Zoom apologizes for security failures, says it has 200M+ DAUs vs. 10M in Dec., and plans to freeze development of new features to focus on security and privacy
And An FBI Warning Brian Krebs / Krebs on Security : ‘War Dialing’ Tool Exposes Zoom's Password Problems Kari Paul / The Guardian : ‘Zoom is malware’: why experts worry about the video conferencing platform Kate O'Flaherty / Forbes : Use Zoom? Here Are 7 Essential Steps You Can Take To Secure It James Rogers / Fox News : SpaceX bans its employees using Zoom over privacy concerns, report says Cristiano Lima / Politico : Multiple state AGs looking into Zoom's privacy practices Ivan Mehta / The Next Web : Zoom is a godforsaken mess — but it can be fixed Monica Chin / The Verge : Zoom has disabled a feature that was exposing users' LinkedIn profiles Michael Kan / PCMag : Were You Zoom-Bombed? Video of It May Now Be on YouTube, TikTok for All to See Mercury News : Zoombombing: FBI warns video calls are getting hijacked Marlize van Romburgh / Silicon Valley Business Journal : Zoom CEO outlines changes as platform's security practices come under scrutiny from multiple state AGs Brad Ward / TalkAndroid.com : Zoom puts a pause on features while security issues are resolved Jason Koebler / VICE : Zoom Has Security Flaws. It's Still Fine to Use JI Stark / futuros : Zoom me mintió, Zoom me dijo que encriptaba y no era verdad Ben Makuch / VICE : 8chan Users Coordinated Antisemitic Zoombombing Campaign Jacob Siegal / BGR : Zoom responds to backlash over privacy concerns Byrne Hobart / The Diff : Amazon Sees Like a State Phil Muncaster / infosecurity-magazine.com : Zoom Patches Three New Bugs in Scramble to Support Remote Workers Matt Milano / IT Management : Zoom Pivots to Security Amid Ongoing Criticism Bhushan Akolkar / coinspeaker.com : Peloton (PTON) Stock Down 4.36%, Company Launches Android TV App FP Trending / Firstpost Tech : Zoom apologises for flaw that could allow attackers to acquire Windows password, promises to fix issues Andrew Hutchinson / Social Media Today : Video Meeting App Zoom Vows to Focus on Improving Security Amid Massive User Growth TIME : Zoom Is Struggling With Security Flaws as Demand for Videoconferencing Spikes Aroon Deep / MediaNama : After growing 20x and facing privacy missteps, Zoom freezes feature updates for 3 months Sean Keane / CNET : Zoom boss says it'll freeze feature updates to address security issues Tweets: Mitch / @_g0dmode : #Zoom chat allows you to post links such as \\x.x.x.x\xyz to attempt to capture Net-NTLM hashes if clicked by other users. Zoom / @zoom_us : We appreciate the scrutiny and questions we have been getting - about how the service works, about our infrastructure and capacity, and about our privacy and security policies. These are the questions that will make Zoom better [Blog Post] https://blog.zoom.us/... by @ericsyuan Patrick Wardle / @patrickwardle : Kudos to @zoom_us: https://blog.zoom.us/... In *one* day: ✅ “Released a fix for the UNC link issue” ✅ “Released fixes for both Mac-related issues” Promise to: ✅ Engage in pen-tests ✅ Improve bug bounty program ✅ Enact feature freeze to focus on safety/privacy issues 😇✌️ https://twitter.com/... Ethan White / @ethanwhite : Dear @zoom_us - as part of your focus on privacy and security over the next 90 days there is something we could critically use in education: the ability to record only the host side of a call. This will allow us to record and share classes without compromising student privacy. https://twitter.com/... @dhh : This sounds great, but it's hard to take too seriously when the stance is “actually we were already doing great and being very transparent but you just didn't see it”. How you can say that while still lying about being end-to-end encrypted is something. https://www.theverge.com/... @mikko : Zoom's actions today remind me of the 2002 feature freeze of Microsoft, which started their journey to better Windows security. “When we face a choice between adding features and resolving security issues, we need to choose security”, said Bill Gates. https://www.wired.com/... Vivek Wadhwa / @wadhwa : Have been using @zoom_us but am going to insist that if people want to speak to me, they use @Skype instead. Zoom is a disaster area for security and privacy: https://techcrunch.com/... SpaceX and Nasa just banned it: https://www.reuters.com/.... @ucsbinfosec : Zoom Lets Attackers Steal Windows Credentials, Run Programs via UNC Links #UCSBinfosec #ucsb #ITsecurity #cybersecurity #UCCyberStrong #infosec https://www.bleepingcomputer.com/ ... https://twitter.com/... Stephen L Rose / @stephenlrose : This is great to hear! Well done Zoom! Zoom announces 90-day feature freeze to fix privacy and security issues https://www.theverge.com/... via @Verge Ellen Shapiro / @designatednerd : I was stunned Zoom's servers hadn't been crushed by increased traffic before this, but 20x growth in 3 months without the whole system exploding is amazing. This'll be a case study in scaling for the ages. https://twitter.com/... Nilay Patel / @reckless : The biggest question facing Zoom is whether these gaffes are move-fast-break-things mistakes, or reflective of a deeper culture of disrespect for user privacy. Or... both. https://www.theverge.com/... Nilay Patel / @reckless : Also: you sort of expect these issues as consumer products go to the enterprise. But Zoom is an enterprise product, and it appears that none of its enterprise customers did any sort of worthwhile vendor security review. Dave Kennedy / @hackingdave : Good read and response from Zoom. As mentioned earlier they are handling this the right way. Zero day dropped March 30th - fixed April 1st. UNC issue fixed and more. Impressive. Lots of communication and clarity - that's a good thing. https://blog.zoom.us/... Darren Herman / @dherman76 : Zoom had 10M DAU in Dec compared to 200M DAU now. Wow. 