Media

Zoom Will Enable Waiting Rooms By Default To Stop Zoombombing (techcrunch.com) 47

Zoom is making some much-needed changes to prevent "Zoombombing," a term used to describe when someone successfully invades a public or private meeting over the videoconferencing platform to broadcast shock videos, pornography, or other disruptive content. The act was recently mentioned on the Department of Justice's website, warning that users who engage in this sort of video hacking could face fines and possible imprisonment. TechCrunch reports: Starting April 5th, it will require passwords to enter calls via Meeting ID, as these may be guessed or reused. Meanwhile, it will change virtual waiting rooms to be on by default so hosts have to manually admit attendees. [...] Zoom CEO Eric Yuan apologized for the security failures this week and vowed changes. But at the time, the company merely said it would default to making screensharing host-only and keeping waiting rooms on for its K-12 education users. Clearly it determined that wasn't sufficient, so now waiting rooms are on by default for everyone.

Zoom communicated the changes to users via an email sent this afternoon that explains "we've chosen to enable passwords on your meetings and turn on Waiting Rooms by default as additional security enhancements to protect your privacy." The company also explained that "For meetings scheduled moving forward, the meeting password can be found in the invitation. For instant meetings, the password will be displayed in the Zoom client. The password can also be found in the meeting join URL." Some other precautions users can take include disabling file transfer, screensharing or rejoining by removed attendees.

Privacy

Apple Brings Its Hardware Microphone Disconnect Feature To iPads (techcrunch.com) 26

Apple has brought its hardware microphone disconnect security feature to its latest iPads. From a report: The microphone disconnect security feature aims to make it far more difficult for hackers to use malware or a malicious app to eavesdrop on a device's surroundings. The feature was first introduced to Macs by way of Apple's T2 security chip last year. The security chip ensured that the microphone was physically disconnected from the device when the user shuts their MacBook lid. The idea goes that physically cutting off the microphone from the device prevents malware -- even with the highest level of âoerootâ device permissions -- from listening in to nearby conversations. Apple confirmed in a support guide that its newest iPads have the same feature. Any certified "Made for iPad" case that's attached and closed will trigger the hardware disconnect.
China

Zoom's Encryption Is 'Not Suited for Secrets' and Has Surprising Links To China, Researchers Discover (theintercept.com) 61

Meetings on Zoom, the increasingly popular video conferencing service, are encrypted using an algorithm with serious, well-known weaknesses, and sometimes using keys issued by servers in China, even when meeting participants are all in North America, according to researchers at the University of Toronto. From a report: The researchers also found that Zoom protects video and audio content using a home-grown encryption scheme, that there is a vulnerability in Zoom's "waiting room" feature, and that Zoom appears to have at least 700 employees in China spread across three subsidiaries. They conclude, in a report for the university's Citizen Lab -- widely followed in information security circles -- that Zoom's service is "not suited for secrets" and that it may be legally obligated to disclose encryption keys to Chinese authorities and "responsive to pressure" from them.
Security

A Hacker Has Wiped, Defaced More Than 15,000 Elasticsearch Servers (zdnet.com) 17

For the past two weeks, a hacker has been breaking into Elasticsearch servers that have been left open on the internet without a password and attempting to wipe their content, while also leaving the name of a cyber-security firm behind, trying to divert blame. From a report: According to security researcher John Wethington, one of the people who saw this campaign unfolding and who aided ZDNet in this report, the first intrusions began around March 24. The attacks appear to be carried with the help of an automated script that scans the internet for ElasticSearch systems left unprotected, connects to the databases, attempts to wipe their content, and then creates a new empty index called nightlionsecurity.com. The attacking script doesn't appear to work in all instances, though, as the nightlionsecurity.com index is also present in databases where the content has been left intact.
Twitter

Twitter Discloses Firefox Bug That Cached Private Files Sent or Received via DMs (zdnet.com) 42

