{"id":18888,"date":"2022-04-28T12:30:11","date_gmt":"2022-04-28T20:30:11","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/04\/28\/news-12621\/"},"modified":"2022-04-28T12:30:11","modified_gmt":"2022-04-28T20:30:11","slug":"news-12621","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/04\/28\/news-12621\/","title":{"rendered":"Think the video call mute button keeps you safe? Think again"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2019\/10\/siri-ios13-listening-100813002-large.3x2.jpg?auto=webp&amp;quality=85,70\"\/><\/p>\n<p><strong>Credit to Author: Evan Schuman| Date: Thu, 28 Apr 2022 11:35:00 -0700<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">Have you recently been on a video confefence call, hit the &#8220;mute&#8221; button and then offered up some nasty comments about a client or a colleague \u2014 or even the boss? <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Or maybe while in a conference room with colleagues \u2014 muted \u2014 and pointed out that some proposed action would violate the terms of a secret acquisition in its final stages? <\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you were comfortable that the mute button was actively protecting your secret, you shouldn&#8217;t have been.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Thanks to some impressive experimentation and <\/span><a href=\"https:\/\/wiscprivacy.com\/publication\/vca_mute\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">research from a group of academics<\/span><\/a><span style=\"font-weight: 400;\"> at the University of Wisconsin-Madison and Loyola University Chicago, utterances made while the app is in mute are still captured and saved into RAM.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">On one level, this is something we all already knew. When a user is muted and says something, most videoconferencing apps will display a note alerting the user that they&#8217;re talking while muted. How could it say that if it weren&#8217;t listening while the mute button is on?\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Just as Apple\u2019s Siri or Amazon\u2019s Alexa are always listening for a command word, so, too, are those &#8220;muted&#8221; applications.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The real question is whether those captured utterances are at meaningful risk for being accessed by an attacker or an insider. First, anything saved in volatile memory is lost \u2014 theoretically \u2014 the instant the machine restarts or shuts down. Therefore, we are looking at the exposure after the utterance is made and <em>before<\/em> that machine restarts. Depending on the user\u2019s behavior, that timeframe might be a few hours, a couple of days \u2014 possibly multiple weeks.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Generally, stealing data from volatile memory is difficult, but not impossible. As the report authors said in a group interview, if a bad guy gets into volatile memory, the user and the enterprise have a lot bigger concerns than some saved utterances during a mute. Still, it could happen.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The mute issue is solely based on the app and how it handles such data.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">One of the lead authors of the report is Kassem Fawaz, an assistant professor in the <\/span><span style=\"font-weight: 400;\">Electrical and Computer Engineering<\/span><span style=\"font-weight: 400;\"> Department at the University of Wisconsin-Madison who is also affiliated with Wisconsin\u2019s Computer Sciences Department.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cThe main implications have to do with the inherent trust users are placing in these <\/span><span style=\"font-weight: 400;\">videoconferencing apps,\u201d Fawaz said. \u201c<\/span><span style=\"font-weight: 400;\">We did not find evidence of audio leaving the user\u2019s devices. The only exception was telemetry data leaving from Cisco Webex, which has been fixed since our disclosure to Ciscom. However, even when the user presses the mute button, the app still has access to the audio stream and the user is trusting that the app is well-behaved. The other implication is that the mute functionality \u2014 similar to turning off the camera \u2014 should not be left to the app, but should be either OS-controlled or hardware-controlled.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Fawaz\u2019s point about the camera is that the team found that a camera \u201coff\u201d button truly halted any video from being captured in any way. Not so much with audio. Sometimes, the browser can make a difference. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cOn Chrome, mute means mute,&#8221; Fawaz said. &#8220;We can&#8217;t say about Safari or Firefox.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The university\u2019s report was mostly about trust in the app makers. If the vendors are acting honorably and respecting privacy, cybersecurity, and security compliance issues, then the risk is minimal. If they are <\/span><i><span style=\"font-weight: 400;\">not <\/span><\/i><span style=\"font-weight: 400;\">acting that way, users and enterprises could be in trouble. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">The report didn\u2019t draw conclusions on how the app makers were behaving, but merely stressed that each one can go in its own direction.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">That said, the rules of secrecy and even the rules of being a nice person should apply here. With the imminent-acquisition scenario, if you\u2019re not allowed to discuss certain details, don\u2019t say them in front of a microphone with outsiders regardless of what the mute toggle displays. As for being nice, how about not saying nasty comments about your colleagues or clients at all?\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The cardinal rule of email and security\/compliance is, \u201cBefore you type an email\/message, envision yourself testifying to it in open court. If that makes you uncomfortable, don\u2019t type it.\u201d It\u2019s not a far leap to extend that rule to speaking something in front of a microphone.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For example, I use an Apple Watch. Several times during a typical day, it will say loudly \u201cI didn\u2019t understand that\u201d or \u201cHere\u2019s what I found on that topic.\u201d Although it is highly annoying and frustrating, it\u2019s an effective reminder that I need to take that watch off before saying anything that I don\u2019t want the world to know. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">You need to keep in mind the same thing when using a mobile device or a desktop device \u2014 especially while using a videoconferencing app.<\/span><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3658974\/think-the-video-call-mute-button-keeps-you-safe-think-again.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2019\/10\/siri-ios13-listening-100813002-large.3x2.jpg?auto=webp&amp;quality=85,70\"\/><\/p>\n<p><strong>Credit to Author: Evan Schuman| Date: Thu, 28 Apr 2022 11:35:00 -0700<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p><span style=\"font-weight: 400;\">Have you recently been on a video confefence call, hit the &#8220;mute&#8221; button and then offered up some nasty comments about a client or a colleague \u2014 or even the boss? <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Or maybe while in a conference room with colleagues \u2014 muted \u2014 and pointed out that some proposed action would violate the terms of a secret acquisition in its final stages? <\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you were comfortable that the mute button was actively protecting your secret, you shouldn&#8217;t have been.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Thanks to some impressive experimentation and <\/span><a href=\"https:\/\/wiscprivacy.com\/publication\/vca_mute\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">research from a group of academics<\/span><\/a><span style=\"font-weight: 400;\"> at the University of Wisconsin-Madison and Loyola University Chicago, utterances made while the app is in mute are still captured and saved into RAM.<\/span><\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3658974\/think-the-video-call-mute-button-keeps-you-safe-think-again.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[11063,5897,25882],"class_list":["post-18888","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-data-privacy","tag-privacy","tag-videoconferencing"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18888","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18888"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18888\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18888"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18888"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18888"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}