Zoom's 90-day plan to enhance the security of its video conferencing platform recently came to an end. First initiated on April 1, 2020, a time where the company faced scrutiny from users who experienced a brief phenomenon that would become known as Zoombombing. Since then, and several other security issues including when Great Britain's Prime Minister, Boris Johnson, Tweeted a photo of himself in the country's first-ever virtual cabinet meeting held via the popular video conferencing system where his meeting ID got exposed, causing many to question if Zoom was secure.
Following these mishaps, and amid a global pandemic, the likes of which we have not seen for over 100 years, Zoom today reports, it reached over two trillion in April 2020. According to Zoom Founder and CEO, Eric Yuan, during the first few months of 2020, Zoom's team worked around the clock to support the sudden influx of new and different types of users on its platform. Yuan added:
"The sudden and increased demand for our systems was unlike anything most companies have ever experienced"
The company set out on its new-found quest to further secure its platform with world-class security, and address more user demands along the way. In a series of seven commitments Zoom set out to address in its 90-day plan, the folks at Zoom enacted a feature freeze, effective April 1, and shift all our engineering resources to focus on our biggest trust, safety, and privacy issues." Video conferencing developers over at Zoom HQ then enacted a 90-day freeze on all features not related to privacy, safety, or security. "We released over 100 features including the following during this timeframe," a spokesperson for the company said in an email.
"As March came to a close, we realized that our singular mission to deliver frictionless video communications to hundreds of millions of daily meeting participants needed to include an equal focus on security and privacy – areas where we needed to do more," Yuan said.
Zoom 5.0's launch was among the most monumental of the giant's AES 256 GCM encryption, available to all users, after facing backlash. Yes, all free and paid accounts now have AES 256 GCM encryption. The company also released a feature that lets users report other users, set passwords for waiting room, and limited screen sharing. Zoom meeting hosts even gained the ability to disable many device logins, give unmute consent, cloud recording 'expiration,' and gain a tighter grip on Zoom Chat controls. During this phase, the company acquired Keybase to realize end-to-end encryption as well as to offer customized data routing based on user geography.
"Going forward, we have put mechanisms in place to make sure that security and privacy remain a priority in each phase of our product and feature development security requirements, risk assessment, threat modeling along with established secure code guidelines, self-service scanning, and CI/CD tools."
I am told, Zoom established processes that will be of benefit for the tech giant well into the future, as it will likely face other challenges as it battles user demand and scalability. Yuan wrote in a statement, the company has the skeleton of a plan when future security issues arise, for instances such as testing, automated test execution, web testing tools, secure configuration, integrity monitoring, confirm requirements, internal system monitoring to assess security, health, and the threat landscape the company face.




