D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

[LUG] zoom not fit for purpose

 

I was already sceptical of Zoom even before Covid-19 catapulted it into the limelight but as it came up here just recently and people were already using it, here's a (shamelessly cribbed from someone else online) list of the unforgivable crap they've been caught at recently:
- installing a hidden web server on macOS clients that persists even 
after uninstalling Zoom (https://www.theverge.com/2019/7/10/2068 ... 
nerability)
- claiming to have end-to-end enryption while actually only delivering 
endpoint-to-server encryption (https://www.google.com/url?sa=t&rct=j&q 
... Leug4pNcUP)
- leaking information to Facebook 
(https://www.bloomberg.com/news/articles ... sonal-data)
- leaking information to other customers who happen to share a domain 
(https://www.vice.com/en_us/article/k7e9 ... ses-photos1)
- actively evading installer security checks on macOS 
(https://twitter.com/c1truz_/status/12447376729308241932)
- leaking credentials due to a very ill-advised 'feature' 
(https://www.bleepingcomputer.com/news/s ... attackers/)
- using easily guessable meeting id numbers that allow random people on 
the internet to join (zoombombing) 
(https://mobile.twitter.com/dhh/status/1 ... 74885836813)
And today's new addition:

- Zoom Lets Attackers Steal Windows Credentials via UNC Links
(https://www.bleepingcomputer.com/news/security/zoom-lets-attackers-steal-windows-credentials-via-unc-links/)

Seriously what the hell are these people doing?

Conclusion: only use it if forced to at gun point by whoever is paying your salary. If you're a sysadmin put your foot down and overrule your pointy haired boss and ban it at the network edge already.
Microsoft Skype or even Facebook Messenger would be a less terrible 
choice at this point. _Not communicating_ would be a better choice than 
using Zoom at this stage.
--
The Mailing List for the Devon & Cornwall LUG
https://mailman.dcglug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq