{"id":396,"date":"2020-12-11T07:46:03","date_gmt":"2020-12-11T12:46:03","guid":{"rendered":"https:\/\/pbacyber.com\/?p=396"},"modified":"2020-12-11T07:47:37","modified_gmt":"2020-12-11T12:47:37","slug":"the-ftc-takes-aim-at-zoom","status":"publish","type":"post","link":"https:\/\/pbacyber.com\/index.php\/2020\/12\/11\/the-ftc-takes-aim-at-zoom\/","title":{"rendered":"The FTC Takes Aim at Zoom"},"content":{"rendered":"<p>By Jennifer K. Wagner J.D., Ph.D.<\/p>\n<p>&nbsp;<\/p>\n<p>2020 brought an unexpected and massive surge in the use of video conferencing platforms. In the midst of a deadly pandemic and public health guidelines intended to flatten the curve through deterrence of non-essential in-person interactions, Zoom and similar video conferencing platforms have provided a way for people to stay connected and companies (including law firms) to continue to do business. Indeed, the Commonwealth Court of Pennsylvania recently noted Zoom and similar platforms do provide the type of \u201csimultaneous contemporaneous communication\u201d necessary for conducting a business \u201cmeeting\u201d (<em>M4 Holdings, LLC v. Lake Harmony Estates Property Owners\u2019 Association<\/em>, 237 A.3d 1208, 1220). The precise scale of Zoom\u2019s growth has been <a href=\"https:\/\/www.theverge.com\/2020\/4\/30\/21242421\/zoom-300-million-users-incorrect-meeting-participants-statement\">disputed<\/a> (due to distinctions between daily active users and daily meeting participants), but Zoom\u2019s userbase has <a href=\"https:\/\/www.ftc.gov\/news-events\/press-releases\/2020\/11\/ftc-requires-zoom-enhance-its-security-practices-part-settlement\">reportedly<\/a> swelled to more than 30 times the size it was a year ago (growing from 10 million daily users in December 2019 to 300 million by April 2020). For comparison, Google Meet and Microsoft Teams <a href=\"https:\/\/www.theverge.com\/2020\/4\/30\/21242421\/zoom-300-million-users-incorrect-meeting-participants-statement\">apparently<\/a> had &gt;100 million and 75 million daily users, respectively during that same timeframe, and Microsoft Teams <a href=\"https:\/\/www.techrepublic.com\/article\/watch-out-zoom-microsoft-teams-now-has-more-than-115-million-daily-users\/\">recently reported<\/a> 115 million daily active users.<\/p>\n<p>&nbsp;<\/p>\n<p>While Zoom has become so popular that it\u2019s its own verb (\u201cDo you want to Zoom?\u201d), this rapid growth has not been without growing pains. For several months, people have been questioning whether it is safe to Zoom and drawing attention to cybersecurity and privacy issues within the platform. Reported concerns included, e.g., a security researcher\u2019s discovery of the Zoom installer creating a local web server on users\u2019 Macs (reported on <a href=\"https:\/\/www.wired.com\/story\/zoom-bug-webcam-hackers\/\">Wired<\/a>), the veracity of Zoom\u2019s encryption claims (reported on <a href=\"https:\/\/theintercept.com\/2020\/03\/31\/zoom-meeting-encryption\/\">The Intercept<\/a>), troublesome <a href=\"https:\/\/en.wikipedia.org\/wiki\/Zoombombing\">Zoombombing<\/a> incidents (reported, e.g., by <a href=\"https:\/\/www.npr.org\/2020\/04\/03\/826129520\/a-must-for-millions-zoom-has-a-dark-side-and-an-fbi-warning\">NPR<\/a> and the <a href=\"https:\/\/www.nytimes.com\/2020\/03\/20\/style\/zoombombing-zoom-trolling.html\">New York Times<\/a>), and traffic being routed through China (reported by <a href=\"https:\/\/techcrunch.com\/2020\/04\/03\/zoom-calls-routed-china\/?guccounter=1&amp;guce_referrer=aHR0cHM6Ly9ueW1hZy5jb20vaW50ZWxsaWdlbmNlci8yMDIwLzA0L3RoZS16b29tLWFwcC1oYXMtYS1sb3Qtb2Ytc2VjdXJpdHktcHJvYmxlbXMuaHRtbA&amp;guce_referrer_sig=AQAAAKAb32Easl4ue8kZ8fELzqcHgKKSKcJZZgPGV3dkG5D00WeLuZyVuGUbpZ0UaTimvf4L7rmnNwb-jZYZ32_DeBy_OVQDRYChXpy9ZZ-t7EuQuxTaAQc3sFlslzdfZcZDyb0UyYNlaMkLXPB1PSPi_Wp28oijsVzlctIUBmXBeKWE\">TechCrunch<\/a>). In April, the U.S. Attorney for the Western District of Pennsylvania (Scott Brady) and Pennsylvania Attorney General Josh Shapiro <a href=\"https:\/\/www.attorneygeneral.gov\/taking-action\/covid-19\/u-s-attorney-scott-brady-and-pennsylvania-attorney-general-josh-shapiro-warn-against-zoom-bombing-and-hacking-teleconferences-during-coronavirus-pandemic\/\">warned<\/a> about zoombombing specifically and announced that such activity would be investigated and prosecuted by the Western Pennsylvania COVID-19 Task Force. New York Attorney General Letitia James had investigated Zoom and <a href=\"https:\/\/ag.ny.gov\/press-release\/2020\/attorney-general-james-secures-new-protections-security-safeguards-all-zoom-users\">announced an agreement<\/a> in May that the company would improve its features in order to implement a comprehensive data security program, provide additional privacy controls for free accounts, and take steps to protect users from abusive conduct. Just a month ago, Zoom found itself in trouble with the Federal Trade Commission (FTC) for unfair and deceptive trade practices related to its data security and privacy practices.