{"id":185475,"date":"2021-02-22T10:14:36","date_gmt":"2021-02-22T07:14:36","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/are-clubhouse-chats-leaking-heres-what-we-know\/"},"modified":"2021-02-22T10:14:36","modified_gmt":"2021-02-22T07:14:36","slug":"are-clubhouse-chats-leaking-heres-what-we-know","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/are-clubhouse-chats-leaking-heres-what-we-know\/","title":{"rendered":"#Are Clubhouse chats leaking? Here\u2019s what we know"},"content":{"rendered":"<p>&#8220;<strong>#Are Clubhouse chats leaking? Here\u2019s what we know<\/strong>&#8221;<br \/>\n<img decoding=\"async\" src=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2021\/02\/william-krause-2gzn9qRw8wI-unsplash-e1612418861681-796x419.jpg\" \/><\/p>\n<div>\n                            Clubhouse\u2018s <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>eal lies in its off-the-record nature where users <span>can voice chat with each other candidly, in ephemeral \u2018rooms.\u2019<\/span>\u00a0But what if bad actors could\u00a0snoop upon your live conversations?<\/p>\n<p>A report from <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/thebarsys.com\/\">Bloomberg<\/a> noted that over the weekend, an unidentified user was able to crack the service and listen to conversations.\u00a0<span>The user, believed to be based in China, made their own website to capture audio streams from the app<\/span>. The company has now banned the user and said that it has implemented new \u201csafeguards\u201d to stop future unauthorized access.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Some Chinese developer made an Android \/ PC compatible player for Clubhouse, put it on GitHub, and this guy is like \u201cClubhouse has been hacked &amp; it\u2019s coming out of China.\u201d Then he goes on Clubhouse chatrooms to \u201cverify this hack.\u201d <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/t.co\/7lbZDJa772\">https:\/\/t.co\/7lbZDJa772<\/a><\/p>\n<p>\u2014 Rui Ma \u9a6c\u777f (@ruima) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/ruima\/status\/1363540267832279043?ref_src=twsrc%5Etfw\">February 21, 2021<\/a>\n<\/p><\/blockquote>\n<p>This incident comes only a week after Clubhouse\u2019s announcement of <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.engadget.com\/clubhouse-tightens-security-over-china-spying-fears-200000561.html\">tightening security measures<\/a>, including preventing the app from \u201ctransmitting pings\u201d to China-based servers and additional encryption to protect conversations.<\/p>\n<p><em>[Read: Addicted to Clubhouse? These apps will make it even better]<\/em><\/p>\n<p>A report prepared by the\u00a0<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cyber.fsi.stanford.edu\/io\/news\/clubhouse-china\">Stanford Internet Observatory<\/a>\u00a0(SIO) noted that China-based company Agora provides the backend for Clubhouse, and it transmitted user ID numbers and chatroom IDs in plaintext. Neither Agora nor Clubhouse have commented on this partnership publically.<\/p>\n<p>Former <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">Facebook<\/a> security executive Alex Stamos, who also contributed to SIO\u2019s report, said that\u00a0<span>\u201cClubhouse cannot provide any privacy promises for conversations held anywhere around the world.\u201d\u00a0<\/span><\/p>\n<p>He also observed Clubhouse used previously undocumented servers run by EnjoyVC. We don\u2019t know what service this company provides to the app, and what implication it might have on users.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Another interesting finding was the undocumented use of servers run by &#8220;GUANGZHOU ENJOY_VC COMMUNICATION <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/technology\/\" data-internallinksmanager029f6b8e52c=\"4\" title=\"Technology\" target=\"_blank\" rel=\"noopener\">TECHNOLOGY<\/a> CO., LTD.&#8221; aka EnjoyVC.<\/p>\n<p>Neither Agora or EnjoyVC are listed as data sub-processors by Clubhouse.<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/t.co\/g4bnLzXIKQ\">https:\/\/t.co\/g4bnLzXIKQ<\/a><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/t.co\/QKU6SBHUJu\">https:\/\/t.co\/QKU6SBHUJu<\/a><\/p>\n<p>\u2014 Alex Stamos (@alexstamos) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/alexstamos\/status\/1361761683430014977?ref_src=twsrc%5Etfw\">February 16, 2021<\/a>\n<\/p><\/blockquote>\n<p>In response to SIO\u2019s report, Clubhouse said that it doesn\u2019t have servers in China as the app hasn\u2019t been officially launched in the country. It added that some users in China found a workaround to install the app and \u201cconversations they were a part of could be transmitted via Chinese servers.<em>\u201c<\/em><\/p>\n<p>Security measures taken by the audio apps seem sufficient for now, but it might want to have a wider audit to avoid a Zoom-level fiasco.<\/p>\n<p>Safety and privacy are a huge part of Clubhouse\u2019s appeal. <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/TwitterSpaces\">Twitter<\/a> and Facebook are already exploring ways to build live audio chat products, and more security incidents might make users think of switching to other platforms.<\/p>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/thenextweb.com\/security\/2021\/02\/22\/clubhouse-audio-leak-china\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Are Clubhouse chats leaking? Here\u2019s what we know&#8221; Clubhouse\u2018s appeal lies in its off-the-record nature where users can voice chat with each other candidly, in ephemeral \u2018rooms.\u2019\u00a0But what if bad actors could\u00a0snoop upon your live conversations? A report from Bloomberg noted that over the weekend, an unidentified user was able to crack the service and&#8230;<\/p>\n","protected":false},"author":1,"featured_media":185476,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/img-cdn.tnwcdn.com\/image\/tnw?filter_last=1&fit=1280,640&url=https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2021\/02\/william-krause-2gzn9qRw8wI-unsplash-e1612418861681.jpg&signature=ca74cc941c320b6c28c4629e320442bd","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[94639],"class_list":["post-185475","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-clubhouse"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/185475","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=185475"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/185475\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/185476"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=185475"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=185475"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=185475"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}