FTC finalizes settlement with Zoom

Digital lock with the Zoom logo

The Federal Trade Commission (FTC) has finalized its settlement with video conferencing company Zoom, threatening strict penalties if the service fails to uphold government-mandated security requirements.

The FTC investigated Zoom last year and complained that it had misled users by claiming to offer end-to-end 256-bit encryption, when it actually maintained the encryption keys. The company also stored unencrypted meeting data on its servers for up to 60 days before moving it to secure cloud storage, the complaint said.

The FTC also alleged Zoom secretly installed software bypassing anti-malware protections for Mac users and left it there, even after users deleted the Zoom app.

Zoom originally settled with the FTC in November 2020, which required the company to tighten its security controls. It still had to publish a description of the consent agreement package in the Federal Register and allow 30 days for public comment, after which it was allowed to issue the final order.

The order forbids Zoom from misrepresenting the service's security features or controls. It also mandates an information security program, under which the company puts safeguards in place to protect individuals' data, which it calls Covered Information.

If a data breach occurs, Zoom must assess any risks to data security that it caused. It must implement a security review of any new meeting services or updates to existing ones and conduct a quarterly vulnerability scan.

The company must also use a range of technical protections to shield user data from snoopers. These include a randomized naming system when saving video recordings on users' local devices, strong password authentication, and the use of automated tools and rate-limiting to detect bots and brute-force attacks.

The final order also makes direct reference to data encryption, calling for "protections, such as encryption, tokenization, or other same or greater protections, for Covered Information collected, maintained, processed, or stored by Respondent, including in transit and at rest."

The lack of end-to-end encryption was especially worrying given Zoom routes some information through Chinese servers, which the University of Toronto's Citizen Lab revealed in a report on the company's security practices. Zoom suspended three user accounts for hosting meetings on topics disagreeable to the Chinese government.

Zoom has already begun making some changes. The company bowed to pressure from privacy activists in June 2020, announcing it would offer end-to-end encryption to all users, not just paying ones. It began offering that feature in a technical preview last October.

If Zoom violates this final consent order, each violation could incur up to a $43,280 civil penalty, the FTC warned in its original settlement announcement.

Danny Bradbury

Danny Bradbury has been a print journalist specialising in technology since 1989 and a freelance writer since 1994. He has written for national publications on both sides of the Atlantic and has won awards for his investigative cybersecurity journalism work and his arts and culture writing. 

Danny writes about many different technology issues for audiences ranging from consumers through to software developers and CIOs. He also ghostwrites articles for many C-suite business executives in the technology sector and has worked as a presenter for multiple webinars and podcasts.