eclipse / microprofile-marketing

Apache License 2.0
13 stars 9 forks source link

Marketing Calls: Secure access from unintended visitors #478

Closed debbiehoffman closed 3 years ago

debbiehoffman commented 3 years ago

As we had an unwanted guest on the marketing call today, it seems we will need to find a way to prevent that in the future. While we want the calls open to those who want to participate, seems we won't be able to keep it open for all/anyone who obviously has a different agenda from the rest of us.

Some ideas found in this article: https://blog.zoom.us/keep-uninvited-guests-out-of-your-zoom-event/ - using the waiting room to enter the meeting, control who can screen share (host only), and, should someone still get in and cause problems:

Suspend participant activities: Hosts and co-hosts can pause the meeting to remove and report an offending party and prevent further disruption. Click the Security icon and select “Suspend Participant Activities” to temporarily halt all video, audio, in-meeting chat, annotation, screen sharing, and recording, and end Breakout Rooms. You can resume the meeting by re-enabling the individual features.

TetianaFTV commented 3 years ago

Totally agree, Debbie. I've already emailed to John that we need to get back to the rule that each attendee should be approved by the host before joining. Also, this is a good idea to give a host permissions to mute/delete attendees from the call.

On Mon, 12 Apr 2021 at 19:26, Debbie Hoffman @.***> wrote:

As we had an unwanted guest on the marketing call today, it seems we will need to find a way to prevent that in the future. While we want the calls open to those who want to participate, seems we won't be able to keep it open for all/anyone who obviously has a different agenda from the rest of us.

Some ideas found in this article: https://blog.zoom.us/keep-uninvited-guests-out-of-your-zoom-event/ - using the waiting room to enter the meeting, control who can screen share (host only), and, should someone still get in and cause problems:

Suspend participant activities: Hosts and co-hosts can pause the meeting to remove and report an offending party and prevent further disruption. Click the Security icon and select “Suspend Participant Activities” to temporarily halt all video, audio, in-meeting chat, annotation, screen sharing, and recording, and end Breakout Rooms. You can resume the meeting by re-enabling the individual features.

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/eclipse/microprofile-marketing/issues/478, or unsubscribe https://github.com/notifications/unsubscribe-auth/AJHFTS7MCFPHDE77VA675JDTIMULDANCNFSM42ZW5RGQ .

--

jclingan commented 3 years ago

Yeah, I’ve already changed tomorrow’s steering committee call to waiting room.

On Apr 12, 2021, at 10:36 AM, TetianaFTV @.***> wrote:

Totally agree, Debbie. I've already emailed to John that we need to get back to the rule that each attendee should be approved by the host before joining. Also, this is a good idea to give a host permissions to mute/delete attendees from the call.

On Mon, 12 Apr 2021 at 19:26, Debbie Hoffman @.***> wrote:

As we had an unwanted guest on the marketing call today, it seems we will need to find a way to prevent that in the future. While we want the calls open to those who want to participate, seems we won't be able to keep it open for all/anyone who obviously has a different agenda from the rest of us.

Some ideas found in this article: https://blog.zoom.us/keep-uninvited-guests-out-of-your-zoom-event/ - using the waiting room to enter the meeting, control who can screen share (host only), and, should someone still get in and cause problems:

Suspend participant activities: Hosts and co-hosts can pause the meeting to remove and report an offending party and prevent further disruption. Click the Security icon and select “Suspend Participant Activities” to temporarily halt all video, audio, in-meeting chat, annotation, screen sharing, and recording, and end Breakout Rooms. You can resume the meeting by re-enabling the individual features.

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/eclipse/microprofile-marketing/issues/478, or unsubscribe https://github.com/notifications/unsubscribe-auth/AJHFTS7MCFPHDE77VA675JDTIMULDANCNFSM42ZW5RGQ .

--

aeiras commented 3 years ago

+1.

@jclingan can we re-set all calls to have the restrictive rule to be admitted to the calls? Thank you, Tetiana and Debbie.

edbratt commented 3 years ago

John,

Thanks. Maybe this is all we need.

A couple of more ideas to secure our Zoom settings:

  1. disable "Allow participants to rename themselves"
  2. disable "Allow removed participants to rejoin"
  3. disable the "Whiteboard"
  4. disable screen "Annotation"

The first two can be turned on/off by the host during the meeting ... either in the Security menu, or by the Participant panel "..." at the bottom of the participants panel. If the crasher can't change their name, I suspect the host could find their participant menu entry more easily (today, the crasher was changing it's name so they were jumping around on the "participants" list).

All folks who will host meetings should spend some time to become familiar with the security option button for control during meetings (see here https://support.zoom.us/hc/en-us/articles/360041848151-In-meeting-security-options) -- especially the panic button: Suspend Participant Activities (see this blog post https://blog.zoom.us/new-ways-to-combat-zoom-meeting-disruptions/). the current list of "Security" controls is below [1]. One thing to practice might be, how to resume features and the meeting if we've had to kick someone out.

For future reference, once a user joins, it does not appear they can change their name for screen annotations. User name is briefly shown when the annotation is first added. The Host (or user) can also view the user name of the annotation if they click the "annotations" button (only visible apparently when screen sharing) -- then click the "select" tool (at least in the desktop app). From there, you can hover over the "artwork" to view the name of the user that created the annotation.

A "guest" user can set their name to anything they like prior to joining so I don't know how reliable an indicator that actually is. The meeting report, that is generated with each zoom meeting, lists all attendees by their initial name, but as with the annotation, I think a Guest attendee can enter anything they want as their initial participant name. Perhaps if an attendee is "reported" the Zoom police can get more accurate details about that attendee.

-- Ed

Current Security button controls:

On 4/12/2021 10:39 AM, John Clingan wrote:

Yeah, I’ve already changed tomorrow’s steering committee call to waiting room.

On Apr 12, 2021, at 10:36 AM, TetianaFTV @.***> wrote:

Totally agree, Debbie. I've already emailed to John that we need to get back to the rule that each attendee should be approved by the host before joining. Also, this is a good idea to give a host permissions to mute/delete attendees from the call.

On Mon, 12 Apr 2021 at 19:26, Debbie Hoffman @.***> wrote:

As we had an unwanted guest on the marketing call today, it seems we will need to find a way to prevent that in the future. While we want the calls open to those who want to participate, seems we won't be able to keep it open for all/anyone who obviously has a different agenda from the rest of us.

Some ideas found in this article: https://blog.zoom.us/keep-uninvited-guests-out-of-your-zoom-event/ https://urldefense.com/v3/__https://blog.zoom.us/keep-uninvited-guests-out-of-your-zoom-event/__;!!GqivPVa7Brio!N26ZpOCoiXo8HW8CeuKVlGXlMf5Jd39UtpxaXJC9sWavxVAkpVHMLS4vWj87ZdA$

using the waiting room to enter the meeting, control who can screen share (host only), and, should someone still get in and cause problems:

Suspend participant activities: Hosts and co-hosts can pause the meeting to remove and report an offending party and prevent further disruption. Click the Security icon and select “Suspend Participant Activities” to temporarily halt all video, audio, in-meeting chat, annotation, screen sharing, and recording, and end Breakout Rooms. You can resume the meeting by re-enabling the individual features.

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/eclipse/microprofile-marketing/issues/478 https://urldefense.com/v3/__https://github.com/eclipse/microprofile-marketing/issues/478*3E__;JQ!!GqivPVa7Brio!N26ZpOCoiXo8HW8CeuKVlGXlMf5Jd39UtpxaXJC9sWavxVAkpVHMLS4v7Df4-8M$, or unsubscribe

https://github.com/notifications/unsubscribe-auth/AJHFTS7MCFPHDE77VA675JDTIMULDANCNFSM42ZW5RGQ https://urldefense.com/v3/__https://github.com/notifications/unsubscribe-auth/AJHFTS7MCFPHDE77VA675JDTIMULDANCNFSM42ZW5RGQ*3E__;JQ!!GqivPVa7Brio!N26ZpOCoiXo8HW8CeuKVlGXlMf5Jd39UtpxaXJC9sWavxVAkpVHMLS4vLvTqnog$ .

--

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://urldefense.com/v3/__https://github.com/eclipse/microprofile-marketing/issues/478*issuecomment-817999025__;Iw!!GqivPVa7Brio!N26ZpOCoiXo8HW8CeuKVlGXlMf5Jd39UtpxaXJC9sWavxVAkpVHMLS4v1UnJNzw$, or unsubscribe https://urldefense.com/v3/__https://github.com/notifications/unsubscribe-auth/AC5WM3VW4WQD3R4IGQ2XOJDTIMV4ZANCNFSM42ZW5RGQ__;!!GqivPVa7Brio!N26ZpOCoiXo8HW8CeuKVlGXlMf5Jd39UtpxaXJC9sWavxVAkpVHMLS4vh9F9ONc$.

jclingan commented 3 years ago

Found a way to address security by claiming host using host code and then host enabling waiting room.