Social networking giant Twitter today disclosed a bug on its platform that impacted users who accessed their platform using Firefox browsers. From a report: According to Twitter, its platform stored private files inside the Firefox browser's cache -- a folder where websites store information and files temporarily. Twitter said that once users left their platform or logged off, the files would remain in the browser cache, allowing anyone to retrieve it. The company is now warning users who share workstations or used a public computer that some of their private files may still be present in the Firefox cache. Malware present on a system could also scrape and steal this data, if ever configured to do so.
Privacy

The Internet is Now Rife With Places Where You Can Organize Zoom-bombing Raids (zdnet.com) 38

The internet is rife with online communities where users can go and share Zoom conference codes and request that pranksters connect and hurl insults, play pornographic material, or make death threats against other participants -- in a practice called Zoom-bombing or a Zoom raid. From a report: ZDNet began tracking the tactic since mid-March when the term was first coined following a TechCrunch article. Ever since then, Zoom-bombing incidents have increased, as articles in major news outlets like the New York Times and the BBC have made the practice a favorite pastime for all the teenagers stuck in their homes during the current coronavirus (COVID-19) quarantines. From a niche prank that started on a derelict Discord channel, Zoom-bombing has now spread to enormous proportions -- being so rampant these days that the FBI sent a nationwide alert last week, urging companies, schools, and universities to take steps to secure their Zoom channels. But as Zoom-bombing became more popular, more pranksters wanted to join on the fun, and more users wanted their friends' Zoom meetings disrupted. And as the old saying goes; where there's a demand, there's always a supply. Over the course of the past week, the number of places on the public internet where you can request a zoom raid from a gang of bored teenagers has exploded.
The Internet

Akamai, Amazon, Netflix, Microsoft, and Google Join Internet Routing Security Effort (theregister.co.uk) 13

A community effort to improve the internet's routing security has won the backing of some of the web's biggest names. From a report: Amazon, Google, Facebook, Microsoft, Akamai, and Netflix, among others, have signed up to the Mutually Agreed Norms for Routing Security (MANRS) group, in their roles as content delivery networks (CDNs) and cloud providers (CPs). MANRS's goal is to shore up the internet's lax security when it comes to routing people's connections around Earth. It is, essentially, depending on the circumstances, too easy for miscreants to hijack and redirect internet traffic from legit servers to malicious machines so that web browsing and other online activities can be snooped on or meddled with. This widespread issue is something that has become increasingly important in the past few years as the number and size of connectivity breakdowns and attacks on the global system have grown. Criminals and possibly government spies have realized the potential that exists in snatching people's internet traffic for surveillance, disruption, and theft. The MANRS group pushes four main approaches, two technical and two cultural: filtering, anti-spoofing, and then coordination and validation.
Privacy

SpaceX Bans Zoom Over Privacy Concerns (reuters.com) 52

Elon Musk's rocket company SpaceX has banned its employees from using video conferencing app Zoom, citing "significant privacy and security concerns," according to a memo seen by Reuters, days after U.S. law enforcement warned users about the security of the popular app. From a report: SpaceX's ban on Zoom Video illustrates the mounting challenges facing aerospace manufacturers as they develop technology deemed vital to national security while also trying to keep employees safe from the fast-spreading respiratory illness. In an email dated March 28, SpaceX told employees that all access to Zoom had been disabled with immediate effect. "We understand that many of us were using this tool for conferences and meeting support," SpaceX said in the message. "Please use email, text or phone as alternate means of communication."

NASA, one of SpaceX's biggest customers, also prohibits its employees from using Zoom, said Stephanie Schierholz, a spokeswoman for the U.S. space agency. The Federal Bureau of Investigation's Boston office on Monday issued a warning about Zoom, telling users not to make meetings on the site public or share links widely after it received two reports of unidentified individuals invading school sessions, a phenomenon known as "zoombombing."

Security

A Feature on Zoom Secretly Displayed Data From People's LinkedIn Profiles (nytimes.com) 39

After an inquiry from The New York Times reporters, Zoom said it would disable a data-mining feature that could be used to snoop on participants during meetings without their knowledge. From a report: For Americans sheltering at home during the coronavirus pandemic, the Zoom videoconferencing platform has become a lifeline, enabling millions of people to easily keep in touch with family members, friends, students, teachers and work colleagues. But what many people may not know is that, until Thursday, a data-mining feature on Zoom allowed some participants to surreptitiously access LinkedIn profile data about other users -- without Zoom asking for their permission during the meeting or even notifying them that someone else was snooping on them. The undisclosed data mining adds to growing concerns about Zoom's business practices at a moment when public schools, health providers, employers, fitness trainers, prime ministers and queer dance parties are embracing the platform. An analysis by The New York Times found that when people signed in to a meeting, Zoom's software automatically sent their names and email addresses to a company system it used to match them with their LinkedIn profiles.
Privacy

Microsoft President Calls Washington State's New Facial Recognition Law 'a Significant Breakthrough' (geekwire.com) 48

Microsoft President Brad Smith took a break from responding to the COVID-19 outbreak this week to praise Washington state's landmark facial recognition regulations. Washington Gov. Jay Inslee signed a bill Tuesday that establishes rules specifically governing facial recognition software. From a report: Smith called the law an "early and important model" and "a significant breakthrough" in a blog post published Tuesday. Some cities have enacted their own facial recognition rules, but Washington is the first to establish statewide regulations. "This balanced approach ensures that facial recognition can be used as a tool to protect the public, but only in ways that respect fundamental rights and serve the public interest," Smith said. The new law requires public agencies to regularly report on their use of facial recognition technology and test the software for fairness and accuracy. Law enforcement agencies must obtain a warrant before using facial recognition software in investigations unless there is an emergency. The bill also establishes a task force to study the use of facial recognition by government agencies. Under the bill, public entities using facial recognition software to make decisions that produce "legal effects" must ensure a human reviews the results. That category includes decisions that could affect a person's job, financial services, housing, insurance, and education.
Privacy

Cloudflare Launches a DNS-Based Parental Control Service (bleepingcomputer.com) 58

Cloudflare introduced today '1.1.1.1 for Families,' a privacy-focused DNS resolver designed to help parents in their efforts to safeguard their children's online security and privacyââââââ by automatically filtering out bad sites. From a report: This new tool makes it simple for parents to add protection from malware and adult content to the entire home network, allowing them to focus on working from home instead of worrying about their kids' online safety. "1.1.1.1 for Families leverages Cloudflare's global network to ensure that it is fast and secure around the world," Cloudflare's CEO Matthew Prince said in an announcement published today.
Security

Cash App Scammers Are Using Coronavirus To Exploit People (qz.com) 34

An anonymous reader shares a report: Reyna is a teenager in Florida whose family is strapped for cash amid the economic slowdown caused by the coronavirus. When the uber-popular beauty influencer Jeffree Star tweeted that he'd be giving out $30,000 via payment service Cash App to a random person who retweeted him, she did just that. Star's offer seems to have been legitimate -- and drummed up a lot of attention for the influencer. A woman actually won the $30,000, and Reyna missed out. But then another Twitter user messaged Reyna asking whether she wanted to get $250, she told Quartz. "My goal is to help those in need or need emergency cash," the person said. The catch was that she'd have to pay $25 first. "Your deposit along with our other earnings allows us to immediately send you your payment," the person said. Reyna sent the cash, and that's when the Twitter user blocked her, and her money was gone, she said.

What happened to Reyna is a popular Cash App scam called "cash-flipping," according to Satnam Narang, researcher at the cybersecurity company Tenable. Con artists are taking advantage of the coronavirus by pretending they are helping the needy. While Reyna simply got a direct message to lure her in after she expressed interest in a legitimate giveaway, other scammers have been promoting fake giveaways in public tweets adding "#coronavirus" in order to reach more people. Sometimes they will request money through Cash App pretending that it's a verification mechanism. "They'll say, you won this giveaway, send us $10 to verify to win 500 bucks," Narang said. The scammers say they have a special way of modifying the transactions through payment applications like Cash App, Paypal, Zelle, Venmo, or Apple Pay, Narang wrote in a blog post explaining the scams. "All they ask for is that the recipient share the initial cut with them for providing them this so-called service." This, of course, is all made up.

IOS

Apple's iOS 14 May Turn iCloud Keychain Into a True 1Password and LastPass Competitor (theverge.com) 28

Apple's native iOS password manager may be getting an overhaul later this year with the presumed release of iOS 14 that will make it more competitive with third-party options like 1Password and LastPass, reports 9to5Mac. From a report: Right now, iCloud Keychain can store your passwords and help autofill them on the iPhone, where copying and pasting long strings of letters and numbers or manually doing so has been a headache since the advent of the mobile touchscreen. But it doesn't have reminders for changing those passwords like competitors do, and it doesn't support two-factor authentication (2FA) options. That means users are still stuck using potentially insecure methods like SMS or email in the event that they do have 2FA set up.
Security

Ex-NSA Hacker Drops New Zero-Day Doom for Zoom (techcrunch.com) 22

Zoom's troubled year just got worse. From a report: Now that a large portion of the world is working from home to ride out the coronavirus pandemic, Zoom's popularity has rocketed, but also has led to an increased focus on the company's security practices and privacy promises. Hot on the heels of two security researchers finding a Zoom bug that can be abused to steal Windows passwords, another security researcher found two new bugs that can be used to take over a Zoom user's Mac, including tapping into the webcam and microphone. Patrick Wardle, a former NSA hacker and now principal security researcher at Jamf, dropped the two previously undisclosed flaws on his blog Wednesday, which he shared with TechCrunch. The two bugs, Wardle said, can be launched by a local attacker -- that's where someone has physical control of a vulnerable computer. Once exploited, the attacker can gain and maintain persistent access to the innards of a victim's computer, allowing them to install malware or spyware.
Security

OpenWRT Code-Execution Bug Puts Millions of Devices At Risk (arstechnica.com) 60

Dan Goodin writes via Ars Technica: For almost three years, OpenWRT -- the open source operating system that powers home routers and other types of embedded systems -- has been vulnerable to remote code-execution attacks because updates were delivered over an unencrypted channel and digital signature verifications are easy to bypass, a researcher said. Security researcher Guido Vranken, however, recently found that updates and installation files were delivered over unencrypted HTTPs connections, which are open to attacks that allow adversaries to completely replace legitimate updates with malicious ones. The researcher also found that it was trivial for attackers with moderate experience to bypass digital-signature checks that verify a downloaded update as the legitimate one offered by OpenWTR maintainers. The combination of those two lapses makes it possible to send a malicious update that vulnerable devices will automatically install.
[...]
The researcher said that OpenWRT maintainers have released a stopgap solution that partially mitigates the risk the bug poses. The mitigation requires new installations to be "set out from a well-formed list that would not sidestep the hash verification. However, this is not an adequate long-term solution because an attacker can simply provide an older package list that was signed by the OpenWRT maintainers." From there, attackers can use the same exploits they would use on devices that haven't received the mitigation. OpenWRT maintainers didn't immediately respond to questions asking why installation and update files are delivered over HTTP and when a longer-term fix might be available. In the meantime, OpenWRT users should install either version 18.06.7 or 19.07.1, both of which were released in February. These updates provide the stopgap mitigation.

Security

Marriott Discloses New Data Breach Impacting 5.2 Million Guests (cnet.com) 12

An anonymous reader quotes a report from CNET: Marriott International said Tuesday that names, mailing addresses, loyalty account numbers and other personal information of an estimated 5.2 million guests may've been exposed in a data breach. This is the second major security incident to hit the hotel group in less than two years. Marriott said it spotted that an "unexpected amount" of guest information may've been accessed at the end of February using the login credentials of two employees at a franchise property. The hotel group said information exposed may include names, addresses, emails, phone numbers and birthdays as well as loyalty account details and information like room preferences. Marriott said the investigation is ongoing but that it doesn't believe credit card numbers, passport information or driver's license numbers were exposed. In 2018, Marriott announced that hackers compromised the reservation database for its Starwood division, exposing records of up to 383 million guests and more than 5 million passport numbers.
Communications

FCC Mandates Robocall-fighting Tech Be in Use By End of June 2021 (cnet.com) 20

The Federal Communications Commission voted Tuesday to finalize rules requiring phone companies to use the Shaken/Stir protocol to automatically block calls to fight illegal robocalls. The new rules mandate the use of the technology by all voice providers by the end of June of 2021. From a report: The rules come after Congress passed and President Donald Trump signed into law the Traced Act last year. The law, which makes Shaken/Stir compliance mandatory for all voice service providers, directed the FCC to develop rules within 18 months. The FCC has said previously that eliminating the wasted time and the nuisance caused by illegal scam robocalls could save the US economy $3 billion annually.
Privacy

Zoom is Leaking Peoples' Email Addresses and Photos To Strangers (vice.com) 35

Popular video-conferencing Zoom is leaking personal information of at least thousands of users, including their email address and photo, and giving strangers the ability to attempt to start a video call with them through Zoom. From a report: The issue lies in Zoom's "Company Directory" setting, which automatically adds other people to a user's lists of contacts if they signed up with an email address that shares the same domain. This can make it easier to find a specific colleague to call when the domain belongs to an individual company. But multiple Zoom users say they signed up with personal email addresses, and Zoom pooled them together with thousands of other people as if they all worked for the same company, exposing their personal information to one another.
Security

FBI Re-sends Alert About Supply Chain Attacks For the Third Time in Three Months (zdnet.com) 26

The FBI has issued an alert on Monday about state-sponsored hackers using the Kwampirs malware to attack supply chain companies and other industry sectors as part of a global hacking campaign. From a report: This marks the third alert about this particular group sent this year, in as many months, after the FBI sent alerts on January 6 and February 5. This time around, the FBI highlighted that some of the group's targets are organizations in the healthcare industry, currently grappling with the coronavirus (COVID-19) outbreak. Besides sending out a PIN (Private Industry Notification), the FBI has also published two Flash alerts, one containing YARA rules to identify the group's Kwampirs malware on infected networks, and the second containing a technical report, complete with IOCs (indicators of compromise).
Encryption

Zoom Meetings Aren't End-to-End Encrypted, Despite Misleading Marketing (theintercept.com) 74

An anonymous reader shares a report: Zoom, the video conferencing service whose use has spiked amid the Covid-19 pandemic, claims to implement end-to-end encryption, widely understood as the most private form of internet communication, protecting conversations from all outside parties. In fact, Zoom is using its own definition of the term, one that lets Zoom itself access unencrypted video and audio from meetings. With millions of people around the world working from home in order to slow the spread of the coronavirus, business is booming for Zoom, bringing more attention on the company and its privacy practices, including a policy, later updated, that seemed to give the company permission to mine messages and files shared during meetings for the purpose of ad targeting.

Still, Zoom offers reliability, ease of use, and at least one very important security assurance: As long as you make sure everyone in a Zoom meeting connects using "computer audio" instead of calling in on a phone, the meeting is secured with end-to-end encryption, at least according to Zoom's website, its security white paper, and the user interface within the app. But despite this misleading marketing, the service actually does not support end-to-end encryption for video and audio content, at least as the term is commonly understood. Instead it offers what is usually called transport encryption.
Further reading: Regarding Zoom.

Slashdot Top Deals