Researchers: Zoom sometimes uses encryption keys issued by servers in China, uses a flawed encryption method, and hence is not suited to communicate secrets
but it can be fixed Stephen Warwick / iMore : Today on Zoom: ‘Not suited for secrets’, encryption issues and more Mercury News : Zoombombing: FBI warns video calls are getting hijacked Tweets: Glenn Fleishman / @glennf : I compiled a list of every known Zoom security exploit, software bug, privacy failure, and bad decision (many now remediated) and what you can do about each of them. I had to add six in the last two days while writing & editing it. @TidBITS https://tidbits.com/... @ayshardzn : Zoom has seen a 535% rise in daily traffic in the past month, but security researchers say the app is a ‘privacy disaster’ https://www.theguardian.com/ ... Dan Gillmor / @dangillmor : A round-up from Bruce Schneier of the research showing how Zoom's “security” is a sick joke. If you have secrets to keep, don't go near this product. https://www.schneier.com/... @dhh : An exhaustive account of all Zoom's privacy and security transgressions. When you see it all collected like this.. well, just, wow. https://tidbits.com/... @nxthompson : The choices Zoom has made on encryption are reasonable. But they really shouldn't claim it's end-to-end encrypted. And they should stop with the muddled blog posts too. @lilyhnewman digs in deep. cc @dhh https://www.wired.com/... Lily Hay Newman / @lilyhnewman : Zoom has made a lot of claims and used a lot of very specific phrases in describing its encryption protections for meetings. Let's hash it out, shall we? https://www.wired.com/... @dhh : Despite the confusing back-and-forth messaging, it finally seems clear that, no, Zoom is indeed NOT end-to-end encrypted, as they were claiming for a long time. Unlike, say, Apple's FaceTime, which for up to 32 users, indeed IS e2e. https://www.wired.com/... Graham Cluley / @gcluley : A Quick Look at the Confidentiality of Zoom Meetings by the team at @CitizenLab. https://citizenlab.ca/... (I wonder how much longer the UK Govt will be using it for cabinet meetings...) https://twitter.com/... Micah Lee / @micahflee : This is a very good and human-readable post by @matthew_d_green about how Zoom's encryption works, the good parts and the very bad parts, and how Zoom has a solid path forward to fix the most major problems https://blog.cryptographyengineering.co m/ ... David Dayen / @ddayen : Zoom is 2020's version of Milkshake Duck https://theintercept.com/... @dhh : “Meetings on Zoom are encrypted using an algorithm with serious, well-known weaknesses, and sometimes using keys issued by servers in China, even when meeting participants are all in North America, according to researchers at the University of Toronto” https://theintercept.com/... @eff : Zoom has a lot of work to do if it wants to regain users' trust. In the meantime, if you continue using Zoom, consider these settings. https://www.eff.org/... Mikel Bober-Irizar / @mikb0b : Zoom's security just gets worse and worse. Broken encryption (ECB), 128-bit instead of quoted 256-bit, with keys issued by servers in China https://citizenlab.ca/... @zoom_us https://twitter.com/... Felix / @c1truz_ : Check out this blog post if you want to learn more about the technical background of the Zoom issue and its implications. Also, here is the full VMRay Analyzer report https://www.vmray.com/... ✌️ https://twitter.com/... Matthew Green / @matthew_d_green : I wrote a non-technical post on the situation with Zoom and encryption. This mostly summarizes what we know from @citizenlab and Zoom itself: https://blog.cryptographyengineering.co m/ ... @fightfortheftr : Using Zoom? Their video messaging does NOT use end-to-end encryption. Sign the petition to tell @zoom_us to protect your sensitive personal and professional communications. 🔒 https://actionnetwork.org/... @swiftonsecurity : Zoom is getting torn apart. That's not a bad thing. Very very few enterprise tools get the attention of world-class researchers. Even premier applications by huge companies go unexamimed b/c difficulty of obtaining and installing them. Plenty of Tier0 stuff written in C in 2007. Zoom / @zoom_us : We appreciate the scrutiny and questions we have been getting - about how the service works, about our infrastructure and capacity, and about our privacy and security policies. These are the questions that will make Zoom better [Blog Post] https://blog.zoom.us/... by @ericsyuan Richard Bejtlich / @taosecurity : Looks like solid research by @citizenlab. If I'm reading it correctly, actors in China could have access to all the encryption keys needed to see calls. Keep this in mind when you chose to discuss sensitive info using #zoom. Obviously no mil/gov should talk classified on it. https://twitter.com/... Gordon Corera / @gordoncorera : Interesting research from Citizen Lab on Zoom - it raises concerns about Chinese end of the company - ‘during multiple test calls in North America, we observed keys for encrypting and decrypting meetings transmitted to servers in Beijing, China’ https://citizenlab.ca/... Jeffrey Vagle / @jvagle : There