Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is the proven risk that China is snooping on American children? If so, I'm sure I'd have read it everywhere. If not, it's sensationalism. The case is literally and specifically about Zoom having the ability to snoop. Children are ancillary.


I'll reluctantly repeat the below from another post of mine on this thread:

There are two vulnerabilities in particular that can grant access to videos to anyone. One is that Zoom video chat IDs are short enough and low enough entropy to be guessable so it's possible to crash meetings. Also saved videos have a standard naming scheme that makes their file names guessable and therefore accessible publicly, as anyone who knows the file name can access any saved video.

Both of these are deliberate choices. They made meeting IDs short and memorable, which makes them guessable. They also wanted saved videos to have meaningful names derived from meeting and user metadata, but again that means they are guessable, and easy to access without annoying security controls.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: