I can only assume CISO is Chief Information Security Officer? I hadn't seen the acronym before. Bad Zoom for not writing it out in full on the first instance.
"CISO" is a pretty standard acronym. People who don't work in cybersecurity or who don't have that background might not recognize it, but it seems like a minor detail.
Zoom’s 90-day plan to bolster key privacy and security initiatives
51–60 of 113 posts
Re: Zoom’s 90-day plan to bolster key privacy and security initiatives
#52Earlier quoted context omitted.
Occam’s Razor. Zoom usage went up by 8x in a few months. Usually doubling in two years is great for a public company. So that’s 6 years of great growth, compressed into a few months. It shouldn’t be surprising to see six years of security problems also compressed into those three months. I think Zoom is on track to fix these problems quickly and cement their spot as the best solution for videoconferencing.
Zoom had the same security issues with half the traffic. Acting like usage causes them is disingenuous. Technically speaking, zoom has shown off great and remarkably stable/scalable features. But that is orthogonal to whether they are putting people at risk (e.g. not-so-secret therapy sessions) or lying about their feature set (clearly claiming to have end to end encryption).
There's lots and lots of insecure software that Bloomberg doesn't write about. People click on articles about software they use.
Re: Zoom’s 90-day plan to bolster key privacy and security initiatives
#53Zoom's web SDK and web client were down for nearly four days over the weekend with minimal communication, and when they brought it all back they killed a key functionality the education market needs which is the ability to join a meeting without an account: https://devforum.zoom.us/t/in-progress-web-sdk-web-client-fr...
Why is the need for an account a showstopper?
Re: Zoom’s 90-day plan to bolster key privacy and security initiatives
#54Zoom's web SDK and web client were down for nearly four days over the weekend with minimal communication, and when they brought it all back they killed a key functionality the education market needs which is the ability to join a meeting without an account: https://devforum.zoom.us/t/in-progress-web-sdk-web-client-fr...
Actually this isn't true anymore, they have since added the _option_ to not require an account when using the web client. The Web SDK still works like before and also doesn't require an account. But I agree, the way it was handled was harrowing.
Re: Zoom’s 90-day plan to bolster key privacy and security initiatives
#55So were they really sending data to servers in China? From what little I've heard and read about this, that is what stood out to me. Not sure they should ever be trusted again after that.
Serious hypothetical question: suppose you're able to capture all Zoom calls. If you're a foreign government, how do you scale the analysis, and what can you generally do with the information? It'd be hard to get a useful amount of trade secrets or know-how. You'll see partial schematics and design docs, but without much context. At the executive level, you could at least scale the analysis to have actual people moni…
Re: Zoom’s 90-day plan to bolster key privacy and security initiatives
#56Earlier quoted context omitted.
I don't see anything for that domain...
I do, in that link provided in an edit, after getting around google recaptcha (wow securitytrails.com has a shitty website...) Edit: here's a screenshot: https://twitter.com/danehrlich11/status/1247206209876353025/...
Re: Zoom’s 90-day plan to bolster key privacy and security initiatives
#57Re: Zoom’s 90-day plan to bolster key privacy and security initiatives
#58Earlier quoted context omitted.
Zoom had the same security issues with half the traffic. Acting like usage causes them is disingenuous. Technically speaking, zoom has shown off great and remarkably stable/scalable features. But that is orthogonal to whether they are putting people at risk (e.g. not-so-secret therapy sessions) or lying about their feature set (clearly claiming to have end to end encryption).
That's a straw man. GP argues that Zoom's increased popularity implies increased public scrutiny. Not that the problems are OK. There's lots and lots of insecure software that Bloomberg doesn't write about. People click on articles about software they use.
I agree that increased scrutiny does not make the problem ok, but does reveal the problems more quickly.
But the only reason those points matter in the "Should I use Zoom?" question is if you're assuming all other products have the same flaws and just haven't been looked at. To which, I'm pretty confident they don't all share these problems, particularly but not limited to the "blatantly lied about the basic security features".
Re: Zoom’s 90-day plan to bolster key privacy and security initiatives
#59Earlier quoted context omitted.
That's a straw man. GP argues that Zoom's increased popularity implies increased public scrutiny. Not that the problems are OK. There's lots and lots of insecure software that Bloomberg doesn't write about. People click on articles about software they use.
I'm not following your argument. I agree that increased scrutiny does not make the problem ok, but does reveal the problems more quickly. But the only reason those points matter in the "Should I use Zoom?" question is if you're assuming all other products have the same flaws and just haven't been looked at. To which, I'm pretty confident they don't all share these problems, particularly but not limited to the "blatan…
I am not confident of this.
I would assume that anything that isn't actively being sold into the large enterprise market has Zoom-level problems, or worse.
Re: Zoom’s 90-day plan to bolster key privacy and security initiatives
#60I'm still not sure what to think of the whole debacle. Zoom could be a victim of the internet mob justice, where every inevitable misstep is blown out of proportion. Perhaps the mob is helped along by some competing interests. Or Zoom could be yet another tech company with dubious ethics (like U: or F). I doubt they are outright a PLA branch, that would be far too obvious. This isn't just idle musings - I love how Zo…
https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto...