Zoom private chat text between attendees is actually public
twitter.com
twitter.com
Edit: In case it is removed this was the original headline "Zoom private chat text between attendees is actually public"
From the zoom docs.
"If you save the chat locally to your computer, it will save any chats that you can see-- those sent directly to you and those sent to everyone in the meeting or webinar.
If you save the chat to the cloud, it will only save chats that were sent to everyone and messages sent while you were cloud recording."
This is TOTALLY different than all private chat text is public. 100% false. Private chat text is available to the folks who were participants in the private chat. That would be a much more accurate headline.
Now if the recipient of a chat first downloads it to their computer (zoom auto-scrubs if you upload to cloud) and THEN uploads it to the cloud - then whoever has access to it can see it. But this takes a number of steps. Download your chat and then publish your chat publicly. The headline is completely wrong.
They need clearer warnings this will happen, or a design which clearly separates the two info-streams, of differing sensitivity, into separate download steps & filenames.
In a lot of businesses this really is not an issue. Many businesses don't want a lot of bob mockery in private chat. Webinars people want these questions to go over with a supervisor (common question analysis etc). Hosts can set appropriate controls (public chat only / host only etc).
I hope zoom continues to cater to people trying to get work done - which they seem to be, and not this hyper paranoid, totally misleading title crowd.
The solution on hacker news seems to always be to add lots of new steps, warnings, device authentications, encryption keys, block the host from doing this or that etc. I'm already tired to the endless cookie acceptance popups on the public web.
> In a lot of businesses this really is not an issue.
I don't think anyone cares about the business in this situation. Individual privacy and freedoms are more important than shareholder value and micromanager snooping. When you force everyone to engage with their coworkers online, you need to find a way to preserve basic human rights -- like two individuals having a private conversation. Tech that obfuscates that, or exposes the contents of private conversations, should be called out for doing so.
Yes, we want business discussions to be open. But at the same time you have to remember that it's humans that conduct the business (as little as VCs may like that, because they're so hard to control and pacify), and that those humans have human needs and emotions, and will have private conversations wherever conversations can be had.
It is conferencing -> generally public / group meetings.
The permissions are VERY loose by default - anyone can join your personal meeting room if you don't put a password based on a simple set of digits after a URL. People can join with NO account, no login. My own experience trying to do a lot more lockdown - people don't like it, they WANT this free and open approach.
If you want private conversations - lots of apps out there support that. But many apps targeting business have a corporate / compliance / discovery API option. For example, slack is very popular, and admins can get corporate export turned on or discovery API which allows exports of your PRIVATE direct messaging conversations by the company. So if you think zoom letting a user see their OWN messages is bad, slack (often a popular programmer system) let's admins get everything you ever typed.
The one I hate the most are the SSL middleware boxes and decrypt everything.
Somewhat ironic for someone taking so much care to maintain an anonymous 'thoraway' account to give so little weight to other users' desire for robust privacy, that doesn't collapse via confusing docs/interfaces & transient accidents.
If you think privacy is enhanced by all these cookie warnings (when YOU can control / clear etc your cookies) you are probably mistaken.
If Zoom goes to full E2E encrypted chat (this means on-boarding is FAR more complicated than clicking a totally simple URL with some digits) they will likely loose a lot of their market. If they go to E2E encrypted chat and block users from downloading their own chat, even more market share lost.
But the issue here is not your nonsensical digression into cookie warnings. It is: Zoom's docs & UI are confusing ordinary, mass users into inadvertently revealing private chats. Zoom should fix that.
I believe a simple baseline fix would be: offer 2 downloads, one clearly marked/named as "shared transcript - what all participants saw", another clearly marked/named as "personal transcript - what you saw".
[1] https://support.zoom.us/hc/en-us/articles/115004792763-Savin...
Yes, you want to account for people's actual behavior. This isn't going to rise above the level of "minor" if viewed from a security perspective, because it's a self-only attack -- nobody gets any powers they didn't already have, and Alice is hurting herself, not someone else.
(She might inadvertently hurt Carl, if Carl was sending her messages making fun of Bob, but she was allowed to do that anyway.)
A usability or operational perspective might object to the behavior here more strongly.
It's not about hurting people's feelings, it's about information leakage. And to cut off anyone that says passwords shouldn't be shared in a private chat, that's irrelevant. Good infosec security practices in one place do not preclude criticism of bad practices elsewhere. Security is about layers or protection, so any layer with problems should be noted. If that layer happens to be a third party application that mixes private and public channels in some instances and if there isn't warning as to this happening, it deserves to be called out.
Another way to look at it is that any minor information leakage can have a major impact if the information leaked is very important.
It's not irrelevant. There are phone apps with no other purpose than to publicize your location. If you should happen to be a fugitive, using such an app would be a bad move. Does that make the privacy leak in the app a security problem? No, how could it? If you don't want your location publicized, the answer isn't to remove the only feature from a location-sharing app so you can run NOPs in peace. It's to stop using the app.
Your misuse of a feature that performs exactly as advertised can't justify calling that feature a security problem. The people responsible for the feature don't know how you're using it. The use pattern is the security problem, and it needs to be addressed by people who (1) know what it is, and/or (2) are responsible for it. Zoom fulfills neither criterion.
That's clearly not the case here. It's irrelevant in that in the context of this specific discussion, which this application, which is marketed towards enterprises as secure, an argument that a sharing of private information accidentally though bad UI is the problem of the user for putting private information in that private channel is irrelevant.
> Your misuse of a feature that performs exactly as advertised can't justify calling that feature a security problem.
That depends on how we classify "exactly as advertised". If the overall claims of the product as to being secure are easily and often circumvented on accident through poor UI, then that may be a security or privacy problem. If that place it's advertised is not something that most users will encounter during normal usage, then how it's advertised is of little consequence.
One extreme end of this would be something hidden deep in the EULA or privacy policy that advertised how this works, and the other extreme end would be an alert every time you use it that explains this. I think one is obviously a problem (to the point that it looks purposeful), and the other obviously isn't, but the only difference between them is where the information is placed or how assured you can be that the user has encountered and hopefully understood it. I think this clearly indicates that the problem is not whether certain behavior is advertised, but how aware users are made of how the application functions.
I was under the mistaken impression that this would include one-on-one chats between the _non-host_ members of the meeting.
According to my reading, she will by default include everything she typed and any messages sent to her. That's a horrible default if true.
A fair number of use cases benefit from being able to see private chats - webinar replays it's nice to see the questions folks are asking, but usually host in a large webinar doesn't want to chat spam everyone by allowing 300 people to post to everyone. So they can set it host only, download, then edit and include to whomever cares what questions are getting asked.
> IMPORTANT: I can only find evidence that Zoom by default creates a log of private messages WITH THE HOST. This happens regardless of whether the session is recorded. It isn't a good design decision from a privacy perspective. But it's not the same as recording all* messages.*
https://twitter.com/rcalo/status/1244404664260411392
It's not super clear what a "host" is in Zoom parlance. Is it the meeting creator, or do they mean the host as in the person you were chatting with?
Hosts are privileged to have control over the meeting, e.g. can toggle recording or shut it down (so everyone gets disconnected and sees "was ended by host" or something like that), etc.