That was July.
https://www.schneier.com/blog/archives/2019/07/zoom_vulnerab...
I read the linked article. At no point did it (or as far as I can recall any of the coverage at the time) say that the video stream data could be accessed via the local web server. The problem was already bad; no need to make spurious claims to make it worse.
Zoom's older competitors; Microsoft (Skype), Google (Meet), WebEx, etc have undergone similar scrutiny with the similar results - bad press followed by engineering fix.
I know we all make mistakes, bugs happen, etc. However, if you can't reason through why it's not safe to bind an HTTP server to localhost and consider clients trusted on a laptop that might also run a web browser ... This and other prominent bugs suggests that among other things, security was not a part of the culture or mindset of the rank and file. I don't think you can use "it's a startup, bro" as an excuse for that.
They need scrutiny, especially given that their security record is subpar. Bad actors aren't self-isolating themselves from internet during pandemic.
If I were a bad actor, I'd totally go after Zoom as an attack vector, given its sudden adoption, without proper security reviews by organizations.
This software smells like it started as an internal tool for a company that escaped.
My wife sent me a link to join a meeting for testing. Normally when you have a link and want to have a desktop app use it there's some protocol handler that's registered with the app.
Nope - you click the link, it downloads what appears to be an on-the-fly generated exe that talks to desktop zoom.
I get the "remove all friction" sentiment but it feels so off compared to any other web/desktop stack of technology.
The best way to weather it is to write secure software that doesn't do stupid thngs (like reinventing sudo without protections) and not to slimy things (like trying to deceive your users about your lack of end-to-end encryption). If you choose to do those things instead, people are going to talk about it.
It doesn't help that Zoom has a history of bad practices. Just last year Apple had to issue a silent security updates to macOS to patch Zoom's zero day vulnerabilities Zoom denied existed.
... and so on