Trolls break into meetings on Zoom
businessinsider.com
businessinsider.com
Yes, shared by the Prime Minister, number and all. What a time to be alive.
Edit, because downvotes: government email addresses can be retrieved easily through public records laws, and is done routinely, and can easily be scraped or inferred. I've done both many, many times, and it's trivial.
Or do these guys just post this kind of stuff without even running it by their security folks?
To me, this sounds like a security 101 type issue.
The current UK PM is not the type to ask experts about whether it's a good idea, anyway.
https://www.washingtonpost.com/world/europe/boris-johnson-co...
> Johnson, on his doctor’s recommendation, has withdrawn into his chambers for seven days and will forgo all public appearances and in-person group meetings. He will have his food left at the door to his apartment, his aides said.
> “He’s self-isolating in his flat,” said his official spokesman.
That without a doubt all changed many times and somewhat supprised they are using Zoom, and would of thought at least would of contracted to run their own private server connected via VPN. Very supprised and when American politicians all loved their blackberry's, they had their own dedicated servers they controlled access to, supplied by RIM.
But the DOH and all the other government departments are entities unto themselves, and I'm not that up on anything the last couple of decades, but suspect that there isn't any common solution to enable what they need to do for remote working in isolation. I'm sure much will change after this. Also fairly sure GCHQ probably bashing their heads on the table.
But I can see how they got to where they are, knowing aspects of government workings and departmental fencing, still - does kinda make you go WTF still.
Not nearly hard enough. Not even close to hard enough. They need help with that, possibly with heavy machinery.
Not smacking their heads into the table nearly hard enough. Not even close.
Literally copying the literal Stasi approach to spying (not the rest, just spying) would simultaneously improve the quality of the data and reduce the negative side effects relative to the UK’s Investigatory Powers Act 2016.
The macho pose that comes out everytime someone suggests they should be subject to, you know, the law and behave better than Stalin's henchmen is very worrying.
So who is the politician who will is effective enough to provide true oversight and rein them in when required.
Name that politician. Any party.
Do you see the problem now?
Yes see, this is why almost nobody in the general population takes opinions like yours at all seriously.
Core parts of GCHQ might love the potential honey pot. But their offshoot NCSC [1] will be table-flipping big time.
* [1] https://www.ncsc.gov.uk/
I suspect Zoom just happens to be the choice this particular group has settled on. While across government people have been scrabbling to just make something work now that security's previous modus operandi is being trumped by the need to let people work from home.
Government even more than the private sector have been slow to allow for home working. I'm hopeful this will change that.
I think France is also funding/developing Matrix.
There's also EU Public License (EUPL). One notable example of software that uses it is Pi-hole.
One more interesting thing I can think of is Joinup, whose idea is to share solutions between administrations in the EU: https://joinup.ec.europa.eu/
If a government anointed any given handful of OS organizations as preferred benefactors of donations, I'd expect grifters to infiltrate those organizations and parasitically siphon off the funds one way or another.
Incentives matter. Government incentives are to be popular, or attract the support of other people who are popular or influential. Being efficient or effective is only a small part of that. I don't know that there's a good solution to the incentive problem.
I’d expect companies like Raytheon, Cerner, Lockheed Martin, Boeing, and HPE/CSC/DXC to win a supermajority of those contracts.
Please check https://joinup.ec.europa.eu/collection/eu-fossa-2/news/how-c...
If the EU wants an open-source conferencing solution they have to do it in-house (whether from scratch or fork an existing solution) and treat it like a business with a clear objective and actual employees (instead of benevolent devs donating their time & effort) including positions which open source projects often deem unnecessary like UI & UX design, and so on.
https://support.zoom.us/hc/en-us/articles/201363093-Deployin...
Basically it's doable, but if you can prevent people complaining about the fans taking off and the CPU usage... why would you risk it?
Zoom automatically switches between quality levels based on your connection speed, who's talking and the size of the viewport. 720p would look fairly rough when fullscreened on most non-mobile displays, but it's orders of magnitude more than necessary when viewed as a thumbnail on a mobile device. Making multi-user video work in a mostly seamless fashion is a surprisingly hard problem.
