<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is Zoom conferencing safe to use or not? in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/36230#M4596</link>
    <description>&lt;P&gt;Right.&amp;nbsp; Although, as a security person, I may hate to admit it, the &lt;A href="http://www.infosecbc.org/" target="_blank" rel="noopener"&gt;Vancouver Chapte&lt;/A&gt;r is using Zoom for its &lt;A href="https://community.isc2.org/t5/Chapters/Vancouver-Chapter-virtual-meeting-June-12/m-p/36088#M461" target="_blank" rel="noopener"&gt;June 12th virtual/remote meeting&lt;/A&gt;.&amp;nbsp; As part of the testing for holding it, we tried to figure out whether you actually need a Zoom account or have Zoom installed to "attend."&amp;nbsp; The answer seems to be "no," but with some caveats.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Right, this is complicated. And I'm not sure that I am able to test a complete "no-install" situation, since my machines &lt;STRONG&gt;all&lt;/STRONG&gt; appear to be contaminated with Zoom.&amp;nbsp; (More on that later.) (I'm pulling up the old Android tablet right now to try and remove Zoom from it (it was a pre-5 version anyway: 4.4.5391.0520) and see if I can test that.)&amp;nbsp; (But it never did cooperate.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On my main desktop, I have never installed Zoom (since I don't have a Webcam on it), but I have done some work on my rslade@gmail.com account (via the Avast browser), and have used the Chrome browser with a Zoom install on the same account. I seldom use Edge, so I don't think I have anything installed on the Edge browser, but the install via Chrome seems to have "contaminated" my desktop Win10 machine in its entirety.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, Fred set up a test meeting, and, on the Edge browser, I entered the URL and got the screen that shows as&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="zoom no install reg 6.PNG" style="width: 999px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/4189i8144C08A8FAA894D/image-size/large?v=v2&amp;amp;px=999" role="button" title="zoom no install reg 6.PNG" alt="zoom no install reg 6.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Figure: zoom no install reg 6.PNG&lt;BR /&gt;I registered using my rmslade@shaw.ca address, which I have never before used for a Zoom meeting. This resulted in&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="zoom no install reg 5.PNG" style="width: 999px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/4190i801C799DBBABE132/image-size/large?v=v2&amp;amp;px=999" role="button" title="zoom no install reg 5.PNG" alt="zoom no install reg 5.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Figure: zoom no install reg 5.PNG&lt;BR /&gt;I clicked on the link (the lo-o-o-ng URL) provided, and got&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="zoom no install reg 4.PNG" style="width: 918px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/4191iDD488B906CBB0A54/image-size/large?v=v2&amp;amp;px=999" role="button" title="zoom no install reg 4.PNG" alt="zoom no install reg 4.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Figure: zoom no install reg 4.PNG&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, at this point, I have to strongly note that I did &lt;STRONG&gt;not&lt;/STRONG&gt; click on the "download &amp;amp; run Zoom" link. I &lt;STRONG&gt;did&lt;/STRONG&gt; click on the "join from your browser" link. This, unfortunately, brought up&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="zoom no install reg 3.PNG" style="width: 932px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/4192i8721325BAD12AF89/image-size/large?v=v2&amp;amp;px=999" role="button" title="zoom no install reg 3.PNG" alt="zoom no install reg 3.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Figure: zoom no install reg 3.PNG&lt;BR /&gt;which was definitely not in my browser. Any of them. It was Zoom.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this point, looking back at my browser, I took a screenshot of&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="zoom no install reg 1.PNG" style="width: 994px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/4193iD78C690CD7DD4876/image-size/large?v=v2&amp;amp;px=999" role="button" title="zoom no install reg 1.PNG" alt="zoom no install reg 1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Figure: zoom no install reg 1.PNG&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;There are two things to note. The first is that I definitely did not click on the "download Zoom" link. The second is to note the bottom message on the screen about Zoom_[hex numbers].exe. I did not either run or save it. As previously noted, the fact that Zoom came up was from a previous install via a different browser. At this point, I probably don't have any machines in the house that are uncontaminated by Zoom.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, Zoom is very "helpful" about getting onto your machine. As a malware researcher, I'm not sure how I feel about that. On the one hand, we can probably offer the meeting to anyone with a browser, regardless of whether they have a Zoom account or have ever used Zoom. On the other hand, as a drive-by download, it works great, and I'm not really thrilled aobut having stuff installed on my machine with lots of access that I never gave it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone is welcome to join our meeting, of course, but anyone who has not used Zoom is particularly welcome, and we'd love to hear about your experiences.&amp;nbsp; The registration for the meeting is &lt;A href="https://clio.zoom.us/meeting/register/tJckcu-prDkjGtCvVwZC2Kq3KkEo5Jo740q8" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&amp;nbsp; It starts at 2 pm, Pacific time, but Fred and I will be on from 1:30 pm, and, if you want to do some testing from a "cold" machine and see how easy or hard it is to get on, we'd be grateful.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jun 2020 19:03:48 GMT</pubDate>
