Zoom Security - Should you Worry? - CTO Advisor 119
Transcript
hey guys going to Keith Townsend from the CTL advisor yes we have to prepare Li well to the les CTO dose or CTO advisor video we're kind of combining the two the worlds are colliding that we did with Joel Pisco so we're doing the next CTO Lagarde's their podcast live if you're listening to this you can find me on twitter at CTO of Iser you can find this on linkedin or you can go to youtube or slash CTO advisor to find these live versions of the videos but feel free we're going to continue to record the audio we have a returning guest we are in the middle of this cold mid-nineteen based work from home movement I'll probably be deep monetized from YouTube because of it doesn't matter because I don't monetize the videos anyway haha catchy YouTube we have with us again Nathan Avery solutions architect Nathan welcome back to the program hey thank you thank you glad to be here thank you for inviting me yeah I'm glad you are you you you got up you at least have I heard those who listening Nate at least has on a shirt I don't know yeah yeah waking up and having to do the work thing it is easier to just follow the motions as best as possible and do what you normally do you're just changing the location but the work remains the same so Nate it's ironic that we're talking about this topic which is zoom security and we're having this conversation over zoom so what better experts to talk about zoom security than people actually using the product yeah and you know we've been in it for a few minutes and you know knock on wood we haven't had anyone barge in yet and hijack this thing so I think you're doing ok pictures and you know kind of just do weird stuff and I'll get it too I've been running the zooms for church service and I'll get into like some of the weird things that's happened even with some of the mitigations I've taken but I love your you thought of this topic you've you're kind of on the ground you're both a collaborator and you serve customers what's the deal like I'm you zoom for the first 4 years probably and I've never other than a couple years ago they had that one security issue with the web server that they have running on on Macs etc I've never really heard the conversation about security issues in zoom what's the rundown what what are the security experts kind of warning us about now yeah so uh the things that I've seen out there reading the literature same is a lot of a lot of us out here I you see the warning of encryption right hey is your communication encrypted from endpoint to endpoint you know all the way through there's a discussion about your data possibly going off to other places that you don't anticipate like Facebook and others and then there's the other issue of people just barging into the meetings as we discussed and what happens a lot of times is there will be a single article that goes over multiple vulnerabilities and and it is bad I mean we you have that many different things but then they get conflated and it all turns into this weird ball of oh my goodness should I even use this product any longer and and and that's a legit concern I don't want to downplay it I don't want to downplay the security implications of this but I think that we have to evaluate it the same way we would any other tool that shows security vulnerabilities and you ask yourself one do these vulnerabilities apply to me in my particular circumstance and - is there a mitigation factor and then I'll add a third one which is all these things combined is that enough for me to no longer use this product and go somewhere else so let's let's take this chunks the first at the architect level question is zoom the right product for a customer or environment in Germany and when I say zoom I don't mean Justin we're talking about WebEx GoToMeeting bluejeans any of these sass services if you're advising someone that we're trying to follow like the DoD guidelines - security would you recommend any of these sass services for super-secret communication unless the vendor has said hey we meet your guidelines and maybe they've built a separate version of it that meets those guidelines on a different infrastructure they know I would and I think to be fair I've seen people white labels ooh so I think zoom resells white box zoom to other people so you could zoom from one secure location to another on a private networking additional layers of security but as he sensed service generally speaking I wouldn't recommend a someone needing that level that DoD level security for a secret and above I wouldn't recommend the USAC I don't I don't know if any of these sacs providers claim that they're that they have DoD level security on any of their products not not the generically commutes consumer level solution right that's a good point you bring up that zoom in particular seems to have I believe they do have a server side offering that you can run in your own infrastructure I've seen some references to that but I've also heard of other instances where vendors build solutions on top of zoom so they'll take that zoom core and build our own stuff around it so if someone builds a security shell around it that meets your needs right you know that may be a way around it but again now you're looking at other vendors that are still using that that core so we've kind of established if you're a secret top secret type of environment whether your government or your apple you don't want the latest iPhone 12 League generally speaking you probably wouldn't use a public service like zoom in general for sharing sensitive information as I'm doing this and I read Wow zoom is selling my data to Facebook which I'm a paintings own customer the the service that we're using today to do the podcast I pay zoom 15 bucks a month for the premature doing there so I expect them not to sell my data to Facebook like what should be the expected transaction between he paid experience and what you've read zoom is a doing with petitioned Facebook and my gaiter so for $15 a month I would expect the vendor to be very upfront about what it is I'm getting and receiving I expect them to tell me very well where my data is going who it's going to what the expectation is in that relationship however I don't think a lot of us are using it for in a paid manner right so if I'm talking to friends I'm talking to my mom I'm talking to whoever we're using the free version and like the saying goes if the service is free then you are the product so in a situation like that I'm not really too shocked that my data could go elsewhere because other vendors have done that for so long I think we're a little desensitized to it yeah and I think that was my follow-up question to that you answered it already what have we become decent besides to that if I do anything on the internet and I'm not giving my credit card well that's a whole nother story maybe my credit card information you get exposed but I'm expecting generally that if I'm paying you your business model isn't to sell my data if I'm not paying you then anything that I do will be sold to another provider I think is the the trade off most consumers are mayshen however the thing that I am surprised at is as a consumer if I'm having my church service via Zoom as somebody jumps in and then shares porn does that want me the person who is consuming the service or is that on xone for not protecting me from them okay so that's a situation where if you have an external entity drop dropping in yeah that's that's both right so the expectation should be for the vendor to provide the tools in a secure space right some defaults that prevent such an action from happening and then they should also provide you the consumer with an understanding of those tools so that they're enabling you to turn them on turn them off or whatever because there are certain situations where you may want to turn that off you may not wish to provide a password for instance because you're trying to reach as a wide an audience as possible and you're trying to lower the barriers for people to come in however the vendor should make sure that you understand the risks in doing so and they should make sure that that default is in place to protect you and then if you want to go against it hey that's that's on you and you understand the risks so that's this is that shared security model that the cloud providers talk about all the time that we're gonna give you all the tools that you need to secure your s3 buckets but if you don't apply them then yeah there's not really much we can do however the Zoom CEO was on sea in the other day and seeing one seen in doing some really softball questions and they were I thought they made a very good excuse form hey mr.
