‘War Dialing’ tool exposes Zoom’s password problems
krebsonsecurity.com
krebsonsecurity.com
As a consequence, I suspect Zoom's security is more likely than not to improve going forward... although it will surely take a long while. Security is Capital-H Hard.
Also, I cannot think of any other multi-video-conferencing solution that "just works" and has been as thoroughly stress-tested and attacked by bad actors in the wild at such a large scale. If Zoom does a decent-to-good job fixing all the security issues, it looks likely to continue to dominate its market.
Or they're having productivity problems like every other company right now and are spinning it to seem like they are on top of things. These security issues have been around for years.
Con: After the product was released :)
The "war dialing" issue is a great example. Webex has had the exact same "flaw" for a decade, with the exact same solution - set a meeting password. Other solutions like Google Meet or Skype have the "lobby" approach.
Zoom was founded in 2011 by Eric Yuan, a lead engineer from Cisco Systems and its collaboration business unit WebEx.[1] [1] https://en.wikipedia.org/wiki/Zoom_Video_Communications#Hist...
https://casetext.com/statute/california-codes/california-bus...
Usability is the zoom priority, and the reason why people who already own more secure, no cost, solutions like Teams, Skype or Google Meet buy Zoom.
As with most things, its a trade off.
You should also always have some reasonable rate limit of any sort of API query, if someone is querying rooms at 10qps or more, there's clearly something wrong.
Your memorable phrase is 'correct horse battery staple'.
<copy> <generate new phrase in $LANG>
Its not often that people without a common language have zoom meetings anyway[1] Probably available on a Linux system at /usr/share/dict/american-english
[2] '^[a-z]+$'
[3] log_2(77649^4)
I will add: security and convenience are always polar opposites.
The most successful companies are typically the ones that can get away with being as convenient as possible for the longest.
I’m open to being proven wrong, and as eythian implied, I may in fact be subconsciously cherry-picking times where security and convenience were opposites and missing times where they were not, but even with that awareness no counter examples are coming to mind.
It's not always ideal though. I've organized meetings with 10+ people, want able to attend the meeting and now nobody can join the session.
"it just works" doesn't mean "its a superior product". I use Zoom over hangouts whenever I'm on a call with more than ~3 people, but automatic gcal integration + being fully functional from a browser means that hangouts makes more sense sometimes.
(I also don't have nearly the amount of issues you do with hangouts. The biggest problem for me is how much worse they handle crosstalk, which isn't an issue when there are only a couple of people on a call.
I've never used the web version, but it wouldn't surprise me if it's not the same experience. The video and audio encoding and decoding stuff seems like it just makes more sense as a native app. Given the number of variables that browsers, versions, sandboxing, etc. bring to the equation, I can tell you where I'd spend the majority of my efforts if I were doing video chat: on a great native app. You have a lot more control over that experience, IMHO.
Anyway, your comment reads to me like someone who will never install it, but I would encourage you to at least test out the difference to see why it's become so popular.
Latest Safari/macOS.
They have a lot more ability to ensure it works when it's their own binary. When you're relying on a bunch of browser functions, it's way harder.
The browser version is a last resort.
So people keep saying "it just works" because Zoom has a noticeably high ratio of works compared to almost any other video conferencing software. It does not mean it works 100% of the time flawlessly for every single user ever always and forever.
FWIW, of the hundreds of Zoom calls I've had, many with non-technical people, I have yet to encounter any issues. I cannot say the same for most other video conferencing products I have used. YMMV, take with grain of salt, caveat emptor, etc.
You are saying because they had lax security, now they will have good security.
It is even harder when you try and graft the security on after the fact. Security needs to be a consideration from day 1, not once youve your minimal product. Proper security may steer architecture decisions that may be difficult or impossible which to adapt. This is especially true for internet facing services.
I had a hell of a time bolting on authentication/permission to an internal API (not web based) at a previous employer. By the time I left, we had all users authenticating, but only maybe 20% of the API surface had permissions beyond being authenticated. It was a CRUD API over +300 objects. Yeah, everything was audited, so we couls recover from a malicious or bumbling idiot authenticated user, but the exposure was way to high with people having far more access than their roles needed. It was a mess.
You’re kidding... right?
One kind is missing something or unintended consequences. Making all URLs clickable opens a UNC attack due to some obscure Windows "feature", for example. Or having N digit numbers means they're technically iterable, but this is the same for cellphones, and there are workarounds.
The other kind is security holes caused by explicitly working to bypass security restrictions yourself. Installing a server with webcam permissions that you don't cleanup so reinstallation is easier for you (don't be surprised when other apps start telling it to switch on the webcam), impersonating the system root password dialog (don't act surprised when other apps steal the password from you), claiming end to end encryption without being clear about where and when it's on, and others.
