Zoom banned from New York City schools due to privacy and security flaws
fastcompany.com
fastcompany.com
First of all, Zoom has been used in education for a long time. The quote about switching to Teams because it's FERPA-compliant is disingenuous -- Zoom says they are too. [1]
Second, Zoom has been receiving tons of scrutiny recently while e.g. Microsoft Teams hasn't received any. (Nor has Google Meet.)
I'm really not sure how I feel about this. It's been hard enough already on teachers to adopt remote learning, now they're expected to switch platforms after a couple of weeks, presumably mostly because of sensationalistic media reports of "Zoombombing" which a teacher can trivially prevent?
Maybe MS Teams is worse? But MS will, at least, make sure to keep the pedophiles and racists at bay.
Prior to the age of 'zoombombing', frictionless entry to every meeting was a nice feature, and meeting IDs are difficult enough to guess (11 digit number) that entry of uninvited guests basically never happened.
Now that everyone has so much spare time, the worst elements of society are using it to try to harass children. I guess the tragedy of the commons kicks into full swing and we must have passwords going forward.
Slow video? A few random disconnects? These are the kinds of issues that result in second chances. Random men showing up naked in your classfull of kids, or random racists coming in your class to call the black kid an n-word? Yeah, I'm fair certain that results in a, "Thanks, but no thanks. We'll find something else."
I know your argument is the correct one, but it's frustrating to see Zoom caught up in a furore of media-driven controversy.
That’s the the point though: Zoom doesn’t “work well” if you include basic security as a required part of “working.”
Zoom using ECB mode for encryption, and transmitting keys to China says everything. They just don’t care about security at all.
Everyone in the banking industry I work with has blocked or banned Zoom for longer than COVID-19 has been around. Microsoft Teams seems to be the new Default choice, if only because everyone is using office365 already and anything is better than WebEx.
After this my personal impression is that it is just an obtrusive piece od adware, which happens to behave like a rootkit in some parts...
Yawn.
The U.K. even held a cabinet meeting over Zoom.
There’s a lot more than schoolwork taking place on Zoom unfortunately.
The incidence is of course going way up, but it really is overblown on the quantity. The biggest issue are those that post links on twitter or some place public (same issue for Hangouts).
Saying Zoom has a bombing issue feels like saying Linux doesn't get viruses.
The password is the same for everyone. Are you seriously saying that kids won't share the link/password online themselves as pranks? This reduces the risk from "anyone can join" to "anyone with password can join". The waiting rooms helped at least, but the passwords reduce, not stop, zoombombing.
But yes, that was my point - shared passwords don't prevent conference-bombing on any service.
Zoom already announced that the password option will be set by default starting tomorrow.
How often are teachers starting the zoom calls as admins so they have total control over them and can easily disable zoom bombers?
How do we know this is happening more than once every million zoom calls?
The problem is that while Zoom is ok at best, and really pretty terrible for classroom (two kids + my fitness bootcamp are all virtual now), the user experience for everything else is really even worse. So in a time when we really need video chat, viable alternatives are scarce.
There is a lot of angry emotional fanboi-ism around Zoom that is very very odd to see in support of a video conferencing app. Whoever is downvoting comments like this, I'd love to hear your POV.
I feel like recent concerns over zoom are actually quite reasonable. I've never been a zoom hater, my company adopted it with my blessing and we continue to use it although we are now having reasonable, IMO, misgivings and considering alternatives.
But, to be fair, Zoom has already been shown to be lying about e2e encryption. Fool me once...
How many free passes are we going to give these jagoffs?
But, the situation with Zoom is vastly different. It's obvious by now that Zoom took shortcuts and even worse, actively circumvents security features of the OS and actively leverages insecure encryption (e.g ECB mode). There have been plenty of other issues also and more to come as CitizenLab has already pointed out.
So, objectively speaking its okay and I wouldn't blame anyone for seeking alternative solutions.
But honestly, setting up a zoom meeting with a public link is just asking for trouble
But Zoom clearly offers the best videoconferencing product along many dimensions: ease of use, quality of video, etc. Students are already receiving subpar instruction due to the unceremonious transition to remote learning by schools that clearly aren't prepared. So unless the privacy/security issues are actually impacting learning on a large scale, perhaps it makes more sense to stick with the product people are already using.
In this case, some large part of the issue was in deceptive (at best) promotional material. Does that mean people understand messaging, even if they don't understand encryption?
I'm sure many readers here have seen incredible breaches of trust and security, such as Equifax, go almost entirely without punishment. This is an interesting case in the opposite direction. It is worth noting for balance that Zoom does appear to have favoured usability, and successfully so.
And NYC is going to have many students with only a mobile phone plan or similarly bad internet (and a bunch with no internet at all, but that's another discussion). Efficient is important.
One of the large strengths of tools like Zoom over the typical WebRTC-P2P thing is that they can avoid exactly that, and e.g. maintain a stable audio only (or extremely low-quality video) conference for people on slow connections.
That's 4.5Mbps of stable upload required from the presenter. This requires at least ASL2+ and not everyone will be able to reach it. So it's relatively common, but can't really be expected.
>Key management and encryption happens automatically.
That implies that they could do MITM if they chose to do so because of the lack of a way to ensure you are actually talking to who you think you are talking to. If that is true then you still have to trust them and e2ee is in a sense pointless.
So in the end I'm not sure what good will come of this decision, while it will definitely cause some confusion.
It's possible I missed something and that Zoom truly is notably worse than any of the common alternatives. I'm partially posting this in the hopes that anyone can point out whether this is the case.
And yes Zoom is definitely worse than a self hosted OSS solution like Jitsi (or even Jitsi without the self hosting) but we all know that that's not going to happen.
School's have IT. It isn't always competent IT (I speak from experience), but clear instructions from up high can lead it
IT people are hammered right now, nobody has time to futz around with some random oss tool that will further stress overutilized remote infrastructure.
Edit: If I'm honest I'm not even sure how meet.jit.si can function at it's current scale. Especially because I've found no way to send them money.
Sure other solutions might be just as bad but that is hardly and argument against ditching Zoom immediately. If you've missed the many articles about their weirdly bad security you should definitely go read them.
The one truly sensitive issue is the zoombombing, and I haven't been able to figure out whether that's truly a security bug or if zoom is just the biggest attack surface and has some terrible default settings.
At this point, I think it's more than fair to be worried about Zoom's security.