Researchers Find Major Encryption Flaws in Zoom Video Meetings

A new report reveals that Zoom uses a weak, custom encryption scheme rather than the robust AES-256 standard it claims to offer. The study also uncovers that meeting encryption keys sometimes route through servers in China.

A new report from the Citizen Lab exposes significant security weaknesses in Zoom's teleconference platform, revealing that the company uses a custom, flawed encryption scheme instead of the robust AES-256 standard it advertises. Researchers discover that Zoom actually uses a single AES-128 key in ECB mode for all participants in a meeting, a practice that security experts strongly discourage because it preserves visible patterns in the encrypted audio and video data.

The investigation highlights alarming infrastructure concerns regarding the handling of these encryption keys. Researchers verify that the AES-128 keys are sufficient to decrypt Zoom traffic intercepted on the internet, and they observe these keys sometimes transmitting to participants via servers located in China. This routing occurs even when all meeting participants and the subscribing company are located outside of China.

These infrastructure routing issues tie into Zoom's corporate structure, as the report notes the Silicon Valley-based company owns three entities in China that employ over 700 software developers. While this arrangement serves as a labor arbitrage strategy to increase profit margins, researchers warn it potentially makes Zoom responsive to pressure from Chinese authorities. Ultimately, the report concludes that Zoom's current security architecture makes the platform unsuitable for confidential communications.

Read More at the original source →