info@josefelgueroso.com
2021-09-23
Zoom, a provider of videoconferencing services, has agreed to pay 85 million dollars to settle a lawsuit concerning its security claims and practices. Earlier this year, it reached a settlement with the US Federal Trade Commission, which had alleged that Zoom made misleading statements about the security and privacy of its services. This article summarizes the plaintiffs' claims in the lawsuit and the company's settlement with the Commission.
Zoom is a provider of videoconferencing services that have become widely used during the pandemic. Users can schedule and host a Zoom meeting by creating a Zoom account and downloading Zoom's application, available for Windows, Mac, iOS, and Android.
Zoom collects user information, such as names, email addresses, and date of birth, and information about users' devices, network, and connection. If the user has a paid subscription, Zoom collects the billing address and the payment information.
In addition, Zoom collects certain information shared during Zoom meetings, such as recorded meetings that users store on the company's cloud service, chat messages, and files.
The information that users share during Zoom meetings often includes sensitive information, such as health, financial, and business information.
11 individuals and two churches, on behalf of themselves and the supposed class of all Zoom users in the United States, sued Zoom in a federal court in California. The plaintiffs were Zoom users who alleged that (1) Zoom had shared the plaintiffs' personal information with third parties (including Facebook, Google, and LinkedIn) without the plaintiffs' permission, (2) Zoom had falsely claimed that its services were secured by end-to-end encryption, and (3) Zoom had failed to prevent the unauthorized joining of Zoom meetings by intruders who displayed child pornography and used racist language.
The lawsuit was based on the following:
Zoom filed a motion to dismiss, and the judge dismissed the claims related to Zoom meeting intrusions if they relied on the harmfulness of the intruders' content or were based on Zoom's status as the speaker of that content. The judge also dismissed the claims that were based on invasion of privacy, negligence, California's Comprehensive Data Access and Fraud Act, California's Unfair Competition Law, and fraudulent concealment. The judge, however, granted the plaintiffs' permission to amend their complaint to correct deficiencies related to the dismissed claims.
Under the settlement, Zoom agreed to pay 85 million dollars and take steps to prevent intruders from joining Zoom meetings. In addition, Zoom will train its employees on privacy and security.
The Commission alleged that Zoom had deceptively misrepresented its security measures and that it had circumvented a security measure adopted by Apple.
Deceptive Representation Regarding End-to-End Encryption
In various blog posts, Zoom had indicated that the security of its services was a reason to use it. In particular, it had mentioned end-to-end encryption as one of the reasons for its growth.
End-to-end encryption protects communications by ensuring that only the participants have the cryptographic keys to decrypt the communication. No person other than the sender or the recipient can read or modify the communication.
The Commission alleged that since 2016 Zoom had asserted in various materials (including its website and its security guides) that it offered end-to-end encryption to secure the communications between users during Zoom videoconferences. In a 2019 white paper, Zoom indicated that it offered end-to-end encryption for Zoom meetings, webinars, and chat sessions; it added that end-to-end encryption meant that the communications could only be decrypted by "authenticated participants who have the key required for decryption." Zoom also made similar statements in response to questions from users or potential users of its services.
The Commission alleged that, in fact, Zoom did not provide end-to-end encryption for Zoom meetings (except for Zoom's Connecter product, which is hosted on a customer's own servers). According to the Commission, Zoom's servers retained the cryptographic keys that allowed Zoom to access the contents of its users' meetings.
Deceptive Representations Regarding the Level of Encryption
The Commission alleged that since 2017, Zoom had indicated in various materials (including blog posts, security guides, and in direct communications with users or potential users) that it offered Advanced Encryption Standard (AES) 256-bit encryption to secure Zoom meetings. "256-bit" refers to the length of the key (often a string of numbers or letters) required to decrypt the communication: a longer key offers more security, because a potential attacker would have to try more possible keys before finding the correct one.
The Commission alleged that, in fact, Zoom used AES 128-bit encryption to secure Zoom meetings. This provided less security for Zoom meetings, because attackers would have to try fewer possible keys.
Deceptive Representations Regarding Secured Cloud Storage for Zoom Meetings
The Commission alleged that in its security guide Zoom had claimed that recordings of Zoom meetings were stored encrypted in its cloud service once the meeting ended.
In fact, according to the Commission, Zoom kept recorded meetings unencrypted up to 60 days before being transferred to secure storage, where they were then encrypted.
Unfair Circumvention of Apple's Privacy and Security Safeguard
In 2018, Apple updated its Safari browser to protect its users from malware. The update required users to interact with a dialogue box if a website or link attempted to launch an outside application. According to the Commission, Zoom updated its app for Mac desktop computers to secretly deploy a web server called "ZoomOpener" to bypass Apple's new security safeguard. The Commission alleged that consumers received no notice about the ZoomOpener web server and had no opportunity to consent to its deployment.
The Commission alleged that the ZoomOpener web server for Mac computers harmed consumers by limiting Apple's security measures. In addition, the Commission alleged that the ZoomOpener web server introduced two security vulnerabilities. First, the ZoomOpener web server allowed the download and installation of software without checking whether the software originated from a trusted source. Second, the ZoomOpener web server exposed users to local denial of service attack, because a hacker could send continuous requests to join a meeting, making the target computer inaccessible.
Corrective Measures
The Commission ordered Zoom to implement corrective measures under a plan that will be in effect for 20 years.
The corrective measures include the following:
Zoom reaches $85M settlement in ‘Zoombombing’ lawsuit, (TechCrunch, 2021-08-02)
Order Granting in Part and Dismissing in Part Zoom's Motion to Dismiss (Federal District Court for the Northern District of California, 2021)
Zoom Complaint (Federal Trade Commission)
Zoom Decision and Order (Federal Trade Commission)
Security Now 769, Zoom's E2EE Design, 2020-06-02 (the segment about Zoom begins at 01:39:23)
Key (cryptography) (Wikipedia)
End-to-End Encryption (Wikipedia)