SpaceX Bans Zoom Over Privacy Concerns (reuters.com) 52
Elon Musk's rocket company SpaceX has banned its employees from using video conferencing app Zoom, citing "significant privacy and security concerns," according to a memo seen by Reuters, days after U.S. law enforcement warned users about the security of the popular app. From a report: SpaceX's ban on Zoom Video illustrates the mounting challenges facing aerospace manufacturers as they develop technology deemed vital to national security while also trying to keep employees safe from the fast-spreading respiratory illness. In an email dated March 28, SpaceX told employees that all access to Zoom had been disabled with immediate effect. "We understand that many of us were using this tool for conferences and meeting support," SpaceX said in the message. "Please use email, text or phone as alternate means of communication."
NASA, one of SpaceX's biggest customers, also prohibits its employees from using Zoom, said Stephanie Schierholz, a spokeswoman for the U.S. space agency. The Federal Bureau of Investigation's Boston office on Monday issued a warning about Zoom, telling users not to make meetings on the site public or share links widely after it received two reports of unidentified individuals invading school sessions, a phenomenon known as "zoombombing."
NASA, one of SpaceX's biggest customers, also prohibits its employees from using Zoom, said Stephanie Schierholz, a spokeswoman for the U.S. space agency. The Federal Bureau of Investigation's Boston office on Monday issued a warning about Zoom, telling users not to make meetings on the site public or share links widely after it received two reports of unidentified individuals invading school sessions, a phenomenon known as "zoombombing."
Re: (Score:2)
Re: (Score:1)
Re:Our company did the same (Score:4, Informative)
With Zoom you can create an online meeting and invite 50 people to it by just giving them a URL. They click on the link and join the meeting, possibly from their browser, done.
Last time I tried Skype you couldn't do that, i.e. you needed to have every chat member in your contact list as "friend" or whatever they call it. Imagine managing an online class like that.
Re: (Score:2)
Re: (Score:3, Informative)
If you think Zoom is shitty, you have never used Citrix or Cisco. Nobody uses Microsoft Teams even though it's included in every single Office license, so most companies already have access.
Re:Our company did the same (Score:4, Interesting)
Nobody uses Microsoft Teams
Speak for yourself. We use Skype for Business primarily, but my team is moving more and more onto Teams. My prior company used WebEx(Cisco?) and they can keep that shit. I've been on a couple of Zoom calls, have never ran one myself, but it seemed to be ok.
Re: (Score:2)
Businesses use GoToMeeting or WebEx all the time. as they are better set up for security in mind.
Re: (Score:2)
Re:Our company did the same (Score:4, Informative)
Re: (Score:2)
Re: (Score:2)
Maybe MS is behind creating the virus!
(Not trolling,
Re: (Score:2)
We've started using teams for our daily meetings. Most people keep the camera off, but you can also just type into the chat if that's what's available to you at the time. So far, as long as everyone is on a mobile device, the whole thing has been pain-free. The only issues I've seen is when someone is at a PC trying to get an external mic working.
Re: (Score:2)
Re: (Score:2)
It's like 1996 all over again, only instead of Netscape it's Slack?
Re: (Score:2)
Re:Our company did the same (Score:5, Insightful)
Maybe, that's because, like Microsoft products, they are easy to get started with?
Groups, that have been using teleconferencing before continue to use whatever services they always did, but new users go to Zoom because it is easy?
Schools, kindergartens, karate- and dance-studios, haven't used such systems before — and would've mocked any suggestion they ever will — but needed to get something rapidly. Without any pre-existing expertise, they chose the easy over the good...
That said, I am not at all sure, Zoom really is as "shitty" as you claim it to be...
Re: (Score:2)
Re: (Score:3)
Re:Our company did the same (Score:5, Funny)
I've used all of them (although I've never heard of BlueJeans). They're all shitty. Since they all have free versions I assume they all spy on you.
Zoom has a very important premium feature though, and, oddly, it is *only* available in the free version: it cuts off meetings after 40 minutes.
Re: (Score:3)
Where I work we use business Skype. I am not sure if there is a limit to the number of people that can join a meeting, but I know that you do not need to be in the contact list. I have brought in outside vendors for meetings by sending them an email with a url. Personal skype, I don't know what the limitations are. Bu
Re: (Score:3)
We looked at Jitsi [jitsi.org], it does voice & video - seems secure. You can run an app on your Android or Apple 'phone or use a web browser like Firefox or Chromium. You can download & run it on your own servers [jitsi.org], it is open source. There is also a hosted place that you can go to [meet.jit.si].
Re: Our company did the same (Score:1)
seems secure
Pray tell, what the fuck does that mean?
What's with the negative Zoom posts? (Score:3)
Zoom was well known prior to this but saw almost no media coverage prior to state lockdowns. Why is there a sudden interest in everything that is wrong w/Zoom's application rather than the ease of use in getting it up and running as well as their seemingly immediate attempts to clean up what has been found?
Is this like the negativity around Tesla? People invested in other technologies and their related companies are pissed about the uptick in share price and their attempts to bring it back down or are these issues really that important?
Re:What's with the negative Zoom posts? (Score:5, Insightful)
>Why is there a sudden interest in everything that is wrong w/Zoom's application
Probably because it's the essential counterpoint to the sudden surge in people spreading the word of the ease-of-use.
Ease of use is wonderful if you're not discussing anything sensitive, but security is far more important for anyone discussing stuff that would be a target for espionage. Which means Zoom is a poor option for cutting edge engineering meetings, anything involving attorney-client privilege, etc,etc,etc. And because it's a tool most people were unfamiliar with a month ago, it's a fair bet that most of them are still unaware of the security problems.