    <dc:creator>rslade</dc:creator>
    <dc:date>2020-06-08T19:03:48Z</dc:date>
    <item>
      <title>Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34355#M4224</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to "The Intercept" Zoom has some issues, which can result in data leakage, privacy and apparently has encryption issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does it have issues, during this crisis, as it is being actively used even by New Zealand Government agencies too for updates:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://theintercept.com/2020/03/31/zoom-meeting-encryption/" target="_blank"&gt;https://theintercept.com/2020/03/31/zoom-meeting-encryption/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.businessinsider.com.au/zoom-privacy-issues-fbi-facebook-data-sharing-2020-3?r=US&amp;amp;IR=T" target="_blank"&gt;https://www.businessinsider.com.au/zoom-privacy-issues-fbi-facebook-data-sharing-2020-3?r=US&amp;amp;IR=T&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://arstechnica.com/tech-policy/2020/03/zooms-privacy-problems-are-growing-as-platform-explodes-in-popularity/" target="_blank"&gt;https://arstechnica.com/tech-policy/2020/03/zooms-privacy-problems-are-growing-as-platform-explodes-in-popularity/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or does someone have an agenda against the company?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:29:10 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34355#M4224</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-10-09T09:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34356#M4225</link>
      <description>&lt;P&gt;There's always room for a good conspiracy theory isn't there? But, the IPO has passed and we are living with a deflated stock. Zoom software has always had some &lt;STRONG&gt;serious software defects&lt;/STRONG&gt; that have been discussed in public for years. Did they ever fix them? No. Did anyone have the need to use their software? No. Times have changed. Now, they need to go back and re-engineer their product if they care about their reputation and stock price. Want more conspiracy? Just look at the &lt;STRONG&gt;49 CVEs&lt;/STRONG&gt; on record&amp;nbsp;&lt;A href="https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=zoom" target="_blank" rel="noopener"&gt;here&lt;/A&gt;. Btw those are just the published ones...&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 02:20:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34356#M4225</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2020-04-01T02:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34357#M4226</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/887781263"&gt;@AppDefects&lt;/a&gt;&amp;nbsp;&amp;nbsp; Thanks for the information - interesting that lots of new Zoom domains are being created actively every day:&amp;nbsp; &lt;A href="https://securityaffairs.co/wordpress/100752/cyber-crime/coronavirus-zoom-campaign.html" target="_blank"&gt;https://securityaffairs.co/wordpress/100752/cyber-crime/coronavirus-zoom-campaign.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During this current worldwide situation.&amp;nbsp; Seems they need to do a lot of work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 03:13:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34357#M4226</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2020-04-01T03:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34359#M4227</link>
      <description>&lt;P&gt;How long is this story going to run?&amp;nbsp; &lt;A href="https://www.theverge.com/2020/3/31/21201234/zoom-end-to-end-encryption-video-chats-meetings" target="_blank"&gt;https://www.theverge.com/2020/3/31/21201234/zoom-end-to-end-encryption-video-chats-meetings&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 03:30:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34359#M4227</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2020-04-01T03:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34360#M4228</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/887781263"&gt;@AppDefects&lt;/a&gt;Yes, add another CVE against Zoom:&amp;nbsp; They have some work to do:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.itnews.com.au/news/zoom-for-windows-leaks-network-credentials-runs-code-remotely-545883?eid=3&amp;amp;edate=20200401&amp;amp;utm_source=20200401_PM&amp;amp;utm_medium=newsletter&amp;amp;utm_campaign=daily_newsletter" target="_blank"&gt;https://www.itnews.com.au/news/zoom-for-windows-leaks-network-credentials-runs-code-remotely-545883?eid=3&amp;amp;edate=20200401&amp;amp;utm_source=20200401_PM&amp;amp;utm_medium=newsletter&amp;amp;utm_campaign=daily_newsletter&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 03:32:43 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34360#M4228</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2020-04-01T03:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34368#M4230</link>
      <description>&lt;P&gt;We use it, and I don't think it is a big problem.&amp;nbsp; Like a lot of companies, they have been thrust into the limelight due to Corona, and some issues are showing up.&amp;nbsp; The privacy policy thing I'd like to understand, did they make changes to practices, or just clarify their policy language?&amp;nbsp; That is, were they selling a bunch of information, then stopped when they got caught, or did they have very permissive language originally, but better practices, then trued up to the practices.&amp;nbsp; I see a lot of complaints about people being able to crash meetings.&amp;nbsp; OK, so enable your meeting passwords, which they have recently changed to as a default because of this.&amp;nbsp; Maybe they should have had that as default for a while, but they offered it, for users to use to protect their meetings, and if they weren't used, are they to blame?&amp;nbsp; Lastly, the encryption thing. To me it depends on what you consider and end.&amp;nbsp; In a one on one call, the ends could be seen as the users.&amp;nbsp; However, in a group conference call, the ends include the conferencing server, as they have to.&amp;nbsp; You couldn't scale to a 100 users with 99^2 encrypted streams between them.&amp;nbsp; Slightly overzealous marketing?&amp;nbsp; Sure.&amp;nbsp; That said, heavy on the slightly.&amp;nbsp; Their definition of E2E encryption is far less concerning to me than a lot of things I see every day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The iOS SDK thing, I'll give them poor monitoring practice marks, but the fact that it was only iOS to Facebook seems to indicate that is what it was, poor development practices that allowed something to be enabled.&amp;nbsp; If they were serious about monetizing that information, they would have done it with a lot more client types.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the end, I think they are generally a good company and product.&amp;nbsp; There are certainly risks associated, as always, but one can minimize them, and in the balance of what they provide, I think it is a net gain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 11:55:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34368#M4230</guid>
      <dc:creator>mgorman</dc:creator>
      <dc:date>2020-04-01T11:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34373#M4231</link>
      <description>&lt;P&gt;I just saw this one, and have to update my comments to say that I think they have more quality issues than I thought.&amp;nbsp; Some of the articles seem to be piling on, but things like this one show that they have poor practices from a security standpoint, so the balance is tipping in risk/reward.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 14:14:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34373#M4231</guid>
      <dc:creator>mgorman</dc:creator>
      <dc:date>2020-04-01T14:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34379#M4233</link>
      <description>&lt;P&gt;There are a significant number of security issues with Zoom, but, overall, it seems to be a possible tool, if you know, and accept, the specific risks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the moment, the major one seems to be the popularity.&amp;nbsp; As previously noted, at the moment &lt;STRONG&gt;everyone&lt;/STRONG&gt; wants to get on the Zoom/teleconferencing bandwagon, and &lt;STRONG&gt;everyone&lt;/STRONG&gt; is trying to download the app.&amp;nbsp; (The fact that the Apple App Store, the Google/Android Play Store, and the Microsoft Store all have apps called zoom that have nothing to do with teleconferencing doesn't make things any easier.)&amp;nbsp; Just to be clear, we are talking about &lt;A href="https://zoom.us/" target="_blank" rel="noopener"&gt;zoom.us&lt;/A&gt;, and if you download something from some other zoom domain you may be in (malware) trouble.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A lot of hackers seem to be having fun with the conference number guessing.&amp;nbsp; Since conferences are identified and managed via a nine digit number, hackers can "join" your conference if they guess the right number.&amp;nbsp; At the moment, this seems to be more of a game where they "share" pr0n (drat you, &lt;A href="https://community.isc2.org/t5/Member-Support/Request-to-remove-profanity-adult-content-filters/m-p/13328#M2651" target="_blank" rel="noopener"&gt;dreaded "community" pr0n filter&lt;/A&gt;) in the middle of family calls, and other such annoyances (and sometimes more than &lt;A href="https://www.businessinsider.com/aa-intergroup-meetings-zoom-bombing-trolls-alcoholics-anonymous-2020-3" target="_blank" rel="noopener"&gt;annoyances&lt;/A&gt;).&amp;nbsp; At the moment there doesn't seem to be too much in the way of targetted attacks.&amp;nbsp; You can use a "password" to "protect" you call, but, since it is only a (six digit?) number, I'm not sure how much protection there is against automated password sequencing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, Zoom seems to have a pretty cavalier attitude towards security and privacy.&amp;nbsp; It may become the "Facebook" of teleconferencing.&amp;nbsp; Be aware of the various threats, attacks, and vulnerabilities, but, particularly in the midst of this crisis, it may be an acceptable risk for the communications benefit.&amp;nbsp; We, in the &lt;A href="http://www.infosecbc.org/" target="_blank" rel="noopener"&gt;Vancouver Chapter&lt;/A&gt;, are trying to set up a virtual meeting and presentation, likely around April 17th.&amp;nbsp; (In fact, I'm running a practice test, for those interested in Zoom meetings, in less than an hour:&lt;/P&gt;&lt;P&gt;Topic: Security SIG test meeting&lt;BR /&gt;Time: Apr 1, 2020 11:00 AM Vancouver&lt;/P&gt;&lt;P&gt;Join Zoom Meeting&lt;BR /&gt;&lt;A href="https://us04web.zoom.us/j/679324276" target="_blank" rel="noopener"&gt;https://us04web.zoom.us/j/679324276&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Meeting ID: 679 324 276 )&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 17:55:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34379#M4233</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2020-04-01T17:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34384#M4236</link>
      <description>&lt;P&gt;HI All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apologies if this upsets anyone:&amp;nbsp; &lt;A href="https://www.theregister.co.uk/2020/04/01/zoom_spotlight/" target="_blank"&gt;https://www.theregister.co.uk/2020/04/01/zoom_spotlight/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's just a headline from the Register UK source.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even the Prime Minister of UK was caught using Zoom - crazy people.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 19:43:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34384#M4236</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2020-04-01T19:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34386#M4237</link>
      <description>&lt;P&gt;Tech Crunch created a summary page of recent concerns.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://techcrunch.com/2020/03/31/zoom-at-your-own-risk/" target="_blank"&gt;https://techcrunch.com/2020/03/31/zoom-at-your-own-risk/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 20:51:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34386#M4237</guid>
      <dc:creator>kpinkham</dc:creator>
      <dc:date>2020-04-01T20:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34387#M4238</link>
      <description>&lt;P&gt;And more comes out of the woodwork:&amp;nbsp; Apparently NZ Government stated one could use Zoom up to the level of RESTRICTED - given the circumstances, I think there is a case for the Privacy Commissioner to step in purely on the protection of PII given the current circumstances.&amp;nbsp;&amp;nbsp; They should stop using it immediately.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://threatpost.com/two-zoom-zero-day-flaws-uncovered/154337/" target="_blank"&gt;https://threatpost.com/two-zoom-zero-day-flaws-uncovered/154337/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 21:39:55 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34387#M4238</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2020-04-01T21:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34389#M4239</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/467994801"&gt;@kpinkham&lt;/a&gt;There an item called Zoom Bombing as well.&amp;nbsp; Found this piece on how to protect yourselves, should you wish to carry on using Zoom.&amp;nbsp; &lt;A href="https://www.linkedin.com/pulse/3-ways-protect-your-zoom-meetings-jason-little/?trackingId=wiZMBiHJSv2NxRGbQiTWvA%3D%3D" target="_blank"&gt;https://www.linkedin.com/pulse/3-ways-protect-your-zoom-meetings-jason-little/?trackingId=wiZMBiHJSv2NxRGbQiTWvA%3D%3D&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 23:24:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34389#M4239</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2020-04-01T23:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34409#M4247</link>
      <description>&lt;P&gt;90 day feature freeze to "clean up security and privacy".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.theverge.com/2020/4/2/21204018/zoom-security-privacy-feature-freeze-200-million-daily-users" target="_blank"&gt;https://www.theverge.com/2020/4/2/21204018/zoom-security-privacy-feature-freeze-200-million-daily-users&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2020 16:51:00 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34409#M4247</guid>
      <dc:creator>kpinkham</dc:creator>
      <dc:date>2020-04-02T16:51:00Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34419#M4250</link>
      <description>&lt;P&gt;Interesting:&amp;nbsp; &lt;A href="https://www.securityweek.com/zooms-security-and-privacy-woes-violated-gdpr-expert-says" target="_blank"&gt;https://www.securityweek.com/zooms-security-and-privacy-woes-violated-gdpr-expert-says&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could be a case of GDPR issues as well.&amp;nbsp; I wonder what CCPA would make of this too?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2020 21:58:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34419#M4250</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2020-04-02T21:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34442#M4253</link>
      <description>&lt;P&gt;Well, a few more issues with encryption.&amp;nbsp; Plus some interesting points about Zoom's relationship with China.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://theintercept.com/2020/04/03/zooms-encryption-is-not-suited-for-secrets-and-has-surprising-links-to-china-researchers-discover/" target="_blank" rel="noopener"&gt;https://theintercept.com/2020/04/03/zooms-encryption-is-not-suited-for-secrets-and-has-surprising-links-to-china-researchers-discover/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the quick (really quick!) and dirty attitude to development.&amp;nbsp; Particularly in regard to crypto.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto-a-quick-look-at-the-confidentiality-of-zoom-meetings/" target="_blank" rel="noopener"&gt;https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto-a-quick-look-at-the-confidentiality-of-zoom-meetings/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, also, some advice on &lt;A href="https://nakedsecurity.sophos.com/2020/04/03/5-things-you-can-do-today-to-make-zooming-safer/" target="_blank" rel="noopener"&gt;making Zoom safer&lt;/A&gt;.