Seems that to succeed you don’t focus on security till you get caught.
None of this will change unless there is a shift of liability back onto companies for securing data.
Seems that to succeed you don’t focus on security till you get caught.
None of this will change unless there is a shift of liability back onto companies for securing data.
Security bloggers are all about attention - shiny thing. That's why there's a semi-annual story that gets some traction with a headline like "Experts from FooCorp warn that the honeymoon is over, viruses have arrived on MacOS!" Zoom is the new Apple for this shit.
Zoom has lots of issues, but the pile-on is just dumb. Everything has issues. Do you use a phone? Landlines are not encrypted, mobile is encrypted with defective security, and carriers have access to all metadata, all data, and provide CALEA access as a service.
So yeah, there's a risk that your sales call, or 5th grade english class, or other meeting could be compromised by some malicious third party. How does the probability/impact of that stack up against the probability that your salesman or 5th grader's grandmother will be infected and die from exposure?
I've worked and architected systems for people with very high confidentiality requirements. Guess what? They don't use internet-based remote collaboration systems to remotely collaborate. The only common system that comes to mind that you might be able to use in these scenarios is an on-premise version of Webex, assuming it still exists!
It's not dumb, it's a response to incentives! As you noted in the second paragraph! Researchers want attention, which is only natural.
Why is reacting to known security vulnerabilities in the software you distribute so controversial? It's not rocket science to keep your openssl dependency up to date. I agree that there will always be unknown vulnerabilities that they introduce themselves, but if they knowingly ignore public vulnerabilities it's just negligence imho.
Slack, Teams & co flat-out ignored calls and screen sharing until now. They were sidelined so-so features. Hell, on Slack you couldn't even see screen sharing from mobile, and you did not even got a notification that another person is sharing. Never mind missing even the most basic annotation features.
No wonder Zoom eats all the pies now. Sure, they made a lot of mistakes, but it was a huge landfall on a small(ish) company. That said, if the others top up their game, I'm happy to get rid of an additional app - but that's how market works.
Upd: These are not mistakes. They did all that intentionally, fogetting about the security for convenience even when it was beyond reasonable imho.
Upd2: Why downvotes? Some recent headlines from Hacker News:
- "Zoom rolled their own encryption scheme, transmit keys through servers in China"
- "Zoom meetings aren’t end-to-end encrypted, despite marketing"
Are you calling these "mistakes"?
I think Zoom certainly deserves the criticism that they're getting regarding security. But until the alternatives figure out things on the functionality front, I don't think that's a sufficient reason to kick Zoom to the curb.
Look at the problems they've had over the past month:
- "Zoombombing" is a thing because the default meeting configuration didn't require a password, making it easier for attendees—legitimate or not—to join.
- Issues with the installer were in part caused by shady workarounds they took to reduce friction during the installation.
And yet, they're doing just fine with their "UX first, security later" approach. So I guess I'm underscoring your point: we absolutely need more consumer protection.
Side-note: I wonder if Zoom is getting into trouble in Europe over any of this?
Some European organizations are banning it from business computers.
I only use it for semi-public discussions, and run it on a Windows 10 laptop that isn't used for anything else, so I'm not that bothered by the security issues.
In the meanwhile, imho they are under so much pressure to behave that in the next few months might really make some progress in this field. I mean, right now Zoom is the most independently "audited" video conferencing app in the world and many newspapers and state attorneys are investigating [1].
I trust the power of the press.
[1] https://www.nytimes.com/2020/03/30/technology/new-york-attor...
Another issue was that until recently the ID number was prominently displayed in the application window. Many people (including Boris Johnson) shared screenshots on social media with the ID included.
Now if I can’t have a private conversation online it’s much more important to me. A month or two ago it was important, but probably not as much as usability and reliability
Many traditional organisations (schools, enterprise, etc) that care for security, in my experience, did so for GDPR compliance and to the extent that they were compliant. A lot of businesses weren't even being malicious, just negligent.
So, on the whole, regular users don't seem to care, and since users don't hold businesses accountable for it, businesses don't really care.
NB: Users refers to any random person who isn't in the tech industry. Like, probably, your neighbour or the random person walking their dog.