Video Calling and Video Conferencing: How to Protect Yourself From Hackers
From homeschooling for kids to full telecommuting to staying in touch with friends and family, we increasingly rely on internet technology to stay connected. It looks like this trend will only intensify over time.
Video conferencing is one of the most important elements of this process. In April 2020, the daily number of attendees for meetings using the Zoom platform reached 300 million, while in December 2019 there were only 10 million. The number of users has increased thirtyfold in just four months! The pandemic has resulted in the Zoom app becoming one of the most downloaded in recent months. Video conferencing is used not only by students, teachers, relatives, business partners, and community groups of all sizes, but also by famous personalities such as Alan Greenspan, former chairman of the Board of Governors of the US Federal Reserve, and Boris Johnson, Minister of Great Britain. But how safe are video calls and what should you do to protect yourself from the risks?
In this article, we'll focus on the main issues related to video conferencing security and the steps you can take to protect yourself.
How secure are video calling and video conferencing?
The US government believes that, given the potential for hacker attacks, moving to remote work is a national security issue. The US National Security Agency recently evaluated 13 of the most popular video calling tools.
The assessment took into account, among others, the following criteria:
Does the service use end-to-end encryption that limits the ability of outsiders to intercept or eavesdrop on calls?
Does the service use multi-factor authentication that reliably protects user accounts?
Is the technology based on verifiable open-source that is considered more reliable than proprietary software?
Is data exchanged between the video calling tool and third parties or affiliates?
Can users, if necessary, permanently delete data from the service and its repositories (both from the client-side and from the server)?
The full version of the report is available here - but in short, the NSA believes that every video call service has some kind of vulnerability or even several. For example:
Google G Suite and Microsoft Teams are not end-to-end encryption or open source.
Data wiping is not fully implemented in Cisco WebEx, Zoom, Slack, and Skype for Business.
GoToMeeting doesn't have multifactor authentication.
The NSA has awarded the highest ratings to WhatsApp from Facebook, Signal (WhatsApp also uses the code for this app), and Wickr. While the report is not definitive, it does provide a useful overview of the main issues related to video conferencing security and highlights the fact that no product on the market meets all reliability criteria.
The main aspects of video call security
Key security aspects of video calls include:
End-to-end encryption
End-to-end encryption provides strong security for video conferencing, making the call only available to the appropriate users and no other person or service, including the application itself. You can read more about data encryption and how it works in our article "What is encryption".
The ability to intercept and record video calls by strangers
Can outsiders watch or record your video calls? Who can join your calls and how? With schools transferring students to Zoom online, breaching the privacy of video calls could be a safety issue for children. Calls in Zoom are accessed by navigating to a short digital URL that can be easily generated or matched.
Terms of use for your account data
How strict are privacy policies such as the EU's General Data Protection Regulation or California's privacy policy? How transparent are the terms of use of the application regarding the collection of user data and the provision of access to this data to third parties?
Storing data associated with your video calling application on your computer or smartphone
This is especially important if you are dealing with sensitive information or documents.
For example:
Skype saves the photos you receive on your device unless you change this setting (you can do this by selecting Messages from the Settings menu on your Android or iOS device).
If you download a chat from a video call to Zoom, it will also include the content of private chats between individual call participants. This can cause problems if you do not want someone other than the addressee to see your private messages during a work call.
The presence of monitoring tools inside the application
Zoom is often criticized for its attention tracking feature, which informs the call organizer if a participant has switched to another window for 30 seconds or more. This feature allows employers and teachers to check if their employees or students are following a workshop or lesson.
The ability to accidentally download malware and, as a result, become a victim of a hacker attack
For example, can users unknowingly download apps that will gain access to the camera and microphone? An app or malware can provide personal information to a hacker who can then sell it, make it public, or use it for other purposes.
So, some of the security vulnerabilities in Zoom have already been reported. In 2019, it was discovered that the Zoom app was installing a hidden web server on users' devices, with which the user could be forcibly added to a video chat. Another loophole could take over control of a Zoom user's Mac, including control of the webcam and microphone. Zoom's developers are constantly patching discovered vulnerabilities and reporting their successes on the company's blog.
Examples of hacker attacks related to video calls
One of the most discussed examples of attacks on video calls in recent years is "Zoom bombing". This is the name given to intrusions into videoconferences to disrupt them - for example, intruders may shout racist slogans or threats. Although the name of this phenomenon refers to the Zoom app, similar incidents have occurred with other video conferencing platforms, including WebEx and Skype. On March 30, 2020, the FBI announced an investigation into the increased number of cases of interception of video calls.
Several forums, including Reddit and Discord, have had concerted attempts to break into Zoom video conferencing. Twitter users offered passwords to video conferencing that could be connected to without the permission of the participants. Some negligent pupils and students disrupted online lessons in this way and incited their comrades to such behavior.
TikTok and YouTube were distributing recordings of Zoom video calls in which unauthorized users intruded into the video chat with offensive, racist, or anti-Semitic statements, after which the organizer of the call had to end the conference.
Previously, a simple Google search for addresses containing the string "Zoom.us" yielded links to non-password-protected conferences, which made it possible to connect to calls without an invitation.
Open intrusion into video conferencing, however unpleasant and discouraging for participants, is far less worrying than the unnoticed presence of outsiders, which can pose a serious risk to both corporate security and personal data privacy.
Recently, Forbes magazine reported that hackers had sold over 500,000 sets of stolen Zoom credentials, which included personal call URLs and Zoom host keys. A significant portion of these credentials likely included reusable passwords that hackers obtained from other sources.
In response, Zoom said:
“ We've already recruited several organizations to find these password databases and the tools that were used to create them, as well as a company that has already shut down thousands of websites that tricked users into downloading malware or providing their credentials. We are continuing to investigate the situation, blocking accounts that have been compromised, asking users to change their passwords to more secure ones, and considering implementing additional technology solutions to support our efforts. ”
Zoom call online risks and dangers ”
Ways to secure calls on Zoom
Since the outbreak of the COVID-19 pandemic, Zoom has become the most popular video conferencing application, overtaking both the familiar Skype messenger and the FaceTime application, which was widely used to make video calls to friends.
The rapid growth in user numbers has also led to growing dissatisfaction with Zoom not taking the security of its users' video calls seriously enough. The lack of end-to-end encryption that some users have counted on was also a concern. Zoom has released call privacy guides on its blog and video but encourages users to take action.
7 Tips to Secure Your Zoom Calls
Limit access to meetings with passwords and mandatory authentication. This will prevent strangers from connecting to the call. Exclude unwanted or disturbing participants from the conversation.
Limit screen sharing. This ensures that only the right people can share the screen.
Be vigilant when following links or opening documents sent to you. Use other communication channels to make sure that the link or document was sent to you by your interlocutor.
Do not show anything unnecessary in the frame. For example, remove all personal belongings or photographs of your children from the frame if you do not want to be viewed. You can also change the background behind you in Zoom (other video conferencing applications, such as Skype, can blur the background).
Make sure there is nothing extra on your screen before showing it to participants. For example, other tabs or windows of private conversations that can be opened, or documents that may contain sensitive financial information or personal data. Be careful not to accidentally show a letter with your address on it, your passport, credit card, or anything else that no one else should see.
Check your settings. Some security settings are not installed by default. Zoom settings for a personal computer and a mobile device are different - in the computer version, they are more detailed and give more control over security than in the mobile version. For example, in the PC version, the call organizer has more management tools at its disposal, and users can manage blocked accounts.
Try to stay tuned for app updates. This keeps you up to date with all the security and privacy features available.
Ways to secure video calls
Each platform has different ways of securing video chats, so it is important to be aware of the specifics of your specific platform. However, many of the general principles remain the same for all video communications applications.
Here are some basic tips to help make video calls safer:
Don't show too much
Keep track of what you share online, including your words and behavior in video calls. There is always a risk that someone might record you or spy on you without being noticed. Personal information should only be disclosed if absolutely necessary.
Don't share a video chat link with everyone
Do not post it to public posts on social media, online profiles, or send it in group emails or share it where others can see it. Invite people from within the app and warn them not to share the link with anyone else.
Turn on video call message forwarding notifications
That way, you know if someone else's email inviting you to chat is being passed on, and you can make sure no one else is on the call. Otherwise, you can figure out why the invitation fell into the wrong hands. Schedule another appointment with your new login information if necessary.
Set a strong password
Most video calling apps offer the ability to password protect calls. Create a strong password that is difficult to guess. Set strong passwords and do not use the same password for different applications and services.
Update your software regularly
Most often, security vulnerabilities and exploits are found in outdated versions of applications. Updates often include security fixes that address bugs and vulnerabilities. Keeping your video conferencing app up-to-date is one of the most effective ways to protect yourself from hackers because it is by releasing updates that developers fix security breaches. This is a precaution that should always be taken, not just for video calling and video conferencing applications. Updating apps and other software on your devices are straightforward across all major platforms. In most cases, you won't even have to do anything other than confirming the update. Make sure the participants in the conversation are also using the latest version of the app.
Deny further connection of participants as soon as all invitees join the conference
If one of the invited participants loses the connection to the chat, you need to temporarily allow the connection so that such a participant can return and deny it again.
Use the lounge function
These features allow participants to be directed to a separate virtual room before the conference begins. The host or presenter manually admits only the required participants to the conference. You can talk to each participant at the start of the call to make sure no one else is in the meeting.
Examine the materiel
It is always a good idea to know all the specifics of your video conferencing software before using it. Go through all the settings, look at the user profile, explore all the available options in case you need to change any of them. If something is not completely clear and you are not sure how to proceed, make a note to yourself to deal with this issue later.
how to protect video calls online
Take advantage of additional security features
It never hurts to go over your video call settings to see if you can add extra security.
For example:
Skype lets you choose whether other people can find you by phone number or email address.
FaceTime also gives you the ability to allow or prevent other people from finding you by your phone number or email address. Disabling this feature can be useful if you are not eager to renew relationships with classmates who have not been seen since school, or distant relatives.
In Google Duo is a function of "tuk-tuk", which allows the call recipient to see the camera image of the caller before answering the call. If you don't like this idea, click on the three dots in the upper right corner of the Duo app's home screen, go to settings and disable this feature.
Call only those you know
Make sure you can trust the person you are talking to before disclosing any personal information. Only accept chat requests or calls from people on your friend list.
Enable two-factor authentication
This will make it more difficult for hackers to gain access to your devices or accounts since the system will require not only a password but also an additional PIN.
Close the application when not using it
Corporations will try to spy on you whenever possible, so it's best not to help them with this. Cover the webcam on your device when not in use, and always close the app after using it, rather than just switching out of it.
Don't let conferences be recorded
Prevent anyone other than the host from recording the conference, or set up notifications to know when someone starts recording.
Disable any options that give the application too many rights
For example, any settings that allow the transfer of data to third parties, as well as all functions that are supposedly supposed to help improve your user experience by providing advertising companies or partners with access to your data. Turn off the settings that allow strangers to find you, add you as a friend, join your group or conversation, or send you messages. Disable the ability to record audio and video from your camera for all users. Set passwords for all services.
Only play video from your camera when needed
By turning off your webcam and switching only to voice communication, you will prevent any attempts to find out personal information about you that the surrounding objects may give out. It also reduces bandwidth usage and improves overall sound and picture quality.
If you plan on inviting many participants, a webcast format may be more appropriate than a video call.
A webcast is an online conference or presentation. Participants can watch speeches, ask questions to speakers and communicate with each other. Webcast control is only available to the host and select speakers. This format can help better control large numbers of participants.
Exercise caution when using public Wi-Fi networks
The features of free Wi-Fi hotspots that appeal to users are equally attractive to hackers - for example, the ability to connect without authentication. This allows attackers to gain unhindered access to unsecured devices connected to such a network. Therefore, when connecting to public networks, you need to take precautions.
Give your phone only to those you fully trust
With your phone in hand, an attacker can easily install a hacker application and create big problems for you.
Remember, hackers and cybercriminals are very adventurous. The growing use of video conferencing is making it a priority target for cybercriminals. Companies looking to stay ahead of the game will not only need to improve their video calling technology, but they will also have to work tirelessly to protect users.
And you can take care of yourself with the help of an antivirus solution, which protects your personal computer and Android devices from viruses, reliably stores passwords and personal documents, and encrypts data that you send or receive through a secure connection ...

Comments
Post a Comment