Zoom bolsters software security in latest move to reassure users
Full article566 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The updates are an effort to adapt to the unprecedented amount of people using Zoom during the pandemic.
Zoom, the videoconferencing service whose popularity has soared during the coronavirus pandemic, on Wednesday said it was adding security measures to its software following scrutiny from independent researchers.
The next version of Zoom, to be released this week, will have stronger encryption for data sent between participants in a meeting to prevent tampering, the Silicon Valley-based company said. The software will also allow Zoom account administrators to choose which parts of the world they route their data through. The upgrade follows a report from the University of Toronto’s Citizen Lab that found Zoom routed some meeting encryption keys through China.
The updates are an effort to adapt to the unprecedented amount of people using Zoom as they work from home during the COVID-19 pandemic.
Zoom had about 200 million daily meeting participants in March, and the Silicon Valley company at first appeared unprepared for the privacy and security implications of the surge. “The risks, the misuse, we never thought about that,” Zoom CEO Eric Yuan told the New York Times.
But after researchers found vulnerabilities in the Zoom app that malicious hackers could use to compromise users’ communications, and some U.S. lawmakers criticized the company’s practices, Zoom pledged to prioritize security. The company also brought in experts to improve its bug bounty program, and has earned praise from researchers for quickly fixing software bugs.
Even so, some government bodies, including the U.S. Senate and Germany’s foreign ministry, have reportedly restricted use of the app over security concerns.
But all software has vulnerabilities. How vendors and users deal with them determines how exposed organizations are.
“When it comes to any external vendor, you’re constantly balancing the reward of the service they offer with the risk of using that service,” said Bruce Potter, chief information security officer of security company Expel.
Zoom’s exposure to public scrutiny has made the app more secure, Potter wrote in a recent blog post. “They’re not burying their heads in the sand and they’re being very transparent.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Wyden seeks upgraded NSA security guidance on commercial VPN use
The Collective Cyber Defense letter wrote your next vendor questionnaire
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/zoom-software-update-security-coronavirus/