A question a couple of my clients have called me to troubleshoot an issue that I want to bring to light. And it’s one that I have been able to reproduce rather easily.
Here’s the rundown.
If you have Zoom 5.91 or earlier installed on your Mac, and you’re running macOS Monterey 12.1 or earlier, and the Zoom app is running but not in a meeting of any sort, you’ll eventually notice that the orange dot that denotes when your microphone is in use appears in the top right corner on the menu bar. It will look like this:
One of the things that was added to macOS Monterey was a notification that lets you know when the microphone is in use. And that notification is the orange dot that you see above. And it appears that the Zoom app is apparently using the microphone. Which I confirmed by checking control center.
I tested this after reboots and in one case a reinstall of macOS and always got this result. Now to be clear, my guess is that Zoom are not spying on their users. But this isn’t a good look for Zoom regardless as many people are going to assume that they are. And in the process of researching this, I found out two things:
- First, this was supposedly fixed in version 5.91 of Zoom as per these release notes. But that apparently does not seem to be true as I was able to reproduce this numerous times on numerous macOS computers with version 5.91. This takes away Zoom’s ability to say that users should simply update to the latest version.
- Second, I am not alone in seeing this. This thread in the Zoom community along with this thread on Stackexchange details people seeing this as well. So clearly this is a pervasive problem that hasn’t been addressed by Zoom.
My advice is that you should only run the Zoom client when you actually need it until this gets addressed. Or if you’re really paranoid, use another conferencing product. As for Zoom, they’ve had their issues with security over the years. If you search my blog you will find those stories with ease. They need to step up and put this to bed quickly if they want to avoid going back to the days where trust in their product was questionable at best.
UPDATE 2/11/22: Zoom said that it has fixed the issue in version 5.9.3. But they said that in version 5.9.1 so I would only run Zoom when you need to run it to mitigate this issue should it still be present.


Zoom To Pay Up Big Time In “Zoom-Bombing” Class Action Lawsuits
Posted in Commentary with tags Lawsuit, Zoom on April 24, 2022 by itnerdFor those of you who aren’t aware of this. “Zoom-Bombing” is when uninvited guests crash your Zoom meeting and do anything from just listen in to playing porn, or anything in between. It was a big deal a couple of years ago. This led to a string of class action lawsuits against Zoom claiming:
I guess Zoom decided that it was cheaper to settle than to fight. Which has led to them settling 14 different class action lawsuits:
As part of the settlement agreement, Zoom Video Communications, the company behind the teleconference application that grew popular during the pandemic, will pay the $85m to users in cash compensation and also implement reforms to its business practices.
And here are the changes that Zoom must make:
As part of the settlement, Zoom has agreed to over a dozen changes to its business practices that are designed to “improve meeting security, bolster privacy disclosures and safeguard consumer data”, according to court documents.
As part of those changes, the company is required to develop and maintain a user-support ticket system to track reports of meeting disruptions, a documented process for communicating with law enforcement regarding disruptions that include illegal content, a suspend-meeting button and the ability to block users from certain countries.
A lawyer representing Zoom put out a comment putting some spin on this:
Mark Molumphy, a partner at Cotchett, Pitre & McCarthy, LLP said:
“Millions of Americans continue to use Zoom’s platform with the expectation that their conversations will be kept private and secure. This groundbreaking settlement will provide a substantial cash recovery to Zoom users and implement privacy practices that, going forward, will help ensure that users are safe and protected.”
But at the same time a lawyer representing the plaintiffs had this to say:
Tina Wolfson, a partner at Ahdoot Wolfson said:
“In the age of corporate surveillance, this historic settlement recognizes that data is the new oil and compensates consumers for unwittingly providing data in exchange for a ‘free’ service. It also compensates those who paid for a product they did not receive and commits Zoom to changing its corporate behavior to better inform consumers about their privacy choices and provide stronger cybersecurity.”
Now, you don’t have to wait for Zoom to make changes to protect yourself from being “Zoom-Bombed”. Here’s my tips for using Zoom safely:
The first four items will help you to mitigate “Zoom-Bombings”. The last three are more of a suggestion to protect your privacy.
Hopefully Zoom learns from this as this is not the first time that Zoom has paid up to make a lawsuit go away. And I have to imagine that cutting these cheques is starting to get expensive.
Leave a comment »