Jump to content

Recommended Posts

Posted
Under GDPR, any new process within the school must have a Data Protection Impact Assessment completed before it's used. This needs to be signed off by the DPO.

I presume that this has been done for Teams and is therefore good to use, however Zoom cannot be used if it has not been signed off on.

is this applicable for Google Hangout as well?

Posted

Hi. A DPIA has to be completed on any new process however although I'm not particularly familiar with the product, its Privacy Policy does appear to be covered under the general Google policy.

You should get the OK from your DPO before distributing it though.

  • Thanks 1
Posted
Zoom is dangerous, sorry. A little research will show how badly it's made and worse still how little the devs care about security. I couldn't give two hoots about what anyone's DPO says about it because they don't have a bloody clue!
  • Thanks 1
Posted
Part of the problem is that people have seen the government use it and are assuming it safe to use and think if it good enough for them it good enough for us - regardless of whatever concerns we raise.
Posted

Link: Zoom boss apologises for security issues and promises fixes [bBC News]

 

Zoom is to pause the development of any new features to concentrate on safety and privacy issues, in the wake of criticism from users of the app.

 

In a blog, the chief executive of the video conferencing app apologised for "falling short" on security issues and promised to address concerns.

 

He said that the use of Zoom had soared in ways he could never have foreseen prior to the coronavirus pandemic.

 

One security expert said he hoped the company culture would change.

 

Zoom is now being used by millions of people for work and leisure, as lockdowns are imposed in many countries.

 

Eric Yuan spoke candidly about how "usage of Zoom ballooned overnight".

 

"As of the end of December last year, the maximum number of daily meeting participants, both free and paid, was approximately 10 million. In March this year, we reached more than 200 million, he said.

 

He admitted that despite "working around the clock" to support the influx of new users, the service had "fallen short of the community's - and our own - privacy and security expectations".

 

"For that, I am deeply sorry," he wrote.

 

"We did not design the product with the foresight that, in a matter of weeks, every person in the world would suddenly be working, studying, and socialising from home," he wrote.

 

"We now have a much broader set of users who are utilising our product in a myriad of unexpected ways presenting us with challenges we did not anticipate when the platform was conceived."

 

Zoom has been criticised for a range of privacy issues, including sending user data to Facebook, wrongly claiming the app had end-to-end encryption, and allowing meeting hosts to track attendees.

 

Ex-NSA (National Security Agency) hacker Patrick Wardle identified a series of issues, including a flaw which left Mac users vulnerable to having webcams and microphones hijacked.

 

Security consultant Graham Cluley said that Zoom faced "a crisis".

 

"It risked losing a large amount of goodwill it had received because of revelations about its less-than-perfect attitude towards security and privacy."

 

The fact that it was addressing some of the "alarming vulnerabilities" and had recognised the need to focus on security rather than "adding bells and whistles" was good news, he said.

 

"Let's hope that the company's culture will change from its previous 'fast and loose' attitude when it comes to such concerns," he added...

Posted

We have just allowed this for one group of staff in our Trust - for one purpose only. They have been booked on some training, and the training firm uses Zoom to deliver the training.

 

That's it. That's all I'm comfortable with them doing at the moment.

Posted

Taken from LinkedIn (from the MD of Fox Red Risk)

 

Why everyone is hating on Zoom is beyond me! It's OUR responsibility to do

hashtag

#applicationsecurity reviews on products BEFORE use. We all have different

hashtag

#infosecurity needs after all.

 

What should happen...

Employees - We want Zoom

InfoSec & DP - Ok. We will do a review

InfoSec & DP - It has FB Login, let's just check the SDK for that...oh it sends a lot of data to FB. Boss, are you happy with that?

CISO - DPO I don't think this complies with GDPR, would you inform & advise the CEO

DPO - Sure, CEO, before we use Zoom I need to let you know about the privacy issues...

CEO - Thanks. CISO, work with DPO to resolve.

