episode.ascii — live render
● episode

News Update – Zoombombs ahoy

TL;DRZoom bombing surged in early 2020 as Zoom's user base exploded from 10M to 200M. Trolls exploited unprotected 9-digit meeting IDs using war-dialer tools to crash classrooms and workplaces with slurs and explicit content.

Jordan & Scott discuss zoombombing.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: As a heads up, the audio I'm about to play you goes from real quiet to real loud really fast. Also, someone might be using a racial epithet. It's kinda hard to tell, but to be safe, discretion is advised.

Speaker 2: Remember, now how many hydrogens do I have? I have Well, that was really unnecessary. Whoever did that, that's your warning. Don't do that again.

Speaker 1: Three weeks ago, a significant chunk of the working population, office workers, educators, basically most white collar jobs started working remote.

Speaker 3: So Kyle, you can leave the session now. I think your behavior is very inappropriate.

Speaker 1: And with that transition, millions of people found themselves in need of a video conferencing solution. Hundreds of millions of them flooded onto the app, Zoom.

Speaker 3: You you can either turn off your video and audio and remain in the Zoom session, or you may leave the Zoom session.

Speaker 1: And assures any technology company isn't going to love that kind of newfound scrutiny.

Speaker 2: It was scary to be honest with you. Just you didn't know what was gonna pop up next.

Speaker 1: Any new technology is going to flex under the weight of that many new users.

Speaker 2: First, they they said stuff like, we you know, we're just here talk about racism.

Speaker 1: Within a few days, people had figured out that the meeting ID system Zoom used was vulnerable.

Speaker 2: And then the screen started flashing things like swastikas and pornography.

Speaker 1: That it was very easy to join random calls between other groups of people. Within a week, someone had built a dedicated tool to do it.

Speaker 2: If we were able to get in on your your call,

Speaker 4: we can find out where you live.

Speaker 1: Which is when the troll showed up. This is Zoom bombing on this hacked update. So I guess my first question is, are you on Zoom?

Speaker 5: Yeah. Aren't we all now?

Speaker 1: I think we're all on Zoom.

Speaker 5: I'm pretty sure we are all on Zoom. I'm on it professionally and socially.

Speaker 1: I think for about a month now, it's basically utility.

Speaker 5: Yeah. Like, I probably spend more time on Zoom these days, at work especially, than not on Zoom these days.

Speaker 1: So what is Zoom bombing?

Speaker 5: Well, Zoom bombing is essentially just joining someone else's Zoom. So you're kind of raiding into their Zoom call. Is that

Speaker 1: it's like I FaceTime people someone regularly. I've never dealt with someone crashing into my FaceTime. Yeah.

Speaker 5: Just showing up.

Speaker 1: Yeah. Just just popping in. Yeah. I make phone calls sometimes because I'm old. I've never had someone burst onto my phone call.

Speaker 5: Well, I'm older, so I've had a party line, so I have.

Speaker 1: This feels like Zoom feels like it's doing I mean, Skype for for heaven's sake. Like, I've never had someone burst onto a Skype call. I've never really heard of this particular problem of people bursting their way into private conversations.

Speaker 5: Yeah. I just think that Zoom existed in a space for a long time, and people used it. You know, it was kind of a solution primarily for technology companies to do primarily, you know, work based meetings. And then all of a sudden, one day, it was like, this is just how we all connect. Mhmm. And I think, you know, with that increased, you know, business, truthfully, has come increased scrutiny and attention.

Speaker 1: Mhmm. I think it went from 10,000,000 users as of the end of last year. I think at the last tally, it's about 200,000,000.

Speaker 5: Yeah. It's probably more still. I assume it's just constantly going up. Mhmm. Like, my fiance works out on Zoom. You know, I'd use it for work. We have we play board games with friends on Zoom. Like, literally everything in every social aspect of our life revolves around Zoom or lots of them. And lots of professional aspects of work revolve around Zoom these days.

Speaker 1: So Zoom has 10,000,000 primarily enterprise clients. This happens. What happens to that meeting ID system? How does it flex under the weight of this?

Speaker 5: Well, it's it's like any kind of, you know, addressing system because, really, all the the meeting ID is is the address inside of the Zoom system. So imagine it's like an IP address for a computer on the Internet. If you know the address, you could reach out to that computer. And the Zoom ID system is just nine digit code. And if you know the nine digit code, you can reach out to that meeting.

