News: 1587588879

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

After intense scrutiny, Zoom tightens up security with version 5. New features include not, er, spilling video calls to network snoops

(2020/04/22)


Zoom's ongoing game of whack-a-mole with security bugs in its code continued today with the [1]imminent emission of version 5 , replete with support for 256-bit AES-GCM encryption.

It's the latest in the video-conferencing software maker's 90-day plan to overhaul its [2]platform's dodgy security after a hellish few weeks at the hands of security researchers, privacy activists, and journalists. As hundreds of millions of netizens, forced to stay home and work remotely if possible amid the coronavirus pandemic, flocked to Zoom's chat products, its code fell under intense scrutiny. Various shortcomings were found – from end-to-end encryption that didn't exist to wobbly password protection on calls.

The encryption upgrade in Zoom 5.0 will better protect data in transit – it previously used AES-ECB, which [3]leaked video frames to eavesdroppers. "System-wide account enablement will take place on May 30," Zoom's Colleen Rodriguez said of this improvement.

In addition to the encryption, Zoom will allow account admins to select which of its data centers can handle users' data, after some of Zoom's servers in China ended up handling calls from outside China. So now you'll be able to choose which region of the world your chats can flow through.

However, it is with the user experience where Zoom may start to come a little unstuck as it ramps up security by making its platform, frankly, a little harder to use. One of the contributing factors to its success was the frictionless way in which netizens were able to connect, at the unfortunate cost of iffy security.

Don't Zoom off elsewhere: Google plugs video-chat service Meet into Gmail as user eyes start wandering [4]READ MORE

Witness the [5]Zoom-bombing phenomenon , made possible by brute-forcing IDs for password-less meetings, somehow bypassing the call passwords, or by scanning social media for shared access details.

To lock things down a little more, the Waiting Room feature, where participants are kept in individual virtual waiting rooms to be vetted by the host, will be on by default for basic, education and single-license Pro accounts. Meeting passwords, in theory already on for most customers, may have their complexity defined by administrators.

Your humble vulture has had personal experience of non-technical acquaintances struggling with the waiting room concept and there is a danger that by making the experience more secure, Zoom risks customers looking elsewhere for their face-to-face fix.

Other changes include a UI shift to group security features together as well as improved host controls to permit the meeting host to easily report users or disable the ability for participants to rename themselves. Passwords are also set by default for cloud recordings, and larger organisations will welcome the ability to link contacts across multiple accounts.

Breathless from its trumpeting, the company urges punters "to update your Zoom app to Zoom 5.0, please visit zoom.com/download".

We'd suggest holding fire a bit longer – at time of writing, only version 4.x was available. We've asked the company exactly when the wonders will be bestowed and will update when it responds. ®

Sponsored: [6]How To Accelerate Brilliant Digital Experiences With Low-Code



[1] https://blog.zoom.us/wordpress/2020/04/22/zoom-hits-milestone-on-90-day-security-plan-releases-zoom-5-0/

[2] https://www.theregister.co.uk/2020/04/03/zoom_security_improvements/

[3] https://www.theregister.co.uk/2020/04/03/dont_use_zoom_if_privacy/

[4] https://www.theregister.co.uk/2020/04/17/gmail_inbox_meet/

[5] https://blog.zoom.us/wordpress/2020/03/20/keep-uninvited-guests-out-of-your-zoom-event/

[6] https://go.theregister.co.uk/tl/1936/-8552/how-to-accelerate-brilliant-digital-experiences-with-low-code?td=wptl1936

Anonymous Coward

Their response to everyone calling them incompetent was to announce that they have a new version that fixes everything, and direct people to a download link for the old version?

Seems like the perfect company to be recording confidential meetings. Anyone have the URL to download all of the UK cabinet meetings?

Also, where are GCHQ and the NSA and their equivalents around the world? They have been telling us all these years that their main job is securing government communications, and spying on other people was a spare-time sort of thing... but they couldn't set up downing street with a video conferencing solution that met even the most basic security requirements? Do they not have a placement student who could modify the template on one of the many WebRTC demos to "create a bespoke secure government grade video conferencing platform using military grade end to end cryptographic encryption cryptography" in less than a day month?

Pascal Monett

I'm sorry, you are obviously operating under the obsolete idea that security services exist to ensure that government activity is secure.

That is last-millennium thinking.

These days, security services are there to ensure the government that the people they govern are happy and complacent and won't come with pitchforks to put their heads on a spike. To ensure that, their job is to listen to everybody, scrape all social networks and record every tweet to ensure that pubic ire is directed to the acceptable scapegoats (immigrants, foreigners, the French, arabes, asians, etc).

Therefor, the GCHQ is perfectly happy with the Chinese being able to listen in to UK gov meetings, since they will get the information anyway through Huawei 5G routers that have yet to be installed.

Ah, the miracles of technology have no bounds.

Makes my job harder

Anonymous Coward

Already having enough trouble persuading higher powers to read the Ts&Cs before signing up, version 5 doesn't fix everything (it's still decrypted at the server as far as I can tell for example) but the headline is "Zoom tightens up security" so all previous arguments will be ignored because everything's ok now.

Anonymous Coward

My bigger problem isn't the security issues per se. Even in aggregate, discovered so closely together I've seen worse in my time.

My concern was the tone and character of the response Zoom would return to their concerned customers. I'm fairly often on the hook for managing our response to our customers for security incidents we're possibly responsible for [open source middleware - weekly occurrence, naturally]. When a customer says something like "Help me understand what was going on CVE-2022-192729" what they _actually_ want to know are the answers to little questions like "How did you let this happen?", "How did you find out about this?" and most importantly "What are you going to do to stop this happening again?"

When we went to Zoom and asked them to provide us a formal response to their recent security incidents, the text returned was nowhere near up to snuff for an enterprise software vendor. The text was trite, dismissive and arrogant. For example on the topic of how they installed a fully unauthenticated, open to the world web server on everyone's machines without asking, the response reads thusly:

"Zoom is not malware. Zoom is safe to use for both you personally and businesses, but you should read through on how to best protect yourself and your company. Throughout the past few days, social media (mostly infosec twitter) is gushing with various opinions and hot takes about Zoom being malware due to multiple issues found with it. Some of these issues are indeed problematic (and are/were taken care of by Zoom) and some of the issues that are being raised and discussed in social media are in fact not bugs or issues with Zoom itself but issues with the way operating systems work."

They quote some nobody infosec blogger [yeah - that's not even their own words they sent to us] in order blame us for getting hit, they blame the "gushing infosec twitter" for finding their massive security fuckup and they blame operating systems for letting them get away with it. This is the calibre of company we're dealing with, and frankly I do not believe that is good enough for other companies to be trusting Zoom with their secure, corporate communications.

Lorribot

The website says the download is 4.6.12 but the file you downlaod reports as 5.0.0.0.

They need to put more effort in to the details.

Q: What do Bill Gates and Bill Clinton have in common?
A: Their ratings climb whenever they do something unethical.