Beware the Zoom boom

Zoom work meeting / Photo: Reuters
Zoom work meeting / Photo: Reuters

The video conferencing platform has sharpened its cybersecurity features, but users should remain prudent.

Thanks to the world’s increasing need to conduct lives virtually, video conferencing company Zoom's daily meeting participant numbers have ballooned to 300 million, sending its market cap skyrocketing to some $35 billion. Whilst some COVID-19 habits might prove temporary, the way society draws on communication software as a lifeline is expected to persist well beyond the current crisis. As employees begin to trickle slowly back into Israeli offices, and the UK begins to explore a pandemic exit strategy, it is clear that Zoom is here to stay.

Whilst Zoom is safe for most people, the growing reliance on its service by governments and the judicial system for sensitive operations has increased pressures on the company to tackle outstanding privacy and security vulnerabilities. Indeed, Zoom, having held a somewhat unsatisfactory record in the cyber arena, seems to have turned over a new leaf with its announcement last week of a "90-day plan" to revamp its security and privacy standards, the first milestone of which is a new version of the platform, Zoom 5.0.

Zoom has previously been met with criticism for the transmission of users’ data through servers in Chinese data centers. China’s cybersecurity laws, allowing the Chinese government to access data kept on local servers, have been heavily criticised internationally over fears for the possibility of cyber espionage. Companies who refuse to comply with Chinese data localization laws and to disclose their encryption keys to the government could face serious penalties. To combat this, Zoom 5.0 will allow paying customers to pick the data centers from which their calls are routed. Free users are unable to change their regions, but those outside of China will not have their data routed through Chinese servers.

Additionally, following reprimands over its misleading claims about its end-to-end encryption, Zoom has introduced GCM encryption to Zoom 5.0, intended to bolster the protection of data in transit and its resistance to tampering. However, the platform still lacks complete end-to-end encryption, compelling organisations which want to hold themselves to the highest possible standard to think twice when interacting with the platform.

Four precautions to protect your Zoom meetings

Change and lock your default settings, so that they cannot be changed at individual user level. Consider limiting the ability to share screens only to the meeting host - this feature has been proven to be prone to abuse. It is also advisable to turn off the functionality allowing chats to be saved, since this is a particularly buggy part of Zoom. This feature also raises privacy questions - private chats between users should not be publically available after being saved. To prevent "Zoombombing", the intrusion of uninvited users into a meeting, set up Host Keys, password protect your meetings, and make sure not to use your Personal Meeting ID (PMI) to set up new meetings - doing so can allow others who already have your PMI to enter other meetings in which you are also using your PMI.

Compulsory waiting rooms are also an efficient way of controlling who enters your meeting, since it gives the host maximum control over who is admitted. In this situation, the host first enters the meeting, and then lets everyone else in. It also means that, once the meeting is underway, people who then try to join will be kept in the waiting room until approved.

Recordings must be made sparingly and carefully, since the host has the power to record the meeting without the participants’ knowledge. It is therefore best practice to ensure that everyone in the meeting consents to being recorded before a meeting begins. Consider only permitting recordings to be saved to the cloud to enhance levels of security. Saving to the cloud means that once the recording is complete, it will only be accessible by the host and authenticated users.

Select a data center region, to have more control over where your meeting data is stored. As mentioned, paying Zoom users can now whitelist and blacklist data center regions when scheduling meetings and webinars.

Syvanne Aloni is a paralegal and Avishai Ostrin is Head of Privacy and Data Protection at Asserson Law Offices.

Published by Globes, Israel business news - en.globes.co.il - on May 7, 2020

© Copyright of Globes Publisher Itonut (1983) Ltd. 2020

Zoom work meeting / Photo: Reuters
Zoom work meeting / Photo: Reuters
Michael Rogers  credit: Team8 The spy who came into Israeli tech

Former US National Security Agency head Michael Rogers is now a partner at VC fund Team8. He talks to "Globes" about intelligence, geopolitics, and what amazes him about Israel's tech industry.

Dr. Neal Tsur credit: Yossi Zamir "Trump was just an excuse for market drop"

Dr. Neal Tsur studies what makes complex systems like stock markets ripe for change, and he has put his money where his theory is.

Roy Goldenberg  credit: Jonathan Bloom Making a better world for the disabled

Personal experience motivated Roy Goldenberg to become Israel director of TOM Tikkun Olam Makers. "TOM will be one of the biggest organizations to come out of Israel," he says.

Itay Raved  credit: Jonathan Bloom From a rooftop in India to running Tesla Israel

Itay Raved's career drifted from law to media consulting to acting, before he finally found his niche.

Dr. Adi Tzoref-Lorenz credit: Jonathan Bloom "My research says I don't accept there is no answer"

The death of a cancer patient spurred Dr. Adi Zoref-Lorenz into developing the OHI index, which allows the diagnosis of the HLH side effect from cancer immunotherapy, based on two blood tests.

Dr. R  credit: Jonathan Bloom Wounded in his tank, now R develops protection systems

"I was close to death, but it sharpened my awareness of the products we develop for the IDF."

Ella Kenan  credit: Yossi Cohen A fighter of fake news about Israel

Ella Kenan saw online denial of October 7 happening straightaway. "I realized we had 24 hours, or we were doomed"

Liron Horshi credit: Jonathan Bloom Wiz's talent manager nurtures $1b workforce

Wiz's $32 billion sale to Google was rooted in the cloud security product if offers but could not have been achieved without the quality of its employees built by human resources chief Liron Horshi.

Yoav Shoham  credit: Eyal Izhar Yoav Shoham: AI isn't too smart, it's too dumb

AI21 Labs founder and CEO Prof. Yoav Shoham talks to "Globes" about dubious doomsday predictions, what should really concern us, and what could make Israel a global AI leader.

Record public company profits  credit: Tali Bogdanovsky Profits peak, but reckoning awaits

In what may seem a paradox, profits grew in almost every sector on the Tel Aviv Stock Exchange last year, but the boom was largely fueled by government spending.

Insightec COO and general manager Eyal Zadicario credit: Ness Productions After 25 years of losses Insightec focuses on profit

Insightec COO and general manager Eyal Zadicario tells "Globes" about himself and the Israeli ultrasound company's long battle to change the medical world.

Amit Shaked credit: Tomer Lesher Driven to succeed but balancing ambition with wellbeing

At just 14, cybersecurity company Rubrik VP Amit Shaked began a B.Sc. in Computer Science and Math and mapped out his entire future, which included IDF service in the 8200 unit, and an inevitable huge startup exit.

Advs. Roy Keidar and Netanella Treistman credit: Nicky Westphal AI blind spot startups can no longer afford to ignore

How AI governance can assist startups and enhance their ability to succeed.

Dr. Ola Gutzeit  credit: Ketty Hakim The doctor breaking new ground in fertility

"We know nothing about the female reproductive system," says Dr. Ola Gutzeit of Rambam Hospital. She seeks to change that, and hence change IVF for the better.

Google CEO Sundar Pichai  crediit: Shutterstock Why Google is paying so much for Wiz

Lagging its competitors in cloud and AI, and facing challenges to its core advertising business, Google could be looking to spend its way out of trouble.

Donald Trump speaking on the deck of the USS Gerald R. Ford  at its launch in 2017 credit: Reuters/Jonathan Ernst Houthis between hammer and anvil

President Trump appears determined to end the Houthi threat to shipping, while Iran has abandoned the last active arm of its "axis of resistance."

Twitter Facebook Linkedin RSS Newsletters גלובס Israel Business Conference 2018