<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Picking a Collab Tool - NSA Help in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Picking-a-Collab-Tool-NSA-Help/m-p/35147#M2623</link>
    <description>&lt;P&gt;On April 24, 2020, the U.S. National Security Agency (NSA) released advice on&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Selecting and Safely Using Collaboration Services for Telework&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;showing criteria to use in your selection and assessing those criteria for 13 commercial products.&lt;/P&gt;&lt;P&gt;The assessment table is based on claims by the companies offering those service, and not on any NSA testing. Even with that caveat, the document looks helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Three items are online at NSA:&lt;/P&gt;&lt;P&gt;Press release&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://www.nsa.gov/News-Features/News-Stories/Article-View/Article/2163484/working-from-home-select-and-use-collaboration-services-more-securely/" target="_blank" rel="noopener"&gt;Working from Home? Select and Use Collaboration Services More Securely&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://media.defense.gov/2020/Apr/24/2002288653/-1/-1/0/CSI-SELECTING-AND-USING-COLLABORATION-SERVICES-SECURELY-SHORT-FINAL.PDF" target="_blank" rel="noopener"&gt;Selecting and Safely Using Collaboration Services for Telework&lt;/A&gt;&lt;/STRONG&gt; - &lt;EM&gt;Short form&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Lists the criteria and includes the full comparison table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://media.defense.gov/2020/Apr/24/2002288652/-1/-1/0/CSI-SELECTING-AND-USING-COLLABORATION-SERVICES-SECURELY-LONG-FINAL.PDF" target="_blank" rel="noopener"&gt;Selecting and Safely Using Collaboration Services for Telework&lt;/A&gt;&lt;/STRONG&gt; - &lt;EM&gt;Long form&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Adds a paragraph explaining each of the criteria. Same table as the short form.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Observations:&lt;/P&gt;&lt;P&gt;1. Since the information is based on company documentation and not testing, you may need added information for your purposes. For instance, under End-to-End Encryption for Zoom, the table says Yes - Partial. Only if you have seen the reports for Zoom will you know that E2E is only for two-party connections. All group connections are encrypted only between clients and the central server (which may or may not be in the same country as participating clients).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. The legend code for Basic Functionality is a bit obscure in small print below the table.&amp;nbsp;&lt;/P&gt;&lt;P&gt;(a) text chat, (b) voice conferencing, (c) video conferencing, (d) file sharing, (e) screen sharing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. There are typos in the table footnotes, where it says 12 instead of 2 and 14 instead of 4 (Zoom E2E).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PLUS&lt;/P&gt;&lt;P&gt;A report available gives solid reasons to think long and hard before selecting Zoom:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://images.fullspectrumcyber.io/whitepapers/Zoom+China+and+Protecting+the+DIB.pdf" target="_blank" rel="noopener"&gt;Zoom-ing in on You: Why Other Video Conferencing Platforms may be a Better Choice&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Pointing out that, in addition to teh previously identified lie from Zoom that they use E2E encryption, they also claimed to use AES 256, but Citizen Lab reported that,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;"However, a recent report found that Zoom only uses a single AES-128 key in Electronic Codebook (ECB) mode, which is less secure than AES-256, and ECB is not recommended for streaming media.13 Bill Marczak and John Scott-Railton from The Citizen Lab argue:&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Zoom's encryption and decryption use AES in ECB mode, which is well-understood to be a bad idea because this mode of encryption preserves patterns in the input. Industry-standard protocols for encryption of streaming media (e.g., the SRTP standard) recommend the use of AES in Segmented Integer Counter Mode or f8-mode, which do not have the same weakness as ECB mode.&lt;A href="https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto-a-quick-look-at-the-confidentiality-of-zoom-meetings/" target="_blank" rel="noopener"&gt;14"&lt;/A&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;UAYOR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;P&gt;(Also posted on my &lt;A href="https://cragins.blogspot.com/2020/04/picking-collaboration-tool-nsa-help.html" target="_blank" rel="noopener"&gt;Randomness Blog&lt;/A&gt;.)&lt;/P&gt;</description>
    <pubDate>Tue, 28 Apr 2020 22:01:15 GMT</pubDate>
    <dc:creator>CraginS</dc:creator>
    <dc:date>2020-04-28T22:01:15Z</dc:date>
    <item>
