3CX WebMeeting Security vs Zoom

Status
Not open for further replies.

Michelle King

Platinum Partner
Joined
Mar 28, 2018
Messages
1
Reaction score
2
Could someone at 3CX provide 3CX security comparison to Zoom? It is one of the most asked questions we are getting right now as we help educators and healthcare facilities operate remotely.
 
Could someone at 3CX provide 3CX security comparison to Zoom? It is one of the most asked questions we are getting right now as we help educators and healthcare facilities operate remotely.

I +1 this. One of the security issues was with numeric meeting IDs that could be quickly scanned through to access current meetings.
 
+1 Came to the forums looking for exactly this. Zoom being in the news lately over its less than desirable security measures has left many of our clients asking us how the security compares with 3CX WebMeeting.

Another area for concern that people had with Zoom was how they were using TLS to the central server for encryption but then this server was acting as a "man in the middle" therefore communications between users from the central server perspective were not encrypted.
 
  • Like
Reactions: BrettTPF
Common question we are receiving also. I know MFA is a feature request in the ideas section, it will hopefully be high on the consideration list.
 
  • Like
Reactions: BrettTPF
Here are a few key items to point out in comparing the two.
1 You have the option to enable the Approve participants that join the meeting option.
2 3CX doesn't use random numbers for meetings, the links are your Click to Meet link.
3 Click2Link can be customized to include numbers and letters.
4 Your URL is going to be unique, it is not going be https://zoom.us/j/881235896 (side note those are just random numbers I punched in)
So an attacker is going to have to know your unique URL for example http://companyname.yourstate.3cx.net/ then they are going to have to know your name for your click2meet.
This reduces the change of bots crawling numbers like they can on zoom to join an open meeting.

I cannot attest to the security that happens between the 3CX meeting host and the clients, But a quick wireshark shows that the meeting starts with TLS1.2 and then the data is transmitted via UDP between the client and server.
1586958407138.png
 
So an attacker is going to have to know your unique URL for example http://companyname.yourstate.3cx.net/ then they are going to have to know your name for your click2meet.

Don't forget that beyond the FQDN & URL complexity layer and the 'approval' feature, there's also the fact that even if someone DOES know your click2meet URL, they are not allowed to enter your meeting without the organizer being present.
 
Don't forget that beyond the FQDN & URL complexity layer and the 'approval' feature, there's also the fact that even if someone DOES know your click2meet URL, they are not allowed to enter your meeting without the organizer being present.
Are there any plans to introduce password-protected meetings? I understand the attackers would need to know the fqdn and url as well as be allowed to enter the meeting but let's be honest, those are all pretty easy to side-step. Zoom's issues were brought to light by the sudden increase in popularity because of current events. I am not sure what the actual popularity numbers are between Zoom and 3cx, however, when more people start "poking" at a product, issues can be discovered.

The "approval" feature does not have much security in it as the participant is asked to enter their name, attackers could enter whatever they wanted, the organizer would not know if what they entered was correct. Seems like a password and name at that screen would resolve that concern.
 
From today's news:
Hackers Are Selling a Critical Zoom Zero-Day Exploit for $500,000
People who trade in zero-day exploits say there are two Zoom zero-days, one for Windows and one for MacOS, on the market.
 
Are there any plans to introduce password-protected meetings? I understand the attackers would need to know the fqdn and url as well as be allowed to enter the meeting but let's be honest, those are all pretty easy to side-step.

They really aren't. Not in 3CX. You're thinking zoom.
if it's easy to side step, you are hereby challenged to guess my FQDN and a meeting link of mine :)

Now lets do the same for Zoom. Go here https://zoom.us/j/123456789 replace 123456789 with random combinations and happy randomly joining people's meetings.


Zoom's issues were brought to light by the sudden increase in popularity because of current events. I am not sure what the actual popularity numbers are between Zoom and 3cx, however, when more people start "poking" at a product, issues can be discovered.

Agreed. I do also want to add that we take product security very seriously and we tend to 'poke' our product security-wise before releasing it to the public. Seeing some of the mistakes Zoom has made in this part make me cringe a bit. Especially the 9 digit meeting ID and 0 URL complexity. It's as easy as guessing someone's meeting ID.


The "approval" feature does not have much security in it as the participant is asked to enter their name, attackers could enter whatever they wanted, the organizer would not know if what they entered was correct. Seems like a password and name at that screen would resolve that concern.

A password feature will eventually be available. Regardless, security concerns for WebMeeting are completely unwarranted as 3CX does not suffer from the issues Zoom does.
 
  • Like
Reactions: hogan71088
Could someone at 3CX provide 3CX security comparison to Zoom? It is one of the most asked questions we are getting right now as we help educators and healthcare facilities operate remotely.

To create a 1:1 comparison would be very hard to make - as on the core both platforms are vastly different. 3CX uses open standard technology called WebRTC and it is reviewable for everyone how data streams are managed and encrypted (TLS, DTSL, SRTP). You can track it from within your browser.