<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong><em>What was at issue with the FTC and what does the proposed consent order require?<\/em><\/strong><\/p>\n<p>Details of the FTC investigation came to light when the FTC <a href=\"https:\/\/www.ftc.gov\/news-events\/press-releases\/2020\/11\/ftc-requires-zoom-enhance-its-security-practices-part-settlement\">announced<\/a> it had filed a draft administrative <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/cases\/1923167zoomcomplaint.pdf\">complaint<\/a> and proposed <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/cases\/1923167zoomacco2.pdf\">consent agreement<\/a> on November 9, 2020.<\/p>\n<p>&nbsp;<\/p>\n<p>In the complaint, the FTC alleged five ways that Zoom violated Section 5(a) of the Federal Trade Commission Act (<a href=\"https:\/\/www.law.cornell.edu\/uscode\/text\/15\/58\">15 U.S.C. \u00a7\u00a741-58<\/a>, as amended):<\/p>\n<ul>\n<li>by claiming it provided end-to-end encryption for all meetings;<\/li>\n<li>by claiming the level of encryption was 256-bit encryption when it was only 128-bit encryption;<\/li>\n<li>by misrepresenting the encryption of recorded meetings stored on the cloud, as such recordings could remain unencrypted for up to 60 days before being moved to secure cloud storage;<\/li>\n<li>by circumventing Safari browser safeguards with ZoomOpener, its installer that created a local web server on users\u2019 Apple devices; and<\/li>\n<li>by not disclosing the real details about the ZoomOpener to consumers (i.e., misrepresenting that software updates were bug fixes and failing to disclose to consumers the software updates were deploying the ZoomOpener, that this would circumvent the Safari browser safeguards, and that it would remain on the Mac device even if the Zoom app was uninstalled).<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>The FTC <a href=\"https:\/\/www.ftc.gov\/news-events\/blogs\/business-blog\/2020\/11\/zooming-zooms-unfair-deceptive-security-practices-more-about\">noted<\/a> on its website that Zoom had already \u201cdiscontinued most of the practices challenged in the complaint\u2026\u201d This is perhaps not a surprise given the company\u2019s <a href=\"https:\/\/ag.ny.gov\/sites\/default\/files\/nyag_zoom_letter_agreement_final_counter-signed.pdf\">earlier agreement with the New York Attorney General<\/a>, which obligated Zoom to take many of the same measures to enhance privacy and security of the platform.<\/p>\n<p>&nbsp;<\/p>\n<p>The proposed consent agreement would require Zoom to stop misrepresenting its platform and the platform\u2019s security and privacy features (including how it collects, uses, deletes, or shares user information). It requires Zoom to establish, implement, and maintain a \u201c<a href=\"https:\/\/www.ftc.gov\/enforcement\/cases-proceedings\/192-3167\/zoom-video-communications-inc-matter\">robust<\/a>\u201d and \u201ccomprehensive information security program.\u201d As part of that program, Zoom would need to perform security reviews of its software updates before software updates are released in order to discover not only vulnerabilities but also if the update would interfere with security features of third parties. The consent agreement also requires Zoom to submit to independent security assessments every other year to identify and address internal and external security risks. The duration of the consent order is 20 years. <a href=\"https:\/\/www.federalregister.gov\/documents\/2020\/11\/13\/2020-25130\/zoom-video-communications-inc-analysis-to-aid-public-comment\"><strong>The public has an opportunity to comment on the proposed consent agreement until December 14, 2020<\/strong><\/a><strong>.<\/strong><\/p>\n<p><strong><em>\u00a0<\/em><\/strong><\/p>\n<p>This enforcement action was a 3-2 decision by the FTC, and separate dissenting statements were issued by Commissioner Slaughter and Commissioner Chopra. A one-page majority <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1582922\/1923167zoommajoritystatement.pdf\">statement<\/a> was provided by FTC Chairman Simons and Commissioners Phillips and Wilson in which they emphasize the goal is to ensure \u201ca safe and secure Zoom that can continue to provide essential services to enable Americans to conduct business, engage in learning, participate in religious services, and stay connected.\u201d While this remark gives a nod to the diverse purposes that such a technological platform can serve, it discounts that alternatives are or should be available so that customers (individuals and businesses alike) are able to enjoy such activities without having to sacrifice their security and privacy interests.