LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 04-21-2020, 06:51 PM   #16
bassmadrigal
LQ Guru
 
Registered: Nov 2003
Location: West Jordan, UT, USA
Distribution: Slackware
Posts: 8,792

Rep: Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656

Quote:
Originally Posted by hitest View Post
Yes. The CEO of Zoom was not prepared for the unprecedented need for the software, and he admitted that their security policies were lacking. My understanding is that they've worked to improve the security of their application.
Two of those articles were from mid-2019 and it seems those major security flaws have been resolved (not discounting the seriousness of the flaws, but I don't believe they're currently an issue). Zoom still needs more work to become a decently secure platform, but most of what you hear now is just that people need to remember to password protect their conferences.
 
Old 04-21-2020, 07:11 PM   #17
Skaendo
Senior Member
 
Registered: Dec 2014
Location: West Texas, USA
Distribution: Slackware64-14.2
Posts: 1,445

Rep: Reputation: Disabled
Quote:
Originally Posted by bassmadrigal View Post
Two of those articles were from mid-2019 and it seems those major security flaws have been resolved (not discounting the seriousness of the flaws, but I don't believe they're currently an issue). Zoom still needs more work to become a decently secure platform, but most of what you hear now is just that people need to remember to password protect their conferences.
The one from Verge is three weeks old. Now, I don't trust Verge very much (if at all) but if it's been over a year and they still have serious security issues (like routing everything through China, The CCP is not a friend, my friend), there is something very very wrong, and I trust Zoom less than I trust Verge.
 
1 members found this post helpful.
Old 04-21-2020, 08:18 PM   #18
hitest
Guru
 
Registered: Mar 2004
Location: Canada
Distribution: Debian, Void, Slackware, VMs
Posts: 7,342

Rep: Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746Reputation: 3746
Quote:
Originally Posted by Skaendo View Post
The one from Verge is three weeks old. Now, I don't trust Verge very much (if at all) but if it's been over a year and they still have serious security issues (like routing everything through China, The CCP is not a friend, my friend), there is something very very wrong, and I trust Zoom less than I trust Verge.
I respect, acknowledge and appreciate your observations. Unfortunately I need Zoom to keep in touch with my social group. The application security is not something that sits well with me.
 
Old 04-21-2020, 11:03 PM   #19
Richard Cranium
Senior Member
 
Registered: Apr 2009
Location: McKinney, Texas
Distribution: Slackware64 15.0
Posts: 3,858

Rep: Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225
Quote:
Originally Posted by bassmadrigal View Post
Two of those articles were from mid-2019 and it seems those major security flaws have been resolved (not discounting the seriousness of the flaws, but I don't believe they're currently an issue). Zoom still needs more work to become a decently secure platform, but most of what you hear now is just that people need to remember to password protect their conferences.
Well, only if you don't mind the contents of your conference to be available to the employees of Zoom and the company itself to mine and exploit.

Whatever is in your conference is unencrypted on the zoom servers themselves. If that's not a problem to you (and it is not a given that it must be problem for you), then you're golden.

Otherwise, maybe check out https://jitsi.org/ You could even run your own server.
 
Old 04-22-2020, 10:38 AM   #20
bassmadrigal
LQ Guru
 
Registered: Nov 2003
Location: West Jordan, UT, USA
Distribution: Slackware
Posts: 8,792

Rep: Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656Reputation: 6656
Quote:
Originally Posted by Richard Cranium View Post
Well, only if you don't mind the contents of your conference to be available to the employees of Zoom and the company itself to mine and exploit.

Whatever is in your conference is unencrypted on the zoom servers themselves. If that's not a problem to you (and it is not a given that it must be problem for you), then you're golden.

Otherwise, maybe check out https://jitsi.org/ You could even run your own server.
I've only used it for work and like many, it's mandatory. Luckily, since I'm military, we are only allowed to host with a "Zoom for Government" account, so it is secured. But the fact they don't have E2E encryption for everyone is just plain stupid.
 
