Tired of ads? Enjoy an ad-free experience by signing up.
  • Insights
    This article was written by a TIA community member. Insights pieces undergo the same rigorous editorial process that newsroom-produced articles have.
Kevin Reed · · 4 min read

Banning Zoom isn’t the answer to countering cyberattacks

A few weeks ago, the Singapore government decided to suspend the use of the video conferencing app Zoom after internet pranksters hijacked an online geography lesson for secondary school students. The Ministry of Education has since resumed its use with new safeguards in place for users.

“Zoombombing,” as the cyberattack trend is called, has become a real issue over the past few weeks due to Zoom’s sudden popularity, which has eclipsed Microsoft’s Skype and Teams platforms, Google’s Meet, Cisco’s Webex, Citrix’s GoToMeeting, and others.

Photo credit: Visuals

The thing is, those other platforms aren’t necessarily any more secure than Zoom, and therefore aren’t a panacea for those wishing to find an “unhackable” video conferencing service.

On March 20, Zoom CEO Eric S. Yuan published a blog post on how to keep uninvited guests out of events and meetings, and how the company was shifting its engineering resources “to focus on our biggest trust, safety, and privacy issues.”

So with the firm putting security measures in place days and weeks ago, why are breaches like Zoombombing still happening?

Issue 1: The lack of education and cyberhygiene

Each Zoom meeting uses nine to 11 digits in its meeting ID, so attackers have simply been using apps and similar services to guess valid meeting IDs at the rate of 100 IDs per second. Doing back-of-the-envelope calculations, we can see that it would take them only a few minutes to stumble across meetings in progress.

With passwords still not mandatory for all Zoom users to enter chats, hackers and pranksters can easily find meetings to break into and disrupt.

ID hacking apps can be found online easily enough; even unsophisticated users can try their hand at digital trolling.

But the biggest problem lies in the fact that meeting hosts themselves aren’t following – or don’t even know of – Zoom’s new recommendations on security.

These include locking meetings with passwords, knowing how to remove unwanted or disruptive participants, automatically muting microphones and cameras when participants join, getting members to join a waiting room first before being permitted into a meeting, turning off file transfer, setting up private chats, and more.

Issue 2: Updating Zoom clients in a timely manner

With 200 million users on Zoom, it’s become more difficult for the platform to issue updates to its software. The company can’t simply invite all of its users to update at the same time. Otherwise, the equivalent of a distributed denial of service attack would occur and overwhelm Zoom’s servers.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

Community Writer

Kevin Reed

Now CISO at Acronis, top global cyber protection company. 20+ years in cyber security, has supervised security strategies of leading world banks, the 10 billion NASDAQ traded search engine, and more