🤯 https://blog.zoom.us/... Kim Zetter / @kimzetter : Nice pro-active response from Zoom about the security issues recently uncovered. Contrast this with how @Voatz responded recently when MIT researchers found issues with its mobile voting app and it went into attack mode against the researchers. https://twitter.com/... @dhh : “While we never intended to deceive any of our customers, we recognize that there is a discrepancy between the commonly accepted definition of end-to-end encryption and how we were using it”, you don't say. I still am not clear what's up after reading this https://blog.zoom.us/... Ryan Naraine / @ryanaraine : Zoom: “We did not design the product with the foresight that, in a matter of weeks, every person in the world would suddenly be working, studying, and socializing from home...” https://blog.zoom.us/... D.K.R. Boyd / @reflectingman : Lawsuit: Zoom illegally sold users' personal data - CBS News https://www.cbsnews.com/... Audrey / @audreyaurus1 : Data is more precious than gold... https://www.cbsnews.com/... @wajahatali : Can Facebook, Zoom and big tech stop being evil for a month? Just pause until the end of #coronavirus please. Please. “Zoom sued for allegedly sharing users' personal data with Facebook” https://www.cbsnews.com/... via @cbsmoneywatch Thomas Brewster / @iblametom : New - Guess who spent over $1 million on Zoom tech in just a few days? CDC, FEMA and NIH. As in all the US gov bodies responding to the coronavirus crisis. This is where Zoom security and privacy needs to be much better. https://www.forbes.com/... Troy Hunt / @troyhunt : The good news is that flaw only impacts Mac users. The bad news is that this one impacts PC users: https://arstechnica.com/... @nytimesbusiness : Zoom, the videoconferencing app, said today that it would turn off a data-mining feature that could be used to snoop on meeting participants after inquiries from The Times https://www.nytimes.com/... @nytimes : Until today, a feature on Zoom allowed some participants to access LinkedIn profile data about other users — without Zoom asking for their permission or even notifying them that someone else was snooping on them https://www.nytimes.com/... Rogue P. Bigham / @jeffbigham : there's a lesson here... not sure what that lesson is yet, but there's a lesson — “Privacy experts said the company seemed to value ease of use ... over instituting default user protections.” https://www.nytimes.com/... @metacurity : Zoom Windows Client Vulnerability Allows Attackers to Steal Windows Credentials of Users Who Click on Links @LawrenceAbrams https://www.bleepingcomputer.com/ ... https://metacurity.com/...
Context & Ripple Effects
Zoom's apology lands at the peak of a scrutiny wave it did not choose: an FBI warning about hijacked calls, multiple state attorneys general opening privacy inquiries, SpaceX banning the app internally, and a lawsuit alleging the company sold user data — all while daily active users exploded from 10M in December past 200M. The 90-day feature freeze is the company conceding that its security debt grew faster than its user base.
What makes this more than a mea culpa is what follows within weeks: Zoom appoints a CISO Council and Advisory Board and brings on Alex Stamos as an outside advisor (April 8), then ships a 5.0 release built exclusively around security and encryption upgrades rather than features.
First-order effects
- Zoom's own product roadmap stops: every planned feature is shelved for 90 days while engineering goes to encryption and call-management fixes, directly answering the Zoombombing incidents behind the FBI warning.
- Enterprise buyers like SpaceX get their position validated — the ban becomes a template other IT departments can cite when deferring Zoom deployments pending the security overhaul.
Second-order effects
- State attorneys general now have a public commitment to measure Zoom against, turning the apology into a compliance benchmark that shapes how the privacy inquiries proceed.
- Security researchers gain standing: the bug disclosures and 'war dialing' findings that forced this freeze establish that external scrutiny, not internal QA, sets Zoom's release cadence for the quarter.
Third-order effects
- If the pattern holds, pandemic-era hypergrowth makes security remediation a gating function for consumer software companies generally — the 200M-to-300M surge shows usage compounding faster than any normal patch cycle, so vendors may need standing external advisory structures like Stamos's role rather than crisis hires.
- The episode also foreshadows a trust problem beyond code: Zoom later had to quietly correct its own 300M DAU claim as misleading (April 30), suggesting growth metrics themselves become contested terrain when regulators and press are auditing everything a company says.
The trend: Hypergrowth video conferencing is entering a phase where security credibility, not feature velocity, determines which platforms enterprises and regulators will tolerate.