Using a single stream would substantially degrade the experience, which may be a worthwhile tradeoff for high-security environments but certainly wouldn't be a worthwhile tradeoff for most users.
I may be spoiled with a good real 50/10 Mbit connection but for me in 2020 720p is the bare minimum. Expecially when screen sharing.
(No idea how widespread encoder/decoder support is compared to vanilla h264 though)
I’ve noticed over the years that FaceTime is much more likely than other video chat software to drop the video connection and move to audio only in case the connection is unstable whereas most others will hitch and lag for 30 seconds before looking into it, so maybe they got around it by only shipping the video in one or two resolutions?
How many participants can you have in a FaceTime group call?
I have also noticed that FaceTime drops the video much more often that other software.
> HIPAA/PIPEDA plans start at $$200 per month per account, which comes with 10 hosts.
Apple's FaceTime is not HIPAA compliant because they haven't filed the paperwork.[1]
(Obviously, there are a lot more steps to it than signing a Business Associate agreement, but I would bet FaceTime is probably a little more secure than Zoom)
1. Go to zoom.com 2. Click "Join a meeting" 3. Enter meeting id and click Join 4. Ignore the automatic app download 5. Go back 6. Click "Join a meeting" again 7. Enter meeting id and click Join again 8. Ignore the app download again 9. Click at "If nothing prompts, click here" 10. Click "Join from your browser" 11. Agree to terms of service 12. Enter password and name, click Join
Yes, it actually requires you go back and try again at step 5. What dark pattern?
https://support.microsoft.com/en-us/office/find-and-replace-...
Ah, the guy at the top left.
Stage 1: This company you probably hadn't heard of before is blowing up / changing the world!
Stage 2 (current stage): Actually it turns out this company has some unexpected problems!
Stage 3: Actually this company is actively contributing to society's One Big Problem!
Stage 4: Actually here is why Zoom actually isn't as bad as everyone thinks!
Stage 5: This OTHER company you probably hadn't heard of before is blowing up / changing the world!
Honestly in my experience, there's no real benefit when compared with Skype, Hangouts, or Discord except for the frequently mentioned large 50 person+ video streaming.
The things that needs to work for a video call is: The network must be reasonably reliable and not overloaded. The camera must be configured and not privacy blocked. The correct recording device must be used, it must be recording (opportunity for both user error and OS issues here). If hardware codes are used (a requirement on lower end devices) it must support low enough bitrates, must have the right options.
Typically all these things are slightly different between different devices and operating systems. It's typically easy to build a proof of concept with great quality and reliable connections between two given devices over a given network. It's super hard to make a product that is reliable enough that millions of users only rarely run into issues.
To be competitive in videoconferencing these days, you need:
* Low latency, so people don't talk over each other
* Video and audio compression that doesn't get confused by dropped packets.
* Setup so easy first-time users won't be late to their video job interview.
* Group calls for 10+ people
* HD quality
* Adaptive bitrates, for users on different speed links
* Skip-free audio even if a user's link goes from uncongested to heavily congested.
* Reliable support for every webcam and USB headset on the market, and hot-plugging them during the call, and changing OS permissions during the call.
* Reliable support for unreliable bluetooth headsets and unreliable bluetooth dongles.
* Echo cancellation that works with every device and room configuration going. Including devices that have their own built-in echo cancellation.
* Audio that's clear even in the presence of background noise, and different people at different distances from the microphone.
* Users behind every type of misconfigured firewall you can imagine.
* Roaming between different Wifi access points, and between wifi and cell data while on a call (including links with no connectivity sometimes)
* Never (or almost never) forcing a user to update their software at the moment they're trying to join an important meeting or job interview.
* Update support (or long-term compatibility) for users who don't have administrator rights.
* Graceful recovery if the user sleeps then resumes their device.
* Screen sharing that retains good readability, even if a user has unwisely made the text on their presentation a bit small.
