A new Zoom vulnerability is leaking data from people's LinkedIn profile
3 min. read
Published on
Read our disclosure page to find out how can you help MSPoweruser sustain the editorial team Read more
The coronavirus outbreak has forced people to rely on conferencing apps and that has brought Zoom some overnight success. However, the company has been suffering from its own fame as researchersย disclosedย severalย Zoomย relatedย vulnerabilities.
Now, The New York Times has discovered a potential data mining bug in Zoom that is leaking data from people’s LinkedIn profiles. The vulnerability is hitting those who have subscribed to a LinkedIn service for sales prospecting, calledย LinkedIn Sales Navigator. Once the service has been enabled, they could quickly access LinkedIn data of everyone on the call without them knowing about it. The data includes locations, employer names and job titles.
In tests conducted last week, The Times found that even when a reporter signed in to a Zoom meeting under pseudonyms โ โAnonymousโ and โI am not hereโ โ the data-mining tool was able to instantly match him to his LinkedIn profile. In doing so, Zoom disclosed the reporterโs real name to another user, overriding his efforts to keep it private.
Reporters also found that Zoom automatically sent participantsโ personal information to its data-mining tool even when no one in a meeting had activated it. This week, for instance, as high school students in Colorado signed in to a mandatory video meeting for a class, Zoom readied the full names and email addresses of at least six students โ and their teacher โ for possible use by its LinkedIn profile-matching tool, according to a Times analysis of the data traffic that Zoom sent to a studentโs account.
– The New York Times
Thankfully, Zoom has acted on the Times findings and is in process of disabling the feature. In a statement, the company said it took usersโ privacy โextremely seriouslyโ and was โremoving the LinkedIn Sales Navigator to disable the feature on our platform entirely.” In a separate statement given to The NYT, LinkedIn said, it worked โto make it easy for members to understand their choices over what information they shareโ and would suspend the profile-matching feature on Zoom โwhile we investigate this further.โ
People donโt know this is happening and thatโs just completely unfair and deceptive.
– Josh Golin, Executive Director, Campaign for a Commercial-Free Childhood
Itโs a combination of sloppy engineering and prioritizing growth. Itโs very clear that they have not prioritized privacy and security in the way they should have, which is obviously more than a little concerning.
– Jonathan Mayer, Assistant professor (Computer Science), Princeton University
On Thursday, it sent an automated message to users saying it had disabled the LinkedIn profile-matching feature โdue to administrative issues.โ โWe will notify you when the app is re-enabled,โ the message read.
Earlier today, the company paused all the feature updates to concentrate on fixing the security issues. Over the next 90 days, Zoom will be using all its resources to better identify, address, and fix security and privacy issues proactively. So, Zoom wonโt be adding any new features in the next 3 months. It will also conduct a comprehensive review with third-party experts and representative users to understand and ensure the security of its service. Learn more about this announcement here.
User forum
0 messages