NYC Just Banned Zoom From Classrooms, and I Think They Aimed at the Wrong Target

NYC Just Banned Zoom From Classrooms, and I Think They Aimed at the Wrong Target

Tech News covid-19 edtech privacy remote-learning zoom

Been meaning to write this for a few days and kept getting pulled back into work calls, which is sort of the whole point of this post, so here we go.

Earlier this month New York City's Department of Education told every public school in the system to stop using Zoom for remote classes and switch over to Microsoft Teams instead. If you haven't been following along: this is the same Zoom that half the internet has been living inside of for the past four weeks, the one your book club uses, the one my company switched to on March 16th when we all got sent home. NYC is the largest school district in the country, something like 1.1 million kids, so this isn't a small decision. And I get why they made it. I just don't think it's the right one.

The backstory, quickly, in case you've been too busy doom-scrolling to keep up: "Zoombombing" became a thing almost overnight. Randos crashing meetings, screen-sharing porn into classrooms, that whole mess. The FBI's Boston field office put out a warning about it near the end of March after a couple of ugly incidents at Massachusetts schools. Eric Yuan, Zoom's CEO, responded on April 1st by announcing the company was freezing all new feature work for 90 days so engineering could focus entirely on privacy and security fixes. A few days after that, Zoom turned on passwords and waiting rooms by default for free and single-license Pro accounts, which is exactly the kind of thing that should've been the default from day one, sure. But it happened. Fast, actually, for a company this size.

And this is the part that bugs me: almost none of the Zoombombing incidents were some deep flaw in Zoom's code. They happened because meeting links got posted in public places, or because hosts didn't turn on a password, or because "screen share: anyone" was left on. That's a defaults problem and a training problem, not an encryption problem (though Zoom's "end-to-end encryption" marketing turned out to be pretty loosely defined, which is a separate and fair complaint). Fixing defaults is exactly what Zoom just did. Banning the app a few days later, after the fix, feels like showing up to complain about a fire that's already out.

Meanwhile Teams is not some flawless alternative that's been quietly waiting in the wings. It's clunkier to set up, the mobile app has always felt like it was designed by three different teams who never spoke to each other, and I say this as someone who's used it daily at a previous job. Rolling it out to a million students and tens of thousands of teachers with basically no runway, in the middle of April, sounds like its own kind of disaster waiting to happen. I talked to a friend who teaches fourth grade in Queens on Sunday and she was not thrilled, to put it mildly. She'd finally gotten her whole class comfortable clicking into Zoom links every morning at 9. Now she's relearning a new interface on the fly while also, you know, teaching nine-year-olds long division through a webcam.

I don't think this is really about which product is more secure. I think a big public institution needed to be seen doing something after a scary headline, and switching vendors is a much easier thing to announce than "we're going to require passwords on every meeting starting tomorrow," even though the second one probably solves more of the actual problem. Optics over substance. It happens with tech policy constantly and this is just the most visible recent example.

For what it's worth, my own team is sticking with Zoom for now. We turned on waiting rooms the day they showed up as an option, we stopped posting meeting links anywhere public, and in four weeks of daily standups we've had zero incidents. That's anecdotal, obviously, one data point isn't a trend. But it's also kind of the whole argument: the fixes work when people actually use them. Banning the tool doesn't teach anyone to use a password.

Anyway. Back to my own 11am call, which I will be joining through a link that is, in fact, password protected.