FTC Penalizes Zoom Over Deceptive End-to-End Encryption Claims

The Federal Trade Commission reaches a settlement with Zoom after accusing the company of lying about its end-to-end encryption capabilities. The regulator requires Zoom to implement stronger security measures and prohibits future misrepresentations of its privacy practices.

The Federal Trade Commission announces a settlement with Zoom after accusing the video calling giant of deceptive and unfair practices that undermine user security. The FTC reveals that Zoom falsely claims its video calls feature end-to-end encryption, a security measure that prevents anyone, including the company itself, from accessing meeting content.

In reality, Zoom maintains the cryptographic keys necessary to access customer meetings and secures its calls with a lower level of encryption than promised. The FTC complaint also alleges that Zoom stores unencrypted meeting recordings on its servers for up to two months and covertly installs a web server on user computers to facilitate faster meeting entry, which Apple eventually forces the company to remove.

As part of the settlement, the FTC prohibits Zoom from misrepresenting its security and privacy practices moving forward. Zoom agrees to start a vulnerability management program and implement stronger security across its internal network, while a company spokesperson claims the organization already addresses the issues identified by the regulator.

Read More at the original source →