From [Direct sharing in Zoom Rooms](https://support.zoom.us/hc/en-us/articles/214629303-Direct-s...):
> Direct sharing with proximity detection uses the microphone on your laptop to detect the Zoom Room controller.
From [Direct sharing in Zoom Rooms](https://support.zoom.us/hc/en-us/articles/214629303-Direct-s...):
> Direct sharing with proximity detection uses the microphone on your laptop to detect the Zoom Room controller.
If so someone should make a jammer.
When it works, it means someone can walk into an appropriately equipped meeting room, and the software on their machine detects that. The audio, video, and screen sharing all route through the meeting room, rather than the laptop. Virtually zero involvement for the user.
I recall that if you were not signed in to an account on their Org, it would only show up with you as that you were a guest in the room, and you could not do much/anything without someone from that org authorising you.
I dont know if the token is long lived, i would hope its rotated frequently.
i also suspect that because it's above audible range, your average video compression might strip it out.
With WebEx you can turn this off in the preferences. I'd assume Zoom has a similar config setting.
I haven't contacted Lutron yet which is bad of me, and I really should do that, but I don't think they would care since the amount of people who can identify that there's a problem with their devices is small.
I think it's a pretty cool hack.
It's awful in that using the auditory domain is too much an intrusion into the human space. There is enough noise pollution. Interference patterns around the room may generate harmonics at audible frequencies. Young kids can hear high frequencies we forgot we ever could. I can still hear CRT flybacks. Sometimes I thought I heard something electronic in conference rooms but convinced myself it was nothing.
Someone else was complaining about it affecting their cochlear implant. That is horrifying.
It is not so farfetched that it has an adverse affect on health either. America is losing diplomats left and right to some mysterious ultrasonic weapon, or at least that is one of the leading theories.
It is awful that my CPU has to be constantly running a FFT to read this signal. I think Apple has an ASIC which does the Siri voice recognition.
It's awful that it triggers the orange light to be constantly on so you end up ignoring it. What if Zoom is simultaneously using the microphone stream for nefarious purposes.
This is what Bluetooth was made for. This is a worse idea than Wifi over lighting. Even the 9-digit Zoom dial codes are better.
Definitely.
>It is awful that my CPU has to be constantly running a FFT to read this signal. I think Apple has an ASIC which does the Siri voice recognition.
Isn't it the zoom box that has to be doing the detection? The pc is just sending the signal, which wouldn't take much processing.
>It's awful that it triggers the orange light to be constantly on so you end up ignoring it.
I think someone commented that's for the purpose of detecting if someone is muted and notifying them. Still, there should definitely be a choice to disable this behavior. I wouldn't be able to ignore it.
>What if Zoom is simultaneously using the microphone stream for nefarious purposes.
There's a lot of nefarious things they could potentially do even without using the mic, considering it's software already running on your pc that already has an encrypted connection to their servers.
>This is what Bluetooth was made for.
Good point, that would have been better.
If the PC were just sending the signal it wouldn't need the microphone to be on. And it would stop working when people turn off their speakers like a lot of people do in a busy meeting room.
By the way there seem to be other ways to do it too. Not sure if it's Bluetooth but MS Teams warned me in the past that I was in a room with a Surface display (the huge first generation one). It doesn't keep the microphone active though.. I never investigated how it figured that.
Because this “hack”:
* Works on devices without Bluetooth (or that have it disabled)
* doesn’t require anyone installing privileged software or drivers
* gives a very good “in the same room” indicator
* doesn’t require any custom/expensive hardware components
From the description it sounds like it's just a handoff feature, as in you go into a conference room with whatever their conference room product is.
Once you get in handoff range they only need to exchange sufficient information to get the AV equipment to start a connection to the appropriate zoom/webex/whatever channel, and presumably the reverse of getting the original zoom client to close.
I'm assuming there is some work to reduce the likelihood of unintentionally triggering it, and some basic authentication, but this is not a lot of data, and ultrasound is more than sufficient to do it very "instantaneously".