are two things you should never do: 1. Get involved in a land war in Asia, and 2. Roll your own crypto https://citizenlab.ca/... Nicholas Dawes / @nicdawes : When the first phase of this is over, we are going to wake up to the scale of the information security and privacy risks we have all been taking https://twitter.com/... Avi Asher-Schapiro / @aaschapiro : An analysis of Zoom by @billmarczak & @jsrailton reveals it *does not* use industry standard protocols for voice & video— encryption & decryption keys come from Chinese servers. Their conclusion: it's fine for family chats, not for journalists & activists.https://citizenlab.ca/ ... Ethan White / @ethanwhite : Dear @zoom_us - as part of your focus on privacy and security over the next 90 days there is something we could critically use in education: the ability to record only the host side of a call. This will allow us to record and share classes without compromising student privacy. https://twitter.com/... Joe Tidy / @joetidy : NEW: Zoom ‘unsuitable’ for government secrets, researchers say. New study from @citizenlab shows Zoom encryption is crackable and unsafe for high level meets. I understand gov is working on adapting other existing tools ‘at pace’ to deal with the current communications conundrum. https://twitter.com/... Thomas Brewster / @iblametom : People lost their minds when Zoom was sending small pieces of data to Facebook even when users weren't on FB. Wonder how they'll react when they hear Zoom is sometimes handling encryption keys in Beijing, even when callers aren't in China... https://www.forbes.com/... Matthew Braga / @mattbraga : Also worth noting: “For those using Zoom to keep in touch with friends, hold social events, or organize courses or lectures that they might otherwise hold in a public or semi-public venue, our findings should not necessarily be concerning.” https://twitter.com/... Kate Allen / @katecallen : New report from @citizenlab on confidentiality and encryption of Zoom meetings: “Researchers conclude that Zoom uses non-industry-standard cryptographic techniques with identifiable weaknesses and is not suitable for sensitive communications.” https://citizenlab.ca/... Susan Potter / @susanpotter : A fantastic case study in how aggressively “making X easy” inevitably leads to “making X insecure.” If meeting confidentiality is not that important for your company then maybe the user exploit potential is note worthy. Zoom is a risky proposition for your employees to install. https://twitter.com/... Dave Kennedy / @hackingdave : Example of hyperbole for the Zoom discussion and horrid fear-mongering by the media and comments from individuals that are not even security researchers This type of news is exactly what is damaging to the security industry and trust in us. @guardian https://www.theguardian.com/ ... Martin Sfp Bryant / @martinsfp : cc: UK government. https://twitter.com/... Anneke VanWoudenberg / @woudena : An important read for NGOs, #humanrights lawyers, activists and journalists using Zoom during the #COVID19 crisis. Surely this is a problem Zoom should be urgently fixing? #bizhumanrights https://twitter.com/... @mikko : Zoom's actions today remind me of the 2002 feature freeze of Microsoft, which started their journey to better Windows security. “When we face a choice between adding features and resolving security issues, we need to choose security”, said Bill Gates. https://www.wired.com/... Antonio Garca Martnez / @antoniogm : Well, if every societal institution had performed as well as Zoom's infrastructure team, we'd be OK. https://twitter.com/... @andreasklinger : I have more years of experience in engineering than i like to mention. But this does not compute for me... Keeping the infrastructure in check for a 20x on that scale is insanely impressive. Hats off to the zoom eng + infrastructure team. https://twitter.com/... @dhh : This sounds great, but it's hard to take too seriously when the stance is “actually we were already doing great and being very transparent but you just didn't see it”. How you can say that while still lying about being end-to-end encrypted is something. https://www.theverge.com/... @uofgccs : Attention Zoom users! A vulnerability has been identified that could allow an attacker to gain control of a system or collect your Windows credentials. CCS strongly recommends updating your Zoom client immediately. @uofg @GuelphHumberUni More info: https://www.pcworld.com/... https://twitter.com/... Salvador Hernandez / @salhernandez : She was hosting a Zoom meeting for professional women of color, a way to connect and unwind during the pandemic. It got hijacked by trolls yelling the N-word at her https://www.buzzfeednews.com/ ... @buzzfeednews : Zoom meetings are being hijacked by people yelling racist slurs and flooding calls with graphic content https://www.buzzfeednews.com/ ... Vivek Wadhwa / @wadhwa : Have been using @zoom_us but am going to insist that if people want to speak to me, they use @Skype instead. Zoom is a disaster area for security and privacy: https://techcrunch.com/... SpaceX and Nasa just banned it: https://www.reuters.com/....
