FTC finalizes settlement with Zoom

Failure to comply could bring financial penalties

Digital lock with the Zoom logo

The Federal Trade Commission (FTC) has finalized its settlement with video conferencing company Zoom, threatening strict penalties if the service fails to uphold government-mandated security requirements.

The FTC investigated Zoom last year and complained that it had misled users by claiming to offer end-to-end 256-bit encryption, when it actually maintained the encryption keys. The company also stored unencrypted meeting data on its servers for up to 60 days before moving it to secure cloud storage, the complaint said.

The FTC also alleged Zoom secretly installed software bypassing anti-malware protections for Mac users and left it there, even after users deleted the Zoom app.

Zoom originally settled with the FTC in November 2020, which required the company to tighten its security controls. It still had to publish a description of the consent agreement package in the Federal Register and allow 30 days for public comment, after which it was allowed to issue the final order.

The order forbids Zoom from misrepresenting the service's security features or controls. It also mandates an information security program, under which the company puts safeguards in place to protect individuals' data, which it calls Covered Information. 

If a data breach occurs, Zoom must assess any risks to data security that it caused. It must implement a security review of any new meeting services or updates to existing ones and conduct a quarterly vulnerability scan.

The company must also use a range of technical protections to shield user data from snoopers. These include a randomized naming system when saving video recordings on users' local devices, strong password authentication, and the use of automated tools and rate-limiting to detect bots and brute-force attacks.

The final order also makes direct reference to data encryption, calling for "protections, such as encryption, tokenization, or other same or greater protections, for Covered Information collected, maintained, processed, or stored by Respondent, including in transit and at rest."

The lack of end-to-end encryption was especially worrying given Zoom routes some information through Chinese servers, which the University of Toronto's Citizen Lab revealed in a report on the company's security practices. Zoom suspended three user accounts for hosting meetings on topics disagreeable to the Chinese government.

Zoom has already begun making some changes. The company bowed to pressure from privacy activists in June 2020, announcing it would offer end-to-end encryption to all users, not just paying ones. It began offering that feature in a technical preview last October.

If Zoom violates this final consent order, each violation could incur up to a $43,280 civil penalty, the FTC warned in its original settlement announcement.

Featured Resources

How to scale your organisation in the cloud

How to overcome common scaling challenges and choose the right scalable cloud service

Download now

The people factor: A critical ingredient for intelligent communications

How to improve communication within your business

Download now

Future of video conferencing

Optimising video conferencing features to achieve business goals

Download now

Improving cyber security for remote working

13 recommendations for security from any location

Download now

Recommended

Senators question the privacy of cameras in Amazon delivery vans
privacy

Senators question the privacy of cameras in Amazon delivery vans

4 Mar 2021
CISA orders agencies to fix Microsoft vulnerabilities abused by Chinese hackers
Security

CISA orders agencies to fix Microsoft vulnerabilities abused by Chinese hackers

4 Mar 2021
US "unprepared" to defend against AI threats
artificial intelligence (AI)

US "unprepared" to defend against AI threats

2 Mar 2021
Lawmakers signal changes for big tech in antitrust hearings
Policy & legislation

Lawmakers signal changes for big tech in antitrust hearings

26 Feb 2021

Most Popular

How to build a CMS with React and Google Sheets
content management system (CMS)

How to build a CMS with React and Google Sheets

24 Feb 2021
Microsoft Exchange targeted by China-linked hackers
zero-day exploit

Microsoft Exchange targeted by China-linked hackers

3 Mar 2021
How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

26 Feb 2021