Zoom iOS Fixes
Zoom is no stranger to controversy. For example,just last year, they were forced to fix a vulnerability found withing their app that allowed websites to hijack users' webcams, forcing the user to join a Zoom call with no permission needed.Other Zoom Privacy Concerns
And there are other privacy concerns, as well... So much so that they have been called not only a "privacy disaster" but also "fundamentally corrupt" by various security experts for:Participant Surveillance
Currently, Zoom hosts are able to see if participants have their Zoom video window active, meaning they can track whether the participants are paying attention or not, and Administrators are also able to view participants' IP addresses, location data, and device information.Lack of Encryption
Zoom literally lied about this by saying they did use end-to-end encryption, which should secure communication to the point where only users have access to it, but research conducted by Intercept found that to be a complete fabrication. Zoom "clarified" this past Wednesday in a blog post, whereby stating that they don't use end-to-end encryption because it isn't possible on their platform. They they so kindly apologized for any of the confusion that may have been when they "incorrectly" stated they could. Not good! We aren't going to tell you not to use Zoom, because that would be hypocritical of us, considering we use it, as well. But there are steps you can take to safeguard yourself from these violations of privacy:- Make sure you keep your apps up-to-date in order patch any potential holes in security.
- Be vigilant when opening any emails or downloading anything sent from unknown addresses and seemingly legitimate domains that contain spelling errors.
- NEVER open unknown attachments!!
- NEVER click on promotional links in emails, and remember... the cure for Covid-19 is not going to magically appear in your inbox.
- ONLY order your goods and services from authentic sources.
- Do not make meetings or classrooms public. In Zoom, there are two options to make a meeting private: require a meeting password or use the waiting room feature and control the admittance of guests.
- Do not share a link to a teleconference or classroom on an unrestricted publicly available social media post. Provide the link directly to specific people.
- Manage screensharing options. In Zoom, change screensharing to “Host Only.”
- Ensure users are using the updated version of remote access/meeting applications. In January 2020, Zoom updated their software. In their security update, the teleconference software provider added passwords by default for meetings and disabled the ability to randomly scan for meetings to join.
- Lastly, ensure that your organization’s teleworking policy or guide addresses requirements for physical and information security.
The recent, staggering increase means that hackers have taken notice of the work-from-home paradigm shift that COVID-19 has forced, and they see it as an opportunity to deceive, lure, and exploit. Each time you get a Zoom link or document messaged or forwarded to you, I'd take an extra look to make sure it's not a trap.Please don't forget... Bad actors don't care about you, your health, or the welfare of anyone in the world. We here at Petronella Technology Group offer state-of-the-are cyber security training to help keep you and your staff safe while they are working from home. Call us 919-348-4912 if you have any questions. You can also schedule a free consultation by clicking here. You can also download our FREE Remote Security Checklist, which provides you with simple instructions on adding layers of security to your home office. And most importantly, stay safe out there.
Free, practical, and specific to regulated environments. We will email it to you.
No spam. Unsubscribe anytime.