CISO & DPO to Zoom - We like your product but there are some privacy issues we need you to fix

Zoom - Ok...yup...lots of other people have also asked..as a result.we have stopped this feed.

CISO to Infosec/DPO to DP team - Document a standard for secure config and issue to business

InfoSec - Here is how to use Zoom safely.

Business - Cheers! Let's get conferencing!

 

What did happen...

 

Business - AAAAAAAAAGGGHHHHH. How will we work remotely...someone said Zoom was free...ok let's use that.

 

Please feel free to substitute Zoom for a raft of other things from over the years.

About 90% of the queries I had have now been answered and whilst not perfect, I feel more reassured about them than I do about a bunch of other resource providers. At least I know they are working on things ...

  • Thanks 4
Posted

So, working in a huge-multinational our Cyber Security teams have now rated Zoom "High Risk", and as such we're in the process of blocking access for the app and preventing sign up using corporate email. Users can only join a Zoom meeting if its been created by a third party (customer, supplier or similar) and only through Chrome.

 

Zoom isn't an approved corporate application for us, and given we have Teams deployed for all users globally (together with Audio + Video conferencing options) there isn't a lot of reason to not steer users away from it.

Posted
So, working in a huge-multinational our Cyber Security teams have now rated Zoom "High Risk", and as such we're in the process of blocking access for the app and preventing sign up using corporate email. Users can only join a Zoom meeting if its been created by a third party (customer, supplier or similar) and only through Chrome.

 

Zoom isn't an approved corporate application for us, and given we have Teams deployed for all users globally (together with Audio + Video conferencing options) there isn't a lot of reason to not steer users away from it.

 

What reasons did they give for it being placed in High Risk?

Posted
Recording is a bit overblown, anyone could just record their screen anyway. But the main reason MS or Google are better is they have 100s of security people checking their code, 2fa, a lot more to lose, have been doing this for 20 years, and make money by selling the service (except to schools, we're just 'the first hit is free, then you're addicted')
  • Thanks 1
Posted
What reasons did they give for it being placed in High Risk?

 

Too many zero-day vulnerabilities, plus the original privacy policy was causing significant issues for our business. There's also the fact that we have quite a stringent approval mechanism for any new software (everything goes through an independent set of pen tests and security review) that this hadn't gone through.

 

We've totally taken the view that there are business requirements to use Zoom for third party conferences, but we have a very well developed Teams deployment (we do over 10 million minutes of conferencing a month through it) but the windows client as it stands is too much of a risk for us to allow. We continually review these things so if things improve and our third-party security assessments give it a clean bill of health we'll approve it again. Just not for our users hosting meetings through it! :)

  • Thanks 1
Posted

Google Told Its Workers That They Can’t Use Zoom On Their Laptops Anymore

 

Google has banned the popular videoconferencing software Zoom from its employees’ devices, BuzzFeed News has learned. Zoom, a competitor to Google’s own Meet app, has seen an explosion of people using it to work and socialize from home and has become a cultural touchstone during the coronavirus pandemic.

 

Last week, Google sent an email to employees whose work laptops had the Zoom app installed that cited its “security vulnerabilities” and warned that the videoconferencing software on employee laptops would stop working starting this week.

 

“We have long had a policy of not allowing employees to use unapproved apps for work that are outside of our corporate network,” Jose Castaneda, a Google spokesperson, told BuzzFeed News. “Recently, our security team informed employees using Zoom Desktop Client that it will no longer run on corporate computers as it does not meet our security standards for apps used by our employees. Employees who have been using Zoom to stay in touch with family and friends can continue to do so through a web browser or via mobile.”

 

[...]

 

Google isn’t the first company to ban employees from using Zoom. Earlier this month, Elon Musk’s rocket company SpaceX also banned employees, citing “significant privacy and security concerns,” according to Reuters. And on Monday, New York City’s Department of Education urged schools to abandon Zoom and switch to a service from Microsoft.

 

“[We] recognize that we have fallen short of the community’s – and our own – privacy and security expectations,” Yuan wrote on a blog post earlier this month. “For that, I am deeply sorry.”

Posted
Zoom has a chronically bad history when it comes to security and privacy. There is no way I'd use it considering it's history of issues! The installing a webserver based backdoor onto MacOS clients that allowed them to automatically reinstall it when visiting a meeting link issue on it's own should make any DPO's jaw drop.
Posted
Zoom has a chronically bad history when it comes to security and privacy. There is no way I'd use it considering it's history of issues! The installing a webserver based backdoor onto MacOS clients that allowed them to automatically reinstall it when visiting a meeting link issue on its own should make any DPO's jaw drop.

 

Oh, they know that they have done things wrongly in the past and are working hard to fix those mistakes and not create new ones.

The DPIA I did on them 2 months ago is very different to the one that is waiting sign off at the moment.

  • 2 weeks later...
Posted

The DPIA I did on them 2 months ago is very different to the one that is waiting sign off at the moment.

 

I don't suppose this updated DPIA is something you would be willing to share?

Posted
The team up in Derbyshire have done a sterling job on this and it was a pleasure to support them as they pulled this together. It was amazing to have additional support and time from the Coventry team too.

 

Derbyshire CC have now published it on their public guidance to schools around Covid-19. You will find it in the list of downloads on the right hand side.

 

https://schoolsnet.derbyshire.gov.uk/administration-services-and-support/coronavirus-information/information-and-advice-to-schools.aspx

 

We have also had some additional safeguarding points raised by colleagues at KELSI in Kent, as well as having feedback from Zoom’s compliance team. The Zoom compliance team reached out and I was able to discuss issues with their Global Compliance and Risk Officer and the associate Legal Counsel who has been drawing up the policy and other documents relating to children’s data. They had been already been addressing but that many of us had been raising and gave some insight as to their next steps.

 

As we get more feedback from Zoom, and I hope to work with a school on issues with Flipgrid and Teams, we will feedback into updating the DPIA via the Derbyshire team, and then include the additional points from Kent’s safeguarding team.

 

This is superb, this should be posted elsewhere on the forum too, great document not just for Covid but in general will probably help a lot of network manager and policy makers

  • Thanks 1
  • 1 month later...
Posted
Too many zero-day vulnerabilities

Two more vulnerabilities... :(

 

Vulnerability Spotlight: Two vulnerabilities in Zoom could lead to code execution

 

A member of Cisco Talos discovered this vulnerability.

 

Cisco Talos recently discovered two vulnerabilities in the popular Zoom video chatting application that could allow a malicious user to execute arbitrary code on victims’ machines. Video conferencing software has skyrocketed in popularity during the COVID-19 pandemic as individuals across the globe are encouraged to work from home and avoid close face-to-face contact with friends and family.

 

In accordance with our coordinated disclosure policy, Cisco Talos worked with Zoom to ensure that these issues are resolved. TALOS-2020-1056 was fixed in May. Zoom fixed TALOS-2020-1055 server-side in a separate update, though Cisco Talos believes it still requires a fix on the client-side to completely resolve the security risk.

  • Thanks 1
Posted

Zoom have only just decided to enable point to point encryption on the free version - used to have to pay for the feature!

Our staff mostly caught on to Zoom for calls, but don't use for anything confidential.

Staff are aware of teams but yet to fully demo it's capabilities

To me, zoom is ok for personal/social use, but Teams is definitely more for collaborative and presenting presentations without the need to show your full desktop.

Posted
Google Meet for us, we have classroom though-out so makes sense, also mush easier GUI than teams, teaching staff are more confident using Meet due to this.
  • 2 weeks later...
Posted
We are also using Google Meet for any conversations with students. We can control who can start / end meetings, and prevent students from meeting with people outside of our domain.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...