Zoombombing is a crime, not a prank, prosecutors warn
arstechnica.com
arstechnica.com
I tolerate that logic in the real life. Ofc the people who enter are bad, but there will always be bad people, so you're to blame for not protecting against them.
Rooms are password-protected by default. If it must be public, enable the waiting room feature (though there are currently undisclosed zero-day's for it).
We’re a community of mostly professional tech workers, and even we need shit to downvote and flag stuff.
Its also the same kind of excuses heard when a woman was dressing well and gets raped. Then the refrain is "she was asking for it", or "she deserved it with the way she dressed".
Notice that if a front door is unlocked and someone goes inside, its still trespassing. Just because its easier to commit a crime doesnt make the thing not a crime.
(Please note, that I'm making this argument in good faith. I'm sure many here have digitally trespassed on others' computer systems without permission. It's not "trolling"; its a straight-up violation of the CFAA.)
I would have a reasonable amount of privacy if I used a random GUID to provide a hidden link. In that implementation, the link is a username-less password. That's how Craigslist, Pastebin, and email resets for all sorts of services work.
And that too goes to the heart of passwords are inherently obfuscation. But that's a discussion for another time.
Are you high? This is in an entirely different ballpark. You are not seriously equating some trolling and digital damage with the violation of a human body, are you?
Obviously if there are serious consequences there needs to be a deterrant, but this is some trolling on the internet, not rape.
We are "victim blaming" people for severe neglect all the time. Look at Facebook and other services if user data is stolen. It's called neglect or do you say "oh the hacker shouldn't have stolen the data, not Facebook's fault".
Really now? That's uncalled for.
> You are not seriously equating some trolling and digital damage with the violation of a human body, are you?
I am not equating digital trespass with rape. However I am comparing that victim blaming has been used to deflect both, and in the rape, victim blaming is finally rejected as any sort of valid response.
> Obviously if there are serious consequences there needs to be a deterrant, but this is some trolling on the internet, not rape.
That makes trolling sound awfully close to "locker-room talk".
> We are "victim blaming" people for severe neglect all the time. Look at Facebook and other services if user data is stolen. It's called neglect or do you say "oh the hacker shouldn't have stolen the data, not Facebook's fault".
You use the word "neglect". Keep in mind that neglect of a dependent is a crime (indiana https://www.in.gov/meth/files/IC_35-46-1-4_Neglect_of_a_Depe... ). And that definition of neglect doesn't match up with yours in much of any ways. However it is neglect of a dependent if school admins allow sex crimes to happen against public school students in their stead....
And FB is its own problem. Please stop trying to move goalposts.
edit: couple of sources:
AU: https://www.examiner.com.au/story/442855/police-warning-over...
DE: https://www.augsburger-allgemeine.de/panorama/Ein-offenes-Au...
How would they even catch you? Do you live somewhere where the police go door-to-door checking locks? Because that's terrifying...
Oh, and none of this contradicts the main point, which is that nothing in those articles suggests that robbing an unlocked car is legal.
EDIT: though interestingly, at least in some municipalities breaking into an unlocked car may be a lesser crime than forcibly breaking into a locked car. Still a crime, but basically you're charged simply with stealing rather than some sort of breaking and entering.
Let's say you left your front door unlocked overnight, and a teenager opened it and screamed "LEROY JENKINS!" as loud as he could into your home, waking your whole family up, before closing the door and running away.
Would you really say that the teenager deserves to be charged with trespassing or B&E for this? Is jail really the answer to this transgression? If it happened every night, wouldn't you mostly be to blame for never locking your door, especially after experiencing first-hand what happens when you do not?
If Zoom is an analogy for your home, then imagine that your landlord refuses to put an actual lock on the door of your apartment, even after you tell him that people are opening it and screaming into your home.
With that said, most computer intrusions don't include theft or damages of any kind, so theft really isn't a great analogy. If someone does damage, they have done more than simply intrude.
And if you refuse to take steps to prevent these things from happening, the more it happens, the more it becomes your fault (of the fault of whoever is in charge).
Absolutely yes, so that they can learn stupid stuff like this is not tolerated. What if in the middle of that B&E the homeowner shoots the harmless kid?
This idea that petty crimes are tolerable so long as the perpetrator has a "good intentions" is pure irresponsible silliness.
I've always been very surprised zoom has an easily-guessable meeting ID namespace. It's a user experience tradeoff, but in my opinion, either the meeting IDs should be sparse and hard to guess, or there should be passwords (or possibly both).
In that case Zoom needs what any forum software inevitably has to implement: moderating tools. Meeting hosts should be able to ban ips, if they are getting hit via a proxy, the host should be able to mute everyone/disable sharing video of everyone, etc. It’s not that hard to mitigate this stuff, the key word being mitigate not ‘stop’.
So a homeowner or car owner that leaves their door opens should be responsible for burglaries? Someone that wears a nice watch that leads to a mugging?
How about people that commit crimes take responsibility for them?
We should hold the companies and individuals operating on the internet to the highest standard to prevent such security violations. I am talking about a balance of the barrier here. Guessing meeting IDs is such an obvious and trivial attack vector that it should be expected to be abused.
