{"id":3217,"date":"2021-02-22T07:14:36","date_gmt":"2021-02-22T07:14:36","guid":{"rendered":"https:\/\/thenextweb.com\/?p=1339909"},"modified":"2021-02-22T07:14:36","modified_gmt":"2021-02-22T07:14:36","slug":"are-clubhouse-chats-leaking-heres-what-we-know","status":"publish","type":"post","link":"https:\/\/www.londonchiropracter.com\/?p=3217","title":{"rendered":"Are Clubhouse chats leaking? Here\u2019s what we know"},"content":{"rendered":"\n<div><img decoding=\"async\" src=\"https:\/\/img-cdn.tnwcdn.com\/image\/tnw?filter_last=1&amp;fit=1280%2C640&amp;url=https%3A%2F%2Fcdn0.tnwcdn.com%2Fwp-content%2Fblogs.dir%2F1%2Ffiles%2F2021%2F02%2Fwilliam-krause-2gzn9qRw8wI-unsplash-e1612418861681.jpg&amp;signature=ca74cc941c320b6c28c4629e320442bd\" class=\"ff-og-image-inserted\"><\/div>\n<p>Clubhouse\u2018s appeal lies in its off-the-record nature where users <span>can voice chat with each other candidly, in ephemeral \u2018rooms.\u2019<\/span>&nbsp;But what if bad actors could&nbsp;snoop upon your live conversations?<\/p>\n<p>A report from <a href=\"https:\/\/thebarsys.com\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Bloomberg<\/a> noted that over the weekend, an unidentified user was able to crack the service and listen to conversations.&nbsp;<span>The user, believed to be based in China, made their own website to capture audio streams from the app<\/span>. The company has now banned the user and said that it has implemented new \u201csafeguards\u201d to stop future unauthorized access.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\" readability=\"10.446601941748\">\n<p lang=\"en\" dir=\"ltr\">Some Chinese developer made an Android \/ PC compatible player for Clubhouse, put it on GitHub, and this guy is like \u201cClubhouse has been hacked &amp; it\u2019s coming out of China.\u201d Then he goes on Clubhouse chatrooms to \u201cverify this hack.\u201d <a href=\"https:\/\/t.co\/7lbZDJa772\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">https:\/\/t.co\/7lbZDJa772<\/a><\/p>\n<p>\u2014 Rui Ma \u9a6c\u777f (@ruima) <a href=\"https:\/\/twitter.com\/ruima\/status\/1363540267832279043?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">February 21, 2021<\/a><\/p>\n<\/blockquote>\n<p>This incident comes only a week after Clubhouse\u2019s announcement of <a href=\"https:\/\/www.engadget.com\/clubhouse-tightens-security-over-china-spying-fears-200000561.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">tightening security measures<\/a>, including preventing the app from \u201ctransmitting pings\u201d to China-based servers and additional encryption to protect conversations.<\/p>\n<p><em>[Read: <a href=\"https:\/\/thenextweb.com\/plugged\/2021\/02\/18\/clubhouse-apps-scheduling-searching-rooms-bio-host\/\">Addicted to Clubhouse? These apps will make it even better<\/a>]<\/em><\/p>\n<p>A report prepared by the&nbsp;<a href=\"https:\/\/cyber.fsi.stanford.edu\/io\/news\/clubhouse-china\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Stanford Internet Observatory<\/a>&nbsp;(SIO) noted that China-based company Agora provides the backend for Clubhouse, and it transmitted user ID numbers and chatroom IDs in plaintext. Neither Agora nor Clubhouse have commented on this partnership publically.<\/p>\n<p>Former Facebook security executive Alex Stamos, who also contributed to SIO\u2019s report, said that&nbsp;<span>\u201cClubhouse cannot provide any privacy promises for conversations held anywhere around the world.\u201d&nbsp;<\/span><\/p>\n<p>He also observed Clubhouse used previously undocumented servers run by EnjoyVC. We don\u2019t know what service this company provides to the app, and what implication it might have on users.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\" readability=\"10.323529411765\">\n<p lang=\"en\" dir=\"ltr\">Another interesting finding was the undocumented use of servers run by &#8220;GUANGZHOU ENJOY_VC COMMUNICATION TECHNOLOGY CO., LTD.&#8221; aka EnjoyVC.<\/p>\n<p>Neither Agora or EnjoyVC are listed as data sub-processors by Clubhouse.<a href=\"https:\/\/t.co\/g4bnLzXIKQ\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">https:\/\/t.co\/g4bnLzXIKQ<\/a><a href=\"https:\/\/t.co\/QKU6SBHUJu\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">https:\/\/t.co\/QKU6SBHUJu<\/a><\/p>\n<p>\u2014 Alex Stamos (@alexstamos) <a href=\"https:\/\/twitter.com\/alexstamos\/status\/1361761683430014977?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">February 16, 2021<\/a><\/p>\n<\/blockquote>\n<p>In response to SIO\u2019s report, Clubhouse said that it doesn\u2019t have servers in China as the app hasn\u2019t been officially launched in the country. It added that some users in China found a workaround to install the app and \u201cconversations they were a part of could be transmitted via Chinese servers.<em>\u201c<\/em><\/p>\n<p>Security measures taken by the audio apps seem sufficient for now, but it might want to have a wider audit to avoid <a href=\"https:\/\/thenextweb.com\/security\/2020\/04\/03\/zoom-is-a-godforsaken-mess-but-it-can-be-fixed\/\">a Zoom-level fiasco<\/a>.<\/p>\n<p>Safety and privacy are a huge part of Clubhouse\u2019s appeal. <a href=\"https:\/\/twitter.com\/TwitterSpaces\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Twitter<\/a> and <a href=\"https:\/\/thenextweb.com\/plugged\/2021\/02\/11\/everyones-obsessed-with-clubhouse-so-facebook-is-reportedly-making-its-own\/\">Facebook<\/a> are already exploring ways to build live audio chat products, and more security incidents might make users think of switching to other platforms.<\/p>\n<p> <a href=\"https:\/\/thenextweb.com\/security\/2021\/02\/22\/clubhouse-audio-leak-china\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Clubhouse\u2018s appeal lies in its off-the-record nature where users can voice chat with each other candidly, in ephemeral \u2018rooms.\u2019&nbsp;But what if bad actors could&nbsp;snoop upon your live conversations? A report from Bloomberg&#8230;<\/p>\n","protected":false},"author":1,"featured_media":3218,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=\/wp\/v2\/posts\/3217"}],"collection":[{"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3217"}],"version-history":[{"count":0,"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=\/wp\/v2\/posts\/3217\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=\/wp\/v2\/media\/3218"}],"wp:attachment":[{"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3217"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3217"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3217"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}