saggu Posted April 2, 2020 Posted April 2, 2020 Under GDPR, any new process within the school must have a Data Protection Impact Assessment completed before it's used. This needs to be signed off by the DPO. I presume that this has been done for Teams and is therefore good to use, however Zoom cannot be used if it has not been signed off on. is this applicable for Google Hangout as well?
AndyCrow Posted April 2, 2020 Posted April 2, 2020 Hi. A DPIA has to be completed on any new process however although I'm not particularly familiar with the product, its Privacy Policy does appear to be covered under the general Google policy. You should get the OK from your DPO before distributing it though. 1
synaesthesia Posted April 2, 2020 Posted April 2, 2020 Zoom is dangerous, sorry. A little research will show how badly it's made and worse still how little the devs care about security. I couldn't give two hoots about what anyone's DPO says about it because they don't have a bloody clue! 1
mdrabble Posted April 2, 2020 Posted April 2, 2020 Part of the problem is that people have seen the government use it and are assuming it safe to use and think if it good enough for them it good enough for us - regardless of whatever concerns we raise.
6Foot2 Posted April 2, 2020 Posted April 2, 2020 Link: Zoom boss apologises for security issues and promises fixes [bBC News] Zoom is to pause the development of any new features to concentrate on safety and privacy issues, in the wake of criticism from users of the app. In a blog, the chief executive of the video conferencing app apologised for "falling short" on security issues and promised to address concerns. He said that the use of Zoom had soared in ways he could never have foreseen prior to the coronavirus pandemic. One security expert said he hoped the company culture would change. Zoom is now being used by millions of people for work and leisure, as lockdowns are imposed in many countries. Eric Yuan spoke candidly about how "usage of Zoom ballooned overnight". "As of the end of December last year, the maximum number of daily meeting participants, both free and paid, was approximately 10 million. In March this year, we reached more than 200 million, he said. He admitted that despite "working around the clock" to support the influx of new users, the service had "fallen short of the community's - and our own - privacy and security expectations". "For that, I am deeply sorry," he wrote. "We did not design the product with the foresight that, in a matter of weeks, every person in the world would suddenly be working, studying, and socialising from home," he wrote. "We now have a much broader set of users who are utilising our product in a myriad of unexpected ways presenting us with challenges we did not anticipate when the platform was conceived." Zoom has been criticised for a range of privacy issues, including sending user data to Facebook, wrongly claiming the app had end-to-end encryption, and allowing meeting hosts to track attendees. Ex-NSA (National Security Agency) hacker Patrick Wardle identified a series of issues, including a flaw which left Mac users vulnerable to having webcams and microphones hijacked. Security consultant Graham Cluley said that Zoom faced "a crisis". "It risked losing a large amount of goodwill it had received because of revelations about its less-than-perfect attitude towards security and privacy." The fact that it was addressing some of the "alarming vulnerabilities" and had recognised the need to focus on security rather than "adding bells and whistles" was good news, he said. "Let's hope that the company's culture will change from its previous 'fast and loose' attitude when it comes to such concerns," he added...
mavhc Posted April 3, 2020 Posted April 3, 2020 Meanwhile https://krebsonsecurity.com/2020/04/war-dialing-tool-exposes-zooms-password-problems/
localzuk Posted April 3, 2020 Posted April 3, 2020 We have just allowed this for one group of staff in our Trust - for one purpose only. They have been booked on some training, and the training firm uses Zoom to deliver the training. That's it. That's all I'm comfortable with them doing at the moment.
GrumbleDook Posted April 3, 2020 Posted April 3, 2020 Taken from LinkedIn (from the MD of Fox Red Risk) Why everyone is hating on Zoom is beyond me! It's OUR responsibility to do hashtag #applicationsecurity reviews on products BEFORE use. We all have different hashtag #infosecurity needs after all. What should happen... Employees - We want Zoom InfoSec & DP - Ok. We will do a review InfoSec & DP - It has FB Login, let's just check the SDK for that...oh it sends a lot of data to FB. Boss, are you happy with that? CISO - DPO I don't think this complies with GDPR, would you inform & advise the CEO DPO - Sure, CEO, before we use Zoom I need to let you know about the privacy issues... CEO - Thanks. CISO, work with DPO to resolve. CISO & DPO to Zoom - We like your product but there are some privacy issues we need you to fix Zoom - Ok...yup...lots of other people have also asked..as a result.we have stopped this feed. CISO to Infosec/DPO to DP team - Document a standard for secure config and issue to business InfoSec - Here is how to use Zoom safely. Business - Cheers! Let's get conferencing! What did happen... Business - AAAAAAAAAGGGHHHHH. How will we work remotely...someone said Zoom was free...ok let's use that. Please feel free to substitute Zoom for a raft of other things from over the years. About 90% of the queries I had have now been answered and whilst not perfect, I feel more reassured about them than I do about a bunch of other resource providers. At least I know they are working on things ... 4
Ex-MGSTech Posted April 6, 2020 Posted April 6, 2020 . at least with teams we can block them and audit calls made T Can I ask how as Supervision in 365 says it needs an E5 license?
