blank screen video, or maybe a freeze frame of an empty chair, would anyone have noticed?

I remember being in voice chat for a space spreadsheet game [0] and hearing the 'ding' for a new user joining the channel. Everyone knew to stop taking lest a spy discover where our fleet was. I really hope there's a similar reaction in these chats!

[0]eve-online.com

Re: Dutch journalist gatecrashes EU defence video conference

#40
post #5
post #3

The conference chair couldn't help giggling. What was it he said? "Hey you better hang up before the police arrives"?

It's very serious stuff, it's not funny. Someone leaves their doors unlocked it doesn't mean you should be entering. More importantly, how on bloody earth are defence discussions happening in a situation that can so easily be defeated. The officials themselves are to blame for blatantly terrible security protocols.

[deleted]
Post reply on HN