Zoom Meeting IDs Can Be Guessed by This Automated Tool; Company Removes Feature Displaying LinkedIn Data

Zoom recommends users to password-protect meetings to avoid invaders.

Advertisement
By Jagmeet Singh | Updated: 3 April 2020 17:31 IST
Highlights
  • Zoom is claimed to have enabled password protection by default
  • However, Random Zoom meeting IDs were found using zWarDial tool
  • Zoom has disabled the feature displaying LinkedIn details to hosts
Zoom Meeting IDs Can Be Guessed by This Automated Tool; Company Removes Feature Displaying LinkedIn Data

Zoom has disabled the feature that was allowing meeting hosts to see the LinkedIn profiles of attendees

Zoom has claimed to have shifted its focus towards user privacy and security, and the company recently even started restricting uninvited attendees from virtual meetings. However, security researchers are able to highlight its loopholes through an automated tool that can bypass the measures and find 100 Zoom meeting IDs in an hour. The tool called zWarDial is also said to have a success rate of around 14 percent for each instance. In a separate news, Zoom has disabled a feature on its platform that would help meeting hosts see the LinkedIn profiles of individuals, without requiring any explicit permissions.

Security professional Trent Lo and his fellow members of Kansas City-based security meetup group SecKC have built the zWarDial tool that scans for meeting IDs by routing the searches through various proxies on Tor, as reported by cybersecurity expert Brian Kerbs. The tool is said to have the ability to evade the restrictions that the video conferencing app has in place to block automated meeting scans and helps find meetings that aren't protected by a password.

The program uses software-level automation to arrange information about 2,400 Zoom meetings that can include links to join each of those meetings, the date and time of the meeting, and the name of the organiser among other details. Also, it is touted to have a 14 percent chance of finding an open meeting each time it tries to attempt with a random meeting ID.

Guessing of random IDs isn't difficult for hackers as each Zoom meeting ID consists of nine to 11 digits, as noted by Kerbs. This could also allow individuals to join meetings between some professionals or even an online class for school students.

Advertisement

Some instances of disrupting virtual meetings by entering without an invite were noticed in the past. The term for causing disruption has even become famous as “Zoombombing”.

Having said that, the zWarDial tool seems to have no impact on meetings that are protected by a password. This is something that Zoom also recommends and enables by default, as highlighted on one of its support pages.

Advertisement

The company said in a statement to The Verge that passwords for new meetings have been enabled by default since last year.

“We are looking into unique edge cases to determine whether, under certain circumstances, users unaffiliated with an account owner or administrator may not have had passwords switched on by default at the time that change was made,” it added as quoted by the publication.

Advertisement

You can password-protect your Zoom meetings manually by going to the Meetings tab and then clicking the Edit button under your personal meeting ID. You'll then need to check the Require meeting password checkbox and enter your preferential password.

In addition to the issues with meeting IDs, Zoom is found to have the LinkedIn-specific feature in place that was allowing meeting hosts to view your professional details such as location, employers, job titles, and work experience among others. The feature was working as an integration with the LinkedIn Sales Navigator service that is meant for helping sales professionals mine data of their prospects online.

Zoom was automatically sending the name and email addresses of individuals to a company system when they signed in to a meeting to match the details with their LinkedIn profiles, The New York Times found in an investigation. It was also noticed that the feature was overriding privacy settings of users and even providing LinkedIn data when the Zoom profiles were anonymised using pseudonyms for signing in to a meeting.

In a statement to the publication, Zoom said that it was “removing the LinkedIn Sales Navigator to disable the feature” that was available for users who subscribed to the paid service. LinkedIn also separately confirmed the suspension of the feature.

The coronavirus outbreak has led to the massive growth in Zoom meetings. The app surpassed the mark of over 200 million daily users in March. Nonetheless, the ongoing issues are impacting its success. The company even announced a feature freeze for 90 days to address security concerns. It also did fixes to flaws such as silently sharing data with Facebook and apologised for its misleading end-to-end encryption claim.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Zoom meetings, Zoom app, Zoom
Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Announces 'Now or Nothing' Sale in India: Check All Offers
  2. Motorola Edge 60 With 5,500mAh Battery Launched in India: Price, Offers
  3. Samsung Galaxy S25 Ultra Allegedly Saves Life by Stopping Shrapnel
  4. Know All About Apple's New Liquid Glass Design Language
  5. iOS 26, iPadOS 26 Are Compatible With These iPhone and iPad Models
  6. Here's When the OnePlus Nord 5 and OnePlus Nord CE 5 Could Launch
  7. Nothing Phone 3 Leaked Render Suggests Design, Triple Rear Camera Unit
  8. Realme Announces Limited-Time Discounts on Realme GT 7 Series in India
  9. James Webb Space Telescope Captures Stunning Near-Infrared View of Sombrero Galaxy
  10. Android 16 Update Is Coming Soon - Here's What to Expect
  1. OnePlus Nord 5, OnePlus Nord CE 5 Launch Date Leaked: Expected Specifications
  2. NASA Slightly Raises Odds of Asteroid Hitting the Moon in 2032 After Updated JWST Data
  3. James Webb Space Telescope Captures Stunning Near-Infrared View of Sombrero Galaxy
  4. Perseverance Rover Studies Ancient Martian Rocks at Fallbreen and Forlandet Quadrangle
  5. The Prosecutor OTT Release Date: When and Where to Watch it Online?
  6. Eleven OTT Release Date Announced: Know Where to Watch This Tamil Crime Thriller
  7. Nothing Announces 'Now or Nothing’ Sale in India for Nothing and CMF-Branded Products
  8. What is Liquid Glass Interface, Apple’s New Universal Design Language for iPhone, iPad, Mac, and Other Devices
  9. Activision Says It's Working With Nintendo to Bring Call of Duty to Switch After Black Ops 7 Reveal
  10. Asus TUF Gaming F16, TUF Gaming A16, ROG Strix G16 and ROG Zephyrus G14 2025 Variants Launched in India
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.