Not to mention that the very fact that the popularity of Zoom is skyrocketing, is also making it a much larger target, for both black- and white-hat hackers. Not unlike the reason most malware is written for Windows - yeah, it's less secure than the major alternatives, but even if it weren't, it's the big target - you get 20x or more the return on finding a Windows vulnerability than one on Linux or MacOS.
Re: (Score:2, Insightful)
Ease of use is wonderful if you're not discussing anything sensitive, but security is far more important for anyone discussing stuff that would be a target for espionage.
And how do we truly know any of the competitors are better in this regard?
The attacks on Zoom are a hatchet job, pure and simple. Maybe by competitors but possibly to try and drive companies to even less secure alternatives.
Re: (Score:2)
Look at where they're certified to be used. Teams has a DoD cloud and authorization to operate within the DoD, Zoom does not(though it does has FedRAMP authorization in the AWS GovCloud).
Re: (Score:1)
I was more thinking of products besides Teams, like WebEX... but even with that certification I question if Teams is truly more secure. Did the DoD certification involve a truly competent code review? I find it hard to believe that any of them would have truly rock-solid security and no avenues for attack, all of them update clients pretty frequently.
Re: (Score:2)
Re: (Score:1)
Good to know, I just question how the integrity of the product can be maintained with constant releases and shifting toolsets/compilers, is the DoD also reviewing all updates? They may be I guess....
Thanks for letting me know how rigorous the process actually is though, that's good to know.
Re: (Score:2)
The other thing is the datacenter requirements for cloud stuff, which th
Re:What's with the negative Zoom posts? (Score:4, Insightful)
Nearly every companies founder is rather arrogant.
However, the problem is when a company moves from a niche product to suddenly become very popular. We get problems with scaling and security.
I can make a simple to use video system, in under a day, and it would probably scale well for a few hundred users at once. But if it gets popular, the problem is more complex then just adding more servers to handle the bandwidth, but knowing there is going to be an army of people trying to break my program at once. Where before I could just find a troubled user and block their address I now need to harden my code further to make sure if they get past my initial security (interface layer) that they have more levels on the back end servers.
Coding for security in mind is never putting trust in any of your code, no matter how good you are, and build in security catches in areas that the end-user should never be able to reach.
Re:What's with the negative Zoom posts? (Score:4, Informative)
1. No end to end encryption though they claim it.
2. Leaks to Facebook.
3. Leaks to LinkedIn.
4. Throwing people together just because they have the same domain on their email address.
5. For MacOS users, set up an open web server for no apparent reason.
I'm sure you can find a more comprehensive list.
Re: (Score:1)
Cisco has been losing out with their WebEx and Zoom has taken over the market. Thus all of this negative PR. The big tech companies don't like upstarts unless they can be purchased.
Re: (Score:2)
Re: What's with the negative Zoom posts? (Score:1)
Ding Ding Ding (Score:2)
Zoom was heavily shorted going into the Autumn. It has since been going up due to it's popularity during this lockdown.
Looks like all the people that lost money shorting Tesla moved right over to shorting Zoom, are MO with the shitposting.
Problem for them is, that Zoom is actually a really good product compared to other videoconferencing software. So it seems unlikely to deter many from moving to inferior solutions.
Re: (Score:2)
Zoom was heavily shorted going into the Autumn. It has since been going up due to it's popularity during this lockdown.
I assume all the unfortunate institutions that shorted this puppy are trying to talk down the share price in order to cover more cheaply.
Probably by the same people who bought heavily into Bitcoin and shorted Tesla.
Re: (Score:2)
Because Cisco and MS want to spy on you, so they're trying to capture some of Zoom's customers.
Re: What's with the negative Zoom posts? (Score:1)
Re: (Score:2)
You know you can have a password, right? (Score:2)
Re:You know you can have a password, right? (Score:5, Insightful)
You know you can have a password, right? I mean, while a password isn't necessarily foolproof... it's certainly theoretically possible for someone to guess it, but it should keep out unwanted people who might discover a live zoom session id.
In SpaceX's case it's not really random schmucks joining meetings that's the problem. It's the fact that the alleged end-to-end encryption... isn't. SpaceX is subject to ITAR. Zoom collects an enormous amount of data, including company proprietary data it has no business retaining. SpaceX is required by law to protect its engineering data, because another name for an orbital rocket is Overachieving ICBM. It's a wonder SpaceX hasn't required an audited end-to-end encrypted solution long before now. That was a dangerous hole that could have gotten them sued by the federal government and may have cost them defense contracts.
ZoomGOV (Score:1)
for a year now... (Score:2)
Re: (Score:2)
I haven't tried using Skype for some time, it seems most of these video conferencing tools need a lot of work to get going. Unless you have some smart IT people on your staff that work out all the details then assemble a easy to follow checklist to get started with a video conference app. I found Zoom to be really easy to download, install, and begin running. I've not used it for any serious stuff, but I've read stories of school sessions getting zoombombed.
So I guess it comes down to what others said bef
Security Cancel Culture (Score:2)
Re: (Score:2)
Agreed. This is a company that has been thrown into the spotlight, warts and all. Unlike the big boys like Facebook/Google, Zoom is admitting to deficiencies and promising to fix...in short order.
FB would basically give you the finger and keep going. Also its crazy to think that the high security needs of a few specialized,govt security regulated entities like SpaceX etc set the bar for everyone. Like driving a Unimog to the grocery store, just in case.
Then Musk is a Technology Idiot (Score:2)
If you don't know how to use the app then yes it is vulnerable. To make is safe, always use a password and always validate email addresses. Don't publish your meetings on social media or public forums. Fairly simple, something you should be doing with any meeting software or business system.