Zoom itaweka 'strong encryption' kwa wateja watakaolipia

Zoom itaweka 'strong encryption' kwa wateja watakaolipia

Analogia Malenga

JF-Expert Member
Joined
Feb 24, 2012
Posts
5,108
Reaction score
10,191
Zoom ni kati ya mitandao inayotumika sana kufanya mikutano kwa njia ya video, na imepata umaarufu mkubwa baada ya janga la #COVID19 ambalo limefanya watu waitumie zaidi ili kuepuka mikutano ya ana kwa ana

Mtandao huo umekuwa unakumbwa na udukuzi wa mara kwa mara baada ya wadukuzi kuvamia mikutano ya watu na kuweka video za ngono

Mshauri wa Ulinzi wa Mtandao wa Zoom, Alex Stamos amesema, wataongeza ulinzi kwa wateja watakaokuwa wanalipia kupata huduma, na wale watakaokuwa wanatumia bure hawatawekewa ulinzi wowote

Ulinzi utakaoongezwa utapunguza hatari ya kuvamiwa na wadukuzi katikati ya mikutano

===

SAN FRANCISCO (Reuters) - Video conferencing provider Zoom (ZM.O) plans to strengthen encryption of video calls hosted by paying clients and institutions such as schools, but not by users of its free consumer accounts, a company official said on Friday.

The company, whose business has boomed with the coronavirus pandemic, discussed the move on a call with civil liberties groups and child-sex abuse fighters on Thursday, and Zoom security consultant Alex Stamos confirmed it on Friday.

In an interview, Stamos said the plan was subject to change and it was not yet clear which, if any, nonprofits or other users, such as political dissidents, might qualify for accounts allowing more secure video meetings.

He added that a combination of technological, safety and business factors went into the plan, which drew mixed reactions from privacy advocates.

Zoom has attracted millions of free and paying customers amid the pandemic, in part because users could join a meeting - something that now happens 300 million times a day - without registering.

But that has allowed opportunities for troublemakers to slip into meetings, sometimes after pretending to be invitees.

Gennie Gebhart, a researcher with the Electronic Frontier Foundation who was on Thursday’s call, said she hoped Zoom would change course and offer protected video more widely.

But Jon Callas, a technology fellow of the American Civil Liberties Union, said the strategy seemed a reasonable compromise.

Safety experts and law enforcement have warned that sexual predators and other criminals are increasingly using encrypted communications to avoid detection.

“Those of us who are doing secure communication believe we need to do things about the real horrible stuff,” said Callas, who previously sold paid encryption services.

“Charging money for end-to-end encryption is a way to get rid of the riff-raff.”

Zoom hired Stamos and other experts after a series of security failures led some institutions to ban its use. Last week Zoom released a technical paper on its encryption plans, without saying how widely they would reach.

“At the same time that Zoom is trying to improve security, they are also significantly upgrading their trust and safety,” said Stamos, a former chief security officer at Facebook.

“The CEO is looking at different arguments. The current plan is paid customers plus enterprise accounts where the company knows who they are.”

Full encryption for every meeting would leave Zoom’s trust and safety team unable to add itself as a participant in gatherings to tackle abuse in real time, Stamos added.

An end-to-end model, which means no one but the participants and their devices can see and hear what is happening, would also have to exclude people who call in from a telephone line.

From a business perspective, it is hard to earn money when offering a sophisticated and expensive encryption service for free. Facebook is planning to fully encrypt Messenger, but it earns enormous sums from its other services.

Other providers of encrypted communication either charge business users or act as nonprofits, such as the makers of Signal.

Zoom is also dealing with regulators such as the U.S. Federal Trade Commission, which is looking into its previous claims about encryption that have been criticized as exaggerated or false, said Stamos and another person familiar with the matter.

With the Justice Department and some members of Congress condemning strong encryption, Zoom could draw unwanted new attention through a major expansion in that area, privacy experts said.
 
Zoom Sued by Church for Bible Class Hijacked by ‘Sick’ Porn
May 15, 2020 / By Peter Blumberg

One of San Francisco’s oldest churches has joined the chorus of complaints that Zooming is not safe — with a lawsuit claiming its bible study class was “Zoombombed” with pornography.

“The footages were sick and sickening — portraying adults engaging in sex acts with each other and performing sex acts on infants and children, in addition to physically abusing them,” according to the complaint filed Wednesday in federal court.

Immediately after shutting down the virtual class, whose participants were mostly senior citizens, the administrator of Saint Paulus Lutheran Church reached out to Zoom Video Communications Inc. for help, “but Zoom did nothing,” according to the complaint, which was filed as a proposed class action.

“We were deeply upset to hear about this incident, and our hearts go out to those impacted by this horrific event,” Zoom said in a statement. “Words cannot express how strongly we condemn such behavior. On the same day we learned of this incident, we identified the offender, took action to block their access to the platform and reported them to relevant authorities.”

Zoom has seen global usage of its service surge during coronavirus shutdowns, but has come under increasing pressure over vulnerabilities in the app’s software encryption. The company has been sued amid accusations it hid flaws in its app and has seen cases of online trolls sneak in and disrupt web meetings with profanity and pornography.

The company has announced measures to step up security and privacy, including a March blog post aimed at helping users prevent uninvited guests from joining their meetings. Zoom advises users not to broadly share meeting IDs and passwords online.

Saint Paulus said that its May 6 bible study class was hacked by a “known offender — one who has been reported to the authorities multiple times” — and that its congregants’ computer control buttons were disabled during the attacks.
The church is seeking unspecified damages for privacy violations and a court order barring the company from engaging in negligent business practices.
 
Back
Top Bottom