<\/p>\n<p>&nbsp;<\/p>\n<p>In his dissenting <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1582914\/final_commissioner_chopra_dissenting_statement_on_zoom.pdf\">statement<\/a>, Commissioner Chopra provided a focused discussion on the harmful effects that deceptive practices by technology companies have on customers and business competitors. In a poignant critique about where Zoom might be had it followed the law and describing its gains as a \u201cwindfall,\u201d Commissioner Chopra noted, \u201c\u2026we should all be questioning whether Zoom and other tech titans expanded their empires through deception.\u201d He proceeded to underscore how the current approach taken by the FTC to address security and privacy violations is ineffective, pointing out that the victims of Zoom\u2019s deception will not see any direct relief from the settlement\u2014paying customers will not be released from contracts or receive any refunds or credits and business competitors (i.e., competing teleconference platforms) placed at unfair disadvantage by Zoom\u2019s conduct will not be helped either. Commissioner Chopra summarized the shortcomings of the settlement as \u201c<em>No help\u2026No notice\u2026No money\u2026No fault<\/em>\u201d and concluded the settlement would have little deterrent effect. He offered seven recommendations for the FTC to \u201c[r]estore [c]redibility\u201d in its enforcement activities. Among his recommendations, he encouraged the FTC to at least consider engaging in formal rulemaking (so that it could pursue monetary penalties for violations more directly than it currently is able) and engaging in more litigation (to develop legal precedent and rebuild confidence in the agency\u2019s willingness and ability to hold wrongdoers accountable). In his recommendations, Commissioner Chopra also highlighted the importance of the FTC coordinating with other partners (including state attorneys general), noting that such cooperation could lead to \u201csuperior outcomes\u201d and implying that coordination would make better use of scarce resources used to ensure compliance with both the FTCA and similar but distinct state laws against unfair and deceptive acts and practices.<\/p>\n<p>&nbsp;<\/p>\n<p>In her dissenting <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1582918\/1923167zoomslaughterstatement.pdf\">statement<\/a>, Commissioner Slaughter stated the FTC missed an opportunity to address privacy as well as security failures and noted the decision does not provide a real remedy to affected consumers. She discussed the intertwined relationship between security and privacy and expressed her disappointment that the settlement with Zoom did not insist on remedial measures to address privacy in addition to security failings. She also highlighted that the settlement \u201cdoes a disservice\u201d by not requiring Zoom to refund or even notify paying customers who were deceived and noted support for the recommendations put forth by Commissioner Chopra as a means to improve the FTC\u2019s effectiveness.<\/p>\n<p>&nbsp;<\/p>\n<p><strong><em>What might 2021 bring? <\/em><\/strong><\/p>\n<p>It is unclear whether this Zoom consent agreement signals significant changes to the way in which the FTC will engage in the enforcement of privacy and security practices through Section 5 of the Federal Trade Commission Act in the upcoming year. One intriguing development worth watching is, as Daniel Solove and Woodrow Hartzog highlighted <a href=\"https:\/\/teachprivacy.com\/the-ftc-zoom-case-does-the-ftc-need-a-new-approach\/\">in their analysis<\/a>, the new kind of unfairness injury the FTC recognized here with Zoom: circumvention (i.e., the bypass of third-party privacy and security safeguards). Circumvention as an unfairness injury could become particularly interesting in the health information technology (HIT) space as companies move forward with implementation of the <a href=\"https:\/\/www.healthit.gov\/curesrule\/overview\/about-oncs-cures-act-final-rule\">ONC Cures Act Final Rule<\/a>, a rule intended to stop information blocking and promote individual access to health information while continuing to protect privacy and security of patient information.