HomeSecurityZoom's message to its customers regarding...

Zoom's message to its customers about security issues

Zoom

Following the recent discovery of security in the Zoom application, the company published an official response to its customers regarding the issue:  

To our users around the world,

Whether you're a global company struggling to keep its business running, a local government agency working to keep running , a teacher teaching students remotely, or a friend looking to share a happy moment while quarantined, you're all managing unique challenges that have resulted from this global health crisis. During this time of social distancing, we at Zoom feel incredibly privileged to be able to help you stay connected with those you need.

We also feel a huge responsibility. Zoom usage has skyrocketed overnight – far exceeding what we expected when we first announced our desire to help in late February. This includes over 90,000 schools in 20 countries that have taken up our offer to help children continue their education remotely. As of late December last year, the peak number of daily participants, both free and paid, on Zoom was around 10 million. In March of this year, we reached more than 200 million daily participants in video conferences. We are working around the clock to ensure that all of our users – young and old, big and small – can communicate and deliver on their mission.

Over the past few weeks, supporting this influx of users has been a huge undertaking and our sole focus. We’ve strived to provide you with seamless service and the same user-friendly experience that has made Zoom the video conferencing platform of choice for businesses around the world, while ensuring the platform and privacy. However, we recognize that we have fallen short of the community’s expectations – and our own – when it comes to privacy and security. For that, we deeply regret it and want to share what we’re doing about it.

Our platform was originally built primarily for enterprise customers – large institutions with full IT support, from the world’s largest financial services companies to leading telecommunications providers, government agencies, universities, healthcare and telemedicine organizations. Thousands of businesses around the world have conducted exhaustive user, network and data center level security reviews and have chosen Zoom.

However, we didn’t design the product with the expectation that, in a few weeks, every person in the world would suddenly be working, studying, and communicating from home. Now we have a much broader set of users leveraging our product, in a multitude of unexpected ways, presenting us with challenges we didn’t anticipate when the platform was designed.

These new, mostly consumer-facing cases helped us uncover unforeseen issues on our platform. Dedicated journalists and security researchers also helped identify issues. We value the scrutiny and questions we receive – about how the service works, our infrastructure and capacity, and our privacy and security policies. These are the questions that will make Zoom better, both as a company and for all of our users.

What have we done?

With the increased number of users, part of the challenge is ensuring that we provide the appropriate training, tools, and support to help them understand their account features and how to best use the platform.

We offer training seminars, as well as free interactive daily tutorials for users. We proactively promoted many of these resources to help users get familiar with Zoom.

We take several steps to minimize customer support wait times when we receive questions.

We listen to our user community to help us develop our approach.

We have also worked hard to proactively and quickly address specific issues and questions that were raised.

On March 20, we published a blog post to help users address incidents of harassment (or so-called “Zoombombing”) on platform , clarifying protective measures that can prevent it, such as waiting rooms, passwords, and limiting screen sharing.

On March 27, we took action to remove the Facebook SDK in the iOS client and reformatted it to prevent the collection of unnecessary device information from our users.

On March 29, we updated our privacy policy to be clearer and more transparent about the data we collect and how we use it – explicitly clarifying that we do not sell our users' data, have never sold user data in the past, and have no intention of selling user data.

To educate users:

  • A guide for administrators on creating a virtual classroom was developed.
  • We have set out a guide on how to best secure virtual classrooms.
  • We have set a specific K-12 privacy policy.
  • We changed the settings for student users enrolled in the K-12 program so that virtual waiting rooms are enabled by default.
  • We changed the settings for learners enrolled in the K-12 program so that teachers are by default the only ones who can share content in the classroom.

On April 1st:

  • We published a blog to clarify the facts surrounding encryption on our platform – acknowledging and apologizing for the confusion.
  • The participant interest tracking feature has been permanently removed.
  • We have released fixes for both Mac-related issues raised by Patrick Wardle.
  • We have released a fix for the UNC connection issue.
  • We permanently deleted the LinkedIn Sales Navigator app after identifying unnecessary data disclosure from the feature.

You can see Zoom's detailed announcement to its customers here.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS