Zoom 5.0
zoom.us
zoom.us
I think this should fix the main issues people have had with them (at least the most public problem with 'zoom bombing').
There's not much they can do about having all their development in China, but at least their focus on security otherwise seems to be paying off.
###
Quick Feature Summary:
- Mandatory GCM encryption requires Zoom clients to upgrade to 5.0 by May 30th [0]
- Hosts can prevent screenshare, chat, user renaming
- Hosts can report users to Zoom’s Trust & Safety team, who will review any potential misuse of the platform and take appropriate action.
- All hosts may now turn on the Waiting Rooms while their meeting is already in progress.
- Lock your meeting after everyone has arrived to prevent any unwanted disruptions.
- The host may remove a participant and they will be unable to re-enter the meeting.
- Waiting Room enabled by default
- Complex Meeting IDs
- Meeting passwords are now more complex and enabled by default
- Meeting Registration and Authentication (require email registration/restrict meetings to preset profiles)
- All cloud recordings are encrypted with complex passwords on by default.
- Audio Watermarks/Screen Share Watermark (help prevent leaks)
- Message Preview Options (Users can now enable Zoom Chat notifications to not show chat content while screen sharing.)
- Host or account admin can disable the ability for participants to show their profile picture or change it in a meeting.
- Hosts can now select which data center regions they would like their in-meeting traffic to use when scheduling a meeting, and participants can see which data center they are connected to by clicking on the info icon at the top left of the client window.
- Zoom 5.0 supports a new data structure for larger organizations, allowing them to link contacts across multiple accounts so people can easily and securely search and find meetings, chat, and phone contacts.
They could start moving their development to the US. There are plenty of successful software companies in the US. There's a good ecosystem, a huge amount of talent, and tons of enthusiasm about their problem space.
What they can't do anything about is the trust they lost by misleading their customers about their security model.
Anyone know if they still passing non China video data through mainland China server? Unclear from this.
The same you could say about China.
What benefits would they gain by moving development to the US?
> Audio Watermarks: Turn this on to embed a user's personal information into the audio as an inaudible watermark if they record during a meeting. If the audio file is shared without permission, Zoom can help identify which participant recorded the meeting.
here's some old (ugly) code - quite short as you can see:
- encoding: https://github.com/jcelerier/libaudiotool/blob/master/src/li...
- decoding: https://github.com/jcelerier/libaudiotool/blob/master/src/li...
It would be interesting if they found a way to watermark the audio in such a way that removing the mark makes the audio unusable.
A common technique is to add pseudo noise to encode data over the whole audio spectrum. It's related to the spread spectrum techniques used for radio communications resistant to signal degradation (natural or jamming), common in many radio protocols, like your GPS receiver in your phone.
AFAIK these are just used to identify the streaming / download source (e.g. Spotify / TIDAL / Qobuz etc.), rather than the individual user as will be the case with Zoom. It'll be interesting to see what, if anything, has changed with the technology.
I’m not defending (or denouncing, for that matter) this feature, though I have opinions.
If a watermarked audio is leaked, the owner of the account will be liable. If he shared he's zoom credentials, is just as bad as sharing the recording.
Movie studios have done watermarking in the past with DVD screeners. Color laser printers output almost-invible patterns of yellow dots to match a document to a printer. When you download an academic paper as PDF, the PDF generally imprints the IP address and time of the downloader. Watermarking is nothing new.
For a company or government worried about employees leaking sensitive information to the press, this is an intriguing feature.
And if you're a determined whistleblower, this isn't going to stop you anyways.
One day there was an Ars Technica article leaking some news, included a screenshot of RetailMe. I put the screenshot into Photoshop and low and behold there was the employee's ID.
The most extreme example is a secret that if I shared with you, I'd die painfully. You can't threaten me with death or torture because that's what's going to happen to me if I share it with you.
I say this regretfully because I really like the slogan "technology that allows you to say no to things is great", and, of course, it's not what you meant; but, taken to its extreme, the combination of this paragraph with the logic from your first paragraph:
> This is a fantastic feature … technology that allows you to say no to things is great.
means that an imaginary Zoom feature by which it would kill you painfully if you leaked sensitive data would be fantastic.
Where the text "0 participants per room" have been applied too much anti-aliasing.
Eg some previous issues with zoom https://news.ycombinator.com/item?id=22736608
At least, use AES-256 (mode can be optional as most people don't even know what GCM XTS CBC stands for).
https://www.liveabout.com/glx-gls-se-si-lx-what-do-they-mean...
So by saying “GCM encryption” they’re highlighting that the fixed the mode by which they are using AES encryption.
So infuriating. And yes it disappears by itself after a while, but no, I do not need that dialog box.
Anyone know how to turn that off?
Edit: clarifications
> Screen Share Watermark Superimposes the image of a meeting participant’s email address onto shared content in the event a participant takes a screenshot.
On Linux/Wayland at least, there's no API for an app to determine that this is happening. So they'd have to show the watermark all the time.
AFAIK, on iOS, the app is actually sent an event by the OS when a screenshot is captured.
[0] https://security.stackexchange.com/questions/170596/is-it-po...
https://developer.apple.com/documentation/uikit/uiapplicatio...
If you want to elicit a change, the biggest value for your time will be lobbying against FedRAMP and its corollaries.