Education

‘Zoombombers’ want to troll your online meetings. Here’s how to stop them

With hundreds of millions around the world now reliant on the app for work, this unfortunate trend is becoming more common, often involving a bombardment of pornographic imagery.

<h2>&OpenCurlyDoubleQuote;<a href&equals;"https&colon;&sol;&sol;www&period;nytimes&period;com&sol;2020&sol;03&sol;20&sol;style&sol;zoombombing-zoom-trolling&period;html" target&equals;"&lowbar;blank">Zoombombing<&sol;a>” in case you haven’t heard&comma; is the unsavoury practice of posting distressing comments&comma; pictures or videos after gatecrashing virtual meetings hosted by the videoconferencing app <a href&equals;"https&colon;&sol;&sol;zoom&period;us&sol;" target&equals;"&lowbar;blank">Zoom<&sol;a>&period;<&sol;h2>&NewLine;<p>In some cases&comma; online trolls have crashed alcohol support group meetings held via the app&period; &OpenCurlyDoubleQuote;Alcohol is soooo good&comma;” <a href&equals;"https&colon;&sol;&sol;thehill&period;com&sol;policy&sol;technology&sol;490467-zoom-deeply-upset-after-online-trolls-interrupt-virtual-aa-meetings" target&equals;"&lowbar;blank">the trolls reportedly said<&sol;a> to one group of recovering alcoholics&period;<&sol;p>&NewLine;<p>In another incident&comma; a Massachusetts-based high school teacher conducting an <a href&equals;"https&colon;&sol;&sol;www&period;fbi&period;gov&sol;contact-us&sol;field-offices&sol;boston&sol;news&sol;press-releases&sol;fbi-warns-of-teleconferencing-and-online-classroom-hijacking-during-covid-19-pandemic" target&equals;"&lowbar;blank">online class<&sol;a> had someone enter the virtual classroom and shout profanities&comma; before revealing the teacher’s home address&period;<&sol;p>&NewLine;<h2>Easy targets<&sol;h2>&NewLine;<p>The problem is that Zoom meetings lack password protection&period; Joining one simply requires a standard Zoom URL&comma; with an automatically generated nine-digit code at the end&period; A Zoom URL looks something like this&colon; https&colon;&sol;&sol;zoom&period;us&sol;j&sol;xxxxxxxxx<&sol;p>&NewLine;<p>&nbsp&semi;<&sol;p>&NewLine;<p>Gatecrashers may only have to try a handful of code combinations before successfully landing a victim&period; The meeting’s host doesn’t need to grant permission for others to join&period; And while hosts can disable the screen share function&comma; they’d have to be quick&period; Too slow&comma; and the damage is done&period;<&sol;p>&NewLine;<p>Last week&comma; Zoom upgraded security on its <a href&equals;"https&colon;&sol;&sol;support&period;zoom&period;us&sol;hc&sol;en-us&sol;articles&sol;360041591671-March-2020-Update-to-sharing-settings-for-Education-accounts&comma;" target&equals;"&lowbar;blank">default settings<&sol;a>&comma; but only for education accounts&period; The rest of the world needs to do this manually&period;<&sol;p>&NewLine;<h2>Video conferencing is incredibly valuable<&sol;h2>&NewLine;<p>Video conferencing technology has matured in recent years&comma; driven by <a href&equals;"https&colon;&sol;&sol;www&period;theverge&period;com&sol;2020&sol;4&sol;1&sol;21202584&sol;zoom-security-privacy-issues-video-conferencing-software-coronavirus-demand-response" target&equals;"&lowbar;blank">massive demand<&sol;a> even before COVID-19&period;<&sol;p>&NewLine;<p>With social distancing restriction&comma; virtual meetings are now the norm everywhere&period; Platforms like Zoom&comma; Microsoft’s Skype and <a href&equals;"https&colon;&sol;&sol;www&period;uctoday&period;com&sol;collaboration&sol;video-conferencing&sol;top-10-video-conferencing-providers-2019-whos-king-of-collaboration&sol;" target&equals;"&lowbar;blank">others<&sol;a> have stepped up to meet demand&period;<&sol;p>&NewLine;<p>Zoom is a <a href&equals;"https&colon;&sol;&sol;azure&period;microsoft&period;com&sol;en-us&sol;overview&sol;what-is-cloud-computing&sol;" target&equals;"&lowbar;blank">cloud-based<&sol;a> service that allows users to freely talk to and share video &lpar;if bandwidth allows&rpar; with others online&period; Notes&comma; images and diagrams can also be shared to collaborate on projects&period; And meetings can have up to <a href&equals;"https&colon;&sol;&sol;zoom&period;us&sol;pricing" target&equals;"&lowbar;blank">hundreds&comma; even thousands&comma; of participants<&sol;a>&period;<&sol;p>&NewLine;<h2>How to stop the trolls<&sol;h2>&NewLine;<p>Zoom is primarily a corporate collaboration tool that allows people to collaborate without hindrance&period; Unlike social media platforms&comma; it was