New York's AG sent a letter to Zoom expressing concern over security vulnerabilities and privacy practices as more users conduct sensitive tasks on the service
on its app, website, security white paper—that its video calls are “end-to-end encrypted,” but when @theintercept asked them about it they said: “Currently, it is not possible to enable E2E encryption for Zoom video meetings.” https://theintercept.com/... Shannon Vavra / @shanvav : The FBI issued a warning today that Zoom and other teleconferencing may not be as private/secure as advertised. As remote work/classes surge w/ coronavirus, this raises privacy, security, & possibly national security issues, as world leaders use Zoom too. https://www.cyberscoop.com/... M.G. Siegler / @mgsiegler : Unclear if the Zoomlash is going to last two weeks, two days, or two minutes in our current distorted temporal state of reality. https://twitter.com/... @cradvocacy : “Zoom should update their terms to ensure that data collected during meetings from any participant or host is explicitly excluded from any advertising or marketing use...” says CR's @JustinBrookman. See our tips for enhancing your privacy on Zoom: https://www.consumerreports.org/ ... Jason Koebler / @jason_koebler : Design flaw in Zoom lets random strangers video call people and also leaks photos and email addresses of anyone using nonstandard email addresses: https://www.vice.com/... @vice : A Zoom user filed a class action lawsuit against the company for sending data to Facebook, arguing that Zoom violated California's new data protection law. https://www.vice.com/... Arvind Narayanan / @random_walker : Zoom is also a privacy disaster https://blogs.harvard.edu/... The creepiest feature is attention tracking. If it's on, it reports to the host if a user clicks away from the Zoom window for 30 seconds. As we all know, your boss constantly watching your screen is a great way to work. Yuan Yang / @yuanfenyang : The UK: We really shouldn't give our sensitive data to Huawei if we can't guarantee the integrity of its security Also the UK: We should give it all to Zoom instead Also see: https://theintercept.com/... https://twitter.com/... @ow : Zoom is such a dodgy/misleading company across the board and using it should be reconsidered 🙅♀️ https://theintercept.com/... @jilliancyork : I was willing to write off the other stuff about Zoom, but not this. I'll be looking for a better solution for anything personal. https://theintercept.com/... @profcarroll : Zoom: “We take privacy seriously.” NY AG: “We too take privacy seriously.” https://www.nytimes.com/... FBI Boston / @fbiboston : FBI Warns of Teleconferencing and Online Classroom Hijacking During COVID-19 Pandemic: As large numbers of people turn to video-teleconferencing (VTC) platforms to stay connected in the wake of the COVID-19 crisis, reports of VTC hijacking are emerging ... https://www.fbi.gov/... Josh Gerstein / @joshgerstein : ‘Without end-to-end encryption, Zoom has the technical ability to spy on private video meetings and could be compelled to hand over recordings of meetings to governments or law enforcement in response to legal requests.’ https://twitter.com/... Marta L. Tellado / @mltellado : Great reporting by @allenstjohn who wrote about the privacy concerns of using Zoom. Thanks, Doc Searls @dsearls for elevating this issue & calling @consumerreports “the greatest moral conscience in the history of business” https://www.consumerreports.org/ ...
Context & Ripple Effects
Zoom entered April 2020 with its user base exploding — 10M daily users in December to 200M+ by the time of this letter — while its security story unraveled in public: it had marketed meetings as "end-to-end encrypted," then conceded that was not currently possible, the FBI warned teleconferencing may not be as private as advertised, and a user filed a class action over data sent to Facebook. New York's AG letter turns that press problem into a legal one.
The letter is the first formal regulatory step in what became a year-long arc: Zoom's apology and feature freeze days later, an agreement with the same AG by May, and by December an SEC and US attorney investigation. Even Zoom's own business partner moved around it — Dropbox privately paid hackers to find bugs in Zoom's code rather than trust the company's process.
First-order effects
- Zoom now faces a state regulator demanding answers on vulnerabilities and privacy practices at the exact moment sensitive government, legal, and classroom use is surging on the platform — with the FBI warning amplifying the stakes for institutional buyers.
Second-order effects
- Enterprise customers and partners stop relying on Zoom's own assurances: Dropbox's private bug-bounty push shows partners hedging, and rivals can compete on verifiable security claims like true end-to-end encryption that Zoom has admitted it cannot yet offer.
Third-order effects
- State attorneys general emerge as first movers on consumer-tech security, establishing the playbook — inquiry letter, settlement, then federal escalation — that culminated in the SEC and US attorney probes; security posture becomes a procurement gate for video conferencing rather than a marketing line.
The trend: Pandemic-driven video conferencing growth is colliding with a layered regulatory response — state AGs first, then federal agencies — forcing platforms to treat security as a compliance obligation rather than a selling point.