After we witnessed, what I believed to be an upward trend of collaboration companies actually collaborating, the recent news of yet another flaw in Zoom's system caught me off guard. In a blog post titled, "Our focus on security in an open collaboration world," Sri Srinivasan, SVP/GM, Team Collaboration Group, Cisco, set the record straight. They will not sacrifice end-user security for connectedness. He wrote:
"Interoperability and openness should never be a trade-off with security, and our users shouldn’t believe they need to sacrifice one over the other. Interoperability and security can and should work in unison, and this requires today’s software companies to work with some basic norms on how we collectively secure our mutual customers"
Srinivasan was responding to yet another verified weakness in Zoom's conferencing platform. For me, this signified the dawn of a new era in workplace collaboration, which could shake up the market more than we expect, going into 2020. Collaboration mega brands have worked together in recent months, with news coming from Microsoft Ignite, Dreamforce, and other major tech conferences of collaboration software/hardware developers working together.
Today, what we've seen, I believe, could signify a paradigm shift. Companies like Cisco could, as a result, become even more insular and less willing to step across the aisle to make the connected workforce a reality, reverting to a not-so-distant history of non-collaboration across the vendor landscape.
Smaller Brands Are Upsetting Legacy Providers
From Cisco's response, it is clear they are, at best, frustrated with Zoom. Such faults in a system can lead to a lack of investor confidence, and a loss of profit due to a sort of trickle-down effect that occurs after security threats get exposed.
The reality is, Cisco and Zoom need each other to thrive in an ever-changing collaboration market. Slack, BlueJeans, and, Microsoft have all gained more traction in the past few months, giving the big brands a reason to be nervous in the game of dominating the collaboration sphere.
What Happened?
This is not the first time Zoom's stirred the pot with Cisco. Back in July, we reported a US-based security startup made Cisco and Zoom aware of a dangerous exposure in one of Zoom's APIs used for Webex. The threat made it easy for anyone to identify meeting IDs so they can eavesdrop on calls at their convenience. Zoom has since remedied the blunder.
Cisco says they were notified of another "Serious security risk with the Zoom Connector for Cisco on October 31, 2019." They added, "We followed our well-established process to investigate the issue," and went on to say, "We believe Zoom had also been notified on October 31, or thereabouts. On November 18, our CISO notified Zoom’s CISO of our findings and advised immediate action to address all security risks."
In revealing the threat, Cisco effectively got out in front of the problem before it exploded in their faces. It also reinforced Cisco's commitment to transparency and ensuring customers remain safe as hackers become increasingly more imaginative. Diving back into the dilemma, the Zoom Connector for Cisco is owned and operated by Zoom Video Communications. It connects their cloud to a customers’ internal network as well as Cisco Endpoints/Video Devices and, management interfaces. Srinivasan wrote on Cisco's blog quite eloquently, so I will let him explain the problem in his words:
"Regrettably, the access (through a Zoom URL) for the Zoom Connector for Cisco hosted on zoom.us was accessible without authentication"
He went on to explain, the URL extended access to the device’s web interface by using Zoom’s on-premises API Connector to modify the Cisco web pages so users could access them from the Zoom URL outside their network.
The list of allegations went on, and there was even mention of a "Zoom landing page" that copied Cisco's landing page, not excluding Cisco's logo and branding. Cisco added, they believed Zoom did so with the intention of misleading customers to believe they'd arrived at Cisco's website rather than a publicly accessible URL.
Zoom Reacts
In a statement to UC Today, Zoom shared its thoughts on the matter:




