Clay Tech

"clay-works make things real"

translated from clazytech.com

Here's how I personally think about Zoom's security fuss

Zoom, which everyone uses.

I keep hearing “isn’t there all kinds of talk about security problems with it!?” and getting asked about it. So I’m writing this.

By the way, professionals have already written detailed accounts of the specifics elsewhere.
For example, here’s one.
https://www.itmedia.co.jp/business/articles/2004/22/news026.html

https://wired.jp/2020/04/21/keep-zoom-chats-private-secure/

So in this post I’ll write about my own stance — how I personally choose to deal with this kind of problem.
In an age when software gets updated daily, writing a post chasing the latest minute details isn’t especially useful coming from me, someone who isn’t a professional writer on this subject. That kind of thing is exactly what “please just Google it” is for.

That said, since I’ve brought up Zoom as a case study, I’ll write about a few of the specific circumstances. Something like deriving the abstract from the concrete.

By the way, I’m not a cybersecurity expert, so please don’t take everything here at face value.

Now first, security problems can be understood by dividing them into a few stages. If these get mixed together, no real discussion can happen.

  1. Content at a level of “that’s simply unacceptable design failure, it must be fixed”
  2. Content closer to a cat-and-mouse game with skillful hackers
  3. Content at the level of literacy that anyone living in the modern age ought to look after for themselves

Watching the exchanges circulating in articles and online, I recognize that several things I thought “surely that’s too far” about have already been fixed in the latest version. In fact, it seems like they got fixed the moment someone pointed them out.
Concretely, for example:

I was relieved these got fixed.

Given this string of events, there will be people who say “I will never again use a tool from a company that makes this kind of fatal mistake!” And conversely there will be people who say “They fixed it right away and acted in good faith, well done!”
This isn’t a matter of high or low security awareness — it’s a difference in values.
Incidentally, I’m in the latter camp. Probably because I know extremely well how hard it is to build a product or launch a business.

To say something with the benefit of hindsight: I wasn’t originally using Zoom. A few years ago an investor in the Bay Area recommended it to me and I tried it, but I felt resistance at the “install an app” stage, and after using it once I uninstalled it. If my concern turned out to be justified, well, that’s just how it goes, and if it was to be expected, then it was to be expected — either way I didn’t think it was all that surprising. But since they fixed it immediately, my gut reaction was more “good for them.” That’s about all this means to me.

Design mistakes happen.
Anyone who can’t tolerate that has no choice but to use nothing at all and live shut up in a shell.
Driving somewhere in a car is a risk, and taking a walk along the beach is a risk too (it’s very easy to say this in the present era).
That’s just how things are.

Now, skipping ahead to point 3 for a moment: for example, Zoom recently introduced passwords, but in the end that’s meaningless if handled by someone with low literacy (the password just leaks along with everything else). So frankly, worrying about point 3 in general terms is a waste of effort.
To begin with, it’s a little embarrassing, in this day and age, for someone who can’t even manage this properly to go around saying “Zoom’s security is…”
We’ve reached a world where you can’t get by (comfortably) without taking care of at least the minimum security yourself.
I was impressed to notice the word “infodemic” being used lately, but can you hold the operator of a social media platform responsible for the damage caused by misinformation spread on it? If you catch a virus visiting an illegal porn site, do you demand the browser developer fix that?
It feels like it’s been more than 20 years since the term “internet literacy” started being used, and the tug-of-war between the speed of the times changing and the speed at which literacy takes hold is still ongoing.
On one point — that anyone who gets hold of an ID and password can enter a meeting — Zoom has actually responded generously by creating a “waiting room.” I think that’s admirable. If it were me, I might have just ignored that kind of criticism, something like “protect yourself. If you don’t like it, don’t use it.”

As for point 2, you could say Zoom has volunteered itself as the “discoverer of pitfalls,” the kind of thing talked about in the startup and new-business world. Well, mostly by circumstance.
Google, Facebook, and Amazon constantly have security problems too, and developers everywhere use this information to build defenses into their own tools. In some cases, someone goes bankrupt and everyone around them learns a big lesson from it. That’s how society keeps turning.
Unless someone plays the cat-and-mouse game with hackers, the overall level of security never rises.
Even so, if someone says “I don’t want to use a dangerous tool that’s a target for hackers,” you can just ask back, “so you don’t use Google, Facebook, or Amazon either?” — and I think, quite ordinarily, they do.

Try looking at a site like this one, and it’s genuinely interesting.

List of Personal Information Leak Incidents and Damage Cases
https://cybersecurity-jp.com/leakage-of-personal-information

You’ll see that huge numbers of security accidents and incidents happen every single year.
Do we respond dutifully and properly to each and every one of these, with boycotts and protests?
No. In other words, this is an everyday occurrence.
Reacting excessively only to this particular Zoom case isn’t a very fair stance to take.

In other words, it’s just getting criticized at this particular moment — this is probably growing pains on the way to becoming infrastructure that everyone eventually relies on.
I sometimes think of the stance of leaving a teenage son in the care of a butler and a housekeeper, only to have him take over the family business once he comes of age — a kind of “harvesting” attitude that wasn’t well liked in the ultimate village-society that is the Bay Area (which is why I think I’ll go along with this as much as possible).
That said, it’s also true that for the average person, this is a scene where “it’s okay to run away.”
Which probably just means I’m the odd one out.

But here’s the important thing: other services probably carry similarly problematic issues of their own anyway. And tools locked down tight on security end up being a pain to use.
In that sense too, I personally think there’s a very good chance that “Zoom, having overcome its present troubles and grown from them” will end up being the most usable and safest tool of all.


Originally published in Japanese at https://clazytech.com/2020/04/357/. Translated with LLM assistance and reviewed before publication.