Zoom bombing is the slang term for the practice of uninvited individuals infiltrating a private or public Zoom meeting. Zoom bombers are the digital version of gate-crashers. While some remain silent and merely observe, other Zoom bombers may disrupt the entire meeting by sharing their screens or showing disturbing images. 

Zoom bombing became prominent during the pandemic, when most teams conduct meetings through Zoom. The online platform had to deploy stricter security features to reduce the risk of Zoom bombing. 

Read More about Zoom Bombing

While the phenomenon of Zoom bombing isn’t as widespread or in the news as it was at the peak of the 2020 pandemic, it still happens. Learn more about it.

How Does Zoom Bombing Happen?

Zoom bombing is essentially a digital version of walking into a party when you weren’t invited, but with malicious intent. One of the most common points of entry is the public sharing of meeting credentials. When a host posts a meeting ID or a direct link in a public forum, on social media, or in other open spaces, anyone can grab it and join.

Zoom bombing common entry points

Another risk comes from using your Personal Meeting ID (PMI), especially for public meetings, because it is static. It’s like having the same house key for every single meeting you ever host. Once a bomber has it, they can access any meeting you host using that ID.

Additionally, running an open meeting without a password and without the Waiting Room feature means anyone who clicks the link automatically gives Zoom bombers the green light. Another feature that can pose a risk is the “Join Before Host” feature, which allows participants to join before the host arrives. This feature makes the meeting vulnerable to compromise before anyone legitimate logs in.

Preventing Zoom Bombing

The power to stop a Zoom bomb is almost entirely in the host’s hands. Here’s a checklist of some settings and practices you can adjust to prevent this type of breach.

  • Stop using your PMI: Always schedule your meeting using the “Generate Automatically” option to create a unique, one-time Meeting ID for every session.
  • Require a password: Meetings should have a password to join the meeting, and consider not embedding that password in the meeting link, so it has to be entered manually.
  • Enable the “Waiting Room” feature: This is your digital bouncer. With the Waiting Room enabled, you must manually admit every single participant, allowing you to vet names and keep unknown users out.
  • Restrict screen sharing: Go to Settings and set “Who can share?” to “Only Host”. This feature prevents someone from sharing inappropriate video or imagery.
  • Lock the meeting: Once everyone you expect has joined, use the “Lock Meeting” feature. No new participants can join after this point, even if they have the ID and password.
  • Disable extra tools: Turn off in-meeting features that can be abused, such as “File Transfer,” “Participant Annotation” (doodling on the screen), and “Private Chat” (to prevent harassment between attendees).
  • Be ready to click the eject button: If a bomber sneaks through, go to the “Participants” pane, hover over the name, and click “Remove” to kick them out.

Key Takeaways

Sources

  • https://www.ucop.edu/local-it-client-services/_files/security-tips-on-sharing-zoom-meeting-links-and-zoom-settings.pdf
  • https://www.digital.pitt.edu/news/pantherbytes-blog/zoombombing