&amp;nbsp; (OK, I said "safer."&amp;nbsp; Not completely safe.&amp;nbsp; And China is probably still going to be able to listen in on every conversation.&amp;nbsp; If they want to ...)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(The advice to update is probably important.&amp;nbsp; Zoom &lt;STRONG&gt;does&lt;/STRONG&gt; seem to be making some effort here: Yesterday the client I have on a Windows machine asked me to update, and today, at the end of a call/meeting, the Mac client asked me to update.&amp;nbsp; An old (&lt;STRONG&gt;really&lt;/STRONG&gt; old) Android device tells me to update, but won't install the update.&amp;nbsp; My newer Android phone hasn't said anything, but I suspect it's updated by itself.)&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 18:46:00 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34442#M4253</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2020-04-03T18:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34443#M4254</link>
      <description>&lt;P&gt;If you want to avoid Zoom, there's always &lt;A href="https://github.com/jitsi/jitsi-meet" target="_blank" rel="noopener"&gt;Jitsi Meet&lt;/A&gt;.&amp;nbsp; I have zero experience with it, but I'm dying to try it out ...&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 18:48:17 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34443#M4254</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2020-04-03T18:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34447#M4255</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1324864413"&gt;@rslade&lt;/a&gt;and all:&amp;nbsp; Here is a very good report on Zoom, which many should find very useful in determining their best course of action:&amp;nbsp; &lt;A href="https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto-a-quick-look-at-the-confidentiality-of-zoom-meetings/" target="_blank" rel="noopener"&gt;https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto-a-quick-look-at-the-confidentiality-of-zoom-meetings/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the best thing is - it is Canadian......&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 22:52:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34447#M4255</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2020-04-03T22:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34450#M4258</link>
      <description>&lt;P&gt;The founder and CEO of Zoom has &lt;A href="https://blog.zoom.us/wordpress/2020/04/01/a-message-to-our-users/" target="_blank" rel="noopener"&gt;apologized&lt;/A&gt; to the video conferencing app's millions of users after coming under fire for a host of privacy issues at a time when it has emerged as a vital social and professional lifeline for many.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"We recognize that we have fallen short of the community's -- and our own -- privacy and security expectations," Eric Yuan said in a blog post on Wednesday. "For that, I am deeply sorry."&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Zoom will stop adding new features for the next 90 days and instead focus solely on addressing privacy issues, Yuan said. The company will also release a transparency report, similar to the ones periodically shared by tech giants, which details requests for data or content from government authorities.&lt;/P&gt;</description>
      <pubDate>Sat, 04 Apr 2020 02:17:09 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34450#M4258</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2020-04-04T02:17:09Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34451#M4259</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/887781263"&gt;@AppDefects&lt;/a&gt;The founder may have apologies and promised updates, but when they send the encryption keys to a server in China - I certainly will not be using them for hosting conferences.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.securityweek.com/keys-used-encrypt-zoom-meetings-sent-china-researchers" target="_blank" rel="noopener"&gt;https://www.securityweek.com/keys-used-encrypt-zoom-meetings-sent-china-researchers&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And certainly not for discussions involving PII or Government discussions like the Prime Ministers of UK and Nw Zealand recently did on numerous occasions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Sat, 04 Apr 2020 03:08:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34451#M4259</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2020-04-04T03:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: Is Zoom conferencing safe to use or not?</title>
      <link>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34468#M4260</link>
      <description>&lt;P&gt;Wondering how Zoom was Fedramp approved by the US government after reading all this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://marketplace.fedramp.gov/#/product/zoom-for-government?sort=productName&amp;amp;productNameSearch=zoom" target="_blank"&gt;https://marketplace.fedramp.gov/#/product/zoom-for-government?sort=productName&amp;amp;productNameSearch=zoom&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Apr 2020 16:00:34 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Is-Zoom-conferencing-safe-to-use-or-not/m-p/34468#M4260</guid>
      <dc:creator>kpinkham</dc:creator>
      <dc:date>2020-04-04T16:00:34Z</dc:date>
    </item>
  </channel>
</rss>

