Just because we're letting Zoom into Parliament doesn't mean you can have fun, House of Commons warns Brit MPs
- Reference: 1587565211
- News link: https://www.theregister.co.uk/2020/04/22/no_virtual_zoom_backgrounds_warns_house_of_commons/
- Source link:
At any one time, Parliament will allow 120 members to participate remotely. This is a hard limit set internally and not a consequence of any technical limitations. A Zoom representative told The Register that the Commons has an enterprise plan, which can support 500 participants concurrently.
Irrespective of whether they're present in the chamber or streaming from their kitchen table, parliamentarians will have to wear formal attire. This is a long-standing rule that's seldom relaxed, although in 2017 House Speaker John Bercow allowed male members to attend without wearing a necktie. This exception [2]was made for one-time Sheffield Hallam MP Jared O'Mara , who struggled with the accessory due to cerebral palsy.
Members are encouraged to choose a quiet location to set up camp, where they are shrouded from extraneous noise and unlikely to be disturbed by pets and children [3]à la BBC Dad . They should sit upright – with no slouching – at a desk or a table, and imagine themselves as posing for a passport photo.
The guidance also mentions lighting, with members told to avoid white backdrops – presumably to avoid glare. "Find a position with a plain background behind you," it stated.
Not only is Zoom's strong end-to-end encryption not actually end-to-end, its encryption isn't even that strong [4]READ MORE
"Ideally it wouldn't be white, or a very light colour. Please exclude mirrors, doors, and bright windows… Try to avoid 'busy' backgrounds. Maps or pictures on the wall, or shelves with photos or other visual interesting items may be distracting for viewers."
The guidance also sternly warns against using novelty virtual backgrounds – a feature in Zoom that allows users to juxtapose themselves against an image, allowing them to appear as though they're dialling in from the pyramids, or hanging out on the Death Star.
It also warned members that they will potentially be seen on camera, even when they aren't actively speaking. As such, they should exercise caution and avoid holding sensitive conversations, even when on mute.
And they definitely should avoid mouthing epithets at other members – a lesson learned by erstwhile Labour leader Jeremy Corbyn in 2018, when he appeared to mutter "stupid woman" at Theresa May.
Teamwork makes the dream work
The UK has a bicameral parliament, and the House of Lords has similarly taken action to enable remote participation alongside the current social distancing measures.
The biggest difference is arguably the decision to use Microsoft Teams instead of Zoom – which has proven unpopular with some members.
Baroness Jean Coussins [5]mentioned that despite the perceived security concerns, she finds Zoom – which is used by the Foreign Office to conduct language lessons – easier to use.
"As one of its language students, I found it very easy to participate – much easier than being on Teams. What have the security, or other, concerns been around this House using Zoom from the start when it appears to be acceptable to both the Foreign Office and the House of Commons?" she asked.
Unsurprisingly, no one mentioned the potential for [6]Zoombombers or how to correctly address someone should they manage to crash onto the video conferencing system.
Tory peer Lord Kirkhope of Harrogate also [7]raised an issue of usability . Demonstrating a cast-iron grasp of technical terminology, he said: "I congratulate everybody concerned with this effort to set up virtual TV for us.
"Can anything further be done to aid those Peers and Peeresses who are unable to join the virtual proceedings due to technical or broadband deficiencies in the places where they are locked down?"
This is arguably a fair point. According to the House of Lords website, the [8]average age of its members is 70 , with the oldest born in 1925. And it's not unreasonable to think that they may be living in parts of the country where Openreach vans daren't roam.
Lord McFall of Alcluith, Senior Deputy Speaker of the House of Lords, said that measures would be introduced in the second phase of the virtual sessions' rollout, but failed to mention what they would entail.
Constitutionally, we're in uncharted territory and we look forward to the familial interruptions and technical mishaps that'll bring levity to this otherwise bleak and uncertain time. ®
Sponsored: [9]Legacy Modernization: Finding Your Way With Low-Code
[1] https://www.theregister.co.uk/2020/04/21/uk_commons_agrees_to_allow_zoom/
[2] https://www.yorkshirepost.co.uk/news/politics/disabled-sheffield-mp-jared-omara-opens-his-battle-adjust-life-westminster-549795
[3] https://www.youtube.com/watch?v=Mh4f9AYRCZY
[4] https://www.theregister.co.uk/2020/04/03/dont_use_zoom_if_privacy/
[5] https://www.theyworkforyou.com/lords/?id=2020-04-21a.13.5#g16.4
[6] https://www.theregister.co.uk/2020/04/08/zoom_security_stamos/
[7] https://www.theyworkforyou.com/lords/?id=2020-04-21a.13.5#g16.2
[8] https://www.parliament.uk/about/faqs/house-of-lords-faqs/lords-members/
[9] https://go.theregister.co.uk/tl/1936/-8553/legacy-modernization-finding-your-way-with-low-code?td=wptl1936
The UK has a bicameral parliament
Not any more, for all meanings of "camera"...
UKGovt hacked in 3,2,1....
https://blog.talosintelligence.com/2020/04/zoom-user-enumeration.html
The vulnerability arises from the lack of validation to ensure the requesting user belongs to a queried domain. This allows arbitrary users to request contact lists of arbitrary registration domains. The exploitation process requires the user to properly authenticate to Zoom with a valid user account, the user then sends an XMPP message with the content below to receive a list of users associated with the domain arbitrary_domain.com:
In the reply, the Zoom server discloses a directory of users registered under this domain. This includes details such as the autogenerated XMPP username along with the user's first and last names. This information combined with other XMPP queries could be leveraged to disclose further contact information including the user's email address, phone number and any other information that is present in their vCard. As a large number of users come online with video conferencing for the first time, there is a large attack surface. It's important to note that because this is a server-side cloud issue, as is customary, a CVE will not be assigned.
Re: UKGovt hacked in 3,2,1....
" As of the publication of this blog the issue appears to be patched."
Not that that proves it's secure now. Zoom have had a rather cavalier attitude to security.
"imagine themselves as posing for a passport photo."
So no need to look like themselves.
Zoom seems to work, but it needs the crap of a exe running on your Windows box, otherwise painless. Security doubtful, owned by Chinese.
MS teams is crap, while it offers a web browser mode it only works with Chrome (Edge does not count as another browser, it is Chrome). How come a company the size of MS can't make a system that actually works on many browsers like, say, Zoho can? Security maybe better, but USA jurisdiction.
"How come a company the size of MS can't make a system that actually works on many browsers like, say, Zoho can?"
Don't confuse "can" with "want".
Re: " it needs the crap of a exe running on your Windows box"
Don't know where you got that idea, as Zoom has versions of it' application for [1]Linux, Mac, Android, etc.
Also you don't need the .exe file it downloads when you click on an email link (in Windows), you can just copy the meeting ID and join directly on the Zoom app
[1] https://support.zoom.us/hc/en-us/articles/207373866-Zoom-Installers
BBC Dad
I'm sure everyone has seen this but just in case you haven't (nsfw as has swearing)
https://twitter.com/Ivorbaddiel/status/1251847717539774466
Double bubble
Given that Parliament manages to have two separate catering companies depending on which end of the building you're in, it's no surprise that they have competing, incompatible VC systems.
Re: avoid holding sensitive conversations, even when on mute
Open the pod bay doors HAL.