My issue with Zoom is that they sometimes manage to be "more convenient" than the competition by sacrificing security.  One of my undergraduate classmates found a significant security hole in Zoom that allowed someone malicious to secretly enter you into a video call when you load their website.  It has since been fixed, as has been the issue that prevented you from uninstalling Zoom.  https://medium.com/bugbountywriteup/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5

> This vulnerability leverages the amazingly simple Zoom feature where you can just send anyone a meeting link (for example https://zoom.us/j/492468757) and when they open that link in their browser their Zoom client is magically opened on their local machine. I was curious about how this amazing bit of functionality was implemented and how it had been implemented securely. Come to find out, it really hadn’t been implemented securely. Nor can I figure out a good way to do this that doesn’t require an additional bit of user interaction to be secure.

> Additionally, if you’ve ever installed the Zoom client and then uninstalled it, you still have a localhost web server on your machine that will happily re-install the Zoom client for you, without requiring any user interaction on your behalf besides visiting a webpage. This re-install ‘feature’ continues to work to this day.

Again, both of these issues were fixed a week after the article went live, but the article went live 3 months after informing Zoom about the issues.

-- Pi Fisher
(617)615-NERD


On Wed, 18 Mar 2020 at 15:32, Michael Tartell <tartell@g.harvard.edu> wrote:
Sadly, I won't be able to participate in this one, but if you run them any
week from now on, I'll be online!
WashU isn't going to essential operations until this Monday.  That means on
Monday I'll be working from home, but until then I'm in a big rush to do a
lot of things.

-Michael Tartell

On Wed, Mar 18, 2020 at 1:53 PM Leland Kusmer <me@lelandpaul.com> wrote:

> We'll be using Bryn's paid account (through her work), which doesn't have a
> time-limit on meetings.
>
> See some of you soon!
>
> On Wed, Mar 18, 2020 at 2:47 PM Katarina Whimsy <kdsorceress@gmail.com>
> wrote:
>
> > This is one professor's report on Zoom, but it sounds like the data might
> > be less dubious than feared:
> > https://twitter.com/twwings/status/1239231385543610369
> >
> > I've also been hearing reports that Zoom is extending time allowed due to
> > pandemic? I think? I don't feel like digging any of those up right now,
> so
> > someone else can research it.
> >
> > I can't make tonight's hangout, but I am pleased to hear it's happening.
> > Enjoy y'all! Lemme know when the next one is!
> >
> > ~Kat
> > -------------- next part --------------
> > An HTML attachment was scrubbed...
> > URL: <
> >
> http://cosmos.phy.tufts.edu/mhonarc/boston-change-ringers/attachments/20200318/81b9e985/attachment.htm
> > >
> > _______________________________________________
> > Boston-change-ringers mailing list
> > Boston-change-ringers@cosmos.phy.tufts.edu
> > https://cosmos.phy.tufts.edu/mailman/listinfo/boston-change-ringers
> >
> -------------- next part --------------
> An HTML attachment was scrubbed...
> URL: <
> http://cosmos.phy.tufts.edu/mhonarc/boston-change-ringers/attachments/20200318/db8626d7/attachment.htm
> >
> _______________________________________________
> Boston-change-ringers mailing list
> Boston-change-ringers@cosmos.phy.tufts.edu
> https://cosmos.phy.tufts.edu/mailman/listinfo/boston-change-ringers
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://cosmos.phy.tufts.edu/mhonarc/boston-change-ringers/attachments/20200318/890fd322/attachment.htm>
_______________________________________________
Boston-change-ringers mailing list
Boston-change-ringers@cosmos.phy.tufts.edu
https://cosmos.phy.tufts.edu/mailman/listinfo/boston-change-ringers