The first is normal security work, the second is sleazy. We all forgive the first, but we shouldn't let sleaziness slide.
Another post about Zoom, another comment how it's the only video conferencing platform in the planet that "just works". You know I find that really hard to believe... not least of all because I personally use other solutions without never having major hiccups at all.
On the one side, maximum ease-of-use is a name or code short enough for someone to say over the phone. "Here, just jump into the videoconferencing meeting 'mikefred' or 'john10' or '39584'". That works particularly well for small meetings where it's immediate obvious if someone else joins and you can stop talking and ask them who they are and kick them out if they shouldn't be there.
On the other hand is long random identifiers in a space large enough they're impossible to guess. If you're joining a meeting from a link then nobody cares, but if you're telling someone over the phone or typing it into the phone it sucks. (And you are very often needing to jump from one form of communication to videoconferencing, where there's no way to "just paste a link" into the initial form.)
There's also no real difference between a short meeting name plus password and a long meeting name, except that passwords tend not to be displayed on screen so it's even harder to find it to tell someone over the phone.
Also there's another big issue in how easy or convenient you make it for people from within your domain/company to join, versus outsiders. Half the company wants to make it harder for outsiders to join (for security), the other half (salespeople) want it to be easier.
The only solution, unfortunately, is educating users to understand the differences. Zoom already has most if not all the necessary options, even modes like "waiting room". But the same options will never work for every meeting. Whoever hosts a meeting needs to understand the options. There's just no substitute.
Clicking a long I'd link takes practically training, and entering a short ID would only require training the salespeople how to generate one (would should only be a few clicks tops).
This way, a conference is secure by default and easy for people to join by link, and is still easily accessable by code for when needed.
There was very real value in the distinction to those who used it, but it proved so irresolvably confusing to the vast majority of users that eventually they pulled the plug and just gave the one Sleep option.
Educating users about technicalities they've probably never thought about is really hard. Doing so without an actual training session, just through interface, verges on impossible. And if Microsoft couldn't convince businesses to train their users, I doubt Zoom can.
A and B are on a phone call. A starts a video meeting. B goes to shortlink.dtmf or opens the app, which starts listening. A clicks "transmit room code" which goes over the existing phone connection. B's client hears the signal, decodes it, and gives them a link to join.
If the only method of operation here were for people to invite others by copy/pasting a URL, and the invitees' only method of joining were to click on that link, then long UUIDs or such would be just fine.
But Zoom lets you dial in audio-only from a regular phone. You simply just cannot use "long random string" as an identifier if you're expecting someone to punch it into a telephone keypad. Even having an 9- to 11-digit meeting code plus say a 6-digit passcode would be a burden for some people, though it's really the only way to do that portion of it right.
Now, one thing I do not cut Zoom any slack for is having an API where you can request validity and status of any meeting ID, without any rate limits placed on it. That's Security 101 right there.
Strong disagree; people can handle 10-digit phone numbers, they can handle an order 10-digit meeting ID.
There is no reason why short meeting codes + 2-3 sec delay before joining + temporarily banning users who enter more than 10 invalid meeting codes in a row can't work.
There are ways to improve the security without putting on the clients shoulders. A 6 digit room code is fine if a person can only "war dial" 10 tries before being banned for an hour or so.
Why not give more "Options"?
For example when generating conference id, provide an option to generate more random digits or hash codes. When installing provide an option to customize everything. Meanwhile provide a fast and fool-proof path for rest of users.
I really don't know that zoom has a lot or much at all, but I do know that the number of viable solutions to this could be taken off the table internally because they probably made tech debt commitments in their architecture during their scale up phase that prevents bolting on obvious fixes. I have a lot of sympathy for their position. They aren't evil or bad, but they could do a massive mea culpa PR coup on the level of the netflix culture deck if they did a case study retrospective about the effect of tech debt on scale at critical moments.
It's also a product management fail, where that lack of transparency on encryption is what a project-manager would pull, where a smarter product manager would have weighed the cost of losing their e2e-crypto compliance market.
I can also see why they have security issues because today, security people are on a much longer tailed skill distribution than they were 10y ago and it's hard to listen to most of us. Getting someone to approach it as, "ok, we get that a 9-digit key is literally your product selling UX advantage, let's see what else we can do" is exceedingly rare. Privacy has massive brand implications. Remember blackberry? They launched a new flagship tablet product while their CEO got into an issue with government surveillance and the story became about their risk in India and Asian markets and not whatever that product was called. Zooms story is becoming about privacy problems too.
PMs need to be smarter about this.
Becoming one of the top names in video conferencing and displacing dozens of established players virtually overnight? Sign me up.
What!? That's small thinking. You could be so many greater things than that if you're willing to compromise peoples security and personal information.
Zoom focused all their early engineering muscle on reliability. When we build new products, we don't have infinite resources to attack every front simultaneously. We have finite resources to prove a concept, and we incur debt in just about every other dimension.