On End-To-End encryption and WebRTC in 3CX. 3CX uses SFUs (MCUs) to distribute a multi-point video and must provide stream alteration/detection/management in those autonomous unites. Hence, 3CX utilizes best practice transport security to and from our MCUs. For the future, there is an upcoming feature "WebRTC Insertable Streams https://www.chromestatus.com/feature/6321945865879552" which exactly aims for SFU controlled meeting end-to-end-encryption. TBC... How Zoom managed to confuse end-to-end encryption with transport encryption...

Above my answer are already some good points which are been embedded in 3CX for years to customize your experience and secure meetings.

Please contact your 3CX Channel Manager, they will have more details/Whitepapers on 3CX Meetings.
 
if it's easy to side step, you are hereby challenged to guess my FQDN and a meeting link of mine :)

If your sysadmin is rational your URL will be something like call/phone/voice.yourcustomdomain-with-dashes.3cx.net/join/yourfullname

Security by obscurity isn't actually security. Can you all please plan to have an authorization option on web meetings?
 
Beyond having to guess the whole url, there are 2 layers of authorisation already.

1) Cannot enter a meeting unless the organizer is inside the meeting.
2) Moderate Participants: Accept / Reject someone from entering the meeting. (Authorisation)

Also since i am Leonidas Georgiou working at 3CX and if our IT is rational, my meeting link should be: https://3cx-eu.3cx.net/join/leonidasgeorgiou

In the worst case, even if you guess the FQDN correctly, all you have is a link you can't use since i'm not in the meeting, and will reject you if you try to enter. The ability to ban users will also be available eventually amongst other things.

Again since this a Zoom comparison thread, let me remind you that this is how you enter someone's meeting on zoom: https://zoom.us/j/123456789

In the meanwhile, in 3CX:
https://randomstuffityped-somecountry.3cx.net/join/aFbtUzGj5G-iNb2klg7QyyFn
https://randomstuffityped-somecountry.3cx.net/open/740b30d5babdf0075ae5245889d0c1f7176570f2
 
  • Like
Reactions: Evolute IT
Okay, so maybe I'm not understanding a new feature that has rolled out? But I have never seen the ability to accept / reject someone from entering the meeting.

I can kick folks (I think) from the participants list, but that's not at all the same as being able to selectively allow people into a meeting. Which is what most of us are looking for.
 
Okay, so maybe I'm not understanding a new feature that has rolled out? But I have never seen the ability to accept / reject someone from entering the meeting.

I can kick folks (I think) from the participants list, but that's not at all the same as being able to selectively allow people into a meeting. Which is what most of us are looking for.

The Accept/Reject has been available for several years :) It is easy to miss though. It's under your extension settings > Click2Meet > Moderate Participants. I think this is what you're looking for.
 
The Accept/Reject has been available for several years :) It is easy to miss though. It's under your extension settings > Click2Meet > Moderate Participants. I think this is what you're looking for.

Oh jeeze. The solution was there the whole time.

Complaint / objection removed. Thank you.
 
  • Like
Reactions: i3
While Zoom removed the Meeting-ID from the window title bar, 3CX Webmeetings still keep the URLs in the browser's adress bar. So anyone posting a screenshot or photo with the adress bar will leak the URL which is the only required access code. Also a lot of users still think copying an address from the browser's address bar is the right way to let some join or share a resource - not just in regard to 3CX but in general. The worst case is the owner's URL of any QuickMeeting. This seemingly random URL seems to stay valid indefinitely and I am not aware of any way to revoke this URL.

As far as I know, it is considered best practice to put session IDs and similar authenticators into a cookie and redirect to either a neutral URL or an URL that is otherwise protected. Whereas session IDs usually expire after a reasonable time, the Quickmeeting URLs are valid for a long (indefinite?) time, so by my understanding these URLs should certainly not be kept in the adress bar.
 
While Zoom removed the Meeting-ID from the window title bar, 3CX Webmeetings still keep the URLs in the browser's adress bar. So anyone posting a screenshot or photo with the adress bar will leak the URL which is the only required access code. Also a lot of users still think copying an address from the browser's address bar is the right way to let some join or share a resource - not just in regard to 3CX but in general. The worst case is the owner's URL of any QuickMeeting. This seemingly random URL seems to stay valid indefinitely and I am not aware of any way to revoke this URL.

As far as I know, it is considered best practice to put session IDs and similar authenticators into a cookie and redirect to either a neutral URL or an URL that is otherwise protected. Whereas session IDs usually expire after a reasonable time, the Quickmeeting URLs are valid for a long (indefinite?) time, so by my understanding these URLs should certainly not be kept in the adress bar.

This is something we are working on right now and hope to release soon.
 
  • Like
Reactions: accentlogic
Status
Not open for further replies.

Forum statistics

Threads
111,973
Messages
590,078
Members
164,896
Latest member
sameage