Over 500k Zoom accounts sold on hacker forums, the dark web
bleepingcomputer.com
bleepingcomputer.com
This feels like ridiculous piling on to Zoom. This comes down to the same old password reuse issue. You could almost certainly replace any other service provider with Zoom in that article and not reduce its accuracy. Pounds for pennies, other services have hundreds of thousands of accounts being sold courtesy of credential stuffing.
The assumption of rank incompetence and/or irresponsible cowboy practices seems to be completely appropriate for them...
> When processing requests to establish and change memorized secrets, verifiers SHALL compare the prospective secrets against a list that contains values known to be commonly-used, expected, or compromised.
If Zoom had enforced that passwords can't be from a list of already compromised passwords as this guidance suggests, this attack wouldn't have been nearly as successful. This is just what happens when you don't have a decent security policy, and everyone that doesn't follow basic security best-practices should be called out for it.
More context from the guidance below from https://pages.nist.gov/800-63-3/sp800-63b.html
> When processing requests to establish and change memorized secrets, verifiers SHALL compare the prospective secrets against a list that contains values known to be commonly-used, expected, or compromised. For example, the list MAY include, but is not limited to:
- Passwords obtained from previous breach corpuses. - Dictionary words. - Repetitive or sequential characters (e.g. ‘aaaaaa’, ‘1234abcd’). - Context-specific words, such as the name of the service, the username, and derivatives thereof.
If the chosen secret is found in the list, the CSP or verifier SHALL advise the subscriber that they need to select a different secret, SHALL provide the reason for rejection, and SHALL require the subscriber to choose a different value.
Ideally a modern system should use haveibeenpwned or atleast one of the various lists you can find in password cracking forums.
Who would benefit the most? Skype, Google Voice, Facebook Mesenger ?
I think this is the most likely reason with their explosion in usage due to COVID. Anecdotally, around 25-30% of news articles shared in my company Slack channels recently have been about Zoom. We saw the exact same phenomenon during the 2016 election.
[0] https://jesperjo.com/f/intro-to-multi-factor-authentication
The fixes zoom could implement seem limited to IP address rate limiting and checking passwords against haveibeenpwned (or similar).
They should use MFA but at the very least they should prohibit the use of leaked passwords.
How many US senators are holding calls on Zoom? How many of those calls are about new spending? How useful might it be to be ahead of that curve?
I sure hope so
> Just because everyone else is doing it doesn't mean you should.
or
> If everyone else jumped off a cliff would you?
Or more simply:
> Can you call a practice "gross incompetence" if everyone is doing it?
Yes. Yes you can.
You can run risk analysis on login and add CAPTCHAs to slow down attackers trying credentials, notify account owners on suspicious logins, possibly require confirmation via a link to an e-mail account if the login looks really phisy, make a different risk-convenience tradeoff (e.g. by enforcing 2FA), ...
They won't prevent it completely, but you can make it harder. So I don't think (also) blaming the service for successful large-scale credential stuffing attacks is unreasonable.
1) Looking for Zoom premium accounts, there is actually a pretty good trade in stolen accounts on the dark web. Folks will pay a dollar for example for one of these accounts.
2) This is the more likely one—looking for people who use one shared password across multiple valuable logins.
This is my point.
So n = 1 it's for lulz.
If anything, I suspect this has less to do with hacking and more with insiders abusing their access to the system. Chinese hackers are very often extremely competent day time programmers, and have been known to sell their internal access to the highest bidder[2].
[1] - https://blog.zoom.us/wordpress/2020/02/26/zoom-commitment-us...
[2] - https://intrusiontruth.wordpress.com/2019/07/25/encore-apt17...
https://www.nulled.to/topic/1049984-x352-zoom-accounts-with-...
Nothing in this suggests this is Zoom's fault (except that they might be able to check haveibeenpwned and warn users)
This isn't a reason to not want actual problems in Zoom fixed, but misrepresenting their posture relative to the rest of the industry benefits nobody besides incumbents.
"Reject Pwned Passwords" is a very cheap security improvement during sign-up processes. Of course the problem for Zoom is that they've focused very hard on reducing "Bounce" where people decide they'd rather not sign up, which has led to a lot of the other complaints about Zoom we're also reading.
If you run a service that has an email + password type sign-in, the top TWO items I'd tell you are must haves for that service today - as in if you aren't live they need to be requirements for go-live and if you're already live they should be top of your pile are:
1. Sign-in-with-X services that out-source authentication entirely to somebody else, it doesn't much matter if it's Facebook, Google, Apple, almost anything is better than creating yet another service with yet more credentials. These services are relatively low friction. Zoom does offer this, and if you must have Zoom (as many of us must in this period) then this is the least worst option.
2. Blocking known passwords with something like PwnedPasswords. If you must build your own account authentication either out of hubris or with some genuine rationale for why it's necessary, use PwnedPasswords or a similar service to reject these passwords. Don't have stupid "policies" that sounded good to some idiot who still thinks regular expressions are a pretty neat idea, just reject these known bad passwords.
There are lots of more expensive things I think companies should do if they take security seriously, like implementing WebAuthn (ie FIDO security keys) but the above two are low hanging fruit. If you haven't done them it is something you did wrong.