A First Look at Zoombombing
Chen Ling, Utkucan Balci, Jeremy Blackburn, Gianluca Stringhini
摘要
Online meeting tools like Zoom and Google Meet have become central to our professional, educational, and personal lives. This has opened up new opportunities for large scale harassment. In particular, a phenomenon known as zoombombing has emerged, in which aggressors join online meetings with the goal of disrupting them and harassing their participants. In this paper, we conduct the first data-driven analysis of calls for zoombombing attacks on social media. We identify ten popular online meeting tools and extract posts containing meeting invitations to these platforms on a mainstream social network, Twitter, and on a fringe community known for organizing coordinated attacks against online users, 4chan. We then perform manual annotation to identify posts that are calling for zoombombing attacks, and apply thematic analysis to develop a codebook to better characterize the discussion surrounding calls for zoombombing. During the first seven months of 2020, we identify over 200 calls for zoombombing between Twitter and 4chan, and analyze these calls both quantitatively and qualitatively. Our findings indicate that the vast majority of calls for zoombombing are not made by attackers stumbling upon meeting invitations or bruteforcing their meeting ID, but rather by insiders who have legitimate access to these meetings, particularly students in high school and college classes. This has important security implications because it makes common protections against zoombombing, e.g., password protection, ineffective. We also find instances of insiders instructing attackers to adopt the names of legitimate participants in the class to avoid detection, making countermeasures like setting up a waiting room and vetting participants less effective. Based on these observations, we argue that the only effective defense against zoombombing is creating unique join links for each participant.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Hate Raids on Twitch: Echoes of the Past, New Modalities, and Implications for Platform GovernanceCatherine Han, Joseph Seering, Deepak Kumar, Jeffrey T. Hancock 等CSCW 2023 · 被引用 43 次
- "I'm a Professor, which isn't usually a dangerous job": Internet-facilitated Harassment and Its Impact on ResearchersPeriwinkle Doerfler, Andrea Forte, Emiliano De Cristofaro, Gianluca Stringhini 等CSCW 2021 · 被引用 39 次
- Getting Meta: A Multimodal Approach for Detecting Unsafe Conversations within Instagram Direct Messages of YouthShiza Ali, Afsaneh Razi, Seunghyun Kim, Ashwaq Alsoubai 等CSCW 2023 · 被引用 32 次
- Is It Safe to Share Your Files? An Empirical Security Analysis of Google WorkspaceLiuhuo Wan, Kailong Wang, Haoyu Wang, Guangdong BaiWWW 2024 · 被引用 6 次
- Enforcing End-to-end Security for Remote Conference ApplicationsYuelin Liu, Huangxun Chen, Zhice YangS&P 2024 · 被引用 5 次
它引用的顶会 Paper3
- Detecting Fake Accounts in Online Social Networks at the Time of RegistrationsDong Yuan, Yuanli Miao, Neil Zhenqiang Gong, Zheng Yang 等CCS 2019 · 被引用 86 次
- The Pod People: Understanding Manipulation of Social Media Popularity via Reciprocity AbuseJanith Weerasinghe, Bailey Flanigan, Aviel J. Stein, Damon McCoy 等WWW 2020 · 被引用 24 次
- The Tools and Tactics Used in Intimate Partner Surveillance: An Analysis of Online Infidelity ForumsEmily Tseng, Rosanna Bellini, Nora McDonald, Matan Danos 等USENIX Security 2020
相关 Paper
- Seeing Through: Analyzing and Attacking Virtual Backgrounds in Video CallsFelix Weissberg, Jan Malte Hilgefort, Steve Grogorick, Daniel Arp 等USENIX Security 2025
- Multi-Stage Group Key Distribution and PAKEs: Securing Zoom Groups against Malicious Servers without New Security ElementsCas Cremers, Eyal Ronen, Mang ZhaoS&P 2024 · 被引用 2 次
- Investigating Moderation Challenges to Combating Hate and Harassment: The Case of Mod-Admin Power Dynamics and Feature Misuse on RedditMadiha Tabassum, Alana Mackey, Ashley Schuett, Ada LernerUSENIX Security 2024 · 被引用 10 次
- Beyond Mute and Block: Adoption and Effectiveness of Safety Tools in Social VR, from Ubiquitous Harassment to Social SculptingMaheshya Weerasinghe, Shaun Alexander Macdonald, Cristina Fiani, Joseph O'Hagan 等IEEE VR 2025 · 被引用 12 次
- Investigating the Use and Perception of Blocking Feature in Social Virtual Reality Spaces: A Study on Discussion ForumsQijia Chen, Seyed Mahed Mousavi, Giuseppe Riccardi, Giulio JacucciCSCW 2025 · 被引用 9 次
