Due to the scale of the pandemic ever more businesses and governments institutions are enforcing ‘work from home’ policies in order to keep their employees safe and healthy, and to keep the business going – Social interactions today come down to video calls, social media posts, communicating via instant messaging platforms and for very many of us we make use of Zoom.
In this context, a cyberattack that deprives organisations and families of access to the internet, their devices or data could be devastating – Zoom has had a bunch of security scares recently, as huge numbers of new users flock to it, and as cybercriminals try to take advantage of that. Fortunately, a lot of the problems and risks people are having can be reduced enormously just by getting the basics right.
So here are “things to get right first” – they shouldn’t take you long, and they are easy to do to keep your Zoom safer.
1. Pick the right password.
When setting up Zoom Account its highly recommended to make use of good and strong password – Do not share it, change it as often as you can, make sure you do not reuse the password.
2. Patch early, patch often
Zoom’s own CEO just wrote a blog post announcing a “feature freeze” in the product so that the company can focus on security issues instead. It’s much easier to do that if you aren’t adding new code at the same time.
Why not get into the habit of checking you’re up-to-date every day, before your first meeting? Even if Zoom itself told you about an update the very last time you used it, get in the habit of checking by hand anyway, just to be sure. It doesn’t take long.
3. Use the Waiting Room option
Set up meetings so that the participants can’t join in until you open it up.
And if you suddenly find yourself “on hold until the organiser starts the meeting” when in the past you would have spent the time chatting to your colleagues and getting the smalltalk over with, don’t complain – those pre-meeting meetings are great for socialising but they do make it harder to control the meeting.
4. Take control over screen sharing
Until recently, most Zoom meetings took a liberal approach to screen sharing. Unfortunately this can cause other to share inappropriate things and cause troubles
Actually, it’s not just screen sharing that can cause trouble. There are numerous controls you can apply to participants in meetings, including blocking file sharing and private chat, kicking out disruptive users, and stopping troublemakers coming back.
5. Use random meeting IDs and set meeting passwords
We know lots of Zoom users who memorised their own meeting ID long ago and had fallen into the habit of using it for every meeting they held – even back-to-back meetings with different groups – because they knew they’d never need to look it up.
But that convenience is handy for crooks, too, because they already have a list of known IDs that they can try automatically in the hope of wandering in where they aren’t supposed to be.
It is recommended using a randomly generated meeting ID, and setting a password on any meeting that is not explicitly open to all. You can send the web link by one means, e.g. in an email or invitation request, and the password by another means, e.g. in an instant message just before the meeting starts. (You can also lock meetings once they start to avoid gaining unwanted visitors after you’ve started concentrating on the meeting itself.)
6. Make some rules of etiquette and stick to them.
Etiquette may sound like a strange bedfellow for cybersecurity, and perhaps it is.
But respect for privacy, a sense of trust, and a feeling of social and business comfort are also important parts of a working life that’s now dominated by online meetings.
If you’re expected or you need to use video, pay attention to your appearance and the lighting. (In very blunt terms: try to avoid being a pain to watch.) Remember to use the mute button when you can.
And most importantly – especially if there are company outsiders in the meeting – be very clear up front if you will be recording the meeting, even if you are in a jurisdiction that does not require you to declare it. And make it clear if they are any restrictions, albeit informal ones, about what the participants are allowed to do with the information they learn in the meeting.
Etiquette isn’t about keeping the bad guys out. But respectful rules of engagement for remote meetings help to make it easy for everyone in the meeting to keep the good stuff in.