Live data from Hacker News

‘War Dialing’ tool exposes Zoom’s password problems

krebsonsecurity.com

71–80 of 247 posts

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#72
post #66

Earlier quoted context omitted.

Please don't think of this in entropy terms alone. There is a massive usability difference between the two.

I'm not sure I understand your point. The usability of clicking a link stays equal regardless of the amount of digits in the ID. Adding a password reduces the usability.

An important Zoom feature is that you can dial in from a regular cell phone / landline and conference phones. That's one of the selling points of Zoom.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#73
post #37

TLDR: With 17 digits meeting password is not needed at all. If meeting will be 17 numbers it will be the same as to protect 11 length digit number with 6 digit password. So basically that's the trade off. One could say that password is not the same as meeting ID, but usually they both sent in one email/message and lifetime and protection for them is equal. Also it's easier to input one number than 2 different.

Privately issue a certificate from the organizer and don't just have a link anyone can join.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#75
> "KrebsOnSecurity is not naming the companies involved"

This chart suggests that one of the companies they found was an aerospace company: https://krebsonsecurity.com/wp-content/uploads/2020/04/zward...

I wonder if this is related to the news yesterday that SpaceX has banned the use of Zoom.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#76
post #10
post #5

Not a good idea to use 9 to 11 digit long IDs with no password requirement by default; they should have used at least 128-bit random ids, i.e. 21 character long base64-encoded strings.

Yeah but then it sucks for people calling in to have to punch in a 21+ character long meeting ID

I've always preferred conf systems with a call-me-at function better anyway. With most lines, sign in over phone is a horrible waiting game where one missed digit means sitting through instructions for another minute.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#77

Earlier quoted context omitted.

Yeah but this time, it’s an easy as guessing a world leaders zoom meeting, and tricking them into believing something preposterous

Modern Version: "Shall we play a game?" "Love to" "‼To play Global Thermonuclear War, you must first update your flash player. Click here‼️"

An even more modern version:

"Shall we play a game of Global Thermonuclear War?"

"Sure!"

"Updating Steam client... It seems you're connecting from a new device! Please check the 2FA code sent to your email... Downloading more updates... Here are some popups about unrelated games... Please register an account with MS Game Live!... Downloading patches... [error in wopr.dll]"

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#78
post #37

TLDR: With 17 digits meeting password is not needed at all. If meeting will be 17 numbers it will be the same as to protect 11 length digit number with 6 digit password. So basically that's the trade off. One could say that password is not the same as meeting ID, but usually they both sent in one email/message and lifetime and protection for them is equal. Also it's easier to input one number than 2 different.

It seems to me as if having a password could be a useful feature to get additional features for a call. For example, a webinar host could give a password to a select few authorized to use camera/mic during the call, and just the meeting code to all other spectators. I'm not too familiar with zoom, but this feels like a better application than just two-step call joining.

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#79
post #66

Earlier quoted context omitted.

Please don't think of this in entropy terms alone. There is a massive usability difference between the two.

I'm not sure I understand your point. The usability of clicking a link stays equal regardless of the amount of digits in the ID. Adding a password reduces the usability.

> The usability of clicking a link

The situations and use-cases behind meeting-software are such that you can't rely on this.

There are many situations where you want to transcribe the information. For example, dialing in as voice-only with a private phone based on an e-mail on your work-laptop.

Or perhaps a conference room at a client-site where the client-guy has their corporate-approved presentation laptop, but he can't find the e-mail/chat message with it. Meanwhile you've got it up on-screen, but your device is not approved for any kind of internet connection in this part of the labs, and even your phone has no signal. (Yes, I've been there.)

Re: ‘War Dialing’ tool exposes Zoom’s password problems

#80
post #74

I feel a little bit sorry for the Zoom devs. All of a sudden there are a _lot_ of eyes on Zoom. Every design decision and mistake are under a big microscope, while also presumably having to deal with some major scaling.

It's a ~2k person company with a market cap of $34B. So the valuation is $17M per employee.

I don't feel sorry for them.

Also: this crisis is giving them vast amounts of marketing for free.

I'm based in Sweden. I was just vaguely aware of Zoom until a few days ago - now I suddenly hear of them all of the time from Late Night hosts on Youtube.

Post reply on HN