Security News

Zoom Takes on Zoom-Bombers Following FTC Settlement
2020-11-17 17:18

The "Suspend Participant Activities" feature is enabled by default for all free and paid Zoom users; and, meeting participants can also report a disruptive user directly from the Zoom client by clicking the top-left "Security" badge. That advice includes deleting the vulnerable meeting and creating a new one with a new meeting ID, enabling security settings, or using another Zoom solution, like Zoom Video Webinars or OnZoom.

How to secure your Zoom account with two-factor authentication
2020-11-16 23:04

Follow these steps to better protect your Zoom account with a second layer of authentication. Zoom now provides an extra level of security to your account with two-factor authentication.

Zoom rolls out security enhancements to stop zoombombing trolls
2020-11-16 17:55

Zoom has announced today the rollout of new security enhancements designed to help meeting hosts to block zoombombing attempts and participants to report misbehaving users. Zoombombing happens when Zoom meetings are joined by unauthorized third parties with the goal to disrupt ongoing sessions and harass participants.

FTC orders Zoom to enhance security practices
2020-11-10 10:34

Zoom Video Communications, the maker of the popular Zoom video conferencing solution, has agreed to settle allegations made by the US Federal Trade Commission that it "Engaged in a series of deceptive and unfair practices that undermined the security of its users." The settlement requires Zoom to - among other things - establish and implement a comprehensive security program and to not engage in further privacy and security misrepresentations.

Zoom strong-armed by US watchdog to beef up security after boasting of end-to-end encryption that didn't exist
2020-11-09 21:03

Zoom has been forced to agree to a range of security improvements in a settlement with America's consumer watchdog, the Federal Trade Commission, as a result of earlier wrongly claiming it offered true 256-bit end-to-end encryption. The pact [PDF], announced Monday, obliges the video-conferencing giant to carry out an annual security assessment of its software and have its internal security program assessed by a third-party every two years.

FTC Says Zoom Misled Users on Its Security for Meetings
2020-11-09 18:12

Federal regulators are requiring Zoom to strengthen its security in a proposed settlement of allegations that the video conferencing service misled users about its level of security for meetings. A complaint filed by the agency accused Zoom of deceiving users over security since at least 2016.

Zoom Snooping: How Body Language Can Spill Your Password
2020-11-05 20:34

You've heard of Zoom Bombing, but have you heard of Zoom Snooping? Researchers contend they can extract keystroke data from participants in a video call simply by tracking shoulder movements. "Being security/privacy researchers, and heavy users of such applications ourselves, we wondered what non-obvious private information one can infer by being on the other end of such call/conference videos." Jadliwala told Threatpost by email.

Zoom finally adds end-to-end encryption for all, for free – though there are caveats
2020-10-27 20:09

Zoom has finally added what it says is end-to-end encryption to its video conferencing service at no additional cost for all users, whether they are paying subscribers or not. "We're very proud to bring Zoom's new end-to-end encryption to Zoom users globally today," said Zoom CISO Jason Lee.

Zoom Rolls Out End-to-End Encryption After Setbacks
2020-10-15 15:12

Video-conferencing giant Zoom is rolling out a technical preview of its end-to-end encryption next week. Zoom has faced various controversies around its encryption policies over the past year, including several lawsuits alleging that the company falsely told users that it offers full encryption.

All Zoom users get end-to-end encryption (E2EE) option next week
2020-10-15 12:19

Starting next week, Zoom users - both those who are on one of the paid plans and those who use it for free - will be able to try out the solution's new end-to-end encryption option. Must join from the Zoom desktop client, mobile app, or Zoom Rooms.