FTC finalizes settlement with Zoom

Failure to comply could bring financial penalties

Digital lock with the Zoom logo

The Federal Trade Commission (FTC) has finalized its settlement with video conferencing company Zoom, threatening strict penalties if the service fails to uphold government-mandated security requirements.

The FTC investigated Zoom last year and complained that it had misled users by claiming to offer end-to-end 256-bit encryption, when it actually maintained the encryption keys. The company also stored unencrypted meeting data on its servers for up to 60 days before moving it to secure cloud storage, the complaint said.

The FTC also alleged Zoom secretly installed software bypassing anti-malware protections for Mac users and left it there, even after users deleted the Zoom app.

Zoom originally settled with the FTC in November 2020, which required the company to tighten its security controls. It still had to publish a description of the consent agreement package in the Federal Register and allow 30 days for public comment, after which it was allowed to issue the final order.

The order forbids Zoom from misrepresenting the service's security features or controls. It also mandates an information security program, under which the company puts safeguards in place to protect individuals' data, which it calls Covered Information. 

If a data breach occurs, Zoom must assess any risks to data security that it caused. It must implement a security review of any new meeting services or updates to existing ones and conduct a quarterly vulnerability scan.

The company must also use a range of technical protections to shield user data from snoopers. These include a randomized naming system when saving video recordings on users' local devices, strong password authentication, and the use of automated tools and rate-limiting to detect bots and brute-force attacks.

The final order also makes direct reference to data encryption, calling for "protections, such as encryption, tokenization, or other same or greater protections, for Covered Information collected, maintained, processed, or stored by Respondent, including in transit and at rest."

The lack of end-to-end encryption was especially worrying given Zoom routes some information through Chinese servers, which the University of Toronto's Citizen Lab revealed in a report on the company's security practices. Zoom suspended three user accounts for hosting meetings on topics disagreeable to the Chinese government.

Zoom has already begun making some changes. The company bowed to pressure from privacy activists in June 2020, announcing it would offer end-to-end encryption to all users, not just paying ones. It began offering that feature in a technical preview last October.

If Zoom violates this final consent order, each violation could incur up to a $43,280 civil penalty, the FTC warned in its original settlement announcement.

Featured Resources

Consumer choice and the payment experience

A software provider's guide to getting, growing, and keeping customers

Download now

Prevent fraud and phishing attacks with DMARC

How to use domain-based message authentication, reporting, and conformance for email security

Download now

Business in the new economy landscape

How we coped with 2020 and looking ahead to a brighter 2021

Download now

How to increase cyber resilience within your organisation

Cyber resilience for dummies

Download now

Most Popular

How to find RAM speed, size and type

How to find RAM speed, size and type

16 Jun 2021
EU plans to launch bloc-wide cyber task force
cyber attacks

EU plans to launch bloc-wide cyber task force

22 Jun 2021
What is HTTP error 400 and how do you fix it?
Network & Internet

What is HTTP error 400 and how do you fix it?

16 Jun 2021