News: 1627882143

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Zoom agrees to pay subscribers $25 to put its security SNAFUs behind it

(2021/08/02)


US-based Zoom users may have a little cash coming their way after the video meeting outfit lodged a preliminary settlement in a class action related to some of its less-than-brilliant security and data protection practices.

The settlement was filed Saturday in an attempt to end a class action that alleged Zoom indulged in unlawful activities – including misrepresenting its end-to-end encryption capabilities and unauthorized transfer of personal data to third parties like Facebook, Google and LinkedIn – as well as implementing grossly inadequate security and privacy controls.

The latter led to " [1]Zoombombing " – a distinctly 2020 term describing the hijacking of Zoom meetings, typically to display offensive material or otherwise disrupt people going about their business.

[2]

According to the [3]court document [PDF], the settlement establishes a non-reversionary cash fund of US$85 million to pay claims and fees. Zoom collected approximately $1.3 billion from US subscribers, and the settlement amount represents around six per cent of the total revenues collected based on allegedly unlawful activities.

[4]

[5]

That translates to a 15 per cent refund on core subscriptions, or $25 for more expensive subscriptions. Users without subscriptions stand to take home $15. Legal fees are expected to be US$21.25 million.

The deal requires approval from US District Judge Lucy Koh (who incidentally also presided over one of Apple and Samsung's [6]many court battles ), before it is finalised. Another hearing is scheduled for October 21, 2021.

[7]What is your greatest weakness? The definitive list of the many kinds of interviewer you will meet in Hell

[8]Oracle and AWS trumpeted how their clouds helped Zoom scale. But it turns out Zoom fears its cloud bills and uses co-located kit

[9]Zoom finally adds end-to-end encryption for all, for free – though there are caveats

In addition coughing up cash, Zoom has promised to improve its security, privacy and data measures. It aims to introduce features like in-meeting notifications on who can see, save and share information, privacy statements that disclose the software's sharing of data with third parties, and keeping records of meeting disruptions that involve illegal content. As a part of the settlement, Facebook has been asked to delete any US user data obtained from Zoom's software development kit.

The San Jose-based communications company denied wrongdoing and, at least when it came to Zoombombing, Judge Koh mostly agreed. Section 230 of the Federal Communications Decency Act provides immunity for web site platforms from third-party content. The court concluded that the "bulk of Plaintiffs' Zoombombing claims lie against the 'Zoombombers' who shared heinous content, not Zoom itself. Zoom merely '‘provid[ed] neutral tools for navigating' its service."

[10]

The company released a statement over the weekend, declaring "The privacy and security of our users are top priorities for Zoom, and we take seriously the trust our users place in us."

The Register has reached out to Zoom, but at the time of posting had not heard a reply.

If approved, aggrieved users will be able to apply for their $25 at the not-yet functioning settlement web site [11]www.ZoomMeetingsClassAction.com . ®

Get our [12]Tech Resources



[1] https://www.theregister.com/2020/09/10/zoombombing_attacks_texas/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YQfCXq9Qth@KCNlvtA9ePQAAAMA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://regmedia.co.uk/2021/08/02/zoom_settlement_offer.pdf

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQfCXq9Qth@KCNlvtA9ePQAAAMA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YQfCXq9Qth@KCNlvtA9ePQAAAMA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2017/10/26/apple_and_samsung_new_damages_trial/

[7] https://www.theregister.com/2021/07/26/types_of_interviewer_feature/

[8] https://www.theregister.com/2021/01/13/zoom_prospectus_reveals_colo_infrastructure/

[9] https://www.theregister.com/2020/10/27/zoom_endtoend_encryption/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQfCXq9Qth@KCNlvtA9ePQAAAMA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] http://www.ZoomMeetingsClassAction.com

[12] https://whitepapers.theregister.com/



Sure you do

thinking ape

>>>The company released a statement over the weekend, declaring "The privacy and security of our users are top priorities for Zoom, and we take seriously the trust our users place in us."

No you didn't. If you did then this total fail wouldn't have happened.

Seems like a small fine for being totally dishonest.

They grew their user base, made a ton of money, this is just a bit of tax on it. Until companies get ravaged by fines, they are hardly going to do anything about it

End of the day most people just don't care so much it seems, or have little choice (the network effect).

Re: Sure you do

grsbanks

I agree. They knew exactly what they were doing.

Promising to improve privacy does not make them trustworthy all of a sudden. Someone over at Zoom thought it was a good idea to sell their users' personal details without disclosing it. How do we know that person and mindset are no longer there?

Re: Sure you do

Roland6

>They knew exactly what they were doing.

The reports indicate Zoom used the SDK's from Facebook and others to implement the "Login with xyz social network" functionality, rather than anything more sinister. I suspect they probably even used the SDK with the SDK providers defaults (probably set to collect lots that might be useful to the social network).

Obviously, there is a big takeaway here for developers incorporating third-party integrations using the third-party provided SDK to double-check both the personal information the SDK collects (is it necessary and sufficient to allow your app to work) and what your app is telling users about it's data sharing.

Bottom line: If you have a FB account and on a non-FB app, such as Zoom, you decide to use the "Login with FB" option then it is obvious some of your Zoom data will be passed to FB (and potentially vice versa - many app's will read your social network contacts).

meetings, n.:
A place where minutes are kept and hours are lost.