
The greenhouse of social technologies is the operator of the TEPLODIGITAL program, in which many non-profit organizations can receive high-quality international IT services at reduced prices. One of these services is the service for organizing Zoom calls and webinars.
Due to the stunning growth of Zoom's popularity, attention to the messenger intensified, and therefore, there were more opportunities to monitor various shortcomings of the service, especially in the field of user data protection. Together with uninterrupted data, data protection (both content and metadata) is a priority for any messenger.
Within the framework of our educational video tutorials, we talked about the service . Moreover, we ourselves use Zoom and are not going to (at least for now) to refuse to use it. The greenhouse sincerely welcomes both the discussion about the importance of data protection and criticism of specific messengers. We believe that there is a difference between the statements of “Zoom is faced with safety problems that it is prompt” and “Zoom is structurally unsafe”.
The greenhouse offers to understand the details, for which the messenger is criticized, and to make an idea of whether to use or not this service.
Zoom, as journalists correctly note , has no end-to-end encryption for video calls (End-to-End or E2e Encryption), however, like many other services. That is, calls and video conferences are protected from other users of networks through which the signal passes but is potentially available to the Zoom administration, the researchers of the publication of The Intercept believe, since calls to calls are necessary to optimize the signal (Zoom has not yet commented on this statement). According to journalists, Zoom text chats have completely terminated encryption.
In addition, Zoom does not really publish the so -called Transparency Report - a report on the requests of national states to access user data. On March 18, the international human rights organization Accessnow turned to publish such reports. On April 1, 2020, Eric Yuan, Zoom Executive Director went to the meeting with the requirements of human rights defenders and promised to release such a report within three months.
According to the company itself, Zoom collects IP addresses, data on operating systems and models of devices to optimize calls. In addition, the company claims precautions that do not allow company employees to any data that users are divided. In addition, Zoom notes that it does not divide user data for marketing purposes (unlike Facebook Messenger or Skype).
How it concerns you: you conducted a very secret video discussion, about which one of the Zoom employees knew before it and in real time passed internal corporate restrictions in order to get access to this conversation. Recall, Zoom has 200 million users now.
Zoom does not record conversations . The record is carried out only if one of the users himself pressed the “Start recording” button. Moreover, the host of the meeting may include a special option that will ask the rest of the users, whether they agree to start the recording.
On April 3, 2020, the researchers of The Citizen Lab (Toronto University) found that when initiating a television conference, Zoom customers are sending requests for generating encryption keys to the server in China. On the same day, Zoom replied that this happened in connection with the peak loads and turned off the routing to China.
It should be noted that about 700 developers of Zoom are operating in China (the company has 3 legal entities registered there). According to Citizen Lab, company employees may experience pressure from Chinese special services.
How it concerns you : the greenhouse advises to be careful with Zoom to those journalists and human rights activists if threats are compiled in their models (a model of security audits and lists potential actors interested in cyber attacks), threats may proceed from China, or related state and non -state actors.
A leak of private addresses of mail and userpics at a number of postal providers. Motherboard notes that the built -in function shows the list of contacts on the basis of the mailing address domain. That is, if you have a registered address @te-st.org, you will automatically be shown users with such addresses, since the system will consider that you work on one corporate network. Together with the addresses, userpics will be shown (small images, as a rule, portraits of people) and there is an opportunity to call these people from the video.
The problem is that if for most postal services (such as Gmail, Yahoo and others), Zoom has blocked a similar function, then for postal addresses from smaller regional providers (the article mentions sufficiently niche providers XS4ALL.NL, DDS.NL, and quicknet.nl), data from completely random people will be available to users.
The emergence of such a problem is the result of not the most thoughtful design. The convenient function, which was assumed for corporate users, for mass mail services, especially from other countries (including Russia), turned into unexpected consequences. It is hoped that this vulnerability will be corrected. In the meantime, we advise all users to check the registered address and, if possible, or replace it with corporate or @gmail.com.
How it concerns you: you have mail on the not -known postal server: @yandex.by, @yandex.kz, @citydom.ru, @Starlink.ru. Probably in the near future this will also be repaired.
Two incidents with Apple and Facebook were eliminated in a timely manner. The incident, when Zoom “transmitted Facebook data”, occurred in connection with the use of the original Facebook SDK development package to implement the “Facebook” function. Zoom developers came to the conclusion that Facebook took too many excess data.
How it concerns you: nothing. This has already been repaired.
The question is zoombombing. Meduza writes : “If you forgot to put the password on your session in this messenger, hackers can invade it and arrange a full mess - for example, send a pornographic video to a common chat.” Since April 5, 2020, Zoom included passwords for all the default meetings.
How it concerns you: nothing. This has already been repaired.
Zoom has the AttendEe Tracking function, which allows the administrator to see which users have the Zoom window is not in the open state. However, this function is difficult to perceive as a threat to security.
How it concerns you: if this function is turned on, then it will not be possible to lock on the call.
Thousands of Zoom records were in the public domain . As we have already noted, the video can only be recorded at the request of users. The essence of this vulnerability is that Zoom used the same pattern in the names of the recorded videos that were the users themselves shaved (that is, converted into the 'public' - “available for everyone”). As a result of the fact that the video is called approximately the same, it was not difficult for digital security enthusiasts to gain access to a large number of records.
We believe that it is serious, but by eliminating vulnerability.
How it concerns you: if you recorded a video in the Zoom cloud (the option is not available for free accounts) and shaved it on the third side.
Until this vulnerability has been repaired, we recommend that you turn all your entries into closed mode. And recall the principle: "The best way to protect your data is not to record it."
Citizen Lab researchers have revealed that Zoom uses the Aes-256 encryption algorithm not declared in official documents, and AES-128 in the electronic code book mode (simple replacement mode). On April 3, 2020, the Executive Director admitted that the company could make an encryption design better and promised to rectify the situation.
As it concerns you : while the promised changes in encryption have not been made, the greenhouse recommends to refrain from using ZOOM for especially sensitive/secret conversations to human rights activists and journalists. In cases of exchange of particularly sensitive information, the greenhouse advises using Signal. In cases of webinars, conferences, group calls without transmitting important or sensitive information, Zoom does not carry significant risks.
Be careful and always be critical of the digital tools and services that you use. Only with the help of constant attention can we keep these services accountable and truly safe. When analyzing reliability, long -term factors that affect the safety of the service should be taken into account.
Why does it seem to us that Zoom should not be written off.
It is necessary to take into account a number of system risks: