Starting from the earliest days of the Covid 19 pandemic, adaptability has become a buzzword in almost every sector of daily life for millions around the globe. From financial markets and hospitals to educational systems and world governments adaptability has meant an increased reliance on technology, particularly on services offered by firms such as Google, Facebook and Amazon.
However, while this pivot to an increased dependency on technology may be crucial in protecting ourselves from the pandemic taking place outside our homes, it has also exposed us to the cyber threats within them.
One technology company in particular, the web-based video chatting platform, Zoom, has been both praised and criticized for the services it has offered in recent weeks.
The Good:
Before we break into the difficulties of Zoom, let’s first understand or at least appreciate Zoom’s incredible capabilities to bring our quarantined world together.
Just under a 100 years ago during the Spanish Flu of 1918, quarantining and social distancing led to the closure of thousands of public spaces, even making it illegal to leave your home without wearing flu masks. New York time articles describe empty streets as the society and building as society was effectively shut down.
While this description is not so different from our modern one, the reality is that universities, firms, doctors appointments, even concerts have all gone digital.
When entire multinational firms with thousands of employees are able to operate without a single person leaving their home- that is reason enough to take a step back and appreciate the advances of technology.
Zoom has been an essential part of the most recent digitalization of our society and it is important not to forget that.
However, while Zoom is impressive, it is far from perfect.
The Bad:
Security Issues. Perhaps the most infamous of which is Zoomboming, where individuals hack into and join private meetings, only to subsequently spam both the chat and their video screens with disruptive content ranging from pornographic imagery to symbols of the alt-right. This is accomplished either by inputting random ID numbers, a flaw in Zoom’s initial ID generation as well as online tools which help hackers find Zoom meetings to join.
It was also discovered that when running Zoom on Windows, the videoconferencing system allows hackers to access private username and password information with ease. This is accomplished primarily through links sent via the chat feature found on the Zoom client.
Finally, Zoom claims that all their meetings are end to end encrypted, when in reality, Zoom only follows a self defined definition of this term. When asked about its use of an end to end encryption, a Zoom spokesperson wrote, “Currently, it is not possible to enable E2E encryption for Zoom video meetings. Zoom video meetings use a combination of TCP and UDP. TCP connections are made using TLS and UDP connections are encrypted with AES using a key negotiated over a TLS connection.”
The Intercept further explains this distinction saying: “The encryption that Zoom uses to protect meetings is TLS, the same technology that web servers use to secure HTTPS websites. This means that the connection between the Zoom app running on a user’s computer or phone and Zoom’s server is encrypted in the same way the connection between your web browser and this article (on https://theintercept.com) is encrypted. This is known as transport encryption, which is different from end-to-end encryption because the Zoom service itself can access the unencrypted video and audio content of Zoom meetings. So when you have a Zoom meeting, the video and audio content will stay private from anyone spying on your Wi-Fi, but it won’t stay private from the company”
The Ugly:
Privacy. Zoom has been suspiciously unclear on whether it sells the data it collects on each from each particular user. In a direct quote from its privacy policy last month, Zoom Stated:
“Does Zoom sell Personal Data? Depends what you mean by "sell." We do not allow marketing companies, or anyone else to access Personal Data in exchange for payment. Except as described above, we do not allow any third parties to access any Personal Data we collect in the course of providing services to users. We do not allow third parties to use any Personal Data obtained from us for their own purposes, unless it is with your consent (e.g. when you download an app from the Marketplace. So in our humble opinion, we don't think most of our users would see us as selling their information, as that practice is commonly understood”
In an almost comical opening line, Zoom tiptoes itself around the legal definition of ‘selling’ and while this statement has recently been changed (check out the full statement here), the vague description of the ‘marketing websites’ it uses the collected data for, does appear to be awfully alarming.
Motherboard recently reported that Zoom sends its obtained data to Facebook, whether you have one or not. Using Facebook’s SDK’s (Software Development Kits), every time an individual opens the Zoom app, “Facebook when the user opens the app, details on the user's device such as the model, the time zone and city they are connecting from, which phone carrier they are using, and a unique advertiser identifier created by the user's device which companies can use to target a user with advertisements” .
This issue has since been repaired, as of March 29th, but it does display an overall disingenuous aspect of a company that has risen to prominence during this most stage of our lives.
In Sum:
Know What You Have to Lose.
Zoom has problems, big problems, and while it is doing all that it can to repair them, when personal data and private information are at risk- precaution is highly recommended. That being said, Zoom’s ability to cleanly and comfortably connect us with the world at large cannot be underestimated.
Using Zoom for online classes? Amazing.
UK prime minister Boris Johnson using zoom (and posting the meeting ID!)... Not so much.
Looking further understand these issues and perhaps beef up your own cybersecurity for your firm or workplace? BlueTeam is here to help.