/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

In early April, a developer found protected Zoom call passwords could be quickly cracked; he reported the bug, now fixed, and says he hasn't received a bounty

Tom Anthony :

Tom Anthony

Context & Ripple Effects

Tom Anthony's April 2020 report lands in the middle of Zoom's worst security stretch: days earlier the company had patched its Windows client flaw that leaked login credentials via chat links, and weeks later reporting emerged that partner Dropbox was so worried it had privately paid hackers to probe Zoom's code. The password-cracking weakness fit that pattern of quickly found, quickly fixed bugs.

The bounty dispute is also familiar terrain. Critics had already argued that bug bounty programs can buy silence and sit awkwardly with labor law, and a macOS researcher had withheld exploit details from Apple for exactly this reason — no bounty program, no incentive to disclose responsibly. Anthony going public about being unpaid adds Zoom's name to that ledger.

First-order effects

  • Zoom users on protected calls get the actual fix: passwords that could be cracked quickly are no longer crackable, closing an access path during the period when Zoom's meeting volume was at its peak.

Second-order effects

  • Anthony's public account of receiving no payment pressures Zoom toward a structured bounty program — the same pressure that pushed Dropbox to pay researchers out-of-band rather than wait for Zoom's own process.

Third-order effects

  • If researchers keep publicizing non-payment while companies like Zoom keep absorbing high-severity finds — from Anthony's password flaw through the later Pwn2Own remote code execution disclosure and Patrick Wardle's Mac root-access bug — responsible disclosure starts depending on vendor goodwill or private side payments rather than formal programs, and researchers rationally favor vendors who do pay.

The trend: Videoconferencing's pandemic-era attack surface is turning bug bounty economics into a competitive differentiator, deciding which vendors researchers report to quietly and which ones they embarrass publicly.

Discussion

  • @tomanthonyseo Tom Anthony on x
    So a few months ago I realised Zoom doesn't rate limit password attempts for meetings, and has only 1 million passwords. Meaning you could join private meetings within minutes. 😮 https://www.tomanthony.co.uk/ ...
  • @benthompson Ben Thompson on x
    Another sloppy Zoom security issue. Once again the issue is more about corporate controls and prioritizing security than anything else (which is an issue because it shows intentional bugs wouldn't be found) https://twitter.com/...