How To Actually Think About Zoom

Zoom, which everyone here uses.
I keep hearing “isn’t there a bunch of security problems being said about it!?” and getting asked about it too. So I’m writing this.
By the way, professionals have already written up detailed accounts of the various issues. For example, here’s one. https://www.itmedia.co.jp/business/articles/2004/22/news026.html
https://wired.jp/2020/04/21/keep-zoom-chats-private-secure/
So in this post I’ll write about my own take on how to personally deal with this kind of problem. In an era where software gets updated daily, there’s not much point in someone who isn’t a professional writer chasing the latest fine-grained information. That’s exactly the kind of thing you should just go Google.
That said, since I’m using Zoom as my example, I’ll go over a few specific circumstances first. Concrete before abstract, so to speak.
By the way, I’m not a cybersecurity expert, so don’t take everything here at face value.
First of all, security problems need to be understood by splitting them into several stages. Lump them together and no real discussion can happen.
- Content at the level of an outrageous design mistake that must be fixed
- Content that’s close to a cat-and-mouse game with skillful hackers
- Content at the level of literacy that people living in the modern age should just watch out for themselves
Watching the articles and exchanges circulating online, I’ve noticed that several things I thought “that’s surely not okay” about have already been fixed in the latest version. In fact, it seems like they fixed things the moment they got called out. Specifically, for example:
- If you installed the Zoom app and left it running in the background, it would keep a web server running on its own without you knowing
- Some portion of the data (not sure how much) was routed through servers in China
- User data was being sent to Facebook without consent
Those are the kinds of things. I was relieved these got fixed.
Given this series of events, there are surely people who say “I will never again use a tool from a company that makes such fatal mistakes!” And conversely there are surely people who say “They fixed it right away and acted in good faith, well done!” This isn’t about having high or low security awareness — it’s a difference in values. For what it’s worth, I’m in the latter camp. Probably because I know extremely well how hard it is to build a product or launch a business.
To say this in a somewhat after-the-fact way, I actually wasn’t using Zoom to begin with. A few years ago an investor in the Bay Area recommended it to me and I tried it, but I felt resistance at the stage of “installing an app,” so I used it once and then uninstalled it. Whether you call the concerns exactly what I expected or call them no surprise, either way I didn’t find the story all that shocking. But since they fixed it immediately, my gut reaction was more like “hey, not bad.” That’s all this means to me.
Design mistakes happen. People who can’t tolerate that have no choice but to shut themselves away and use nothing at all. Driving somewhere is a risk, and taking a walk on the beach is a risk too (it’s very easy to say that in this day and age). That’s just how it is.
Now, skipping over point 2 for a moment, on point 3: Zoom recently introduced passwords, but even that is meaningless if handled by someone with low literacy (the password just leaks along with everything else). So frankly, worrying about point 3 in general is pretty much a waste of effort. To begin with, it’s a bit embarrassing, in this day and age, for someone who can’t even manage this much to go around saying “Zoom’s security is…” We’ve reached a point where you can’t live (comfortably) without handling minimum security yourself. I was impressed to notice that the word “infodemic” has recently come into use, but can you hold the operator of an SNS platform responsible for people being swayed by misinformation on that platform? If you got infected with a virus while browsing an illegal porn site, would you demand that the browser developer do something about it? It’s been over 20 years since the term “internet literacy” started being used, and the tug-of-war between how fast the times change and how fast literacy takes root is still ongoing. On one point — that anyone who obtains an ID and password can enter a meeting — Zoom has actually responded quite generously, creating a “waiting room.” I think that’s admirable. If it were me, I might have just ignored that kind of complaint. Something like, “Protect yourself. If you don’t like it, don’t use it.”
As for point 2, you could say Zoom volunteered to take on the “discovery of pitfalls” that gets talked about in the world of startups and new businesses. Well, more by circumstance than by choice. Security problems constantly arise at Google, Facebook, and Amazon too, and developers everywhere use that information to build countermeasures into their own tools. Sometimes one company’s failure becomes a huge lesson for everyone around it. That’s how society keeps turning. Unless someone plays the cat-and-mouse game with hackers, the level of security never rises. And even so, if someone says “I don’t want to use a dangerous tool that’s being targeted by hackers,” you can just ask them, “So you don’t use Google, Facebook, or Amazon either?” — and they’re probably using all of them normally.
Try looking at a site like this; it’s genuinely interesting.
List of personal information leak incidents and cases of damage https://cybersecurity-jp.com/leakage-of-personal-information
You can see that a mountain of security incidents happens every single year. Do we dutifully and properly react to every single one of these, with boycotts or protests? No. In other words, this is an everyday occurrence. Overreacting only to this particular Zoom case doesn’t seem like a very fair stance.
In other words, it’s just being criticized at this particular moment, and this is probably just growing pains on the way to eventually becoming infrastructure for everyone. It reminds me of leaving the care of your teenage son to a butler and a housekeeper, only to have him take over from you once he’s grown — a “harvesting” kind of stance that, as I recall, wasn’t well liked in the very village-society-like Bay Area (which is why I think I’ll go along with it as much as I can). That said, for ordinary people, this is certainly a scene where “it’s okay to run away.” I suppose that just makes me the odd one out.
But importantly, other services all have similarly murky problems of their own anyway. And tools locked down tight on security end up being a pain to use. In that sense too, I personally think there’s a very high chance that Zoom, having overcome its current troubles and grown from them, will end up being the tool that’s both the easiest to use and the safest.
Originally published in Japanese at https://clazytech.com/2020/04/357/. Translated with LLM assistance and reviewed before publication.