not a service that had to engineer ways to manage the bad behaviour of users – until now&period;<&sol;p>&NewLine;<p>In January&comma; Zoom <a href&equals;"https&colon;&sol;&sol;support&period;zoom&period;us&sol;hc&sol;en-us&sol;articles&sol;201361953-New-Updates-for-Windows" target&equals;"&lowbar;blank">issued a raft of security patches<&sol;a> to fix some problems&period; If you get a prompt from Zoom to install updates&comma; you should – but only if these updates are from Zoom’s own app and website&comma; or via updates from Google Play or Apple’s App Store&period; Third-party downloads may contain malware &lpar;software designed to cause harm&rpar;&period;<&sol;p>&NewLine;<p>&nbsp&semi;<&sol;p>&NewLine;<p>While up-to-date software is your first line of defence&comma; another is to keep your meeting URL away from public forums such as Twitter&period; Anyone with meeting’s URL can join&comma; after which they’re free to post comments&comma; pictures and videos at will&period; If you’re hosting a meeting that gets Zoombombed&comma; disable the &OpenCurlyDoubleQuote;screen sharing” option as quickly as possible&period;<&sol;p>&NewLine;<p>Another option for more security is to use the &OpenCurlyDoubleQuote;waiting room” function&period; This makes people wanting to join visible to the host&comma; but keeps them out of the main meeting until they’re allowed in&period; This option is turned off by default&period; You can enable it by signing-in to your Zoom account at <em><a href&equals;"https&colon;&sol;&sol;zoom&period;us&sol;" target&equals;"&lowbar;blank">https&colon;&sol;&sol;zoom&period;us&sol;<&sol;a><&sol;em> and clicking &OpenCurlyDoubleQuote;Settings”&period;<&sol;p>&NewLine;<p>Other tips&colon;<&sol;p>&NewLine;<ul>&NewLine;<li>&NewLine;<p>ensure screen sharing is possible for the host only<&sol;p>&NewLine;<&sol;li>&NewLine;<li>&NewLine;<p>turn off the function that allows file transfer<&sol;p>&NewLine;<&sol;li>&NewLine;<li>&NewLine;<p>turn off the &OpenCurlyDoubleQuote;allow removed participants to rejoin” setting<&sol;p>&NewLine;<&sol;li>&NewLine;<li>&NewLine;<p>turn off the &OpenCurlyDoubleQuote;join before host” setting<&sol;p>&NewLine;<&sol;li>&NewLine;<li>&NewLine;<p>turn on the &OpenCurlyDoubleQuote;require a password” setting for meetings&period;<&sol;p>&NewLine;<&sol;li>&NewLine;<&sol;ul>&NewLine;<figure><iframe src&equals;"https&colon;&sol;&sol;www&period;youtube&period;com&sol;embed&sol;XhZW3iyXV9U&quest;wmode&equals;transparent&amp&semi;start&equals;0" width&equals;"440" height&equals;"260" frameborder&equals;"0" allowfullscreen&equals;"allowfullscreen"><&sol;iframe><figcaption><span class&equals;"caption">This video explains the ins and outs of setting up a safe Zoom session&period;<&sol;span><&sol;figcaption><&sol;figure>&NewLine;<h2>Who are the trolls&quest;<&sol;h2>&NewLine;<p>With many Zoomombing attacks being on educational institutions&comma; it’s likely a large number of these trolls are simply mischievous students who obtain meeting URLs from other students or chatrooms&period;<&sol;p>&NewLine;<p>But zoombombing is by no means restricted to the classroom&period; With the world in lockdown&comma; extremists of all kinds are finding ways to relieve their confinement frustration&period; We’ve known for some time that being able to operate anonymously on the web <a href&equals;"https&colon;&sol;&sol;www&period;psychologicalscience&period;org&sol;observer&sol;who-is-that-the-study-of-anonymity-and-behavior" target&equals;"&lowbar;blank">does not bring out the best in people<&sol;a>&period;<&sol;p>&NewLine;<p>At present&comma; it doesn’t appear Zoombombing is an organised criminal activity&period; That said&comma; it’s probably only a matter of time before someone finds a way to leverage financial reward from the practice&period; This could take the form of business intelligence gleaned from listening in to the meetings of rivals and competitors&comma; in a similar fashion to planting a &OpenCurlyDoubleQuote;bug” in the room&period;<&sol;p>&NewLine;<p>Similarly&comma; we could see a black market for Zoom URLs emerge among professional hackers&comma; who would have new incentives to hack various systems to obtain valuable URLs&period;<&sol;p>&NewLine;<p>Cybersecurity experts&comma; privacy advocates&comma; lawmakers and law enforcement are all <a href&equals;"https&colon;&sol;&sol;www&period;theverge&period;com&sol;2020&sol;4&sol;1&sol;21202584&sol;zoom-security-privacy-issues-video-conferencing-software-coronavirus-demand-response" target&equals;"&lowbar;blank">concerned<&sol;a> Zoom’s default privacy settings don’t do enough to protect users from malicious actors&period;<&sol;p>&NewLine;<h2>The bottom line<&sol;h2>&NewLine;<p>As the COVID-19 pandemic leads the world to do their work online in isolation&comma; the technology that allows this freedom must come under close scrutiny&period;<&sol;p>&NewLine;<p>Zoombombing is progressing from a student prank to <a href&equals;"https&colon;&sol;&sol;www&period;adl&period;org&sol;blog&sol;what-is-zoombombing-and-who-is-behind-it" target&equals;"&lowbar;blank">more serious<&sol;a> incidents of <a href&equals;"https&colon;&sol;&sol;www&period;buzzfeednews&period;com&sol;article&sol;salvadorhernandez&sol;zoom-coronavirus-racist-zoombombing" target&equals;"&lowbar;blank">racist&comma; sexist<&sol;a> and <a href&equals;"https&colon;&sol;&sol;www&period;huffingtonpost&period;com&period;au&sol;entry&sol;nazi-zoombombing-jewish-yeshiva-university&lowbar;n&lowbar;5e84f704c5b692780506d519&quest;ri18n&equals;true" target&equals;"&lowbar;blank">anti-semitic<&sol;a> hate speech&period;<&sol;p>&NewLine;<p>Fortunately&comma; safeguards aren’t difficult to build into such videoconferencing technologies&period; This just requires a willingness to do so&comma; and needs to be done as a matter of urgency&period;<&excl;-- Below is The Conversation's page counter tag&period; Please DO NOT REMOVE&period; --><img style&equals;"border&colon; none &excl;important&semi; box-shadow&colon; none &excl;important&semi; margin&colon; 0 &excl;important&semi; max-height&colon; 1px &excl;important&semi; max-width&colon; 1px &excl;important&semi; min-height&colon; 1px &excl;important&semi; min-width&colon; 1px &excl;important&semi; opacity&colon; 0 &excl;important&semi; outline&colon; none &excl;important&semi; padding&colon; 0 &excl;important&semi; text-shadow&colon; none &excl;important&semi;" src&equals;"https&colon;&sol;&sol;counter&period;theconversation&period;com&sol;content&sol;135311&sol;count&period;gif&quest;distributor&equals;republish-lightbox-basic" alt&equals;"The Conversation" width&equals;"1" height&equals;"1" &sol;><&excl;-- End of code&period; If you don't see any code above&comma; please get new code from the Advanced tab after you click the republish button&period; The page counter does not collect any personal data&period; More info&colon; https&colon;&sol;&sol;theconversation&period;com&sol;republishing-guidelines --><&sol;p>&NewLine;<hr &sol;>&NewLine;<h6><a href&equals;"https&colon;&sol;&sol;theconversation&period;com&sol;profiles&sol;david-tuffley-13731" target&equals;"&lowbar;blank">David Tuffley<&sol;a>&comma; Senior Lecturer in Applied Ethics &amp&semi; CyberSecurity&comma; <em><a href&equals;"https&colon;&sol;&sol;theconversation&period;com&sol;institutions&sol;griffith-university-828" target&equals;"&lowbar;blank">Griffith University&period; <&sol;a><&sol;em>This article is republished from <a href&equals;"https&colon;&sol;&sol;theconversation&period;com" target&equals;"&lowbar;blank">The Conversation<&sol;a> under a Creative Commons license&period; Read the <a href&equals;"https&colon;&sol;&sol;theconversation&period;com&sol;zoombombers-want-to-troll-your-online-meetings-heres-how-to-stop-them-135311" target&equals;"&lowbar;blank">original article<&sol;a>&period;<&sol;h6>&NewLine;

Explore our latest issue...
School News

School News is not affiliated with any government agency, body or political party. We are an independently owned, family-operated magazine.

Recent Posts

Teacher salaries have plummeted relative to minimum and median wages

EXCLUSIVE: Teachers used to be paid two to three times more than minimum wage workers,…

3 days ago

Rolling strikes this week for secondary teachers

After an “overwhelming” vote to reject the latest Government offer, secondary school teachers will begin…

3 days ago

Should second-language learning be compulsory?

Second-language learning should be compulsory, says a new report from a forum bringing together academics,…

3 days ago

New staffing entitlement for learning support coordinators

A new entitlement aimed to improve access to learning support coordinators for schools with students…

3 days ago

Updated secondary subjects raise questions

Educators have raised questions about the Ministry of Education’s new secondary school subjects, set to…

3 days ago

PLD for teachers in New Zealand needs strengthening, says ERO

Professional learning and development (PLD) for teachers needs to be higher impact for teachers and…

1 week ago