CEO you weren't expecting that you know you become the next Kleenex of videoconferencing and that use would explode so therefore security will give you a pass on security I don't buy that because right before we started this conversation I had all sudden one you email me said hey Keith what's the password to the meeting yeah which is something I'm not used to doing his own and then when you entered the meeting I had you are by default left in the waiting area and I had to come and allow you in these are not new features and zoom these are just knobs that zoom has turned on to your point to make the barriers entry to using zoom lower versus as competitors so it's worked but how do we get out the message to the users on these not just zoom but zoom and other services it could be collaboration tools it can be found sharing services etc we're in this collective experience of using these massively powerful data sharing tools and the defaults may not suit our organism our organization's security posture good question so one of the things that I would recommend is that that it falls back onto the local IT groups a lot of times people have said well what's the role of local IT when you have these services that are provided by external parties and it comes back on the internal IT teams to figure out well what are the safe second settings what are those recommended knobs it took to twist and and settings to make so that they can empower their users to still use those tools that have traditionally been labeled shadow IT but make them more friendly to consume internally that's from a business perspective I really loved you brought this up because we have this same challenge on the enterprise side of platinum like we want our customers internal and external to move as fast as they can but in a secure manner we want you to use AWS s3 for hosting your data sets that you serve out to the public because if you're using the s3 now you're not using my internal bandwidth and your resume reducing the friction to making changes to sector all the good stuff I just don't want you to leave the buck is open wide open for people to write to or put sensitive data and those publicly available available buckets yeah yeah so it's a situation where I think that there are options available for a company like a Zune were whoever right and when we're using zoom like you said like Kleenex where for them to take that next step and and really go the enterprise way it's to understand what enterprises need and there's a huge shift between consumer and enterprise and we've seen that happen with Microsoft where they'll say hey here's a tech that's kind of your home version and then here's the same tech that's the enterprise version and typically what the differences are are the levels of controls at a centralized level so that a centralized IT group can flip all the right knobs and switches to help protect the others within their environment and I think that there's a now a path forward for some of these vendors if they want to go into the enterprise space so poor folks in my situation that need to go from using a consumer level to to enterprise class to what generic advice Nia the best advice is to think about your use case right let's go back to those same questions we asked before is what I'm talking about something that secret would I worry if this information were to somehow leak out to outside of my organization is this something that to share with this particular vendor because maybe you know if your coke and you're using Pepsi servers that might be a problem hi and and just again just be careful you know hey or are there some recommended settings out there just if you're gonna take a look at a tool to second Google search the name of that tool plus security see what pops up arm yourself with the data that you need and go for it all right yeah last question are you to stop using zoom now for personal stuff no it is by far been the easiest tool that I've used I said it I teach that I share the experience that I get in church so I'm pre plain I'm replaying the minister's sermon for the service and all of a sudden on the screen I see this writing that says and across the across the video shared out to you know almost 100 people and I'm eat them pulling wires virtually like what's going on they come to find out one of the babies and service had the tablet it turned on the annotation feature and zoom and just wrote heed her dad's name or without the screen and everyone solve it and I'm thinking wow impact inside of zoom to find out how do you disable annotation automatically because anyone is a collaborative tool and anyone can use it to to collaborate yeah so Jeff I thought that was a funny story yeah because you know I could have gone so many different ways way worse than a baby writing it across the screen so Nate what can people find you they can find me on my blog not your dad's IT comm I'm there I'm on Twitter yeah all right you can find us on the web at CTO visors my Twitter ID register for the virtual conference which just less than two weeks away as the record as of the recording of this podcast you can find that at CT Oh a b c comm CQ advisor virtual conference comm talk to you next CQ advisory