      <title>Picking a Collab Tool - NSA Help</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Picking-a-Collab-Tool-NSA-Help/m-p/35147#M2623</link>
      <description>&lt;P&gt;On April 24, 2020, the U.S. National Security Agency (NSA) released advice on&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Selecting and Safely Using Collaboration Services for Telework&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;showing criteria to use in your selection and assessing those criteria for 13 commercial products.&lt;/P&gt;&lt;P&gt;The assessment table is based on claims by the companies offering those service, and not on any NSA testing. Even with that caveat, the document looks helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Three items are online at NSA:&lt;/P&gt;&lt;P&gt;Press release&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://www.nsa.gov/News-Features/News-Stories/Article-View/Article/2163484/working-from-home-select-and-use-collaboration-services-more-securely/" target="_blank" rel="noopener"&gt;Working from Home? Select and Use Collaboration Services More Securely&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://media.defense.gov/2020/Apr/24/2002288653/-1/-1/0/CSI-SELECTING-AND-USING-COLLABORATION-SERVICES-SECURELY-SHORT-FINAL.PDF" target="_blank" rel="noopener"&gt;Selecting and Safely Using Collaboration Services for Telework&lt;/A&gt;&lt;/STRONG&gt; - &lt;EM&gt;Short form&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Lists the criteria and includes the full comparison table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://media.defense.gov/2020/Apr/24/2002288652/-1/-1/0/CSI-SELECTING-AND-USING-COLLABORATION-SERVICES-SECURELY-LONG-FINAL.PDF" target="_blank" rel="noopener"&gt;Selecting and Safely Using Collaboration Services for Telework&lt;/A&gt;&lt;/STRONG&gt; - &lt;EM&gt;Long form&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Adds a paragraph explaining each of the criteria. Same table as the short form.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Observations:&lt;/P&gt;&lt;P&gt;1. Since the information is based on company documentation and not testing, you may need added information for your purposes. For instance, under End-to-End Encryption for Zoom, the table says Yes - Partial. Only if you have seen the reports for Zoom will you know that E2E is only for two-party connections. All group connections are encrypted only between clients and the central server (which may or may not be in the same country as participating clients).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. The legend code for Basic Functionality is a bit obscure in small print below the table.&amp;nbsp;&lt;/P&gt;&lt;P&gt;(a) text chat, (b) voice conferencing, (c) video conferencing, (d) file sharing, (e) screen sharing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. There are typos in the table footnotes, where it says 12 instead of 2 and 14 instead of 4 (Zoom E2E).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PLUS&lt;/P&gt;&lt;P&gt;A report available gives solid reasons to think long and hard before selecting Zoom:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://images.fullspectrumcyber.io/whitepapers/Zoom+China+and+Protecting+the+DIB.pdf" target="_blank" rel="noopener"&gt;Zoom-ing in on You: Why Other Video Conferencing Platforms may be a Better Choice&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Pointing out that, in addition to teh previously identified lie from Zoom that they use E2E encryption, they also claimed to use AES 256, but Citizen Lab reported that,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;EM&gt;"However, a recent report found that Zoom only uses a single AES-128 key in Electronic Codebook (ECB) mode, which is less secure than AES-256, and ECB is not recommended for streaming media.13 Bill Marczak and John Scott-Railton from The Citizen Lab argue:&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Zoom's encryption and decryption use AES in ECB mode, which is well-understood to be a bad idea because this mode of encryption preserves patterns in the input. Industry-standard protocols for encryption of streaming media (e.g., the SRTP standard) recommend the use of AES in Segmented Integer Counter Mode or f8-mode, which do not have the same weakness as ECB mode.&lt;A href="https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto-a-quick-look-at-the-confidentiality-of-zoom-meetings/" target="_blank" rel="noopener"&gt;14"&lt;/A&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;UAYOR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;P&gt;(Also posted on my &lt;A href="https://cragins.blogspot.com/2020/04/picking-collaboration-tool-nsa-help.html" target="_blank" rel="noopener"&gt;Randomness Blog&lt;/A&gt;.)&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 22:01:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Picking-a-Collab-Tool-NSA-Help/m-p/35147#M2623</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2020-04-28T22:01:15Z</dc:date>
    </item>
  </channel>
</rss>

