15 ms·
Zoom Security Exploit: Cracking private meeting passwords
- deleted 6y ago[deleted]
- wolco 6y agochecked 91k passwords in 25 minutes. 250 minutes to crack any password? Meeting will be over before this happens.
- marksomnian 6y agoThat's on just one computer. Depending on how many servers (read: how much in AWS credits) you have access to, you could parallelise it nearly infinitely.
- eat_veggies 6y agoThis attack horizontally scales really well, and you don't have to try all 1 million passwords in the average case
- d4mi3n 6y agoDon't forget that many recurring meetings reuse the same password.
- tinus_hn 6y agoIf you can choose the password, people will also use passwords they use for other things.
- d4mi3n 6y agoI agree, but the point I'm trying to make is that the time to guess the password isn't too big of an issue for passwords that never change. Ideally, Zoom would generate a password for each instance of a meeting. Failing that, having some better factor for authentication (known email or number for a given company's Zoom setup) would make it harder to get in simply by guessing a short password.
- ptasker 6y agoI would imagine using a GPU compute instance would bring this time down significantly.
- eat_veggies 6y agoIt's network bound, not compute bound. A GPU wouldn't really help in this case.
- TomAnthony 6y agoOP here. I tested much higher rates for short bursts, and wasn't ever rate limited, but didn't want to risk blowing anything up. However, with a few AWS instances / lambdas it would have been possible to do it in a few mins. Secondly, and more importantly, I found a variant (mentioned in the article) that allowed me to do this before meetings started, so you could have the password in advance.
- dx87 6y agoYou missed the part where he said that you could just throw more servers at the bruteforce and drastically cut the time required.
- black3r 6y agoOn a single machine with 100 threads. But imagine what NSA (or any other relevant intelligence agency) can do for listening into some foreign government's meetings like the UK one in example. Or what huge corporates can do for corporate espionage.
- deleted 6y ago[deleted]
- andykx 6y agoIt won't necessarily take that long though. That is an upper limit.
- sillysaurusx 6y agoIt seems like one way to mitigate security vulnerabilities is to write software that looks for statistical anomalies. Attempting 1 million passwords in 28 minutes is such an obvious outlier that it's strange we have to guard against it explicitly. It would also catch cheats in video games, for example, since those are statistical outliers too. Is there a name for this kind of program?
- eat_veggies 6y agoYep, it's called novelty and outlier detection. The sklearn page is pretty informative: https://scikit-learn.org/stable/modules/outlier_detection.html https://scikit-learn.org/stable/modules/outlier_detection.ht...
- caiobegotti 6y agoEven a really crude monitoring metric would trigger alerts after a bunch of recurring calls to an endpoint from a specific place. They simple don't care at all or are too dumb to come up with basic security checks.
- nitrogen 6y agoUntil it's a default in frameworks like Spring Boot and in ELK stack logging systems, in most places it's not happening.
- wdb 6y agoGot any examples of such monitoring metric setup? Would love to get an idea what it's good to monitor :) I am thinking of using Grafana with Prometheus. Love to find a nice resource with good ideas of rules/monitoring to have
- caiobegotti 6y agoThat's exactly what I do (or would) use and it does plenty for many type of business and it scales up well. The metrics specifically depend on the rest of your stack though but these days any API gateway or ingress application or service mesh or proxy app can provide endpoints metrics for you nearly out-of-the-box.
- black3r 6y agoRate limiting login attempts is a basic security principle that's both easy to implement and not overly intrusive. This once again confirms that Zoom just doesn't care about having a secure platform at all.
- mcherm 6y ago> This once again confirms that Zoom just doesn't care about having a secure platform at all. I disagree. I think it shows that Zoom (at the time this was created) lacked the skill necessary to create a secure platform. But their prompt reaction and subsequent focus on security has given me hope.
- ziddoap 6y ago> 9th April – Heard from the Zoom team that this was mitigated. > 16th April – Heard they were working on updated bug bounty program. > 15th June – Requested update on BB program. No reply. > 8th July – Asked again if I could submit this for bounty. No reply. > 29th July – Disclosure. Prompt? > Maximum password length of 10 Increased focus on security?
- hungryhobo 6y agonot sure if you've actually read the article
- cosmodisk 6y ago
- Naac 6y ago> 9th April – Heard from the Zoom team that this was mitigated. > 16th April – Heard they were working on updated bug bounty program. > 15th June – Requested update on BB program. No reply. > 8th July – Asked again if I could submit this for bounty. No reply. > 29th July – Disclosure. That's disappointing that Zoom never got back to you regarding the bounty.
- tito 6y agoGut check here on Zoom customer service. Has anyone heard from them in the last 2 months? I've been on a pro plan and 10-seat plan and had 2 issues about events sent to their customer service starting June 3rd. Have not heard back anything besides regular "we're moving slow because of COVID 19" template updates". They used to be responsive, even had a "chat" feature but now that's disabled.
- mystcb 6y agoI am going to raise my hands and say I have heard from them. I logged a support request on March 24th (the day the UK went into lockdown, so I was already expecting a delay). I finally got a response back on July 20th. It is a shame they are slow, as they have been really responsive in the past. Hope that helps set a bit of a benchmark!
- cs02rm0 6y agoBug bounties seem to be a complete wild west. I've reached the point of assuming the odds are stacked so heavily that, from a purely financial perspective, it's not worth the investment just to report an issue let alone find it.
- caiobegotti 6y agoReading the whole story it makes me believe Zoom has really poor securities practices all across their board. Even basic stuff. Incredible.
- ziddoap 6y ago>In other testing, I found that Zoom has a maximum password length of 10 characters, and whilst it accepts non-ASCII characters (such as ü, €, á) it converts them all to ? after you save the password Maximum password length of 10 chars, and auto-converting non-ASCII to '?' are both extremely egregious password practices.. Why does it not surprise me Zoom is doing both. I wonder it they also silently truncate passwords > 10 chars? These are absolute basics. Let alone not rate limiting and the laundry list of other terrible (lack of) security practices.
- fossuser 6y agoThey do silently truncate account passwords greater than 32 characters, but what's (arguably?) worse is they only do it in some places and not others. I use 1Password and sometimes when it pastes in it works, sometimes the UI complains the password is longer than 32 characters. I sent them a screen shot on Twitter [0] figuring their US support people would see it, but they didn't seem to care that much (got some generic response). We just shouldn't be using them: https://zalberico.com/essay/2020/06/13/zoom-in-china.html https://zalberico.com/essay/2020/06/13/zoom-in-china.html [0]: https://twitter.com/zachalberico/status/1257910514966908933 https://twitter.com/zachalberico/status/1257910514966908933
- hmhrex 6y agoThanks for linking that essay. It's a good read. I especially liked the Sarah/Exec conversation. Will definitely keep this one saved for later.
- tinus_hn 6y agoDo Chinese people not use Chinese characters in their passwords?
- yorwba 6y agoEntering Chinese characters requires using an input method engine that turns keyboard input into a list of candidate words from which the user picks the correct one. If you used that method to enter a password, shoulder surfing would be trivial. I think it's usually automatically disabled for password input fields.
- user5994461 6y agoI really hope they just extend the password to 8 upper letters (200 billion combinations) or 10 digits. If they go for a longer and alphanumeric password as it seems they are doing, I am gonna dread having to enter that manually whenever joining a meeting, all because an hypothetically attacker might join in. Might as well switch back to webex for usability.
- jrochkind1 6y agoyou're entering passwords manually to enter zoom meetings? I don't think I've ever done that, usually they are included (hashed) in the URL distributed to participants, as the OP mentioned several examples of.
- lixtra 6y agoSome environments don’t allow copy and paste. For example blackberry work (depending on configuration) on a private phone.
- user5994461 6y agoCan't copy/paste from my desktop to my mobile, or the other way around. Can't copy/paste to the video conference system of a meeting room either.
- techntoke 6y agoWhy public education continues to use Zoom is beyond me. Not only do they use Zoom, they spend upwards of $10/mo per student for it. For that price you get the entire G Suite platform.
- reaperducer 6y agoWhy public education continues to use Zoom is beyond me Some schools and states have banned Zoom. I think New York's educational system is one.
- Figs 6y agoWe tried using Google Meet for work meetings at my university. The experience SUCKED compared to Zoom. There were serious problems like taking 30 seconds to a minute for the screen share widget to popup after clicking the button in Firefox! It was, frankly, unusable for us. We also tried self-hosting Jitsi, and while that kind of worked, we had some problems getting everyone to be able to connect to it and send/receive audio. It went on the backburner of things to look into more later. Zoom has a lot of problems, clearly, but it solved THE most important issue: we can actually communicate successfully with it -- as in right now with minimal additional effort. That's why it won.
