Researchers Find Zoom Encryption Flawed and Linked to Chinese Servers
A new report from the University of Toronto reveals that Zoom uses a home-grown encryption system with serious weaknesses and sometimes routes encryption keys through servers in China. The researchers warn that the platform is not suitable for sharing secrets.
Researchers at the University of Toronto's Citizen Lab discover that Zoom relies on a custom encryption system that contains serious, well-known weaknesses. The report reveals that the popular video conferencing platform does not offer true end-to-end encryption, despite previous misleading claims by the company. Instead, Zoom distributes a single shared key to all meeting participants to secure their audio and video feeds.
The investigation uncovers a surprising geographical issue where Zoom sometimes generates and distributes these encryption keys using servers located in China, even when all meeting participants are in North America. Because Zoom employs at least 700 people across three Chinese subsidiaries, researchers warn the company is potentially legally obligated to disclose these encryption keys to Chinese authorities upon request.
In addition to the problematic encryption routing, the security team identifies a separate vulnerability in Zoom's "waiting room" feature. Based on these accumulated findings, the researchers issue a strong warning to users, concluding that Zoom's current infrastructure is inherently "not suited for secrets" and remains potentially vulnerable to outside pressure.