TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Zoom will enable waiting rooms by default to stop Zoombombing

148 点作者 vpontis大约 5 年前

11 条评论

bretpiatt大约 5 年前
Except waiting rooms have a separate security problem <a href="https:&#x2F;&#x2F;citizenlab.ca&#x2F;2020&#x2F;04&#x2F;move-fast-roll-your-own-crypto-a-quick-look-at-the-confidentiality-of-zoom-meetings&#x2F;" rel="nofollow">https:&#x2F;&#x2F;citizenlab.ca&#x2F;2020&#x2F;04&#x2F;move-fast-roll-your-own-crypto...</a><p>HN thread <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=22768494" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=22768494</a>
评论 #22775504 未加载
评论 #22775981 未加载
评论 #22778440 未加载
bartread大约 5 年前
&quot;Building development teams that include skeptics and realists, rather than just visionary idealists, could keep ensure products get safeguarded from abuse before rather than after a scandal occurs.&quot;<p>On the face of it this sounds fair, but the problem is that being &quot;sceptical&quot; and &quot;realistic&quot; is far easier and requires much less effort than being &quot;visionary&quot;[1]. Too much of the former early on can really suck the life out of a team, increasing the risk that the product fails, or is simply never built.<p>Safeguarding from abuse is much better achieved by systematic thinking and discipline (which are learned skills) rather than hiring &quot;realists&quot; who might simply turn out to be whiners and energy vampires.<p>As much as Zoom is currently in the spotlight, and I can&#x27;t say I&#x27;m overjoyed by a number of the issues I&#x27;ve read about (e.g., encryption keys being passed through Chinese servers?!??), many of them are the problems of success, and every successful company has or will experience their fair share of those.<p><i>[1] I might also add that it&#x27;s far easier to commentate and to critique than to do, eh, TechCrunch?</i>
评论 #22777679 未加载
评论 #22777765 未加载
TACIXAT大约 5 年前
I see some people running meetings who can barely find the chat. I&#x27;m not sure I trust them to manage a waiting room.
评论 #22776378 未加载
arkadiyt大约 5 年前
&gt; Starting April 5th, it will require passwords to enter calls via Meeting ID<p>A meeting id with a password is semantically the same as a longer meeting id (or a meeting id with a character space larger than just digits). I wish they&#x27;d do that instead (make meeting ids longer) so I could continue to enter my company meetings with only a link but not have to worry about getting wardialed.
评论 #22777552 未加载
评论 #22776639 未加载
评论 #22775415 未加载
评论 #22775382 未加载
jdlyga大约 5 年前
I work for a large multi-national media company, and we&#x27;ve been using BlueJeans for video conferencing for the last few years. It&#x27;s been very reliable, but I haven&#x27;t heard of very many others using BlueJeans. I&#x27;m curious if the security issues in Zoom vs its competitors more have to do with the amount of people using it and putting eyes on it.
评论 #22775423 未加载
评论 #22775463 未加载
评论 #22776510 未加载
评论 #22775768 未加载
评论 #22775875 未加载
评论 #22776399 未加载
评论 #22775444 未加载
评论 #22776246 未加载
评论 #22775792 未加载
wcoenen大约 5 年前
Techcrunch links seem to redirect through guce.advertising.com nowadays, which is blocked by my ad blocker. Also, according to redirect-checker.org it takes 5 requests before finally landing on the actual page. Seems excessive.
blackrock大约 5 年前
I’ve used a lot of these tools, and I have to admit, Zoom is the best.<p>As for the Zoombombing, I can’t say that I am surprised. All you really need is the URL.<p>And all the other tools are like that too. Sure, you can require a separate passcode, but damn it, it’s like trying to figure out rocket science to enter the passcode.<p>1) you have to dial the number<p>2) you have to punch in the meeting ID<p>3) you have to punch in the passcode.<p>4) ERROR. You flipped it, and used the passcode for the meeting ID instead. Aargh.. frustration.<p>5) Forget about the passcode. Just let everyone in that has the meeting ID. And monitor if there’s someone unknown on the line.
评论 #22778062 未加载
faitswulff大约 5 年前
Waiting rooms don&#x27;t help because you don&#x27;t see any identifying information. My sister&#x27;s call got zoombombed even with a moderated waiting room. They were trying to keep within their university&#x27;s students, but they couldn&#x27;t see the email addresses associated with the zoom user name in the waiting room, so a griefer got through.
评论 #22777222 未加载
评论 #22776289 未加载
mavsman大约 5 年前
Hopefully they do this for existing users as well. One of my fellow teachers&#x27; classes got bombed today even after we were all sent instructions about securing our meetings, enabling waiting rooms, etc.<p>She didn&#x27;t follow the recommendation because she &quot;didn&#x27;t think someone would join&quot; because she hadn&#x27;t posted the meeting link on social media. You have you protect your users that won&#x27;t protect themselves.
rdlecler1大约 5 年前
Wouldn’t it have been easier to present an option to the presenter once X number of people joined? So 3-5, no, but more then a dialog pops up asking the presenter if they’d like to have a waiting room.
wodenokoto大约 5 年前
My understanding was that chats simply had too easy to guess names.<p>Would this be solved by generating chat names through a cryptographic hash algorithm?<p>I have google docs that are edible by anyone with the link and I’m kinda assuming that the link is as hard to guess as logging in with a password.<p>Am I completely off and in dire need of reevaluating my personal web security?