Speaker 1: So what makes it vulnerable?

Speaker 5: Well, the fact is is that because Zoom, you know, kind of was this more esoteric product and hadn't received this technological scrutiny and been such a target, they'd managed to get by with pretty, you know, open security, options. So, like, passwords aren't by default required or set for meetings. So, like, we have Slack, and we have the ability to kick a Zoom meeting off in any Slack channel with relative ease, and those Zoom meetings are, by default, non password secured. So they've since changed all of that in rapid fashion because, yeah, that's what makes it insecure is, you know, you essentially just have to know the nine digit code, and you can jump into someone's call.

Speaker 1: Mhmm. Is this just kind of a case of a product being as secure as it needed to be back when its user base was considerably smaller?

Speaker 5: Yeah. And, like, the the reality is too is that this is, you know, we've talked about this a bunch of times in the last little while. This probably isn't intentional. This is just a byproduct of what's happening. It was probably secure enough for most corporate and enterprise users because those corporate and enterprise users aren't looking to cause mayhem. But once you start spilling it out to hundreds of millions of everyday people, you're kind of incentivizing a little bit of mayhem.

Speaker 1: I mean, this has now become the way that so many teachers are, like, teaching students. It's educators need a platform on which to get 30 some kids in the same space. 30 some kids in the same space online seems like a recipe for trolling.

Speaker 5: Yeah. Well, and especially, you know, you've got to imagine that's just one classroom. Imagine when you get all of those students. And if they're not actively in a class, they know their friends are. All they need is the nine digit code to blop in and disrupt it and leave. So I know you're seeing a lot of people and students kind of disrupting their, like, you know, cohorts classes because it's like, why not?

Speaker 1: Yeah. There's dedicated Discord servers now for organizing Zoom rates.

Speaker 5: Yeah. See? It's like they've they've gamified it.

Speaker 1: So, like, what are the immediate solutions? Because Zoom did have different security options that existed. They just weren't default. You did have the meeting room system. You did have passwords. What has Zoom since done in response to this? Because this story popped off faster than most stories I see in the tech world. People went from not knowing that this was possible to knowing that it was plausible to knowing that it was endemic in, like, one news cycle. So what has Zoom done as a response to that?

Speaker 5: I think the the big change that'll kinda stem this is they've just made passwords default. If I click new meeting, it immediately has a password. Because the big thing is is the URLs that they send out so, like, if I create a meeting and then invite, you know, you to it, it'll send you a click to join Zoom button. That button has the password embedded in the URL. So it it doesn't affect your user experience. It just affects whether the door is left unlocked.

Speaker 1: Starting something new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button is used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.

Speaker 6: This summer, FanDuel is the best place to bet on goals with new ways to score alternate law.

Speaker 1: What kind of goals? All of them. Including equalizers? Yes. Lollies? Yep. Dinky Chips over the keeper?

Speaker 6: Pretty much any goal you can think of goes further on FanDuel, so let there be goals. All customers can win up to $25 if USA has one shot versus PowerOne. 21 plus in present in select states. Opt in required. Must wager in designated offer market. Max wage of $25. Restrictions apply. See full terms at fendool.com/sportbook. Gambling problem? Call 1800 or 1800.

Speaker 1: So in the intro story, I used this one clip from a CBS piece on a Conejo school district Zoom bombing. I'll just run the clip.

Speaker 2: If we were able to get in on your call, we

Speaker 4: can find out where you live.

Speaker 1: Is that real? Is that an actual danger that if you get Zoom bombed, the people doing it could theoretically figure out who you are, where you live, your personal information?

Speaker 5: You're asking me a question that I don't know the answer to because I don't exactly know how the Zoom back end, makes the connections. Because if you have an independent connection to everybody else in the Zoom call, assuming you're not routing through a, like, a a universal hub or a server, if you actually end up building a connection to each person, then you will have access to their their, you know, remote IP address, and remote IP addresses are actually connected to location data. It wouldn't be like, you know, this exact house. Right. But you'd be able to generally figure out where they are. Yeah.

Speaker 1: Generally speaking, a teenager is Zoom bombing you, though.

Speaker 5: Probably not.

Speaker 1: Cool.

Speaker 5: Yeah. Probably not super interested in getting to know the person whom they've just been super inappropriate to.

Speaker 1: Right. They've also gotten their wrist slapped for their privacy in regards to Facebook and how they encrypt their calls.

Speaker 5: Yeah. They definitely had a spotlight kinda turned and pointed at them. Couple small things. Like, I think they got their wrist slapped or getting currently in the process of getting their wrist slapped for disclosing some data user data to Facebook. It wasn't explicitly expressed in their privacy policy. And, you know, because all of us spent days reading those things, I'm sure it would have made a huge difference. What else did they get in trouble for recently? It seems like they've had a constant stream of stuff. I know they have an encryption issue. They use an AES based encryption tool algorithm, and I don't think their implementation of it is, you know, the best version of itself. Or is the encryption algorithm that they've chosen the best version for the task? So I know that there's a little bit of gripe about that.

Speaker 1: Talk to me about war dialers.

Speaker 5: Yeah. So you mentioned in the intro, somebody has built essentially a custom tool to check meeting IDs and and find open meetings. They did that with such speed because that tool essentially already existed, because war dialing, which is something I'm old enough to remember, you know, back when you had to dial on to the Internet and dial into computers. So So instead of having VPNs and stuff like we do today, your corporation would have a modem bank, and you would dial into the corporation and literally connect to the corporation's network via dial in. So that was called war dialing. It was essentially calling all of the numbers in a certain prefix trying to find a computer that would pick up. So they essentially took that same, you know, kind of algorithm and piece of software. But instead of war dialing, instead of dialing phones, they're literally just reaching out to Zoom meeting IDs until they find ones that respond saying, yeah. I'm open. Do you wanna join?

Speaker 1: Mhmm. Is this why most modern security isn't based on a single key?

Speaker 5: Yeah. Yeah. Yeah. Yeah. Like, with enough of the instances of that war dialer, you can cover pretty much, I think, every possible Zoom ID almost concurrently. So was that kind of meeting spins up, you could know about it if you had enough power.

Speaker 1: Do you think that the community that reworked those war dialers to work for Zoom is gonna try and keep digging? And do you think that they're gonna keep pursuing, Zoom, or do you think this this was just sort of a crime of opportunity? We have software that's good at guessing numbers. They have software that is vulnerable to number guessing. Put it together.

Speaker 5: This is, this is gonna be a controversial statement, but I think Zoom is getting a ton of security analysis for free right now. The community is showing them where their flaws are and making their product better. And the fact that they're responding so timely shows that they're taking it seriously. Like, the fact that they, I think, hot patched, the default password thing, like, a week after it kinda became a big deal, like, that's pretty quick for a big software company. And I think, you know, instead of paying bug bountiers to tell them what's wrong with their software, they're just literally getting the voice of the community who's doing it for them now.

Speaker 1: Hey, everybody. Thanks for listening. Slight update on this story. On April 6, the day before this launches, New York mayor Bill de Blasio has banned Zoom in public classrooms. We wanna hear from you about this. If you're still using Zoom, if you're using something else for your teleconferencing, talk to us on Twitter at hacked podcast or support the show on Patreon, patreon.com/hackedpodcast. Thanks for listening.

Speaker 7: Shopping is always a good deal better at Meijer. Right now, get a $10 coupon with a $100 in store purchase. Coupon redeemable from the seventeenth through twenty third. Also this week, make family meal planning a snap, and fire up the grill with with great BOGOs, including buy one get one free fresh from Meijer pork shoulder butt roast, or buy one get one for a dollar fresh from Meijer boneless pork loin chops. Plus, enjoy fresh and juicy blueberries for $3.99 a pint. Good life quality at real low prices, only at Meijer. Exclusions apply. See all deals in the Meijer app.

Speaker 8: Summer weekends are all about family, sunshine, and making memories together. Before everyone arrives, I stop by my local Total Wine and More to pick up a great bottle, maybe a favorite we already love, or something new to enjoy with dinner on the patio. With so many bottles to choose from, it's easy to discover something amazing. And with the lowest prices, it's easy to grab an extra bottle for the table. Not sure what to pick? Their friendly guides are always there to help. Find what you love and love what you find only at Total Wine and more. Curbside pickup and delivery available in most areas. Visit totalwine.com to learn more. Spirits not sold in Virginia and North Carolina. Drink responsibly. Must be 21.