8 ms·
Dutch journalist gatecrashes EU defence video conference
- kyriakos 6y agoIts amazing how well they took it, laughing and all
- fakedang 6y agoProbably because they secretly knew that if word gets out real fast (which it won't because it'll controlled by them), they'll all be booted from office. Sure word got out, but it need not reach most of the populace.
- rebuilder 6y agoThis is on BBC.com's frontpage.
- fakedang 6y agoYeah, and how many mainlander Europeans read the BBC in English?
- programLyrique 6y agoOther journalists in mainland Europe. And then they publish articles in the native language of their country. In France: https://www.lefigaro.fr/flash-actu/un-journaliste-s-introduit-dans-une-videoconference-confidentielle-de-l-ue-20201121 https://www.lefigaro.fr/flash-actu/un-journaliste-s-introdui... In Belgium: https://www.rtbf.be/info/medias/detail_un-journaliste-neerlandais-parvient-a-s-introduire-dans-une-videoconference-confidentielle-de-l-ue?id=10636662 https://www.rtbf.be/info/medias/detail_un-journaliste-neerla... And so on...
- kyriakos 6y agoProbably a lot of them and even if they don't journalists do as BBC is the source for many articles that are later being translated and editorialized in local newspapers.
- pjc50 6y agoNobody cares about trivia like this when it comes to elections.
- pkz 6y agoThe conference chair couldn't help giggling. What was it he said? "Hey you better hang up before the police arrives"?
- jariel 6y agoIt's very serious stuff, it's not funny. Someone leaves their doors unlocked it doesn't mean you should be entering. More importantly, how on bloody earth are defence discussions happening in a situation that can so easily be defeated. The officials themselves are to blame for blatantly terrible security protocols.
- numpad0 6y agoSomeone leaves door unlocked means you must enter one step and scream out loud before criminals come and trigger a global thermonuclear war. That’s basic ethics for software engineers.
- curiousllama 6y ago> Someone leaves their doors unlocked it doesn't mean you should be entering. Yea, well, it's a useful function of journalism to poke their head in open doors and say "you're doing _WHAT_ in here?!" I slot this in alongside the time US nuclear missile officers were found asleep, with the door open waiting for takeout - simultaneously seriously disturbing and quite funny. https://www.cnn.com/2013/10/23/us/air-force-nuclear-silo-doors-opened/index.html https://www.cnn.com/2013/10/23/us/air-force-nuclear-silo-doo...
- 0dmethz 6y agoI think it's better to have a journalist step in and warn you about your door being open, rather than having someone with bad intentions sneak in, don't you think?
- mekkkkkk 6y agoThis is by far the most effective way to make sure said door is locked in the future. This guy deserves a reward.
- deleted 6y ago
- rosmax_1337 6y agoThey're laughing right now, but really these kinds of mistakes are telling how weak the security of various agencies are.
- fakedang 6y agoEU militaries are a joke tbf. Apart from France and (formerly) the UK, most of them can't do shit except sell firearms to Arab despots. I think someone from Romania here mentioned that they trust the US to protect them more than they trust France or Germany.
- rgblambda 6y agoIf the EU is to become independent from the US as Macron wants it to, then that's going to have to change.
- deleted 6y ago[deleted]
- vagrantJin 6y agoAs a bloc, I don't think EU had much of a choice. US had them on tight leash until DJT came through and force thenm to consider protecting themselves. To think DJT has woken up the EU from their decades long slumber is incredible.
- cptnapalm 6y agoThere was chatter about this back in the mid-2000s about the EU forming their own independent foreign policy. There was lots of ink spilled about the EU's soft power which evaporated as it turns out soft power doesn't exist without hard power. Obama lamented the "free rider" problem where much of the EU wouldn't live up to their treaty obligations. The EU wasn't on a leash; it just didn't bother.
- vagrantJin 6y ago
- dba7dba 6y agoOne of the ways China managed to hack into America's F35 (or F22) fighter development program was listening into a conference call of various vendors discussing project status.
