Live data from Hacker News

Zoom’s 90-day plan to bolster key privacy and security initiatives

blog.zoom.us

61–70 of 113 posts

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#61
post #26

I'm still not sure what to think of the whole debacle. Zoom could be a victim of the internet mob justice, where every inevitable misstep is blown out of proportion. Perhaps the mob is helped along by some competing interests. Or Zoom could be yet another tech company with dubious ethics (like U: or F). I doubt they are outright a PLA branch, that would be far too obvious. This isn't just idle musings - I love how Zo…

It's not blown out of proportions. If anything the major securities issues went mostly unnoticed in the noise of the media trying to bank some ads revenues.

There were 2 RCE that would have allowed anybody to easily take over any computer using zoom. The first one last year was wormable, triggered by simply visiting a website with no interaction (like a javascript ad).

Other video conference tools don't have these because they didn't try to provide the same features or work around the OS.

Except for Skype, that still has one samba relay attack left like zoom, that went mostly unnoticed. From my research they had the exact same issue but blocked the RCE part in 2018 CVE-2018-8311 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8311

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#62

Earlier quoted context omitted.

Why do you think it doesn't make a difference? At a minimum, one country shares a mutual defense pact with most of Europe. The other doesn't (to say the least).

Don't feed the troll, this person is a Winnie the Pooh shill.

Can we really just add the phrase “Winnie the Pooh” to any content or thread to make it inaccessible inside the Great Firewall (except for those stare-sponsored groups with special access)?

Seems like an unintentional DoS vector.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#63

Earlier quoted context omitted.

Why is the need for an account a showstopper?

Many students aren't old enough to create their own accounts and getting parents to create accounts and provide credentials is a bureaucratic mess for the schools I volunteer with.

The school needs an education account and students should be able to join meetings hosted through a school account:

> Students under the age of 18 should not go to www.zoom.us to create an account because (i) they should only be joining Zoom meeting sessions as participants (not separate account holders) through the School Subscriber’s account and (ii) minors are not permitted to create an account per Zoom’s Terms of Service. The School Subscriber’s account administrator (e.g., teachers) should securely and confidentially provide meeting information and meeting passwords to the student users to ensure the school can maintain supervision and control over its student users’ meeting experiences. If students have already signed up for individual accounts, Zoom can assist schools in fixing this.

The school should contact their account rep about this. I bet they can fix it quickly.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#64

I showed Alex Stamos information two days ago that Zoom engineers had surreptitiously spied on women around the world and then assembled their webcams into a single dashboard for Zoom engineers to view. The name of this dashboard was p*ssy4all.dashboard-production.ipa.zoom.us. A quick way to prove this is to type this subdomain into securitytrails.com. It lists a dozen different IP addresses this internal product had…

I'm surprised this isn't a bigger story if it can be substantiated.

Can someone explain what the security trails site shows and how this confirms the allegations?

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#65
post #41

Earlier quoted context omitted.

Why do you think it doesn't make a difference? At a minimum, one country shares a mutual defense pact with most of Europe. The other doesn't (to say the least).

After agressive sanctions from US government for EU, the targeted EU travel ban and current presidents rhetoric, I have zero trust in any kind of mutual defense or military assistance coming from US in the time of crisis. Remember, people of Italy are currently being helped by Chinese doctors while US president ignores and belittles the problem. The talks between France and Germany about creating an independent defen…

> If there's one thing I'm sure of is that China won't share their spying data with my own government.

They'll just share it with their allies; Chinese-state hackers, Russia, Iran, and North Korea so you'll have blackhats after you instead of your government.

Out of the frying pan into the fire.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#66
post #25

I showed Alex Stamos information two days ago that Zoom engineers had surreptitiously spied on women around the world and then assembled their webcams into a single dashboard for Zoom engineers to view. The name of this dashboard was p*ssy4all.dashboard-production.ipa.zoom.us. A quick way to prove this is to type this subdomain into securitytrails.com. It lists a dozen different IP addresses this internal product had…

How is that not the biggest scandal around this company, as opposed to intentional or not misinformation about end to end encryption (not that it doesn't count, but for this one, if it's real, the company should be brought up to public scrutiny).

Seriously - I never expected or need e2e in my video conferencing (I like transport encryption fine and always thought the lock meant that).

But this would be a huge issue if true.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#67
post #41

Earlier quoted context omitted.

Why do you think it doesn't make a difference? At a minimum, one country shares a mutual defense pact with most of Europe. The other doesn't (to say the least).

After agressive sanctions from US government for EU, the targeted EU travel ban and current presidents rhetoric, I have zero trust in any kind of mutual defense or military assistance coming from US in the time of crisis. Remember, people of Italy are currently being helped by Chinese doctors while US president ignores and belittles the problem. The talks between France and Germany about creating an independent defen…

I think I'd be the first to admit that NATO has probably outlived it's useful life as a Cold War construction, but there's still a lot of history there. None of that exists with China, and China seems to be using the crisis in Europe as a means to exert its influence abroad (hello 5G rollout). Does Europe really want to trade that history for a new relationship with a country like China where the structure of that relationship is yet unknown?

Perhaps it's better to actually ask some hard hitting questions about fairness between US-EU trade relations (and admittedly since I am an American, it seems a bit unfair that the EU gets to essentially freeload on US defense in the western hemisphere and we get some stiff tariffs in return). So it seems perfectly reasonable, and probably a good thing, that France and Germany are creating an independent defense pact.

>If there's one thing I'm sure of is that China won't share their spying data with my own government ;P

And? Consider for a moment that sharing of this data between defense partners actually provides a useful signal of mutual capabilities and for what's being collected.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#68
post #26

I'm still not sure what to think of the whole debacle. Zoom could be a victim of the internet mob justice, where every inevitable misstep is blown out of proportion. Perhaps the mob is helped along by some competing interests. Or Zoom could be yet another tech company with dubious ethics (like U: or F). I doubt they are outright a PLA branch, that would be far too obvious. This isn't just idle musings - I love how Zo…

It's not blown out of proportions. If anything the major securities issues went mostly unnoticed in the noise of the media trying to bank some ads revenues. There were 2 RCE that would have allowed anybody to easily take over any computer using zoom. The first one last year was wormable, triggered by simply visiting a website with no interaction (like a javascript ad). Other video conference tools don't have these be…

Sketchy package installer to boot https://macpkghallofshame.tumblr.com/post/138612887932/indis...

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#69

Zoom won the proverbial lottery with this pandemic and lost their ticket through greed/laziness. Great companies are always prepared when their big break comes. Zoom is not a great company.

You don't have to be a great company to win in the market. I'd bet that zoom still maintains dominance and manages to con people into believing that they're super secure now guys.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#70

I showed Alex Stamos information two days ago that Zoom engineers had surreptitiously spied on women around the world and then assembled their webcams into a single dashboard for Zoom engineers to view. The name of this dashboard was p*ssy4all.dashboard-production.ipa.zoom.us. A quick way to prove this is to type this subdomain into securitytrails.com. It lists a dozen different IP addresses this internal product had…

pretty bold claim... when you say "showed" do you mean personally or that you reached out to him somehow with no evidence that he received information about this?
Post reply on HN