A Look into the Privacy Concerns Associated with Zoom

By Brandon Arias

As social distancing measures were implemented throughout the world following the emergence of the Coronavirus pandemic, global demand for a method of remote communication helped Zoom become the most popular videoconferencing service on the market.[1] With the app’s user friendly design, free use for 40 minute meeting intervals, and customers ranging from some of the largest financial services in the world to universities, it is unsurprising that Zoom has become the most common platform for virtual meetings, instruction, and socialization.[2] The platform’s surge in popularity however brought critical scrutiny regarding its security and privacy measures. [3]

Recently, one of the company’s shareholders filed a class action lawsuit alleging that Zoom “failed to disclose issues with its video conferencing platform’s privacy and security”.[4] Zoom is also currently facing a lawsuit seeking declaration that the company violated the California Consumer Privacy Act, which protects consumer data from “unauthorized access and exfiltration, theft or disclosure as a result of the business’ violation of the duty to implement and maintain reasonable security procedures and practices”.[5] The company has been sending user data to Facebook and potentially other third parties, and the suit in question alleges that the company has been doing so without mentioning the practice in their privacy policy.[6] If this claim is true, then the company may have engaged in unauthorized disclosure of their user’s personal information.[7] Zoom discontinued this practice shorty after its existence was made public.[8]

 

To make matters even more concerning, the same company under scrutiny for potential failure to disclose information to both shareholders and users has also been criticized for possibly misrepresenting the platform’s features. Zoom previously claimed on its website that its meetings are supported by end-to-end encryption, which is typically understood as a feature that protects content between users from the company and all outside parties.[9] However when questioned whether meetings are end-to-end encrypted by The Intercept, a company spokesperson replied stating that “Currently, it is not possible to enable [end-to-end] encryption for Zoom video meetings”.[10] Zoom describes their end-to-end encryption method as one involving transport encryption, where the company has access to the encrypted meeting content between users, but lacks the ability to decrypt said content.[11] While Zoom claims that their use of the phrase is not dishonest or misleading, their level of encryption still grants the company access user video meetings which they may be required to hand over upon legal request by law enforcement.[12]

While Zoom has apologized, announced that it will no longer send data to Facebook, and is currently developing proper end-to-end encryption, these legal concerns have already impacted the platforms hundreds of millions of users.[13] Only time will tell if users are able to prove Zoom’s invasion of their privacy, but until then it seems as though many people must continue to conduct their business, education, and socialization in this fashion until the pandemic is over.

 

[1] See Jane Wakefield, Coronavirus: Zoom is in Everyone’s Living Room- How Safe is it?, BBC News (Mar. 27, 2020),  https://www.bbc.com/news/technology-52033217.

[2]  See id.

[3] See id.

[4] Ryan Browne, Zoom Faces Investor Lawsuit Over Privacy and Security Flaws, CNBC, (Apr. 8, 2020, 8:04 AM EDT), https://www.cnbc.com/2020/04/08/zoom-faces-investor-lawsuit-over-privacy-and-security-flaws.html.

[5] Molly Stubbs, Zoom Faces Multiple Class Action Lawsuits Over Privacy Complaints, Expert Institute, https://www.expertinstitute.com/resources/insights/zoom-video-faces-multiple-class-action-suits-over-privacy-complaints/ (last updated Jun. 25, 2020).

[6] Joel Rosenblatt, Zoom Sued for Allegedly Illegally Disclosing Personal Data, Bloomberg (Mar. 30, 2020, 8:39 PM EDT), https://www.bloomberg.com/news/articles/2020-03-31/zoom-sued-for-allegedly-illegally-disclosing-personal-data.

[7] Id.

[8] Id.

[9] Monica Chin, Zoom Isn’t Actually End-to-end Encrypted, The Verge (Mar. 31, 2020, 2:12 PM EDT), https://www.theverge.com/2020/3/31/21201234/zoom-end-to-end-encryption-video-chats-meetings.

[10] Micah Lee & Yael Grauer, Zoom Meetings Arent End-to-End Encrypted, Despite Misleading Marketing, The Intercept (Mar. 31, 2020, 4:00 AM), https://theintercept.com/2020/03/31/zoom-meeting-encryption/.

[11] Id.

[12] Id.

[13] See Tom Warren, Zoom Faces a Privacy and Security Backlash as it Surges in Popularity, The Verge (Apr. 1, 2020, 8:00 AM EDT), https://www.theverge.com/2020/4/1/21202584/zoom-security-privacy-issues-video-conferencing-software-coronavirus-demand-response.