I mean, if I ever switch off Bluetooth it's exactly for the reason that I don't want my device to be detected/tracked. Zoom going around this by using ultrasound is kind of mean, since I can't prevent zoom from using audio if I want to be able to make calls.
That was my interpretation of the feature described earlier in the thread
> But this means that at least some kind of access token must be transmitted over ultrasound. ...
Yup, I agree I'd love to know more about what is involved. I like to think there's a degree of authentication involved, but this is also Zoom. The company that installed a persistent service in order to circumvent a security feature in safari, that also allowed unauthenticated RCE.
> I mean, if I ever switch off Bluetooth it's exactly for the reason that I don't want my device to be detected/tracked.
I had assumed Android and PC had adopted the randomized MACs apple uses to prevent such tracking?
> Zoom going around this by using ultrasound is kind of mean, since I can't prevent zoom from using audio if I want to be able to make calls.
If we assume for now that it is properly authenticated, and has safe tokens to break tracking, identification, etc, then this behaviour seems reasonable. It would require you to open zoom in a room with the requisite enterprise-y teleconference equipment.
But of course that is quite a load bearing "if", and it already appears that they're trying to maintain the channel when they aren't active.
True, and this is why I rarely switch it off, except in situations where I don't want to be visible to devices that I previously connected to. Same for wifi.
I just find it quite over the top to work around user-controlled communication channels like bluetooth that the user might have chosen to disable, by using a medium (sound) that the user cannot switch off and still use the app.
As I noted earlier it works without bluetooth available, but more importantly I suspect, if it were bluetooth everyone would have to peer their devices with every conference room. If it were wifi you'd need to know the network name of the conference room's AV system.
While both options would work, having a single "switch to AV system" button is clearly the best user experience, so you try to make that possible. Given both the app and the AV system have the ability to create and record sound, that's the obvious choice.
But again, I'm not making any statement on the security of the actual implementation from Zoom :D
Where this reasonable solution is actually implemented securely is another question, and Zoom’s track record isn’t exactly fantastic.
Zoom deciding to use the mic while not in use is clearly a terrible bit of behavior :)
Plenty of people use conference rooms for non video chat reasons, and many of those reason have confidentiality rules.
I know for example there are strict rules around what is required to protect client/lawyer confidentiality, and most of the protection goes out the window if you record, or allow some one else to record them. Would zoom listening in on that count? I have no idea
The only class of apps that have any business using a microphone while not in active use are “assistants”, and those have no business doing anything other than listening for their initiator phrase (except haven’t they all been caught sending arbitrary recordings to their parent company?)
Hmm... but, then again, there was that thing where Amazon Alexa was recording people without their knowledge... hmm.
Every place I have worked in the past there have been zero pathway for IT/Developers to notify a lawyer about anything or ask a question.
https://thenextweb.com/news/zooms-scary-webcam-flaw-also-aff...
And then the people in charge of the money would do the math on "this earns us 1 billion dollars and the fine has a 10% chance of happening and would be 100 million... so do it anyways, it's worth the tradeoff". This happens over and over.
No need to use quotes here, that was literally my question :D
> In all US states and probably a lot of countries, recording is illegal without the consent of at least one party to the conversation. In the US, in some states, all parties must consent to recording.
Literally every company that got caught having their assistants record conversations turned around and said the victims were informed and consented through the terms of use agreement.
Their lawyers didn't stop them from claiming to provide end-to-end encryption, a blatant misrepresentation that resulted in receiving a consent order from the FTC [1] and settling a class-action suit for $85M [2], so I don't think it's safe to assume that they would prevent the company from doing obviously unacceptable things.
[1]: https://www.ftc.gov/system/files/documents/cases/1923167zoom...
[2]: https://arstechnica.com/tech-policy/2021/08/zoom-to-pay-85m-...
Meeting start -> probe for hardware -> make decision where to host