I compiled a list of every known Zoom security exploit, software bug, privacy failure, and bad decision (many now remediated) and what you can do about each of them. I had to add six in the last two days while writing & editing it. @TidBITS https://tidbits.com/...
Zoom has seen a 535% rise in daily traffic in the past month, but security researchers say the app is a ‘privacy disaster’ https://www.theguardian.com/ ...
A round-up from Bruce Schneier of the research showing how Zoom's “security” is a sick joke. If you have secrets to keep, don't go near this product. https://www.schneier.com/...
An exhaustive account of all Zoom's privacy and security transgressions. When you see it all collected like this.. well, just, wow. https://tidbits.com/...
The choices Zoom has made on encryption are reasonable. But they really shouldn't claim it's end-to-end encrypted. And they should stop with the muddled blog posts too. @lilyhnewman digs in deep. cc @dhh https://www.wired.com/...
Zoom has made a lot of claims and used a lot of very specific phrases in describing its encryption protections for meetings. Let's hash it out, shall we? https://www.wired.com/...
Despite the confusing back-and-forth messaging, it finally seems clear that, no, Zoom is indeed NOT end-to-end encrypted, as they were claiming for a long time. Unlike, say, Apple's FaceTime, which for up to 32 users, indeed IS e2e. https://www.wired.com/...
A Quick Look at the Confidentiality of Zoom Meetings by the team at @CitizenLab. https://citizenlab.ca/... (I wonder how much longer the UK Govt will be using it for cabinet meetings...) https://twitter.com/...
This is a very good and human-readable post by @matthew_d_green about how Zoom's encryption works, the good parts and the very bad parts, and how Zoom has a solid path forward to fix the most major problems https://blog.cryptographyengineering.co m/ ...
“Meetings on Zoom are encrypted using an algorithm with serious, well-known weaknesses, and sometimes using keys issued by servers in China, even when meeting participants are all in North America, according to researchers at the University of Toronto” https://theintercept.com/..…
Zoom has a lot of work to do if it wants to regain users' trust. In the meantime, if you continue using Zoom, consider these settings. https://www.eff.org/...
Zoom's security just gets worse and worse. Broken encryption (ECB), 128-bit instead of quoted 256-bit, with keys issued by servers in China https://citizenlab.ca/... @zoom_us https://twitter.com/...
Check out this blog post if you want to learn more about the technical background of the Zoom issue and its implications. Also, here is the full VMRay Analyzer report https://www.vmray.com/... ✌️ https://twitter.com/...
I wrote a non-technical post on the situation with Zoom and encryption. This mostly summarizes what we know from @citizenlab and Zoom itself: https://blog.cryptographyengineering.co m/ ...
Using Zoom? Their video messaging does NOT use end-to-end encryption. Sign the petition to tell @zoom_us to protect your sensitive personal and professional communications. 🔒 https://actionnetwork.org/...
Zoom is getting torn apart. That's not a bad thing. Very very few enterprise tools get the attention of world-class researchers. Even premier applications by huge companies go unexamimed b/c difficulty of obtaining and installing them. Plenty of Tier0 stuff written in C in 2007.
