8 ms·
GoogleMeetRoulette: Joining random meetings
- antibland 8y agoDigital roulette opportunities tend to descend into a crusty pit of lasciviousness and harassment.
- ChrisClark 8y agoThat's not what the article is about though. It's about brute forcing yourself into someone else's meeting.
- antibland 8y agoNo chance of sexual misconduct there.
- justusthane 8y agoDid you read the piece? This isn't a tool that you can use to join random meetings for entertainment or whatever - it's a vulnerability disclosure which has already been fixed by Google.
- iamdave 8y agoDid you read the piece? Betteridge's law of Internet Comments in action.
- sephware 8y agoI'm intrigued by this idea of random-socialization online. Obviously the sites like this have thus far catered more towards sexual content, but I feel like there's huge potential for online streaming socialization that Twitch and Discord haven't fully tapped. I can't put my finger on what, but there have been nights I just want to hop online and meet random strangers to talk about common interests about. Kind of like going to a bar to meet people, but with a higher chance that they'll be interested in the same things as you, so a cross between going to a bar and coming to HN to discuss interesting things.
- rspeer 8y agoI believe you are responding to the tongue-in-cheek title, and not to the article (which is about a security hole in Google Meet).
- sephware 8y agoWell shit. Yeah usually I read the article first but the title got me so excited that I wrote the comment because that topic really fascinates me. Oh well. Thanks for pointing it out.
- Joeri 8y agoICQ used to have this in the late 90's. You could find random people on the network based on what they filled out in their profile and start chatting with them. I live in Europe and made a friend in South Africa that way, who I ended up visiting a few years later. Of course, you couldn't do this nowadays because abusive people would show up and ruin it for everyone. I don't know why they didn't back then.
- shobith 8y ago> Of course, you couldn't do this nowadays because abusive people would show up and ruin it for everyone. I don't know why they didn't back then. People who had early access to Internet (or any tech) were more likely to be nerds.
- TallGuyShort 8y agoI don't think you can explain this by simply categorizing people. You can find more than a few stories of nerds being abusive to other people. I think initially the Internet brought people closer together. It was like ham radio - you could connect with people in a relatively small but very distributed community of hobbyists and experts. Once everyone joined and it became ubiquitous, it's had the opposite effect - it's replaced most of our social interactions but there's an increased anonymity and social separation.
- djhworld 8y agoThat was a wonderful read, thank you. The post mentions that Google made some fixes and reverted them due to customer complaints, do we know what those fixes were? Have they fixed the issue?
- timdavila 8y agoIt looks like they fixed the brute forcing PIN issue. When I set up a new meeting, the phone in PIN is 9 digits long (compared to the 4 mentioned in the article) However it seems the recurring meeting number+pin doesn't change. I feel this is a better UI, and only a minor risk with an easy workaround - update the meeting - which you would probably do anyway to remove the attendee who is no longer included
- kxrm 8y agoI just tested this since we use google meet. You can open an existing calendar event and remove the google meet details and recreate them. Seems to give you all new PIN and meet address.
- sarahdavid130 8y agoThat`s really great
- martinald 8y agoSlightly OT, do you have to be on Gsuite enterprise to get intl dial in numbers to show up? It'd be great to have that but it just shows US numbers for me in the UK.
- giovannibajo1 8y agoYes, and that's really unfortunate. Doubling the cost of G Suite to get intl numbers is a hard sell, but US numbers basically make the feature completely unavailable for many people.
- martinald 8y agoIt's actually 5x the cost. $25 vs $5/month for basic.
- foobaw 8y agohow much was the bounty for something like this?
- hsk0823 8y agoWhy would there be a bounty on basically a brute force attack?
- nwsm 8y agoBecause it was effective and he told them?
- oh_sigh 8y agoProbably because no google engineer recognized it as an attack vector.
- femto113 8y agoFelt legit to me. Sites can, should, and do take steps to mitigate brute force attacks, his approach showed some shortcomings in those steps, e.g. they already only allow 3 bad PINs per call, but he showed that by hanging up immediately after the 3rd bad PIN they make it relatively trivial for the attacker to detect the failure. He also demonstrated that due to the partial phone number masking in the UI the attack could be done from an apparently trusted phone number.
- kabes 8y agoBecause combining some smart/interesting methods make the brute force viable in a small enough time frame.
- wongarsu 8y agoWhy should any service allow a brute force attack? I can't brute force my bank pin, and I can't brute force my google password.
- yowie 8y agoYou have a point, I wasn’t expecting a bounty at all. I believe they valued the additional proposed attack vectors, the detailed report and highliting a number of issues that could be fixed to hardening the service. I found that Google values researches and reports beyonf RCEs
- martyvis 8y ago> "I would claim that nobody pays attention or verifies that there are no unexpected attendees before starting a meeting, specially for longer ones." I know for our work Skype for Business meetings we interrogate unidentified guests and boot them if they fail to appropriately identify themselves. I have thought that long running recurring meetings is a security risk because of the use of the same pin
- felipelemos 8y agoWhen you have a long list of attendees in a large organization, it's almost impossible to do that with everyone.
- TallGuyShort 8y agoTo use calculus as an analogy, as the number of people in your meeting approaches infinity, the confidentiality of that meeting approaches 0 anyway. You may still verify everyone's identity, but someone is going to be leaking enough information that it's close enough to just having a lurker who shouldn't be there.
- felipelemos 8y agoUnless you can ensure that everyone on the meeting is an authenticated user or was a approved to join by one.
- TallGuyShort 8y agoNo what I'm saying is with enough people, even if you authenticate everyone, one of them will violate confidentiality anyway. I've been in meetings where there was no teleconferencing of any kind, but sure enough the decision was leaked before being official anyway. As you get more an more people (or as you get enough people that the above solutions are considered unscalable) that approaches inevitability.
- 8y ago
- sbr464 8y agoI recently had a sales call with a potential vendor (they were a startup). They used the same number and meeting code for all of the meetings. I had accidentally called in about 10 minutes early and was dumped into another conversation, and heard the other potential customer talking. It was odd how insecure and weird it was. I think this is a potential issue for all meeting services.
- sbr464 8y agoI also mentioned it to the sales guy, but he was unfazed, which I think shows a lack of respect for customer privacy, even though he probably didn't realize it.
- themodelplumber 8y agoThis is really unfortunate but all too common. Sales guys are typically (as a type/group) improvisational in nature. They actually thrive in insecure environments, because solving problems as they occur (i.e. putting off security for later) gives them more freedom and flexibility _right now_, which is what they crave. They tend to wonder "why are you using valuable money-making time to secure that which is constantly expanding--maybe we won't even need this system tomorrow" and so on. (So goes the thinking; it obviously has its pros and cons...and HN readership eats these guys' psychology for breakfast anyway, with a generally systems-focused mindset)
- wild_preference 8y agoYou keep responding to your own post. Curious why you thought this was appropriate or necessary.
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- acct1771 8y ago
- rb808 8y agoWhat I'd love for every voice conference was an online screen with a list of everyone dialled in (caller Id based). It would be good for security but even better would be a little noise level meter on each line so you can see which %%%%er is heavy breathing all the time. (also a choice of on hold music would be nice but that is just dreaming)
- dfee 8y agoI think UberConference does all of that.
- sunsetMurk 8y agoYup. Uberconf is my go-to, and they have a decent free tier.
- tinus_hn 8y agoCaller ID is not secure, an attacker can spoof any phone number they want.
- spydum 8y agoPretty sure meet does all of that minus the hold music..
- djrogers 8y agoZoom does that - I stopped using my voice-only conference line and use zoom even for voice only calls because of things like that. It’s nice to be able to mute the guy ordering Panera during my calls...
- clubm8 8y agoI'd join but I saw enough penii on the original ChatRoulette - I've hit my quota.
- nojvek 8y agoI do this all the time with BlueJeans. If you mute your speaker and mic, the other party doesn’t even easily know you’ve joined. Most of the times, random codes failed but once I managed to accidentally dial in into a Facebook meeting. Fun times!
- spectaclepiece 8y agoFelt just like reading about Kevin Mitnicks adventures. Such a brilliant piece of work this.
- PeterStuer 8y agoI can't be the only one that thought many meetings could be improved by a random person joining a meeting and asking some obvious questions from outside the company bubble.
- hohenheim 8y agoReading the title I had the complete opposite expectations. Thinking that he is talking about a system where you want to have meeting with random people to talk about business.