Soulfish Posted April 6, 2020 Posted April 6, 2020 So, working in a huge-multinational our Cyber Security teams have now rated Zoom "High Risk", and as such we're in the process of blocking access for the app and preventing sign up using corporate email. Users can only join a Zoom meeting if its been created by a third party (customer, supplier or similar) and only through Chrome. Zoom isn't an approved corporate application for us, and given we have Teams deployed for all users globally (together with Audio + Video conferencing options) there isn't a lot of reason to not steer users away from it.
GrumbleDook Posted April 6, 2020 Posted April 6, 2020 So, working in a huge-multinational our Cyber Security teams have now rated Zoom "High Risk", and as such we're in the process of blocking access for the app and preventing sign up using corporate email. Users can only join a Zoom meeting if its been created by a third party (customer, supplier or similar) and only through Chrome. Zoom isn't an approved corporate application for us, and given we have Teams deployed for all users globally (together with Audio + Video conferencing options) there isn't a lot of reason to not steer users away from it. What reasons did they give for it being placed in High Risk?
Arthur Posted April 6, 2020 Posted April 6, 2020 (edited) What reasons did they give for it being placed in High Risk? The thing with Zoom is that there are so many reasons to choose from! Zoom admits some calls were routed through China by mistake New York City bans Zoom in schools, citing security concerns Zoom is Leaking People's' Email Addresses and Photos to Strangers Zoom 'unsuitable' for government secrets, researchers say Thousands of Zoom recordings exposed because of the way Zoom names recordings Security and Privacy Implications of Zoom (Bruce Schneier) Attackers can use Zoom to steal users’ Windows credentials with no warning The 'S' in Zoom, Stands for Security Zoom has a signed binary that runs any unsigned script Zoom monitors activity on your computer A Feature on Zoom Secretly Displayed Data From People’s LinkedIn Profiles Zoom meetings aren’t end-to-end encrypted, despite misleading marketing Zoom has "rolled their own" encryption scheme, which has significant weaknesses 'War Dialing' tool exposes Zoom’s password problems Zoom iOS app sends data to Facebook even if you don’t have a Facebook account (and Zoom Faces Class Action Lawsuit for Sharing Data with Facebook) 'Zoom is malware': why experts worry about the video conferencing platform Zoom Zero Day: 4+ Million Webcams & maybe an RCE? Just get them to visit your website! Remotely Hijacking Zoom Clients Edited April 6, 2020 by Arthur 2
psydii Posted April 6, 2020 Posted April 6, 2020 MS has some things to say about Team's security: https://www.microsoft.com/en-us/microsoft-365/blog/2020/04/06/it-professionals-privacy-security-microsoft-teams/ Now, I fully expect that Team's reputation will fall once someone publicisise a Teams specific JS injection attack that exploits a weakiness in Electron, but for now that hasn't happened.
mavhc Posted April 6, 2020 Posted April 6, 2020 Recording is a bit overblown, anyone could just record their screen anyway. But the main reason MS or Google are better is they have 100s of security people checking their code, 2fa, a lot more to lose, have been doing this for 20 years, and make money by selling the service (except to schools, we're just 'the first hit is free, then you're addicted') 1
Soulfish Posted April 8, 2020 Posted April 8, 2020 What reasons did they give for it being placed in High Risk? Too many zero-day vulnerabilities, plus the original privacy policy was causing significant issues for our business. There's also the fact that we have quite a stringent approval mechanism for any new software (everything goes through an independent set of pen tests and security review) that this hadn't gone through. We've totally taken the view that there are business requirements to use Zoom for third party conferences, but we have a very well developed Teams deployment (we do over 10 million minutes of conferencing a month through it) but the windows client as it stands is too much of a risk for us to allow. We continually review these things so if things improve and our third-party security assessments give it a clean bill of health we'll approve it again. Just not for our users hosting meetings through it! 1
Arthur Posted April 9, 2020 Posted April 9, 2020 Google Told Its Workers That They Can’t Use Zoom On Their Laptops Anymore Google has banned the popular videoconferencing software Zoom from its employees’ devices, BuzzFeed News has learned. Zoom, a competitor to Google’s own Meet app, has seen an explosion of people using it to work and socialize from home and has become a cultural touchstone during the coronavirus pandemic. Last week, Google sent an email to employees whose work laptops had the Zoom app installed that cited its “security vulnerabilities” and warned that the videoconferencing software on employee laptops would stop working starting this week. “We have long had a policy of not allowing employees to use unapproved apps for work that are outside of our corporate network,” Jose Castaneda, a Google spokesperson, told BuzzFeed News. “Recently, our security team informed employees using Zoom Desktop Client that it will no longer run on corporate computers as it does not meet our security standards for apps used by our employees. Employees who have been using Zoom to stay in touch with family and friends can continue to do so through a web browser or via mobile.” [...] Google isn’t the first company to ban employees from using Zoom. Earlier this month, Elon Musk’s rocket company SpaceX also banned employees, citing “significant privacy and security concerns,” according to Reuters. And on Monday, New York City’s Department of Education urged schools to abandon Zoom and switch to a service from Microsoft. “[We] recognize that we have fallen short of the community’s – and our own – privacy and security expectations,” Yuan wrote on a blog post earlier this month. “For that, I am deeply sorry.”
paulkerton Posted April 9, 2020 Posted April 9, 2020 Zoom has a chronically bad history when it comes to security and privacy. There is no way I'd use it considering it's history of issues! The installing a webserver based backdoor onto MacOS clients that allowed them to automatically reinstall it when visiting a meeting link issue on it's own should make any DPO's jaw drop.