- sm4rk0 6y agoTime to learn that minimal additional effort != best solution. When you drink a soda, minimal additional effort is to throw the can away, but if you think about consequences you'll probably make some additional effort and recycle it.
- eee_honda 6y agoWhat sort of problems did you experience with jitsi in terms of the connectivity you mentioned?
- Figs 6y agoIt's been a few months since we tried it -- so not fresh in my memory any more -- but as I recall, the biggest issue was with audio not working as expected. e.g. you could see people talking in the video feed, but not everyone could hear the audio. I don't think it was just a muted microphone on the other side; my recollection is that some people could hear the audio and some couldn't, but it wasn't clear why not. I remember having to call our group leader by cellphone because he wasn't seeing/responding to the issue in chat and was just continuing on... We did eventually get it working for almost everyone (I don't remember how though, unfortunately) -- but there were two or three people who just couldn't seem to get it to work no matter what they tried, and we ended up going back to Zoom for the next meeting.
- AnonHP 6y agoI can't stand the thought of using Zoom after all the seemingly endless issues on security and privacy (and now this new issue with not paying a bug bounty). For what might probably be a millionth time, what are the best alternatives (preferably free or easily self-hostable or priced low) for occasional calls of the following types: 1. Video calls with some people (say about 10 people max.). The free Jitsi Meet seems good for this. 2. Webinar platform where there are clear distinctions between a presenter and participants, and the presenter chooses what's visible at any point in time (video feed from camera or some file/presentation/screen sharing) and has control over recording the session. 3. Same as #2 but with two presenters on camera (different physical locations) switching back and forth (either as the main view or with the active presenter on the main view and the other in a smaller corner window).
- dehrmann 6y agoSecurity isn't in Zoom's culture or DNA. It's not how they think, so they'll keep having issues.
- coldcode 6y agoMy employer just switched to Zoom (yesterday was my first zoom meeting) and I wondered why we were switching to a company with such lame security.
- twostorytower 6y agoMy org was forced to switch from Zoom to Microsoft Teams and it's become quite apparent Microsoft has a long way to go to catch up. There are small things Zoom did that enhanced meetings that you never even knew or thought about as a user until switching to something else. For example, noise filtering. Zoom has active noise filtering which gets rid of small background noise (like typing or computer fans). Microsoft Teams does not have this, and every meeting with more than a couple people has unbearable background noise and everyone has to be on mute if they're not talking. We're now looking into an enterprise license for Krisp.ai just to remedy this. I am not sure how a trillion dollar company like Microsoft hasn't been able to figure this out yet. Maybe they'll buy a startup like Krisp just to fix it. But hey...at least it's more secure.
- TomAnthony 6y agoYeah, Zoom works very well, and is so much better for video calls than most of the alternatives. I do have sympathy for their team who were suddenly getting a wild amount more traffic, and scrutiny. They have scaled fast and kept the platform up and stable, which is impressive.
- tech234a 6y agoDiscord actually just partnered with Krisp.ai to bring the feature to their app too.
- avh02 6y agoOn the flipside (just an anecdote, not making any points), we had a hard time turning this noise filtering consistently off for a colleague of ours who speaks without a voice box. He kept getting filtered out randomly and we couldn't understand him because of the feature. It was (at the time) turning back on without his knowledge. We eventually got it consistently turned off with one of our zoom admins' help. We get a lot of background noise from him but his voice is more valuable there.
- userbinator 6y agoand everyone has to be on mute if they're not talking. In all the calls I've attended this was always the case anyway, and there seemed to be an implicitly understood rule of "keep yourself muted unless you want to say something". Seeing someone's mute indicator turn off was a cue to pause and wait, as it indicated someone wanting to say something.
- netsectoday 6y agoI believe Zoom's continued struggle represents the state of software development in 2020. 1. Are you a software engineer? 2. How many "security" tickets have you been assigned in your career? 3. Has your employer ever paid for security training for you? (and I'm not talking about annoying powerpoint websites that teach you how to identify phishing emails) 4. Has your organization ever run a blue team / red team exercise? 5. Who is in charge of APPLICATION SECURITY at your company? (Not network security, or database security, but actual APPLICATION level vulns) 6. Does your organization scan for outdated dependencies? (Do you uncover CVEs in your software on your own, or do you check how bad things are when the news tells you something big happened and might be in your stack?) 7. Are you running a web application, and have you implemented ANY security headers? 8. Did your business unit mandate that "we support all browsers", so they still have you running on TLS v1.1? (who tf knows, or cares, am I right?) 9. Do you use the software you built? (Is your personal information in the database, along with legitimate usage stats, and possibly sensitive information you'd like to protect, or do you just write the code and deploy into the void?) 10. Do you have access to the production systems or database? (Most likely the answer is NO, so you wouldn't know about brute-force attacks, invalid requests, corrupted data, or other anomalies the developers should have their eyes on). My diagnosis; the profession of software development is a victim of a hostile takeover from product managers, while pushing engineers out of control of their domain. My recommendation; use the least amount of software you can get by with, and assume it's compromised.
