In early April, a developer found protected Zoom call passwords could be quickly cracked; he reported the bug, now fixed, and says he hasn't received a bounty
Context & Ripple Effects
Tom Anthony's April 2020 report lands in the middle of Zoom's worst security stretch: days earlier the company had patched its Windows client flaw that leaked login credentials via chat links, and weeks later reporting emerged that partner Dropbox was so worried it had privately paid hackers to probe Zoom's code. The password-cracking weakness fit that pattern of quickly found, quickly fixed bugs.
The bounty dispute is also familiar terrain. Critics had already argued that bug bounty programs can buy silence and sit awkwardly with labor law, and a macOS researcher had withheld exploit details from Apple for exactly this reason — no bounty program, no incentive to disclose responsibly. Anthony going public about being unpaid adds Zoom's name to that ledger.
First-order effects
- Zoom users on protected calls get the actual fix: passwords that could be cracked quickly are no longer crackable, closing an access path during the period when Zoom's meeting volume was at its peak.
Second-order effects
- Anthony's public account of receiving no payment pressures Zoom toward a structured bounty program — the same pressure that pushed Dropbox to pay researchers out-of-band rather than wait for Zoom's own process.
Third-order effects
- If researchers keep publicizing non-payment while companies like Zoom keep absorbing high-severity finds — from Anthony's password flaw through the later Pwn2Own remote code execution disclosure and Patrick Wardle's Mac root-access bug — responsible disclosure starts depending on vendor goodwill or private side payments rather than formal programs, and researchers rationally favor vendors who do pay.
The trend: Videoconferencing's pandemic-era attack surface is turning bug bounty economics into a competitive differentiator, deciding which vendors researchers report to quietly and which ones they embarrass publicly.