GrumbleDook Posted April 14, 2020 Posted April 14, 2020 Zoom has a chronically bad history when it comes to security and privacy. There is no way I'd use it considering it's history of issues! The installing a webserver based backdoor onto MacOS clients that allowed them to automatically reinstall it when visiting a meeting link issue on its own should make any DPO's jaw drop. Oh, they know that they have done things wrongly in the past and are working hard to fix those mistakes and not create new ones. The DPIA I did on them 2 months ago is very different to the one that is waiting sign off at the moment.
HC_Netman Posted April 29, 2020 Posted April 29, 2020 The DPIA I did on them 2 months ago is very different to the one that is waiting sign off at the moment. I don't suppose this updated DPIA is something you would be willing to share?
Popular Post GrumbleDook Posted April 29, 2020 Popular Post Posted April 29, 2020 The team up in Derbyshire have done a sterling job on this and it was a pleasure to support them as they pulled this together. It was amazing to have additional support and time from the Coventry team too. Derbyshire CC have now published it on their public guidance to schools around Covid-19. You will find it in the list of downloads on the right hand side. https://schoolsnet.derbyshire.gov.uk/administration-services-and-support/coronavirus-information/information-and-advice-to-schools.aspx We have also had some additional safeguarding points raised by colleagues at KELSI in Kent, as well as having feedback from Zoom’s compliance team. The Zoom compliance team reached out and I was able to discuss issues with their Global Compliance and Risk Officer and the associate Legal Counsel who has been drawing up the policy and other documents relating to children’s data. They had been already been addressing but that many of us had been raising and gave some insight as to their next steps. As we get more feedback from Zoom, and I hope to work with a school on issues with Flipgrid and Teams, we will feedback into updating the DPIA via the Derbyshire team, and then include the additional points from Kent’s safeguarding team. 8
keyboards Posted April 30, 2020 Posted April 30, 2020 The team up in Derbyshire have done a sterling job on this and it was a pleasure to support them as they pulled this together. It was amazing to have additional support and time from the Coventry team too. Derbyshire CC have now published it on their public guidance to schools around Covid-19. You will find it in the list of downloads on the right hand side. https://schoolsnet.derbyshire.gov.uk/administration-services-and-support/coronavirus-information/information-and-advice-to-schools.aspx We have also had some additional safeguarding points raised by colleagues at KELSI in Kent, as well as having feedback from Zoom’s compliance team. The Zoom compliance team reached out and I was able to discuss issues with their Global Compliance and Risk Officer and the associate Legal Counsel who has been drawing up the policy and other documents relating to children’s data. They had been already been addressing but that many of us had been raising and gave some insight as to their next steps. As we get more feedback from Zoom, and I hope to work with a school on issues with Flipgrid and Teams, we will feedback into updating the DPIA via the Derbyshire team, and then include the additional points from Kent’s safeguarding team. This is superb, this should be posted elsewhere on the forum too, great document not just for Covid but in general will probably help a lot of network manager and policy makers 1
Arthur Posted June 7, 2020 Posted June 7, 2020 Too many zero-day vulnerabilities Two more vulnerabilities... Vulnerability Spotlight: Two vulnerabilities in Zoom could lead to code execution A member of Cisco Talos discovered this vulnerability. Cisco Talos recently discovered two vulnerabilities in the popular Zoom video chatting application that could allow a malicious user to execute arbitrary code on victims’ machines. Video conferencing software has skyrocketed in popularity during the COVID-19 pandemic as individuals across the globe are encouraged to work from home and avoid close face-to-face contact with friends and family. In accordance with our coordinated disclosure policy, Cisco Talos worked with Zoom to ensure that these issues are resolved. TALOS-2020-1056 was fixed in May. Zoom fixed TALOS-2020-1055 server-side in a separate update, though Cisco Talos believes it still requires a fix on the client-side to completely resolve the security risk. 1
ITGURU Posted June 7, 2020 Posted June 7, 2020 Zoom have only just decided to enable point to point encryption on the free version - used to have to pay for the feature! Our staff mostly caught on to Zoom for calls, but don't use for anything confidential. Staff are aware of teams but yet to fully demo it's capabilities To me, zoom is ok for personal/social use, but Teams is definitely more for collaborative and presenting presentations without the need to show your full desktop.
stottio Posted June 7, 2020 Posted June 7, 2020 Google Meet for us, we have classroom though-out so makes sense, also mush easier GUI than teams, teaching staff are more confident using Meet due to this.
Bev Posted June 17, 2020 Posted June 17, 2020 We are also using Google Meet for any conversations with students. We can control who can start / end meetings, and prevent students from meeting with people outside of our domain.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now