We appreciate the scrutiny and questions we have been getting - about how the service works, about our infrastructure and capacity, and about our privacy and security policies. These are the questions that will make Zoom better [Blog Post] https://blog.zoom.us/... by @ericsyuan
Looks like solid research by @citizenlab. If I'm reading it correctly, actors in China could have access to all the encryption keys needed to see calls. Keep this in mind when you chose to discuss sensitive info using #zoom. Obviously no mil/gov should talk classified on it. http…
Interesting research from Citizen Lab on Zoom - it raises concerns about Chinese end of the company - ‘during multiple test calls in North America, we observed keys for encrypting and decrypting meetings transmitted to servers in Beijing, China’ https://citizenlab.ca/...
When the first phase of this is over, we are going to wake up to the scale of the information security and privacy risks we have all been taking https://twitter.com/...
An analysis of Zoom by @billmarczak & @jsrailton reveals it *does not* use industry standard protocols for voice & video— encryption & decryption keys come from Chinese servers. Their conclusion: it's fine for family chats, not for journalists & activists.https://citizenlab.ca/ .…
Dear @zoom_us - as part of your focus on privacy and security over the next 90 days there is something we could critically use in education: the ability to record only the host side of a call. This will allow us to record and share classes without compromising student privacy. ht…
NEW: Zoom ‘unsuitable’ for government secrets, researchers say. New study from @citizenlab shows Zoom encryption is crackable and unsafe for high level meets. I understand gov is working on adapting other existing tools ‘at pace’ to deal with the current communications conundrum.…
People lost their minds when Zoom was sending small pieces of data to Facebook even when users weren't on FB. Wonder how they'll react when they hear Zoom is sometimes handling encryption keys in Beijing, even when callers aren't in China... https://www.forbes.com/...
Also worth noting: “For those using Zoom to keep in touch with friends, hold social events, or organize courses or lectures that they might otherwise hold in a public or semi-public venue, our findings should not necessarily be concerning.” https://twitter.com/...
New report from @citizenlab on confidentiality and encryption of Zoom meetings: “Researchers conclude that Zoom uses non-industry-standard cryptographic techniques with identifiable weaknesses and is not suitable for sensitive communications.” https://citizenlab.ca/...
A fantastic case study in how aggressively “making X easy” inevitably leads to “making X insecure.” If meeting confidentiality is not that important for your company then maybe the user exploit potential is note worthy. Zoom is a risky proposition for your employees to install. h…
Example of hyperbole for the Zoom discussion and horrid fear-mongering by the media and comments from individuals that are not even security researchers This type of news is exactly what is damaging to the security industry and trust in us. @guardian https://www.theguardian.com/ …
An important read for NGOs, #humanrights lawyers, activists and journalists using Zoom during the #COVID19 crisis. Surely this is a problem Zoom should be urgently fixing? #bizhumanrights https://twitter.com/...
Zoom's actions today remind me of the 2002 feature freeze of Microsoft, which started their journey to better Windows security. “When we face a choice between adding features and resolving security issues, we need to choose security”, said Bill Gates. https://www.wired.com/...
I have more years of experience in engineering than i like to mention. But this does not compute for me... Keeping the infrastructure in check for a 20x on that scale is insanely impressive. Hats off to the zoom eng + infrastructure team. https://twitter.com/...
This sounds great, but it's hard to take too seriously when the stance is “actually we were already doing great and being very transparent but you just didn't see it”. How you can say that while still lying about being end-to-end encrypted is something. https://www.theverge.com/.…
Attention Zoom users! A vulnerability has been identified that could allow an attacker to gain control of a system or collect your Windows credentials. CCS strongly recommends updating your Zoom client immediately. @uofg @GuelphHumberUni More info: https://www.pcworld.com/... htt…
She was hosting a Zoom meeting for professional women of color, a way to connect and unwind during the pandemic. It got hijacked by trolls yelling the N-word at her https://www.buzzfeednews.com/ ...
Have been using @zoom_us but am going to insist that if people want to speak to me, they use @Skype instead. Zoom is a disaster area for security and privacy: https://techcrunch.com/... SpaceX and Nasa just banned it: https://www.reuters.com/....