- FatalLogic 6y agoAccording to a screenshot that the journalist posted on Twitter, it appears like the video conference session is browser-based, and the pin and username are in the browser URL in plaintext. So then if you can see anyone's screen, or any clear photo of it, you can easily join the conference. Seems like very poor security design if that's so https://pbs.twimg.com/media/EnRlaFeWMAQzyIS?format=jpg https://pbs.twimg.com/media/EnRlaFeWMAQzyIS?format=jpg The software URL format looks similar to that used by Pexip.com
- justinclift 6y agoWell, the page title in that video says "Consolium Videoconferencing", so it's probably something by this company: https://consiliuminc.com https://consiliuminc.com Maybe this? https://consiliuminc.com/product/UniVCX-video-customer-experience https://consiliuminc.com/product/UniVCX-video-customer-exper...
- cblconfederate 6y agothis should require something more than a URL, even a skype meeting would be more secure.
- aequitas 6y agoI wonder, I he was sitting in a suit and in a room with some flags behind him (not in his shirt in an ordinary office) if anyone would have even noticed he was intruding on their conference. They laugh it off now because he doesn't fit in.
- bouk 6y agoProbably if he didn't turn on his camera then nobody would've noticed at all.
- praptak 6y agoNot sure how confidential that conference was but I'd imagine these use at least a 2FA dongle to authenticate. This is surprising.
- pkz 6y agoIt was a six-digit pin of which 5 digits were accidentally shown in a tweet from the Dutch Defence Minister Ank Bijleveld.
- j0057 6y agoYou'd imagine, but this conference software apparently only requires a pin that's visible as a GET parameter in the URL. I don't think you can blame the users for posting a screen shot.
- claudex 6y agoIn this case, you can blame the user. They are the minister of defense, they can (and should) request an audit for the conference system they use. Personally, I think that they didn't want a more secure system like 2FA because it's not convenient for them.
- jakub_g 6y agoZoom introduced meeting passwords a few months ago after similar issues to prevent randos joining meetings by guessing short meeting IDs. But there's a tradeoff between security and usability so they accept passwords as a param in URL, which for 95% cases is a good tradeoff (for example Outlook Zoom plugin generates the URL with password directly in meeting invites). Most people don't live-share their super secret in-progress meeting IDs and passwords on Twitter. Probably more people share their CC number or boarding passes on instagram each day. However what Zoom and other conf tools could do is that they could read the password from the URL and then use `history.pushState()` DOM API to replace the URL and erase the password once the meeting is launched. Downside would be though users wouldn't be able anymore to just copy the URL from browser's URL bar and send to other people to join.
- 6y ago
- FatalLogic 6y agoIf he joined the video conference to watch and listen, but just sent a blank screen video, or maybe a freeze frame of an empty chair, would anyone have noticed?
- snypher 6y agoI remember being in voice chat for a space spreadsheet game [0] and hearing the 'ding' for a new user joining the channel. Everyone knew to stop taking lest a spy discover where our fleet was. I really hope there's a similar reaction in these chats! [0]eve-online.com
- bserge 6y agoCorporation and guild leaders really should put that on their CVs, it's literally management experience!
- ObsoleteNerd 6y agoEve is a special special game. I led/CEO’d a ~200 player Corp (WH/Null pirates) for a fair few years. We had a security division responsible for protecting our web services and communications, custom web and phone apps because we didn’t trust the publicly available ones, an intelligence division responsible for trying to break into enemy services and get info, a propaganda division for feeding false Intel “accidentally” via reddit/etc comments, PR department for managing recruits, and a strict chain of command with levels of management. The bigger corps went even way further than that. It was lots of fun, probably the most fun I’ve ever had in a video game in 35yrs of gaming, but eventually I needed to actually see sunlight again and have a life.
- neurostimulant 6y agoSounds like I would probably love getting into eve online, but u can't find enough time to game anymore on regular basis. My Steam account and old ps3 is still full of games I haven't played yet.
- zaroth 6y agoI think they should be a lot more concerned about the people recording the meeting who don't show up on the attendee list, than of the people who show up and wave in front of the camera.
- inglor_cz 6y agoYeah, the problem with online meetings is that someone else might be taking part as well, unseen and unheard. Does not matter as much if you discuss reconstruction of a mountain hut, matters a lot in defence, espionage or diplomacy.
- 0dmethz 6y agoOf course they respond with the obligatory "we'll report this to the authorities", rather than "thank you for pointing this out in a harmless way we'll do better".
- curiousllama 6y agoIt was humor... The "threatener" was laughing, the audience was laughing, and the journalist laughed too. Probably the best response you can hope for in the moment.
- xuhu 6y agoThe journalist was laughing, but the foreign policy chief just got painted as an emperor without clothes. And the foreign policy chief was laughing, but I bet he was asking himself "who do I send over there to stop them" while trying to maintain the laughing face.
- agilob 6y agoHmmmm >The meeting was ended due to the breach, while a Foreign Affairs Council spokesman told RTL: "Such a breach is illegal and will be reported to the authorities."
- curiousllama 6y agoNote that there are different levels of "secret" when it comes to this stuff. Given the size of that meeting (20+ people) and the reaction, I'd be surprised if the topic matter was more secret than how much the defense agencies pay their employees - secret, no doubt, but not exactly the nuclear launch codes.
- estaseuropano 6y agoIndeed this was a ministerial level conference, the prep meetings are probably more secure and no one would be stupid enough there to share screenshots. At least since Snowden EU leaders probably always assume that someone is listening in. NSA and GHQ had breached Belgacom (Belgian former telecoms monopoly) to listen in on the EU.
- cblconfederate 6y agoEU has no defense anyway so this is not entirely disastrous, though still very unacceptable.
- andrepd 6y agoThis is profoundly depressing. The fact that an EU defence conference is being held... on Zoom, is truly a microcosm of what has been the strategic policy of the EU for the past 20-30 years. We have sold off our independence, out advantages economic and otherwise, for pennies. For minuscule short-term gains, we have sold off our industry, our tech, to a hostile and totalitarian government. Well when I say "we" I mean private enterprise, but also the governments who were supposed to be raking in (though as one German economist said, government and private enterprise are pretty much one and the same). It will come soon a time (in fact, it's pretty much here already) where China calls the shots over us. "Obey, or no microchips for you. In fact, no manufacturing of any kind." Thoroughly depressing.
- Moodles 6y agoThe Zoom security debate has been hashed to death on HN lately, but Webex for example patched some RCEs only a couple weeks ago. I’m not fully convinced Zoom is objectively less secure than all the other alternatives these days. They just get a lot more attention for it. Besides, if the EU defence conference had an open URL or weak password that issue would apply regardless of Zoom, Webex, etc.
- rscho 6y agoThe point of GP is that Zoom is american software, regardless of any particular issue related to the app itself. Which IMO, is a very crucial point. A EU security conference should use EU software, and as little foreign stuff as possible. Otherwise, it's just theater (and it currently really is just that!).
- Moodles 6y agoAll of Zoom’s security team is based in the US to be fair. I don’t really agree in general that the X-conference should use X-software.
- rscho 6y agoWell, if you are using foreign software for sensitive stuff, then you should at least be able to fully review the source and build the app yourself. > All of Zoom’s security team is based in the US That's the point. Thinking that the US are truthful and honest allies of the EU is plain laughable.
- tdons 6y agoWhat's more depressing is that this official has GMail open. How ridiculous is that? Which defense minister outside of the USA uses Google Mail? After Snowden, really? I want to facepalm so hard right now.
- hawk_ 6y agoUnfortunately the bureaucrats still go through dated curriculum to get where they are and there no incentives to keep up with the times, technology or otherwise. These same people decide on the criteria for the incoming class and the vicious cycle goes on.
- toyg 6y agoLet’s be fair: many of these “bureaucrats” went to school when the modern internet didn’t exist. I’m in my early 40s and lived “the new economy” in my teenage years, most 50+ people would have no real familiarity with this sort of tech. Conversely, a lot of under-40 politicians and bureaucrats do grasp the internet - sometimes unfortunately so, considering they can be among the strongest supporters of draconian censorship.
- bserge 6y agoAnd these are the people pushing for laws around encryption. They have no idea what they're doing. In fact, that's really odd - you'd think that by now, tech-competent people would be in positions of power. Why aren't they?