PSA: Zoom Is Dangerous and You Shouldn’t Use It
I don't write articles on subjects where I feel like I wouldn’t truly be adding something to the conversation, and this is a case where I considered not writing this piece. It has already been covered more thoroughly than I am capable of doing here, but I felt it was still worthwhile to reiterate what others have exposed and warn the public of the dangers Zoom presents.
Most people didn’t know too much about Zoom before the pandemic started and hoards of people were suddenly tasked with finding a way to perform their jobs from home. Now, Zoom is a household name, and millions of people are being herded into their user base like swine into a slaughterhouse. Personally, I’ve never used Zoom: I rarely have the need to video conference with more than one person, and in instances where I have needed to, Group FaceTime was more than sufficient. Based on Zoom’s reputation and their habit of completely abusing their users, I would never use their services, and in fact, I think they’re such a malignant company that I’m taking the time to warn CopyrightBro readers.
Last summer, news broke that quickly turned into a scandal, when it was revealed that Zoom was flagrantly abusing users’ trust by having their app automatically reinstall itself after it had been deleted by the user, and then go on to start a Zoom call (with the webcam and microphone enabled) to any website that knew this “feature” existed and wanted to take advantage of it. This was the instance that made me distrust Zoom, and again, this was nearly a year ago.
Now, even more evidence has come out illustrating just how low user security and privacy rank on Zoom’s list of priorities.
Last week, Motherboard reported that Zoom was using software development kits (SDKs) created by Facebook that sends Zoom users’ personal data to Facebook, regardless of whether those Zoom users also had Facebook accounts. They have since removed this SDK, but the fact that it was used in the first place is cause for concern.
A few days later, The Intercept reported that Zoom was flat out lying about how Zoom meetings are encrypted and trying to pass it off as a marketing miscommunication. As John Gruber notes on Daring Fireball, the phrase "end-to-end encryption” is not open to interpretation. What Zoom was actually using is called transport encryption, and it is not as secure. Lying about how secure your platform is will certainly lead to trouble for users. It’s unethical and gross to use false claims of strong encryption for marketing.
Yesterday, Motherboard reported another issue that allowed Zoom users’ personal email addresses and photos to be leaked to complete strangers.
This is a staggering list of major privacy and security concerns for one company to deal with in a year, much less in a week. If your organization is asking you to use Zoom, you should forcefully object and tell them that you don’t agree with their privacy policy (which is a joke). If video conferencing is a must for you, suggest an alternative like Group FaceTime (check out this list from The Verge for some more options). If you absolutely cannot refuse to use Zoom, follow John Gruber’s advice and only use it on an iOS device, where Apple’s sandboxing will protect you more than any other platform is capable of doing. If you don’t use an Apple device, here’s another reason to consider switching.