- ziddoap 6y agoI fully agree with your sentiment, but the specific issues discussed here (having a maximum password length of 10, silently truncating passwords, silently replacing non-ASCII with '?', setting default passwords to 6 numbers, not rate-limiting password attempts) are not things that require a red team / blue team to figure out. They aren't things that require scanning dependencies, auditing source-code, etc. These should be as basic as not storing cleartext passwords.
- FabHK 6y agoAgreed. Yes, the state of InfoSec is bad in most companies, but with Zoom it is really abysmal. World class super bad.
- rkagerer 6y agoIt's unconscionable they still hadn't implemented any sort of rate limiting. It should have been there from day one. For the protection of their customers, and their own infrastructure. After the string of "zoombombings", it should have been a top priority and received ongoing attention from their CEO until implemented. When I began using the platform, I assumed the randomly generated meeting numbers were buttressed by adequate account and connection attempt monitoring on their back end to make them "secure enough". After finding reason to suspect otherwise 5 months ago, I contacted Zoom about it twice and never received a response (from what I can tell support is overwhelmed and tickets even for serious issues like security breaches and billing errors can take months to hit human eyes). The password-in-the-link approach felt to me like security theatre. Yes, it adds value, but really doesn't amount to anything more than a bit of additional URL obfuscation (particularly given the length and character limitations), unless you're distributing passwords separately - which can be onerous for attendees. Hats off to this researcher for forcing the issue and finally incentivizing the company to work on cleaning up their act. But it makes me worry about where else in their platform they took shortcuts. They've really nailed the "frictionless" part (and I commend them for that) but I'm convinced you can achieve a friendly user experience while still maintaining a basic level of security.
- varenc 6y agoAren’t secret unguessable URLs used all the time to secure content? See gdocs, Dropbox shared files, etc. Of course the password shouldn’t be 6 digits...but as long as the URL space is unsearchably massive, say 256 bits, and there’s some basic rate limiting, embedding a “password” or random token in a URL seems an acceptable way to frictionlessly share private content?
- rkagerer 6y agoExactly. The Zoom links don't tend to have a large search space by comparison, and AFAIK all the services you mentioned use connection throttling and other mechanisms to detect and stop abuse before it goes rampant. Appending a passcode is little different than if they were to just use longer meeting numbers in the first place (but with sometimes-worse entropy e.g. when the user changes it to "123456"). So they bought a few more bits (evidently still not enough to beat the bad guys) at the price of extra user hassle. If they were more aggressive on the server side, they could probably get away just fine with the smaller, more convenient links and wouldn't need to push users so hard to turn on "frictiony" features like waiting rooms. Private links work great as long as the team providing them understands the tradeoffs and appropriately mitigates risks. Zoom isn't the first service to be brute-forced [1], and there are more subtle ways for links to leak [2] (e.g. I think someone's tax returns once wound up on Google after the secret Dropbox URL was passed in a referrer header). [1] https://www.theregister.com/2011/05/08/file_hosting_sites_under_attack/ https://www.theregister.com/2011/05/08/file_hosting_sites_un... [2] https://softwareengineering.stackexchange.com/a/325821/79139 https://softwareengineering.stackexchange.com/a/325821/79139
- xtracto 6y agoReminded me of the time when it was possible to brute-force a Hotmail password brute-forcing via the Windows Messenger client connections
- jimktrains2 6y ago> They seem to have mitigated it by both requiring a user logs in to join meetings in the web client Well, that's unfortunate. I don't have a zoom account and have no interest in having one, but sometimes need to attend meetings I have no control over where they're held.
- zemnmez 6y agoas an fyi, csrf protection is not related to bot protection; the csrf protection failure means an attacker can execute this code in another user’s browser (and get no meaningful result)