We look at companies like Facebook and expect them to keep our data safe and if they don't, we hold them accountable even though they are a victim of a crime. Some comment equated that to victim blaming in case of rape and that is just an insane analogy.
Obviously if there is a real world consequence and people having damage they should have the right to get compensated and that is why we expect providers and companies to keep logs, but honestly how do we expect services to develop the highest standard if they can pass the blame to an attacker. At least an equal part if not the majority should be the organization that engineered a vulnerability because in most cases these happen due to improper design. (See programming vs. civil engineering quality discussion)
We are talking about a minor inconvinience through trolling easily fixed by a proper token system on Zoom's end. This is not what the criminal justice system should be prosecuting some teenagers for.
This is silly. There's already plenty of law around contract damages etc. Is there any need to rail about this example, and propose new rules?
If you can show monetary losses due to using Zoom, go ahead and sue. Using a free account? Then there's no contract between you and Zoom - has to be 'value received' to have a contract, and you didn't pay them anything.
Since there are and have been alternative to Zoom for a decade, it's hard to make this some national priority.
Once you introduce sex crimes against children in a public (online) school room setting, all bets are off.
Uhh majority of those seem highly dependent and mostly disconnected from the actual zoomboming act and moreso with what you do once you're in the session.
Also, I'm not sure offhand what all entail "computer intrusion", but from my brief reading here[0], it seems that they must he stretching the definitions. Are you really "hacking" if you just join a meeting that someone posted openly on reddit, inviting others to troll? On the other hand, I've heard of people being prosecuted successfully for typing /../ in a URL or something along those lines.
Not defending people who do it, at least not on principle, but I'm just wary of the application of those laws. Out of all of them the first is the only that makes any sense, but zoom meetings are public now?
[0]https://www.wklaw.com/computer-intrusion-under-federal-law/
>you just join a meeting that someone posted openly on reddit, inviting others to troll?
If you joined the meeting with the full knowledge and intention of trolling yes, that falls under statute. What that other person did doesn't really matter in your prosecution, he might be prosecuted as an accessory to your crime, but his actions don't provide you enough defensive cover.
What you're stating is like a gun murderer saying "I only pulled a lever, which billions of people do every day".
If someone posted a deep URL to a hospital oxygen system inviting reddit to troll, and you go there with the knowledge and intention to troll, and press the off switch and kill a bunch of people, you're going to be prosecuted for their deaths. "I just clicked a button lol" isn't a good defense and will probably just make the judge and jury think even worse of you. Same with typing /../, you're trying to access hidden and potentially protected sensitive information. It's like trying the handles of the cars parked on the road.
What are you doing these days?
Sounds like more than joining a meeting you're not supposed to join (and share your screen). Sounds like actual hacking, like an actual crime.
But I'm on your site, if a student can hack the school, the school should be charged for having such vulns. Same logic on zoom: if you don't have a password / leak that password, it's no wonder that people join. If you design a system so anyone can enter private calls by guessing 9 digits, you're not making private calls.
I don't mean that judgmentally. I'm just curious if/how various factors (pyschology; impulse control; family environment; etc.) come into play.
Trolling the teacher in school is just plain fun. I’m rolling with the parallels today, but again, it’s the same as throwing a paper ball at the teacher when they turn around to write on the board. Most kids in the classroom don’t do it, but it’s just a ton of fun because the teacher doesn’t know who in the crowd did it (and the class doesn’t rat anyone out). You effectively disrupt class for several minutes, and the majority of the class loves that. Same is probably happening with Zoom, the kids are deliberately sharing the links.
Now, if you’re looking for a answer along the lines of ‘are there particular kids that are hyperactive and lack impulse control’, you won’t get that answer from me. Most of us grew out of this by High School, and we’re all doing fine. But, you couldn’t take the joy of doing this stuff away from me in Middle School.
Friends pushing (or being in awe of) it
my fav one was we called some rando and ask for "Frank". The obvious answer was "There is no Frank". You repeat this a couple of times until they get really annoyed, then wait a few hours and have the second person makes the call and say "This is Frank, has anyone called for me?"
Another one was us calling a classmates parents home who we didn't like and who liked to bully us. Convince the parents that the son filled out a form for a raffle at our mall and he won and the parents should come to shop XYZ to pick up the price. Knowing personal info helped with the social engineering ofc.
All this today would create a sh1tstorm but it was business as usual back then. Nobody cared and some people/victims actually saw the humor and even laughed.
This also reminds me of Gary McKinnon who logged into NASA windows servers as Administrator with a null password and no firewall. [1] He was looking for proof of UFO's. Point being, there was no security on the systems and so Gary basically walked in as a guest. No hacking required.
[1] - https://www.theguardian.com/uk/2009/may/25/gary-mckinnon-ext...
I personally dislike applying digital settings to real-world, but if you're going to make a comparison these aren't for the public or on public property.
This is more like invading rented lounge/room in a pub.
These are by no definition mutually exclusive, unless you’re considering the harm of over litigious prosecutors on society.
Their effort would be better spent recommending alternative services or providing guidance for how to configure private Zoom calls.
Kinda knocks down the "hacker kids having harmless fun" image in my book.