Live data from Hacker News

Zoom’s 90-day plan to bolster key privacy and security initiatives

blog.zoom.us

71–80 of 113 posts

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#71
and this is why product over security always wins.

there's mob mentality right now, but zoom got a TON of customers, and now is gonna have proof of end-to-end encryption in a couple of months.

boom.

zoom wins.

honestly just don't talk on zoom about something highly secretive such as ... idk... something a government is interested in as that isn't currently secure, other than that, don't sweat it.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#72
post #64

I showed Alex Stamos information two days ago that Zoom engineers had surreptitiously spied on women around the world and then assembled their webcams into a single dashboard for Zoom engineers to view. The name of this dashboard was p*ssy4all.dashboard-production.ipa.zoom.us. A quick way to prove this is to type this subdomain into securitytrails.com. It lists a dozen different IP addresses this internal product had…

I'm surprised this isn't a bigger story if it can be substantiated. Can someone explain what the security trails site shows and how this confirms the allegations?

The presence of this subdomain does not necessarily prove what exactly _was_ behind this subdomain, but SecurityTrails shows that it did in fact exist during the period when Zoom has misconfigured their network and allowed their DNS records to leak from their internal network.

It additionally appears that there are many other obscene domain names that had leaked out, including f*ckmenumb.athena.ipa.zoom.us [1].

The issue of course is that to my knowledge there are no other historical DNS databases that corroborate the existence of this subdomain, it seems only SecurityTrails has this record.

Two additional notes:

1) The fact that calls are not E2E on Zoom makes the presence of this dashboard entirely possible from a purely technical standpoint. 2) Alex Stamos has been hired by Zoom, which I find interesting timing-wise..., perhaps I am missing context.

[1] https://twitter.com/TwelveSecurity/status/124714209506588672... [2] https://twitter.com/zoom_us/status/1247862458187841537

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#74
post #21

They’re in the same bed as China. I don’t trust them for anything now, this to me is just a PR management exercise. They’re still going to give away your data

So...use a US based video conferencing tool? I'm sure there are no backdoors in those!

[flagged]

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#75
post #51

Earlier quoted context omitted.

"CISO" is a pretty standard acronym. People who don't work in cybersecurity or who don't have that background might not recognize it, but it seems like a minor detail.

Sure, it's a minor detail. And yes, you can say the audience for this post are people who work in cybersecurity. But it costs nothing to introduce the acronym, as is usually recommended. Without it you are alienating anyone who doesn't know the term.

Serious question - would you feel the same way about using CEO or CFO without spelling out what they stand for?

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#76

and this is why product over security always wins. there's mob mentality right now, but zoom got a TON of customers, and now is gonna have proof of end-to-end encryption in a couple of months. boom. zoom wins. honestly just don't talk on zoom about something highly secretive such as ... idk... something a government is interested in as that isn't currently secure, other than that, don't sweat it.

They are very unlikely to have end-to-end security in a couple of months, for the same reason few (if any) of their competitors have it: it is really bandwidth intensive to send full-resolution video of every participant to every other participant. So everyone sends low-res for most participants, and at most one high-resolution stream. To do this you have to be able to make low-resolution streams out of the high-resolution one people are sending you (to pass along to others). That means you have to terminate encryption on the server side. Once you have done that you are no longer "end-to-end". This is just the state of things.

This is a valid tradeoff for most things, but the real problem here is that Zoom claimed (and continues to claim) "end-to-end encryption", while not providing it. That is a lie, and people naturally wonder what else you are lying about.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#77
post #26

I'm still not sure what to think of the whole debacle. Zoom could be a victim of the internet mob justice, where every inevitable misstep is blown out of proportion. Perhaps the mob is helped along by some competing interests. Or Zoom could be yet another tech company with dubious ethics (like U: or F). I doubt they are outright a PLA branch, that would be far too obvious. This isn't just idle musings - I love how Zo…

>dubious ethics

Yeah, I think datamining to steal and sell your LinkedIn account counts as dubious ethics. Or claiming to have E2E but actually they don't.

There is a good share of incompetence as well, like the CSP issues.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#79
post #76

and this is why product over security always wins. there's mob mentality right now, but zoom got a TON of customers, and now is gonna have proof of end-to-end encryption in a couple of months. boom. zoom wins. honestly just don't talk on zoom about something highly secretive such as ... idk... something a government is interested in as that isn't currently secure, other than that, don't sweat it.

They are very unlikely to have end-to-end security in a couple of months, for the same reason few (if any) of their competitors have it: it is really bandwidth intensive to send full-resolution video of every participant to every other participant. So everyone sends low-res for most participants, and at most one high-resolution stream. To do this you have to be able to make low-resolution streams out of the high-reso…

You can also send two streams (high and low quality) from each client and make other clients request the right one from the server. Yes, it's slightly more bandwidth than before and now complexity. No, it doesn't require full mesh of connections to be E2E.

Re: Zoom’s 90-day plan to bolster key privacy and security initiatives

#80

Zoom won the proverbial lottery with this pandemic and lost their ticket through greed/laziness. Great companies are always prepared when their big break comes. Zoom is not a great company.

It looks to me like they've still won the lottery.
Post reply on HN