* Screen sharing of Youtube videos without making them blurry or choppy, even if they're embedded in presentations.
* CPU and battery efficiency.
* Free of charge
* All the above on iOS, Android, Windows, Mac, Linux and WebRTC.
It seems like, in the current use case, this one isn't as important? Institutions would pay for something that does everything else really well. Source: All the paid accounts my institution shelled out for on Zoom in our transition to remote work. So I guess n=1.
But Skype, Discord, Google Hangouts, Facetime and Whatsapp all have a generous free tier. I haven't tried Zoom or Webex but it looks like they do too.
This is not to say it is easy at all, of course; there a thousand things to do to implement it, but I think other fields face similar constraints, like videogame engines and distributed simulations.
"All Skype-to-Skype voice, video, file transfers and instant messages are encrypted"
https://support.skype.com/en/faq/FA31/does-skype-use-encrypt...
https://support.skype.com/en/faq/FA34824/what-are-skype-priv...
The others don't work, are Microsoft UI dumpster fires (Skype), or consume vast amounts of CPU (anything WebRTC for some reason).
There seems to be a law that states that all messenger apps must be bloated slow junk and must accumulate cruft over time until they turn to mush.
They use WebRTC data channels, but nothing else. I'd speculate that this is the reason why they try to push people into using the desktop client.
Why did no one else crack this issue? Google has some smart people and so does MSFT. Perhaps just lack of caring?
I don't get it.
They're probably not huge revenue drivers (if at all). Why would they be a priority for either of those companies? And I can't imagine they're particularly inspiring projects to work on, which can be a self-reinforcing cycle if the best people don't want to work on them.
Cisco didn’t fully understand the opportunity he saw to reduce the amount of friction needed to use most video conferencing (VC) software tools, including the tools by Cisco, which is understandable since Cisco was afraid they might cannibalize sales in their VC hardware business.
2. Related to the above, I have rarely, if ever, had a problem with Zoom quality.
3. The onboarding for new users (basically just share a link) is dead simple. Zoom realized that the install process was a significant barrier and did more than anyone else to lower that barrier (of course, with lots of security/privacy issues to boot, but your average Joe isn't aware of those).
4. A smaller factor but perhaps a bigger one for people using Zoom for personal reasons (e.g. teenagers and college kids) are the 'fun' features like virtual backgrounds.
Also gallery view + image/whatever recognition = ad tech heaven.
Yes. By installing a local web server on every users PC, which was prone to remote execution exploits.
They really don’t give a shit about security and actively try to subvert every security measure put in place by browser and OS-vendors.
Why anyone would trust them with anything is beyond me.
Massive factor here. You can use it and it mostly works extremely well. Much better than almost anything else, including the previously beloved Google Hangouts. In fairness to Microsoft, Teams is probably up there for quality nowadays too, but does lack a good gallery feature.
Compare this with WebEx. I can only assume Cisco are gradually winding it down to EOL because I haven't been on a WebEx call that was anything other than an absolute shitshow since around 2014. Even before this it was really just the best of the worst.
> 3. The onboarding for new users (basically just share a link) is dead simple. Zoom realized that the install process was a significant barrier and did more than anyone else to lower that barrier (of course, with lots of security/privacy issues to boot, but your average Joe isn't aware of those).
Again, agree. Zoom "just works"(TM) for most people, most of the time. And for most people, most of the time, that outweighs any security concerns.
It frustrates me that a certain segment of IT security professionals do not understand this. If you're one of these people, you need to realise that security is necessary but not sufficient. Security is a minimum requirement, but it is not even close to the bare minimum.
Your product actually needs to be good within the context of what users are trying to achieve with it. It needs to do exactly what it's supposed to without drama and fuss. The product is the means, not the end and so, by implication, is the security product.
Human nature is generally to choose things that reduce friction over those that add it, so find a way to build a product that is both secure and gets out of the way.
I really don't get why Jitsi hasn't taken over the world yet, given that it's even simpler: just share the link, and the receiver doesn't even have to install anything.