Now that everyone is using them (precisely because of reliability) the emphasis becomes other things - UX, security, etc.
Tech debt is what the 2nd generation of engineers gets to complain about after the 1st gen made the product succesful at something.
My thing is that there are tons of potential ways to mitigate zoombombing, even incrementally, and that they haven't or chose not to indicates it's because there were cost barriers to doing it. It has the tech debt smell, and it's what I've seen in other orgs.
Then there are ones with vs. without user interaction.
Without user interaction:
- rate limit join attempts so that you at minimum need proxies or a botnet to guess room names.
- do a simple entropy measurement of multiple attempts and rate limit anything that exhibits symmetry or monotonicity.
- add a "correct battery horse staple" style key to the url instead of or in addition to the 9 digit pin so the link is not easily guessable, but still has the mnemonic quality for people entering it manually.
- static personal room ID's only work with a passwd/token (not pin) whereas ephemeral ones can be chosen from a much larger search space. (yes, just add entropy)
- free sessions limited to 40mins or whatever should select from a name space large enough it will take a botnet to hit even one ephemeral session in the 40min timeframe.
- separate the invite link from the login link so that session owners can specify that the user needs to click from their email invite so it gets bound to the browser, and you zoom can set a token before redirecting them to the live session.
with user interaction:
- Obvious one would be a user PIN for ephemeral room IDs.
- Next obvious would be to choose a real security protocol and key management scheme (http://www.lsv.fr/Software/spore/index.html)
Rest of user interactive ones is exercise to the reader, as those are all solved problems.
The challenge is that they require keeping logical state at the application layer, which is specifically the kind of complexity you avoid in your scale-up architecture - and it burns you down the road.
Someone call the feds quickly, that sounds like a very serious crime.
Strange and snarky comment for a "Chief Technical Officer". Software constantly evolves, it's a process of continuous refinement.
Zoom's past success may have been partially attributed to "1st gen engineers" hitting the jackpot. Zoom's fate right now rests on the ability of those "2nd generation engineers" to keep the show going.
More likely just a poorly designed system.
Security is always a game of 'staying ahead' - with a totally new userbase context, the security parameters have changed under their feet. So now they need to quickly adapt their product to the new context.
A vastly new usage context is going to create all sorts of stresses.
You mean it wasn't problem before just because it wasn't being actively exploited before? A problem is a problem regardless if is as of yet undiscovered. Or do you mean it wasn't a problem because it wasn't preventing any forward progress on the product?
Instead of thinking that a product has 'some number of bugs, which when fixed, is perfect' - consider that there are maybe 'infinity' problems. In any given context, those problems are likely to cause differing levels of concern, in different ways, and that in different contexts they may be more likely discovered than not.
For example - Mac is generally considered to be a little bit more 'secure' (heavy quotations) than Windows, the party by design, but partly because of the likelihood of attacker exploits being discovered due to limited market share.
That considerably fewer people are attacking you is a legit thing, especially in light of the potential fallout: 3 weeks ago 'Zoom' was not a pop-culture term, a breach may not have made the big news. Now, everyone's talking about Zoom, so there's a problem and Anderson Cooper is talking about in CNN, the fallout is much worse.
In this 'new context,' the calculus has changed and the impetus to fix certain problems a to maybe actually be concerned about FB login will have changed.
Case and point: SpaceX's decision to not use Zoom made international headlines. This is a huge deal. A zillion IT staff around the world are at least going to read that article. 'Software made in China' they'll read. 'Wait, what?' They didn't know that, does it matter? 'My CEO saw it on the news last night and has asked for a security review, whereas we mightn't have done one otherwise' et. al..
Edit: MY CEO has not asked for a review, I'm making a hypothetical situation here I meant to be speaking in another voice.
Mostly all we can do is triage and it mostly works.
But I'm all for a more sound approach.
I generally like the idea of smartcards, or having some physical thing you carry around which is used to authenticate with systems.
I think focusing on "relative usability" is important too. IMO it should be able to increase relative usability AND security.
For instance, I find unlocking my phone and paying with apple pay is easier to use than taking out my wallet and paying with a card. Having my credit card information encrypted on the phone makes it harder for a thief to access, when compared to gaining physical access to the credit card.
I also use a yuibkey to store cryptographic secrets. Generally I leave it plugged into my laptop, so it does not add inconvenience to me in using it. Before I had to type in a long password to decrypt my SSH key. Now it's stored on a YubiKey, protected by a shorter PIN, and requires a physical touch to perform cryptographic operations. By moving cryptographic secrets from a system with a large attack service (the laptop) to a device which requires physical access and has a smaller attack service(the yubikey), I find the system is easier to use, while increasing security.