Old 04-23-2020, 07:42 AM   #21
kgha
Senior Member
 
Registered: May 2018
Location: Sweden
Distribution: Slackware 64 -current multilib from AlienBob's LiveSlak MATE
Posts: 1,073

Rep: Reputation: 746Reputation: 746Reputation: 746Reputation: 746Reputation: 746Reputation: 746Reputation: 746
Trouble with recent zoom-linux (built with SBo script)

With the most recent version of zoom-linux (3.5.392530.0421) I can't login via the SSO option. This is odd, since zoom's information regarding the March 2323 version states "Resolved an issue where some users were unable to sign in with Single Sign On (SSO)". For me, it's the other way round - it created an issue. I downgraded to an older version that I've stored (2.9.265650.0716) and then the SSO login worked.

Anyone else having experienced this?

Don't know if downgrading will affect basic functionality in any other way.

The web interface is of course always an option. And there's another version announced for release later this week, maybe that will solve the problem.
 
Old 04-23-2020, 04:29 PM   #22
thethinker
Member
 
Registered: Jul 2006
Location: Peabody, MA, USA
Distribution: Xubuntu, Slackware, Pop!_OS
Posts: 297
Blog Entries: 2

Rep: Reputation: 37
Zoom worked out of the box for me, but I'll point out that the linux client does not have all the features of the Windows one. In particular, you cannot control breakout rooms as the Host. That's exactly what I need it for (education....breaking students into groups....need it!), so I'm stuck on windows for the time being.

(Until I get Wine running, I suppose....)
 
Old 04-25-2020, 02:17 PM   #23
Regnad Kcin
Member
 
Registered: Jan 2014
Location: Beijing
Distribution: Slackware 64 -current .
Posts: 663

Rep: Reputation: 460Reputation: 460Reputation: 460Reputation: 460Reputation: 460
It's gonna be a very lonely bored and disappointed hacker who hacks my zoom conferences.

Linux version on my machine allows breakout rooms and as far as i can tell does about everything that windows does except make me angry.
 
Old 04-25-2020, 02:29 PM   #24
Red Squirrel
Senior Member
 
Registered: Dec 2003
Distribution: Mint 20.1 on workstation, Debian 11 on servers
Posts: 1,336

Rep: Reputation: 54
I probably would not run that on your production machine anyway, it has tons of security and privacy issues and is based in China so who knows what kind of system info it's harvesting and who has access to your system while it's running. I would run it on a separate machine or VM to be safe.

I ended up being coaxed to install it too, I put it on my phone, I figure my phone is already spying on me anyway, and I don't let it connect to my main vlan.
 
Old 04-25-2020, 05:26 PM   #25
andrew.46
Senior Member
 
Registered: Oct 2007
Distribution: Slackware
Posts: 1,365

Rep: Reputation: 493Reputation: 493Reputation: 493Reputation: 493Reputation: 493
I don't know enough about encryption to know if this will satisfy those worried about end to end security:

Quote:
AES 256-bit GCM encryption
Zoom is upgrading to the AES 256-bit GCM encryption standard, which offers increased
protection of your meeting data in transit and resistance against tampering. This
provides confidentiality and integrity assurances on your Zoom Meeting, Zoom Video
Webinar, and Zoom Phone data. This version of the Zoom client will support GCM
encryption when it is automatically enabled for all accounts on May 30.
Also this, for those who prefer their data not to be processed in certain countries:

Quote:
Select data center regions when scheduling a meeting
Users can now select which data center regions they would
like their in meeting traffic to use when scheduling a meeting.
This is for the release coming up on April 27, 2020. Link here... My own use of Zoom is for family get togethers during the lockdown and for that I am very, very happy.

Last edited by andrew.46; 04-25-2020 at 05:30 PM.
 
