Hi, this is Upendra Goswami, Associate Editor with Information Security Media Group. I have the pleasure of speaking with Steve Marshall, who is CISO at Vice Technology. And we will be talking about something very interesting today, the security risks attached with AI meeting assistants. And the topic is more relevant now as more and more organizations rely on remote online meetings.
Hi, Steve. Thank you so much for joining me today. No problem at all, Spaner. Steve, recently, I read an interesting anecdote on your LinkedIn post.
You had mentioned that while having a remote video call, you noticed an uninvited AI assistant. Can you throw us some more light on this? Certainly. So it was a really interesting case because it was one that we hadn't come across before.
If you don't know what an AI meeting assistant is, it's a clever piece of technology that you can invite to a meeting. It will record the call, the chat, and the video. It will then transcribe what's said during that meeting and provide outputs in a format that you can search and mine for information. Now, these are very useful tools and lots of companies use them now in order to be able to add them to a meeting, take the information from the meeting in a digital, readable format that they can then push into their CRM system, mine the format and the data that comes back, and add that as case notes and these types of things into their customer relationship management system to get a much richer set of information on customers, what they're looking for, technical aspects, what's been discussed, and those types of things so that they can use it to service customers more appropriately.
So it's a great piece of technology and it can join both video conferences, chat conferences, or chat meetings, but it can also join telephone meetings as well. So it's not just limited to digital formats. It can use analog voice format as well as digital voice formats as well. The interesting thing that seems to have happened is that these seem to have been weaponized by external participants in order to actually use this technology for nefarious purposes.
It's very, very easy. You can go and do a search online for an AI meeting bot. You can largely sign up for them free in a number of cases, set yourself an account up, and then the only things that you need to do is provide the specifics of the meeting, so the meeting URL and the meeting details into that AI chatbot or translate bot, and then it will join the meeting when the meeting occurs. So in our case, we'd set up a Zoom meeting.
We published the URL on the internet so that people could drop in. We decided to do a drop-in clinic for anybody that wanted to come and chat to us for two hours. So we were all in the meeting chatting along nicely, and we noticed a strange participant had come up with a name at company that we didn't recognize. So we did a bit of Google searching while we were on the call, and we found out that it was one of these AI meeting systems.
And we looked a bit further into it and then realized that actually it was recording the call and transcribing exactly what was being said on the call. So we kicked it out of the call immediately. Fascinating. Steve, how did you guys come to know that it is an AI assistant?
And plus, how does the entire thing work? Does it only work in cases where there's an open invitation, essentially when you don't really require an authentication? So we recognized this particular one. This particular one was a product called Fireflies.ai, but we noticed it because the STEM name of it said at fireflies.ai, and we didn't recognize that.
We'd never come across it before. So we found it. We then looked it up and found out that this is what it was and what it was doing. Now, clearly, as things advance in terms of these types of solutions, nefarious ones are just going to add themselves as a, you know, as a standard name of a person.
So in the UK, Dave Smith, probably nobody's really going to bat an eyelid in terms of that type of thing or even another Subarna Goswami in India. It's going to be much more difficult to identify these participants. In our case, we had an open published link. And so it was very easy to be able to scrape that off the Internet.
However, up until very, very recently, especially with Zoom, and I will reiterate that this can occur on any of the conferencing platforms. It's not just Zoom. It will go across Microsoft. It will go across Google Chat, Google Classroom.
It will go across Skype for Business. It will go across RingCentral, all of the ones that you can use. Zoom in this particular case that we've been using clearly is one that everybody's using at the moment is, you know, got massive press and these types of things. Up until very, very recently, it was only using between 9 and 11 digits, numbers, to identify its meetings, which provides a very, very low strength for people actually being able to guess.
The entropy is very low. It's about 30, 32 bits of entropy strength. So it's not very difficult to crack and sequence the numbers that were being used for meeting IDs. There was also a prying eye vulnerability out where there was a website that would actually just go through and tell you what meeting IDs were valid because you could submit it to Zoom at that time, and they would tell you whether it was a valid or an invalid meeting when it was occurring.
So then you could literally just run down every single number, work out which meetings were coming up, put them into the AI meeting assistance. Now, Zoom has recently fixed that. However, the issue is that any legacy meetings that are still in place still have these 9 to 11 digit number within their URL. And that's the code in order to be able to identify the meeting.
The more modern meetings now all use numbers and letters and a much, much longer, which makes the entropy much higher and much more difficult to crack. Sequencing and guessing is, you know, is much more difficult in that regard. But any legacy meetings are still vulnerable to this type of prying eye vulnerability that was identified. It's not a new vulnerability.
That was actually discovered back in July 2019. And there are others that go back prior to that, 2017, 2018, where people have been using meeting IDs and sequencing and these types of things in order to be able to find them. Now, with the AI meeting assistance, they will handle authentication. So if you give them authentication details, they'll be able to log in.
So if you've got a password and that's supplied, they'll be able to log in. If you've got a telephone number and a PIN code, they'll be able to log in. That's why it's really, really important to make sure that, you know, unless you're doing open meetings, that actually you keep those URLs safe. You don't publish them.
You don't post them. And you need to make sure that, you know, they're not being phished or picked up via malware or those types of things as well. But what happens when it's an open meeting? What kind of security measures should be undertaken to avoid such instances?
Yes. So whether it's an open meeting or a closed meeting, you've got very, very similar things that you can do. Generate random meeting IDs. Don't use personal ones.
Personal ones are very easy to guess because they're your name and a couple of other identifying characters. OK, so once that's been exposed in any way, shape or form, then it's very, very easy in order to be able to attach yourself to to meetings that that person does because the URL stays the same all the time. So use random meeting IDs. That way, if one meeting is compromised, it doesn't mean that the next one will be.
So you can restart that meeting, cease, put new meeting out with a new URL. Use authentication if you can. So signed in users are best because then you've got a form of authentication and identity as to who that person is. To an extent, there are always issues.
At worst, use a passcode in order to be able to get in. But as I've already said, you know, AI meeting assistants have the ability to be able to handle authentication. So make sure the passwords kept secret. Use the lobby feature.
So actually get people's coming to the lobby and then admit them one by one. Don't admit them all in one go. Use CAPTCHA for voice. We're kind of all used to using CAPTCHA on websites where it says I'm not a robot.
Actually ask the person to identify themselves on the call. Make sure they've got a voice. Steve, what would be some security or technology solutions that are in place? Are there any in place for this or like such instances?
Yeah, certainly. So you can set up how the links are displayed. You can set up whether you want authentication with the lobbies used. Get IT to go through these features.
Also, when you're sending links out or when links are coming into you, make sure they're the correct link. Look at, you know, understand where they come from. You know, things like email solutions and this type of thing should be able to check that the links are safe, that they haven't been compromised or they're not impersonating because a few of the other things that we're starting to see is what's called Zoom bombing. People are actually adding themselves to meetings and displaying inappropriate content and these types of things.
And we're also seeing people creating links that are very, very close, you know, to these things. So Zoom, for instance, zoom.us. We've seen one that's got three or four O's in the middle. So zoom.us.
You know, it's clearly a fake link, but it's difficult sometimes to spot when you, you know, when you have these sent to you. So make sure that IT have got technology in place to evaluate