Zoom who have had a couple of issues this week that made the news, which did get fixed by Zoom and Apple, now may be having their competitors throw some shade on them. Case in point is GoTo which own GoToMeeting, GoToWebinar among other products. I was tipped off by a reader that they got an email that takes you to this blog entry which details why their security is better than Zoom’s security:
To be perfectly clear, LogMeIn and our meeting products, including GoToMeeting, GoToWebinar, GoToTraining, GoToConnect and join.me, do not have this security design flaw. This flaw is not, and has never been, part of our products.
However, it is helpful to understand the report itself and why the approach has caused such concern. The root of the issue is a web server which is installed as part of Zoom’s native Mac client to allow it to launch the Zoom app from a web page, bypassing the operating system’s security controls. By bypassing normal browser-based security, this web server can be used to activate/trigger the user’s camera (and potentially execute other harmful code on the user’s machine). Worse, when the client is uninstalled, this active webserver is left behind on the machine.
LogMeIn also delivers simple meeting launching from a web browser, but does it in a much more secure way, using URI handlers. As Jonathan writes in his report: “Alternative methodologies like registering custom URI handlers (for example, a xxxx:// URI handler) with the browsers is a more secure solution. When these URI handlers are triggered, the browser explicitly prompts the user for confirmation about opening the app.”This is exactly how we handle our launch of an already installed LogMeIn application such as GoToMeeting and our other collaboration products.
This security posture avoids bypassing operating system or browser security controls. We take a similar stance towards privacy with things like video (we do not enable video by default) and always offering clean uninstalls.
Additionally, we offer the web clients for our products that can be used in scenarios where downloading an application is not an option or is security restricted.
So. I’ll ask the question. Is this informational to reassure customers that GoTo products are secure? Or is this meant to throw a bit of shade on Zoom? Or perhaps both? I guess it depends on your perspective. But I do expect that others who are in the video conferencing game to join in on the fun and perhaps do the same thing that GoTo is doing in some form.
Zoom Seriously Needs To Up Their Security Game And Do So Quickly And Publicly
Posted in Commentary with tags Zoom on April 1, 2020 by itnerdZoom is the app de jour. Companies, individuals, and even the UK Government are using it to keep in touch, conduct meetings, and conduct business. However as Zoom’s profile has increased, so has the scrutiny of the app. And that scrutiny has revealed some troubling flaws within the app:
The Mac related issues can only be exploited if you lose physical access to the Mac. So your best mitigation strategy is to maintain physical control of your Mac and lock the Mac so that nobody can access it. More details can be found here. It is a bit nerdy. Thus for a less nerdy explanation, click here.
Then there’s the fact that Zoom advertises itself as being “end to end encrypted.” Except that it isn’t according to security researchers, which in this day and age is really bad. And what’s worse is that Zoom continues to pedal what I consider to be “fake news” insisting that it is end to end encrypted.
And finally, all of that is on top of a phenomena called “Zoom Bombing” which can be best described as this. An uninvited guest join your meeting and then starts displaying offensive content. It’s become a bit of an unfortunate trend as Zoom has become more popular. You can find out more about this here. But my recommendation is that you enable the Zoom waiting room functionality. It can be best described as this via this document that Zoom has on the topic:
Attendees cannot join a meeting until a host admits them individually from the waiting room. If Waiting room is enabled, the option for attendees to join the meeting before the host arrives is automatically disabled.
All of these issues have the same root cause. Zoom is a company that has more marketing sense than security sense. This is the same company that got caught with a serious flaw that enabled video calls with zero interaction on the Mac, which they sort of fixed. But it wasn’t good enough for Apple as the lack of a fix that they liked forced them to get involved to take action against Zoom in a manner that was and still is unprecedented. Thus it’s hardly surprising that Zoom finds itself in a situation where their shoddy security practices are on full display.
Zoom can fix this, but they need to take decisive action immediately. Here’s what I would look for
I will be interested if Zoom does all of the above. Because if they don’t, I can easily see a scenario where Zoom’s success may be very short lived.
2 Comments »