One could argue a lack of security can lead to a decreases usability. Ex, a system under a successful DoS attack makes the system not very useable. I digress though, as I do not believe this is what you were getting at.
Basically, in both cases (computer/app or dial-in), increasing the number of digits of the meeting ID has very little impact on the users. Forcing a user to enter a password after joining (which is just more digits) does impact the user.
It is a frequent use-case that people join meetings from devices that are not running a calendar application, or the calendar does not have the meeting invite.
For example: conference rooms.
The situations and use-cases behind meeting-software are such that you can't rely on this.
There are many situations where you want to transcribe the information. For example, dialing in as voice-only with a private phone based on an e-mail on your work-laptop.
Or perhaps a conference room at a client-site where the client-guy has their corporate-approved presentation laptop, but he can't find the e-mail/chat message with it. Meanwhile you've got it up on-screen, but your device is not approved for any kind of internet connection in this part of the labs, and even your phone has no signal. (Yes, I've been there.)
Also create dud rooms with prerecorded conversation.
I don't feel sorry for them.
Also: this crisis is giving them vast amounts of marketing for free.
I'm based in Sweden. I was just vaguely aware of Zoom until a few days ago - now I suddenly hear of them all of the time from Late Night hosts on Youtube.
Only on HN could these winners become "victims".
Maybe because the users on here have an unique perspective on developers / development?
This chart suggests that one of the companies they found was an aerospace company: https://krebsonsecurity.com/wp-content/uploads/2020/04/zward...
I wonder if this is related to the news yesterday that SpaceX has banned the use of Zoom.
"Shall we play a game of Global Thermonuclear War?"
"Sure!"
"Updating Steam client... It seems you're connecting from a new device! Please check the 2FA code sent to your email... Downloading more updates... Here are some popups about unrelated games... Please register an account with MS Game Live!... Downloading patches... [error in wopr.dll]"
i think it is even earlier than that:
>Each Zoom conference call is assigned a Meeting ID that consists of 9 to 11 digits.
8 char passwd and 16 digit credit cards came way before 1985.
Never mind, i have committed in memory our daily scrum 9 digit pin code :) Very convenient. And if somebody else were to dial in uninvited into our scrum ... well, it is at their own peril as it carries (especially for a person not hardened by a long tenure at a BigCo) the risk of brain damage, loss of ability to perceive reality as it is, spontaneous suicidal desire, etc.
For those working with current or potential customers remotely, you have to use a solution that is convenient or you don't make money.
Example: tel://18005551212,,<meeting_id>#
I did once put together a hack that would scrape the meeting ID from the Zoom UI and emit the touchtones from my laptop to dial in.
https://gist.github.com/micahbf/91a295016f4472b47acfe317d714...
I may be out of touch with the average biz-guy, but how many people are realistically calling in manually, over traditional phone-lines these days?
Is it really a significant percentage?
Jim from sales who is dialing in from his company's oddball calendar app over Bluetooth on the infotainment system in his rental car probably can't.
Also if you don't want to install the Zoom client, you can just dial in from your cell phone or desk phone.
The same tends to happen with a few colleagues ... Some anecdote.
There was always:
1. someone who was on the road - a traveling consultant or someone in sales
2. a client or potential who called in because of the same, or because they don't sit at a computer all day and/or don't have a headset for their computer.
3. People in a conference room
4. a client who sucks at computers and dials in because they can't figure out how to install the latest version of CiscoGoToZoomMeetingWebEx.exe in IE8 on their macbook.
I have a high quality desk phone on a land line (admittedly, VOIP from FIOS, but not via my computer) and I will fight tooth and nail to keep it.
All that being said, I'm comfortable typing in an arbitrary length password on my phone. All I ask is that it be formatted to make that easy (groups of 3-4 numbers with spaces).
That's even assuming that anti-DOS protection on the phone line is impossible.
In this case, relatively short numeric meeting ids allow users to dial in via plain old phone lines. If my meeting guests had to enter a UUID via their phone keypad, they would probably skip the meeting instead.
Like dialing Facebook even if you're not a Facebook user (https://news.ycombinator.com/item?id=22693792)?
If you want to join the all-hands meetings of a company I used to work for, you only need to go their website and lookup their primary phone number. That's the Zoom meeting ID.
I think "no password" is the bigger issue, because repeated attempts with incorrect passwords can be rate-limited. Zoom should be generating a random 6-digit password for each meeting by default.
There may be use cases for not having any password, but that should be explicitly opt-in and have a warning message to every participant that anyone can join and broadcast in this meeting.
There's never a reason to share the id without the password.
Rate-limiting incorrect password attempts could take a bit longer to implement, but still not a particularly difficult problem to solve.
If you want to keep it private use a password.
we used to do this looking for modems to dial into.
I don't understand why this article exists. It's like a beacon for all the bored skidz now.