A new Zoom vulnerability is leaking data from people's LinkedIn profile

Reading time icon 3 min. read


Readers help support MSpoweruser. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help MSPoweruser sustain the editorial team Read more

Zoom

The coronavirus outbreak has forced people to rely on conferencing apps and that has brought Zoom some overnight success. However, the company has been suffering from its own fame as researchersย disclosedย severalย Zoomย relatedย vulnerabilities.

Now, The New York Times has discovered a potential data mining bug in Zoom that is leaking data from people’s LinkedIn profiles. The vulnerability is hitting those who have subscribed to a LinkedIn service for sales prospecting, calledย LinkedIn Sales Navigator. Once the service has been enabled, they could quickly access LinkedIn data of everyone on the call without them knowing about it. The data includes locations, employer names and job titles.

In tests conducted last week, The Times found that even when a reporter signed in to a Zoom meeting under pseudonyms โ€” โ€œAnonymousโ€ and โ€œI am not hereโ€ โ€” the data-mining tool was able to instantly match him to his LinkedIn profile. In doing so, Zoom disclosed the reporterโ€™s real name to another user, overriding his efforts to keep it private.

Reporters also found that Zoom automatically sent participantsโ€™ personal information to its data-mining tool even when no one in a meeting had activated it. This week, for instance, as high school students in Colorado signed in to a mandatory video meeting for a class, Zoom readied the full names and email addresses of at least six students โ€” and their teacher โ€” for possible use by its LinkedIn profile-matching tool, according to a Times analysis of the data traffic that Zoom sent to a studentโ€™s account.

– The New York Times

Thankfully, Zoom has acted on the Times findings and is in process of disabling the feature. In a statement, the company said it took usersโ€™ privacy โ€œextremely seriouslyโ€ and was โ€œremoving the LinkedIn Sales Navigator to disable the feature on our platform entirely.” In a separate statement given to The NYT, LinkedIn said, it worked โ€œto make it easy for members to understand their choices over what information they shareโ€ and would suspend the profile-matching feature on Zoom โ€œwhile we investigate this further.โ€

People donโ€™t know this is happening and thatโ€™s just completely unfair and deceptive.

– Josh Golin, Executive Director, Campaign for a Commercial-Free Childhood

Itโ€™s a combination of sloppy engineering and prioritizing growth. Itโ€™s very clear that they have not prioritized privacy and security in the way they should have, which is obviously more than a little concerning.

Jonathan Mayer, Assistant professor (Computer Science), Princeton University

On Thursday, it sent an automated message to users saying it had disabled the LinkedIn profile-matching feature โ€œdue to administrative issues.โ€ โ€œWe will notify you when the app is re-enabled,โ€ the message read.

Earlier today, the company paused all the feature updates to concentrate on fixing the security issues. Over the next 90 days, Zoom will be using all its resources to better identify, address, and fix security and privacy issues proactively. So, Zoom wonโ€™t be adding any new features in the next 3 months. It will also conduct a comprehensive review with third-party experts and representative users to understand and ensure the security of its service. Learn more about this announcement here.

User forum

0 messages