(Also, doesn't the gallery view exist in every major videoconf platform? I've seen it in at least Jitsi, Whereby and Gotomeeting... And Zoom's browser mode (which is less accessible than Jitsi's) doesn't even support it.)
It is easy
It just works
It works cross platform (why the hell is this such an issue!)
Quality is good
You can record meetings
The Uni tried a different software before Zoom (forgot the name but it started with a K, from a company I never heard of before). And it was VERY GOOD but the video was choppy.
Zoom isn't 10x better, it's just enough though.
known zoom for a while... the "it just works" and "it has better quality" comments are very surprising to me and got me skeptical. are skype, slack, gotomeeting, hangouts, meet, webex, &c. all really crashing on people now? in a huge conspiracy?
things i thought could be the real reason: novelty (for some/most people), popularity (someone online famous/influencer mentioned it), shadow marketing, luck.
but wikipedia told me is actually going on: schools have decided that zoom will be the de-facto remote schooling platform. a bunch of young people appropriated the platform it seems.
hope that helps. the superiority talk is just that. but now they are in a good position to become better than any other video conferencing software.
Sometimes it's call quality, sometimes it's stability, sometimes it's usability, sometimes it's features.
It's astonishing how so much low-quality software gets distributed, but: yes. Hangouts and Slack are a pain to get everyone logged in / invited to. Everything else on your list just breaks a lot.
> but wikipedia told me is actually going on: schools have decided that zoom will be the de-facto remote schooling platform. a bunch of young people appropriated the platform it seems.
That's a non-explanation. Zoom is popular with young people, sure. Why? The same reason it's popular with everyone else, because it works better.
We switched to Zoom from Skype and Webex simply because it was cheaper.
Maybe we did something wrong, though, and missed features in Hangouts and Skype. If that is the case I'd be very happy if someone could point it out to me. (Our whole university is using Google Hangouts right now, because our administration doesn't want to pay for additional Zoom subscriptions.)
With the lock down, more online classes, more people seeing the Zoom logo?
Fortunately, we have really enlightened people among us who point that out.
Every time.
Normally I'd wave this off as a childish prank, but both the URL and loading screen prominently indicated the name of a major medical school, and the contents of the presentation were proteins and chemical structures. Bombing this meeting in particular seems to be in especially bad taste during a pandemic.
Either that... or it's a way to get high profile attention to blatant security issues in a commonly used business meeting tool where sometimes sensitive information is shared.
However, if we don't secure our systems, what do we expect? If there were no bad-actors in the world, people like tptacek would be out of work. What a glorious world it would be, no need for locked doors, fences, passwords, pin codes and more - but that's not the world we live in.
Instead, we're in a world where Zoom has laughable security for barging into potentially sensitive meetings being conducted by businesses and world leaders[1].
If it takes a few meetings getting trolled for Zoom to finally take action, I'm not going to feel much sympathy. Just be glad trolling is all they're doing right now.
So, while I'm sorry your meeting got trolled, it will just continue to happen until you get mad at the people that made it possible - Zoom.
[1] https://mobile.twitter.com/BorisJohnson/status/1244985949534...
No clue what everyone else is saying.
Trolling is gods way of teaching basic opsec to idiots.
Seriously, if people can troll, they'll troll. It doesn't matter how offended someone else is.
Make it impossible to troll, and guess what happens? No trolls. It's really that simple.
And with systems that apparently world leaders are conducting business with... It really ought to be impossible to troll!
So while it might feel good to get mad at the trolls, you're misdirecting from the actual problem here:
People can dial into unprotected meetings and listen into sensitive conversations that are assumed to be private!
That's scary. Really scary. And we're pretty darn lucky it's just trolling for laughs so far.
My sarcasm calibration is a bit off lately, you surely didn't mean this seriously (I mean, you don't really think this won't happen again)?
For what it's worth, it likely wasn't targeted. My understanding is that the search space is so short that you can just cycle through it until you find something.
Of course different times require different actions but I think that some challenges remain for the _formal_ part of it.
