win Posted April 6, 2020 Posted April 6, 2020 Zoom is being banned by schools across the United States following an increasing number of security and privacy issues reported by the app's users. https://www.techradar.com/news/schools-ban-zoom-citing-security-and-privacy-concerns I guess this is another thumbs up for teams then 2
synaesthesia Posted April 6, 2020 Posted April 6, 2020 Yup, I've emailed out saying please don't use it for school use until further notice. 2
Ditto Posted April 6, 2020 Posted April 6, 2020 Understandably so. I also congratulate every Edugeeker who pushed back on their school until the security risk was understood. As for every DPO who didn't back you, shame on them for not fulfilling their role. Zoom clearly have built a good interface, but shiny, shiny is not enough for professional use.
Ditto Posted April 6, 2020 Posted April 6, 2020 Now playing Devil's Advocate to myself, how many of us have properly risk assessed out Office 365 or GSuite option? 1
nicholab Posted April 7, 2020 Posted April 7, 2020 Does MS not have a numbers of security certificates for Azure/Office 365 security? Also they offer the Office 365 and ATP security centre so you can see your security score.
FishCustard Posted April 7, 2020 Posted April 7, 2020 Now playing Devil's Advocate to myself, how many of us have properly risk assessed out Office 365 or GSuite option? I have. There is a good outline of the security and compliance features of Teams here on the Microsoft website. They're certainly light years ahead of Zoom on this front. The fact that the Government is using Zoom for Cabinet meetings (well - appears to be, who knows what they're actually doing) worries me deeply! 2
Andycat Posted April 7, 2020 Posted April 7, 2020 Zoom changed a few things yesterday, and we had a (family) zoom last night and I had to admit each member through the waiting room rather than them just joining, even with the meeting password. That, at least, is an improvement.
hardtailstar Posted April 7, 2020 Posted April 7, 2020 Zoom changed a few things yesterday, and we had a (family) zoom last night and I had to admit each member through the waiting room rather than them just joining, even with the meeting password. That, at least, is an improvement. https://www.bbc.co.uk/news/technology-52133349 The 'Zoombombing' that seems to be the main report as an issue in the untech world can be put down to user error! The other issues they have seem to gone 'oh crap, we weren't expecting this' and trying to solve them as quickly as possible.
synaesthesia Posted April 7, 2020 Posted April 7, 2020 The big issues remaining are end to end encryption (they say they have, but haven't) and the amount of exploits which still make the password & waiting room requirements moot. Until they're fixed, and they buck their ideas up, it's a no. I don't think there's any issue with personal use (a couple of staff emailed me last night to ask if they should be worried when doing it with their family - no, that's fine) but when possibly confidential information is basically freely available, it can't stay in use in schools. 1
leegcvcc Posted April 7, 2020 Posted April 7, 2020 A lot of Universities appear to be using ZOOM for their Q&A sessions with prospective students. I have said to Post 16 Staff that the students don't need an account to participate, they just need an email address for the Invite and meeting ID to be sent to. I would assume (stupidly) that Uni's would not be using the free version. I have told staff not to use ZOOM for any student meetings. It's still hard trying to tell them to use Teams when 40% of classes are still not provisioned yet (3 weeks) and Microsoft Support are making me jump through hoops to diagnose the issue. More of a 'give them some breathing space' support at the moment and fob you off for as long as possible
jthompson Posted April 7, 2020 Posted April 7, 2020 (edited) https://www.bbc.co.uk/news/technology-52133349 The 'Zoombombing' that seems to be the main report as an issue in the untech world can be put down to user error! The other issues they have seem to gone 'oh crap, we weren't expecting this' and trying to solve them as quickly as possible. My feeling is that the zoombombing thing, whilst in the power of end users to avoid, is symptomatic of the company's posture with regard to usability vs security. They chose to design default settings that enabled zoombombing, in order to chase user growth. If the company didn't anticipate zoombombing becoming a thing after that, then they're either stupid or don't care. What else are they stupid or careless about? Let's blame Zoom, rather than their millions of users. Edit: That's meant as a rhetorical question, but there are probably some actual answers to it. 1000s of recorded meetings found in the open on AWS, for instance. more victims of badly thought through default settings. Edited April 7, 2020 by jthompson
hardtailstar Posted April 7, 2020 Posted April 7, 2020 My feeling is that the zoombombing thing, whilst in the power of end users to avoid, is symptomatic of the company's posture with regard to usability vs security. They chose to design default settings that enabled zoombombing, in order to chase user growth. If the company didn't anticipate zoombombing becoming a thing after that, then they're either stupid or don't care. What else are they stupid or careless about? Let's blame Zoom, rather than their millions of users. Edit: That's meant as a rhetorical question, but there are probably some actual answers to it. 1000s of recorded meetings found in the open on AWS, for instance. more victims of badly thought through default settings. Whilst Zoom are at fault too for security etc. They cannot be blamed for the users that post meeting details to open public domains and then get these people 'bombing' them. Like in the case of the church that posted the meeting details to their social media and got a lot of people joining shouting abuse.