<\/p>\n<p>&nbsp;<\/p>\n<p>Additionally, federal policymakers are increasingly interested in providing the FTC with the tools it needs to ensure cybersecurity and data privacy for consumers and hold businesses accountable when basic, reasonable security and data privacy measures are not taken. In the past year, several bills have been introduced. Three bills prompted by the pandemic (previously discussed on this blog <a href=\"https:\/\/pbacyber.com\/index.php\/2020\/06\/01\/emerging-covid-19-exposure-notification-technology-data-privacy-and-cybersecurity-issues\/\">here<\/a> and <a href=\"https:\/\/pbacyber.com\/index.php\/2020\/06\/23\/bipartisan-legislation-proposed-to-protect-consumer-privacy-during-covid-19\/\">here<\/a>) were <a href=\"https:\/\/www.congress.gov\/116\/bills\/s3663\/BILLS-116s3663is.xml\">S. 3663<\/a> COVID-19 Consumer Data Protections Act of 2020; <a href=\"https:\/\/www.congress.gov\/bill\/116th-congress\/senate-bill\/3749\">S. 3749<\/a>\/<a href=\"https:\/\/www.congress.gov\/bill\/116th-congress\/house-bill\/6866\/text?q=%7B%22search%22%3A%5B%22HR.6866%22%5D%7D&amp;r=1&amp;s=1\">H.R. 6866<\/a> Public Health Emergency Privacy Act of 2020; and <a href=\"https:\/\/www.congress.gov\/bill\/116th-congress\/senate-bill\/3861\/text?q=%7B%22search%22%3A%5B%22S.3861%22%5D%7D&amp;r=1&amp;s=1\">S. 3861<\/a> Exposure Notification Privacy Act. More comprehensive, general data protection bills were <a href=\"https:\/\/www.congress.gov\/bill\/116th-congress\/senate-bill\/2968?q=%7B%22search%22%3A%5B%22S.2968%22%5D%7D&amp;s=2&amp;r=1\">S. 2968<\/a> Consumer Online Privacy Act (COPRA), <a href=\"https:\/\/www.congress.gov\/bill\/116th-congress\/senate-bill\/3456\/text?q=%7B%22search%22%3A%5B%22consumer+data+privacy+and+security+act%22%5D%7D&amp;r=1&amp;s=1\">S. 3456<\/a> Consumer Data Privacy and Security Act of 2020, and <a href=\"https:\/\/www.congress.gov\/bill\/116th-congress\/senate-bill\/4626\/text?q=%7B%22search%22%3A%5B%22S.4626%22%5D%7D&amp;r=1&amp;s=3\">S.4626<\/a> Setting an American Framework to Ensure Data Access, Transparency, and Accountability Act (SAFE DATA Act). While these bills have not made it anywhere close to a vote of the 116<sup>th<\/sup> Congress, they do all have a common feature in that they would entrust enforcement of data privacy and security measures to the FTC and the state\/territorial Attorneys General. The impasse continues to focus on three features: (1) definitional details; (2) whether there should be federal preemption of state laws and (2) whether individuals should have a private right of action. It seems likely that the 117<sup>th<\/sup> Congress will feature fresh efforts to advance privacy law reforms, strengthening both cybersecurity and data privacy authority of the FTC and the state Attorneys General. The FTC\u2019s settlement with Zoom and the corresponding concerns that the consent agreement does not go far enough to address privacy or provide meaningful remedies to consumers and competitors highlights the need for legislative action to ensure that the agency is (and state Attorneys General are) equipped with the tools they need to be effective.<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p>Jennifer K. Wagner, J.D., Ph.D., is a solo practicing attorney and also conducts research as an Assistant Professor in the Center for Translational Bioethics &amp; Health Care Policy at Geisinger. She is a former contributing editor of the Genomics Law Report and has published scholarly articles in prominent legal and scientific journals, including the Journal of Law &amp; Biosciences; Journal of Law, Medicine, &amp; Ethics; Albany Law Journal of Science &amp; Technology; Virginia Sports and Entertainment Law Journal; North Carolina Journal of Law and Technology; Nature Communications; Nature Medicine; American Journal of Human Genetics; Genetics in Medicine; and PLOS Genetics. She served as a AAAS Congressional Fellow in a U.S. Senator\u2019s office in 2014-2015, and her work has been cited by the Supreme Court of the United States. You may follow her on <a href=\"https:\/\/twitter.com\/home\">Twitter<\/a> as @DNAlawyer. Views expressed are her own.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Jennifer K. Wagner J.D., Ph.D. &nbsp; 2020 brought an unexpected and massive surge in the use of video conferencing platforms. In the midst of a deadly pandemic and public health guidelines intended to flatten the curve through deterrence of non-essential in-person interactions, Zoom and similar video conferencing platforms have provided a way for people <br \/><a class=\"read-more-button\" href=\"https:\/\/pbacyber.com\/index.php\/2020\/12\/11\/the-ftc-takes-aim-at-zoom\/\">Read More &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[6,4,36],"tags":[],"_links":{"self":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/396"}],"collection":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/comments?post=396"}],"version-history":[{"count":2,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/396\/revisions"}],"predecessor-version":[{"id":398,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/396\/revisions\/398"}],"wp:attachment":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/media?parent=396"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/categories?post=396"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/tags?post=396"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}