To prevent unwanted people from joining, the host simply has to turn on the waiting room feature -- where people who have dialed in have to be explicitly accepted by the host, which can be done individually or en masse.
Overall I'd say the system works pretty well.
It would be similar to how a credit card number and CCV code are functionally the same as one longer number, except that you don’t go writing the CCV code alongside the credit card number, and that keeps it more secret.
Still not as frictionless as “anyone with the number can join,” but if this continues to be a problem it might be worth doing.
https://support.zoom.us/hc/en-us/articles/360033559832-Meeti...
All in all, Zoom has done a lot of things right, given the extremely challenging competitive environment they're in.
I don't like to join company calls on an anon or personal account but Zoom makes absolutely zero effort to identify who you are and even if you're welcome. Most of the time I drop out and re-join under my corporate account. I cannot force other people to do the same, and their settings UI is insane.
By all accounts, Zoom deserves this intense scrutiny and I hope they take it seriously. All I see them trying to do is get their software on as many machines as possible.
I hope Eric is learning something from this situation and will pay more attention in the future, every business gets those moments, maybe not that publicly.
There isn't even any monetary benefit. Who the heck thinks this is funny?
I know it's largely parts of the 4chan crowd. But who are those boards? Why are the people who go there so nuts?
Do you ever wonder if you've unknowingly met these people in real life? Chances are we all have, right? How do they manage to be so terrible and then go on with their lives?
If you're a long-time Reddit user, you probably already know this, but here goes: He was eventually exposed by a journalist. Surprisingly, he is actually a pretty normal middle-aged man. He worked as a programmer (and was immediately fired when the news aired). He has a disabled wife for whom he is the sole financial support. If I remember correctly, he has adult children, who were aware of what he did on Reddit and had usernames that referenced their relationship with him. Apparently, he used his time on Reddit as a way to relieve stress, or something like that.
I'm not entirely certain what motivates people to act like that online when they're relatively normal offline, but it seems to be a somewhat common occurrence.
Anonymity probably?
I'm a pretty normal dude offline, your average American programmer. On reddit I'm in all socialist/communist subreddits talking about revolution 24/7. Intellectually I agree with intersectional Marxism, but I don't feel comfortable enough to discuss these in real life, and I don't care enough to (or am too lazy to) act upon these ideas in real life. So, when I go to reddit I become "a different person", not because I try to be this person, but the comfort of anonymity allows me to express my ideas easier.
There is trolling-as-prank which is inclusive of others in the forum where it takes place (although it may involve mockery of individuals) and raiding behavior, which is designed to damage the forum itself. The latter is area denial which is meant to gain leverage over a platform and (ideally) to take it over. This originated in rivalries (friendly not-so-friendly) between bulletin- and image-board operators, but has since been weaponized to quasi-political ends.
As far as I can tell, somewhere over the last 15 years, people began to confuse "the internet" with "real life". It's important to know that hosting a public space on the internet is not the same as hosting a public space in real life.
I don't think this is even a so terrible example of trolling. A well run AA group could use it as a teachable moment to reinforce their message. It's certainly memorable.
And the people trolling are probably all hanging out on discord, making friends, having the modern equivalent of old-fashioned fun. Just a bunch of bored people seeing what they can get away with to entertain themselves on the internet.
When I was a kid, the neighborhood boys got caught throwing rocks at cars just because they wanted to see what would happen. They also stuck firecrackers in things. Once some teenagers took a baseball bat to every mailbox on the street while hanging out of a car window. Trolling an AA zoom meeting is significantly less bad than any of that.
I would argue that trolling is actually a bit higher-minded than previous generations of trouble-making. When you're restricted to operating only online, outside of physical space, you have to be a bit more clever in your trouble-making. Clever probing of the world to see how it responds is fun, especially with the constraint of "must be done entirely online". It's also largely harmless, because nobody can get physically hurt, and it leads to better safeguards in our online systems.
If you view trolling in that way, I think it's really a sign that our culture is advancing. If a successful troll is possible, it indicates some kind of weakness that needs to be patched. You can't stop the trolls, so you might as well extract what value you can from their work. Also what and how they troll is a sign of the times. The Trump presidency was fairly predictable if you watched the steady increase in what we'd now call "alt-right" ideology on 4chan. As goes /b/, so goes mainstream culture. I guess, in a way, you could say that trolling is a art.
> you have to be a bit more clever in your trouble-making
Or you know, once you're not 14 years old anymore you can reassess your life and decide it's not ok to DDOS hospitals during an epidemic, or call the swat on someone who beat you in a video game.
Trolling AA isn't criminal, it's just stupid. The only impact it's going to have is that AA organizers will learn how to run an online meeting with a little more security.
I mean, in my darker, misanthropic side of my personality I think it would be pretty funny if someone Zoom-bombed my really, REALLY boring monthly electronic Database system update training I have to go to on Thursday morning at 7am for 90 minutes, and like... played videos of puppies or something. But I get a chuckle out of that thought and drink my coffee and pay attention to the training like I always do.
Who is this 4chan anyway?
There are literally people on the internet who claim white supremacy, and that the Earth is flat.
There certainly exists similar scum/ignorant idiots who would find this funny.
The progression is "People start doing a ton of things over an insecure system" -> "trolls start harassing people". This isn't some sort of reaction to anything about Zoom the company or the software.
I would be curious to see an article about why this happened? Is Zoom better than their countless competitors? They all seem pretty similar in my experience so why is it Zoom that is blowing up because of this and not any of the other companies?
I do think WebEx does some things better than Zoom (I like to share 2-3 apps - for Zoom it's 1 at a time or entire desktop) but Zoom has led to better client adoption for us.
But like, if we're being honest, it probably has a lot to do with how easy it is to start a Zoom call and invite people. You can host a 40 minute meeting for free. No one needs to sign up anywhere. It's super easy to install but also works in the browser if you can't install it. Computer on the fritz? You can call in from your phone. And yeah, they've also used some dirty tricks to make it as easy as possible, and some of those measures (like the auto-reinstall thing) were probably unnecessary. But they've clearly focused on being super super easy to start using, and when their moment came they were primed to seize it.
Last weekend my family had a "month's mind mass" in memory of my grandfather who passed a month ago. We were able to get dozens of people, many of them very non-technical, into the call, and we started basically on time. There was no "it doesn't work on my old phone" or "you mean I have to sign up for gmail?" or "whoops I couldn't get in because I signed in with my work email". That's why Zoom is winning the game right now.
And even then the browser interface is hidden behind multiple attempts to make you install and use their client instead.
Zoom is better than the alternatives on most verticals and has good PR. In fact, justified privacy concerns aside, it's hands down the best vid. conference app I've ever used.
I suspect it seems that way because Zoom was already more aggressively seeking media spotlight as a growth startup, and experiencing more rapid growth in terms of multiples because it had a much smaller install base to start with than established competitors. Also, Zoom is the center of it's company’s business whereas Slack and Webex are just part of a large stable for their respective firms.
But I have the feeling that this is difficult in pratice to use for a AA meeting. I'm actually lucky enough to not to have the need to participate to such a meeting, but from what I understand from it, the anonymous part is important, as well as the possibility for newcomers to participate. I doubt for these reasons that AA meeting groups have a list of participant clearly identified, to whom they can send a password protected link, or that they could use such a list to check that people are someone part of the group.
Unfortunately, I'm not sure that this kind of problem can be fixed (technologicaly. On the non-technology side, we could hope for a world without asshole, but that's only a dream)
(probably the wrong thing to write on HN since this place is uh not known for its sense of humor)
Someone sent me a meeting URL and I clicked it, to see if everything was right.
Little did I know that people just get one Zoom URL for ALL of their meetings.
to the people of zoom, thank you for making this time in our life a lot more pleasurable.
https://en.wikipedia.org/wiki/The_IT_Crowd
It is of course a comedy. The Brits in IT that I've met can compete with anyone on the planet.
Why on earth do you feel like this is an appropriate response to some people joining random zoom meetings?
I must say, this was pretty well done.