localzuk Posted April 7, 2020 Posted April 7, 2020 The big issues remaining are end to end encryption (they say they have, but haven't) and the amount of exploits which still make the password & waiting room requirements moot. Until they're fixed, and they buck their ideas up, it's a no. I don't think there's any issue with personal use (a couple of staff emailed me last night to ask if they should be worried when doing it with their family - no, that's fine) but when possibly confidential information is basically freely available, it can't stay in use in schools.The end to end encryption thing is a non-issue - none of the corporate video tools offer it, as it is impossible to both have central tools and E2EE. Eg. If you add an org want to record meetings for compliance reasons? Can't be encrypted at the server side. Meet, Teams, S4B, none of those are E2EE. They are encrypted in transit and rest, but the servers, and the companies that run them, have access to that data. Totally agree on the other aspects though.
synaesthesia Posted April 7, 2020 Posted April 7, 2020 The end to end encryption thing is a non-issue - none of the corporate video tools offer it, as it is impossible to both have central tools and E2EE. Eg. If you add an org want to record meetings for compliance reasons? Can't be encrypted at the server side. Meet, Teams, S4B, none of those are E2EE. They are encrypted in transit and rest, but the servers, and the companies that run them, have access to that data. Totally agree on the other aspects though. I was of the impression they were touting that but may have misunderstood.
eean Posted April 8, 2020 Posted April 8, 2020 Is the real issue the zoombombing then? Is that down to user error - ie. they're not setting passwords? This link seems to suggest it's a down to user training (but, agreed it should be set to fail-safe). I have concerns about Teams too: The default option for joining a meeting is that everyone can bypass the lobby. It is possible to change this default with a policy but, like zoom, it's not set to the safest option by default. The best level of security is 'People in this Organisation' can bypass the lobby. There is no way of forcing all users to go via the lobby. This means that if a teacher sends a group of students a link, they can have their own meet ups before and after. Is there a way of killing a link after it's been used? Zoom gives the meeting organiser a lot of control, and being able to put students in break-out rooms is amazing. I tried using the whiteboard in Teams and it was hopeless - it was slow and wouldn't work on iOS devices. Are we all going with Zoom or Team because it's what people know, or because it's the best - safety-wise and pedagogically? I had a quick look at Digital Samba, for example. Expensive but has powerful e-learning features - works in any browser without any apps. Are there other tools out there that are better for classrooms?
xlandhenry Posted April 8, 2020 Posted April 8, 2020 (edited) The amount of automatic negativity towards Zoom is unbelievable. If you want to evaluate Zoom for use in a school setting, at least take a look at what its enterprise plan(or education plan as they call it)could offer, not nitpicking its consumer version. Can anybody tell me what kind of classified and super-secret meetings are taking place in schools, that justifies use of end-to-end encryption? Hundreds of large enterprises have been using Zoom in daily high-stakes meetings for years, yet when school starts using it everyone yells "It's not secure"? ============================== Edit: I am not suggesting that you should just 'go ahead and use Zoom". Careful planning, educating your users with best practices etc, are still necessary. Edited April 8, 2020 by xlandhenry
Popular Post elsiegee40 Posted April 8, 2020 Popular Post Posted April 8, 2020 (edited) The amount of automatic negativity towards Zoom is unbelievable. If you want to evaluate Zoom for use in a school setting, at least take a look at what its enterprise plan(or education plan as they call it)could offer, not nitpicking its consumer version. Can anybody tell me what kind of classified and super-secret meetings are taking place in schools, that justifies use of end-to-end encryption? Hundreds of large enterprises have been using Zoom in daily high-stakes meetings for years, yet when school starts using it everyone yells "It's not secure"? ============================== Edit: I am not suggesting that you should just 'go ahead and use Zoom". Careful planning, educating your users with best practices etc, are still necessary. Do you work in education? I suggest you take a look at the Safeguarding requirements in education and also Data Protection law/GDPR. We aren’t doing super secret but we are legally bound to keep young people safe. I don’t think anyone has said that properly rolled out and used, Zoom is a major problem. The problem most education IT staff have is reining in the enthusiasm of people who don’t realise that jumping on the Zoom bandwagon with the consumer version and no checks and balances is not the way forward. The automatic negativity you describe is a bunch of people trying to run an underfunded network remotely with users also working remotely and already trying to do things that their IT was never set up to do and without a budget to make major changes. I have been watching this thread from the beginning and what I see is mutual understanding of the problem with getting education staff to understand how Zoom can be done badly. And with my moderator hat on, I remind everyone that understanding goes a long way especially under the current circumstances. You cannot possibly know the constraints each EduGeek is working under at the moment. Being as blunt (and that’s me being polite) as this poster has been is not the way to help or influence others. If you cannot contribute help to a thread in a supportive manner then please do not post. Edited April 8, 2020 by elsiegee40 7
Ditto Posted April 8, 2020 Posted April 8, 2020 (edited) Totally agree with the above post. To put it briefly, schools discuss matters that relate to children. Those discussions are necessarily confidential. Lack of confidentiality *can* put a child at greater risk of harm. Edited April 8, 2020 by Ditto 1
FishCustard Posted April 8, 2020 Posted April 8, 2020 Can anybody tell me what kind of classified and super-secret meetings are taking place in schools Basically any meeting involving the welfare of children. You mention "classified" - well as schools are part of the public sector, any data created, held, or discussed by them could technically be considered "classified" at minimum Official level. Most information created or held in public sector organisations is Official by default. 1
localzuk Posted April 8, 2020 Posted April 8, 2020 One aspect of this that I don't think has been covered overly well is that this isn't just an issue restricted to Zoom. Sure, Zoom has some unique issues of its own regarding their security and privacy protections, but in reality video chat in general poses a lot of questions in an education setting. For us, we don't allow user of any such tool for interactive video lessons with children that are at home. The risks, we have decided, outweigh the rewards. We cannot control the environment at the other end of the call, and that places all the other participants at risk - of being recorded, of inappropriate content being displayed (either by accident or on purpose), of private information being displayed etc... So, we have instead settled on a policy of allowing broadcasts, via tools like YouTube Live, where teachers can live teach if they wish to, or simply sticking with recorded videos uploaded to be asynchronously viewed by children. I cannot see how a school can fulfil its legal duties and allow full interactive video chats between staff and children. 3
FishCustard Posted April 8, 2020 Posted April 8, 2020 Broadcasts is how I would do it if I needed to. As you rightly said, two-way video chats are far too high risk.
synaesthesia Posted April 8, 2020 Posted April 8, 2020 Yup, we don't allow any live broadcasting with the exception of maybe what's under a visualiser. The risk of people wandering in the background can be resolved simply enough with the background filters, but there's just too many opportunities for nasty allegations or bad goings on which may not be auditable.
xlandhenry Posted April 9, 2020 Posted April 9, 2020 Do you work in education? I suggest you take a look at the Safeguarding requirements in education and also Data Protection law/GDPR. We aren’t doing super secret but we are legally bound to keep young people safe. I don’t think anyone has said that properly rolled out and used, Zoom is a major problem. The problem most education IT staff have is reining in the enthusiasm of people who don’t realise that jumping on the Zoom bandwagon with the consumer version and no checks and balances is not the way forward. The automatic negativity you describe is a bunch of people trying to run an underfunded network remotely with users also working remotely and already trying to do things that their IT was never set up to do and without a budget to make major changes. I have been watching this thread from the beginning and what I see is mutual understanding of the problem with getting education staff to understand how Zoom can be done badly. And with my moderator hat on, I remind everyone that understanding goes a long way especially under the current circumstances. You cannot possibly know the constraints each EduGeek is working under at the moment. Being as blunt (and that’s me being polite) as this poster has been is not the way to help or influence others. If you cannot contribute help to a thread in a supportive manner then please do not post. Sorry my post above sound rude or nonconstructive. Yes I work in education and I fully understand many posts here are taking this with the safeguarding principles in mind, which I also concur with. For my school, Microsoft Teams is not really usable for many of our kids here without a VPN. When teachers need to use Zoom, we require them and kids to stay audio-only as much as possible, and record when turning on camera is needed. Also educate them about the 'controls' that Zoom provides to minimize risks. Again if anyone find my above post offensive I apologize, I just meant to provide a different perspective here.
xlandhenry Posted April 9, 2020 Posted April 9, 2020 Basically any meeting involving the welfare of children. You mention "classified" - well as schools are part of the public sector, any data created, held, or discussed by them could technically be considered "classified" at minimum Official level. Most information created or held in public sector organisations is Official by default. Yes but that doesn't necessarily justified use of E2EE, no?
FishCustard Posted April 9, 2020 Posted April 9, 2020 Yes but that doesn't necessarily justified use of E2EE, no? As mentioned above, E2EE isn't offered on any of the common tools as it would prevent centralised management. However, if by some magic it could be enabled then why not? If something is more secure than it needs to be, great.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now