Zoom Apologizes After Accidentally Routing North American Calls Through China
Zoom admits that a massive surge in traffic causes some North American video calls to mistakenly route through Chinese data centers, exposing encryption keys to local authorities.
Zoom issues an apology after security researchers at Citizen Lab reveal that some North American video calls route through China, along with the encryption keys that secure those calls. This discovery emerges as the video conferencing platform faces intense scrutiny over its security and privacy practices during a massive surge in remote work caused by the coronavirus pandemic.
The company explains that it mistakenly allows two of its Chinese data centers to act as backup servers during periods of extreme network congestion. Although Zoom uses a geofencing system designed to keep regional calls within their respective continents, the unprecedented influx of users overrides these normal boundaries to maintain platform reliability.
Because Zoom does not actually offer end-to-end encryption despite previous marketing claims, the company controls the encryption keys for these meetings. Routing this traffic through China raises significant concerns, as Chinese authorities possess the legal power to demand that Zoom surrender any encryption keys stored on servers within their jurisdiction, potentially exposing private corporate communications.