Old 04-25-2020, 05:27 PM   #26
Gerard Lally
Senior Member
 
Registered: Sep 2009
Location: Leinster, IE
Distribution: Slackware, NetBSD
Posts: 2,184

Rep: Reputation: 1765Reputation: 1765Reputation: 1765Reputation: 1765Reputation: 1765Reputation: 1765Reputation: 1765Reputation: 1765Reputation: 1765Reputation: 1765Reputation: 1765
Quote:
Originally Posted by Red Squirrel View Post
I probably would not run that on your production machine anyway, it has tons of security and privacy issues and is based in China so who knows what kind of system info it's harvesting and who has access to your system while it's running
And who knows what kind of system info Intel CPUs are harvesting and who has access to your system when you boot up an Intel machine? Who knows what kind of system info Dell UEFI firmware is harvesting and who has access to your system when you boot up a Dell machine? Who knows what kind of personal info Google and Facebook are harvesting, day and night, winter and summer, northern hemisphere and southern?
 
Old 04-25-2020, 06:24 PM   #27
Red Squirrel
Senior Member
 
Registered: Dec 2003
Distribution: Mint 20.1 on workstation, Debian 11 on servers
Posts: 1,336

Rep: Reputation: 54
Quote:
Originally Posted by Gerard Lally View Post
And who knows what kind of system info Intel CPUs are harvesting and who has access to your system when you boot up an Intel machine? Who knows what kind of system info Dell UEFI firmware is harvesting and who has access to your system when you boot up a Dell machine? Who knows what kind of personal info Google and Facebook are harvesting, day and night, winter and summer, northern hemisphere and southern?
That's why all my new builds are AMD. Hopefully AMD is not pulling the same crap as Intel though... Unfortunately we don't have much control over hardware level spying. Phones are a huge issue too, wish there were some more easily obtainable open source options or at very least alternative OSes that work on existing phones that aren't just an android spin.
 
Old 04-26-2020, 01:03 AM   #28
Regnad Kcin
Member
 
Registered: Jan 2014
Location: Beijing
Distribution: Slackware 64 -current .
Posts: 663

Rep: Reputation: 460Reputation: 460Reputation: 460Reputation: 460Reputation: 460
The only feature of Zoom on Windows that is not present in ZoomLinux that I have found is playing a movie on your video greenscreen background which is not supported in ZoomLinux. Of course if having an animated background on your videochat background is important to you, you can work it out with OBS if you are motivated to do so.

All night, All day, angels watching over me...
 
Old 04-26-2020, 08:39 PM   #29
Richard Cranium
Senior Member
 
Registered: Apr 2009
Location: McKinney, Texas
Distribution: Slackware64 15.0
Posts: 3,858

Rep: Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225
Right. So. How do you think Zoom is able to tell who's speaking? (You know, so it can highlight that user's video?)

There's a number of ways to do that thing (I've actually worked on a video conferencing application back in my telecom days, albeit on the OAM side), but the easiest way is to examine the video streams. Well, if they are unencrypted, but if you want to mine that stuff anyways...

The alternative would be to have a separate stream of data that indicated you were talking; not impossible to implement by any means whatsoever, but that doesn't mean that Zoom is interested in doing that.

I know that @bassmadrigal stated above the that the US military believes Zoom to be sufficiently private for their particular use cases. Many moons ago, I was in the US military as a signal puke; were I still in, I would insist upon a security audit.
 
Old 04-26-2020, 08:53 PM   #30
Skaendo
Senior Member
 
Registered: Dec 2014
Location: West Texas, USA
Distribution: Slackware64-14.2
Posts: 1,445

Rep: Reputation: Disabled
https://cve.mitre.org/cgi-bin/cvenam...CVE-2020-11500

https://en.wikipedia.org/wiki/Zoom_Video_Communications
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
video conferencing software linux tomv Linux - Software 3 09-10-2014 10:08 AM
Customizable Video Conferencing software sala_mander Linux - Software 0 06-09-2012 01:07 PM
Cross-platform video conferencing software deiussum Linux - Software 2 05-28-2004 03:56 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 05:54 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration