10 ms·
Not a good idea to use 9 to 11 digit long IDs with no password requirement by default; they should have used at least 128-bit random ids, i.e. 21 character long
by devit 7y ago
Not a good idea to use 9 to 11 digit long IDs with no password requirement by default; they should have used at least 128-bit random ids, i.e. 21 character long base64-encoded strings.
- spacehunt 7y agoHow would that support phone dial-ins? (Yes, lots of people still dial into meetings all the time.)
- NikolaeVarius 7y agoI enjoy being able to dial meeting IDs into my phone
- wgjordan 7y agoI would also enjoy being able to punch in '12345' as my password everywhere instead of launching LastPass all the time, but I accept that some conveniences aren't worth security consequences.
- kube-system 7y agoThat's a fine compromise for internal teams. For those working with current or potential customers remotely, you have to use a solution that is convenient or you don't make money.
- umvi 7y agoYeah but then it sucks for people calling in to have to punch in a 21+ character long meeting ID
- toomuchtodo 7y agoCould you not use a telephone intent, where the meeting ID is the suffix to the dial in number with commas for any necessary pauses? Skype for business meeting invites have this. Zoom might then support inviting mobile phone conference participants using SMS, containing the link (think weak 2FA). Example: tel://18005551212,,<meeting_id>#
- anamexis 7y agoThat's not helpful when you have to punch it into a conference room speakerphone. I did once put together a hack that would scrape the meeting ID from the Zoom UI and emit the touchtones from my laptop to dial in.
- toomuchtodo 7y agoThere is always a trade off between security and usability. I like your hack though, any chance you'd put it on Github?
- PeterCorless 7y agoThe most secure computer is a non-networked standalone box sunk in concrete sunk hidden at the bottom of a deep sea trench. It is not, however, very usable.
- anamexis 7y agoI haven't used it in a while, so I wouldn't be surprised if the Zoom bit is broken, but here it is: https://gist.github.com/micahbf/91a295016f4472b47acfe317d714350b https://gist.github.com/micahbf/91a295016f4472b47acfe317d714...
- josteink 7y ago> Yeah but then it sucks for people calling in to have to punch in a 21+ character long meeting ID I may be out of touch with the average biz-guy, but how many people are realistically calling in manually, over traditional phone-lines these days? Is it really a significant percentage?
- apocalyptic0n3 7y agoFar greater than you would expect, I think. This is anecdotal, but we're an admittedly small company (~20-25 employees) and all of our interactions with other companies (clients) are either direct line-to-line or if we do a conference call, we all call in over the phone. Many of the companies who send us WebEx or join.me or Hangouts Meet or whatever invites only send the phone number even, not even bothering to give us a link (and if you go to the room manually in your browser, you're the only one actually connected via computer)
- deleted 7y ago[deleted]
- larrik 7y agoMost of my zoom meetings have at least 20% dial-ins.
- lonelappde 7y agoFrom landlines?
- randycupertino 7y agoWorking in global research, 40% of our ROW (rest of world) sites and vendors use landline or cell pones to join our meetings, depends on their institutional security and IT settings.
- Nextgrid 7y agoThe telephone dial-in option should've been separate - if the user chooses to enable it then they can fall back to shorter IDs, while meetings that don't need it (or where it doesn't make sense anyway - screen shares, presentations, etc) would use longer, more secure IDs.
- azinman2 7y agowhich means all you gotta do is war dial the phone network...
- Nextgrid 7y agoEven if the phone dial-in ID would be enabled by default (which isn't what I am suggesting), the extra latency and cost of brute forcing them over the phone network will make these attacks much harder.
- Symbiote 7y agoAs we've used it at work, the phone dial-in option is the backup plan -- useful when people can't set up their computer's microphone correctly, or lose Internet access for whatever reason.
- bobbyi_settv 7y agoThe "just works" nature is why Zoom is popular. No one wants to have every meeting start with "Is Larry here? Oh, I think he's trying to dial in. I'm going to cancel this meeting and send out a new ID so he can dial in. Everyone watch for that so you can reconnect"
- Nextgrid 7y agoThe second ID can be generated in addition to the first, primary ID.
- bscphil 7y agoYou could even include the option to get approval - pop up says "Mx. Caller ID is calling from 555.555.5555. Approve?" Obviously there's no way to get in through random dialing. And if you get a pile of requests, provide a way to filter incoming numbers and disable the calling ID as soon as everyone is in. That's even assuming that anti-DOS protection on the phone line is impossible.
- chapium 7y agoI've always preferred conf systems with a call-me-at function better anyway. With most lines, sign in over phone is a horrible waiting game where one missed digit means sitting through instructions for another minute.
- panarky 7y agoWhat's worse, entering a 21-character meeting ID on the phone, or entering an 11-character meeting ID plus a 10-character password?
- shiado 7y agoIt's an incredibly simple thing to screw up. I wonder where else they use low entropy random strings. I wonder if their password reset functionality can be brute forced too. Another problem is where they put rate limiting as it seems probable based on this article there are holes.
- andor 7y agoReal engineering is about compromises. In this case, relatively short numeric meeting ids allow users to dial in via plain old phone lines. If my meeting guests had to enter a UUID via their phone keypad, they would probably skip the meeting instead.
- shiado 7y agoThat actually makes sense I didn't know you could dial in with a phone.
- _6fmb 7y agoEvery time I read about a Zoom "screwup" I see a feature that's UX centric. It's pretty cool tbh.
- JadeNB 7y ago> Every time I read about a Zoom "screwup" I see a feature that's UX centric. It's pretty cool tbh. Like dialing Facebook even if you're not a Facebook user (https://news.ycombinator.com/item?id=22693792 https://news.ycombinator.com/item?id=22693792)?
- jlmorton 7y agoI mean, this is intentional. They even allow you to set your meeting ID to a well-known number, like your company's published phone number. If you want to join the all-hands meetings of a company I used to work for, you only need to go their website and lookup their primary phone number. That's the Zoom meeting ID.
- pkulak 7y agoOr my personal favorite for anything you show to a user: https://www.crockford.com/base32.html https://www.crockford.com/base32.html
- bo1024 7y agoGood idea for this! But trickier for phone calling into a conversation. They could also just add 3 digits and a slight delay in their connection API, making it much harder to brute force, albeit only by a constant factor.
- diebeforei485 7y agoThis is likely to support dial-in over the telephone network. I think "no password" is the bigger issue, because repeated attempts with incorrect passwords can be rate-limited. Zoom should be generating a random 6-digit password for each meeting by default. There may be use cases for not having any password, but that should be explicitly opt-in and have a warning message to every participant that anyone can join and broadcast in this meeting.
- x0x0 7y agoThey are as of the update to my client this morning.
- disiplus 7y agoi'm sure the reason for that is the UX. the zoom had a reputation of "just works" and part of it was that is so easy to jump in to a meeting. if now i have to manage access and so on, it would not be "it just works" like it was
- lonelappde 7y agoIn this context, a password is the same as an id. There's never a reason to share the id without the password.