Security experts call Zoom a 'privacy disaster'

(Image credit: Pixabay)

Many people are finding out what it is like to work from home because of the Covid-19 outbreak, which in turn has led to a surge in the use of video conferencing software. Zoom in particular has seen a massive uptick in usage. While that's a good thing for Zoom, it has also raised concerns about the platform's privacy and security.

Just how popular is Zoom these days? As spotted by The Guardian, daily traffic to the Zoom.us download page experienced a 535 percent surge in daily traffic over the past month, according to data from web analytics firm SimilarWeb. And according to SensorTower, Zoom's iPhone app has been downloaded more than any other app in the US for the past several weeks.

This sudden rise has put Zoom under scrutiny, both by security researchers and New York Attorney General Letitia James. The New York Times reports that James recently sent a letter to Zoom asking what security measures it put in place to deal with the increased traffic. The letter also raised some security concerns, saying Zoom has been slow to address vulnerabilities "that could enable malicious third parties to, among other things, gain surreptitious access to consumer webcams."

Zoom responded in a statement, saying it "takes its users' privacy, security, and trust extremely seriously."

"During the Covid-19 pandemic, we are working around the clock to ensure that hospitals, universities, schools and other businesses across the world can stay connected and operational," Zoom added.

Some see Zoom's statement as little more than lip service. Earlier this week, the FBI issued a warning over the practice of "Zoom-bombing," which is the practice of hacking video conferencing software and sessions. Part of the issue is that Zoom's short number-based URLs can be guessed by hackers.

"The FBI has received multiple reports of conferences being disrupted by pornographic and/or hate images and threatening language," the FBI said in a statement to CBS Boston.

Security researchers have also been critical of Zoom on Twitter. Arvind Narayanan, a Princeton University professor and security expert, called Zoom a "privacy disaster." David Heinemeir Hansson, creator of Ruby on Rails and founder of Basecamp, had even harsher words for Zoom.

"What pains me about Zoom being such sleazeballs when it comes to both security and privacy is just how unnecessary it is. They have good fundamental tech! But as the skeletons keep falling out of the closet, it’s clear that the organization is fundamentally corrupt," Hansson said.

Hansson's Twitter feed links to several articles that put Zoom in an unflattering light, including one that claims Zoom deceives people into thinking it has end-to-end encryption when it doesn't.

Zoom has also faced criticism over its Mac installer, which a security researchers called out for bypassing Apple's OS restrictions by using "the same tricks that are being used by macOS malware." To Zoom's credit, Zoom was quick to respond with a fix.

My advice? Do your research on whatever video conferencing software you plan to use, and stay diligent.

Paul Lilly

Paul has been playing PC games and raking his knuckles on computer hardware since the Commodore 64. He does not have any tattoos, but thinks it would be cool to get one that reads LOAD"*",8,1. In his off time, he rides motorcycles and wrestles alligators (only one of those is true).

Latest in Security
An FBI wanted poster for alleged hacker Zhou Shuai.
US Justice Dept announces $10 million bounty on at-large 'hacker-for-hire' cabal it says targeted China critics, religious missionaries, and the Treasury
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
A still from a YouTube video of Senator Mark Warner speaking
Telecoms hack on US government officials is 'worst in nations history' and 'the barn door is still wide open' says senator
HDMI cable
Hackers can wirelessly spy on your display by collecting HDMI signal leaks and churning them through an AI, but I wouldn't break out the tin foil just yet
Computer code and text displayed on computer screens. Photographer: Chris Ratcliffe/Bloomberg
Forcing users to periodically change their passwords should go the way of the dodo according to the US government
An original Apple Macintosh Model M0001, as they celebrate 40th anniversary, is on display in between 2024 Apple models at the independent Apple products store chain Amac, on January 24, 2024 in Utrecht, The Netherlands. Based on the Motorola 68000 microprocessor, the Macintosh was the first successful mouse-driven computer with a graphical user interface.
Major browser providers scramble to patch an 18-year-old vulnerability affecting MacOS and Linux systems but Windows remains gloriously immune
Latest in News
Silent Hill f transmission trailer screenshots
Silent Hill f is not messing around – now it's been banned in Australia
MOUNTAIN VIEW, CALIFORNIA - AUGUST 22: A view of Google Headquarters in Mountain View, California, United States on August 22, 2024.
'Google must divest the Chrome browser:' DOJ renews call for Google to sell Chrome, and Android could be next
Victory screen of Big Rigs showing infamous "You're Winner" message under a three-handle gold trophy
One of the worst games ever made is coming to Steam, but we won't know how cruel this joke is until we see the price tag
Sci-fi character from Dune
Dune: Awakening promises us a breath of fresh air, skipping early access for a full launch with no monthly subscription in May
Baldur's Gate 3 Karlach concept art
'The dream of the tech industry is to sell off your company at an overinflated price and retire,' says actor behind Baldur's Gate 3's Karlach, 'And I feel that's being done with game studios right now'
assassin's creed shadows protector's armor
Assassin's Creed Shadows hits 2 million players, putting it on track to be the series' most successful game yet