Zoom Faces Backlash Over Misleading End-to-End Encryption Claims

An investigation reveals that Zoom uses transport encryption rather than true end-to-end encryption, allowing the company to potentially access meeting content.

Zoom faces intense scrutiny after an investigation by The Intercept reveals that the video conferencing app's end-to-end encryption claims are misleading. While Zoom asserts that meetings are fully protected, the service actually uses TLS transport encryption, which is the same technology that secures standard HTTPS websites. This means the video and audio content remains private from Wi-Fi eavesdroppers but is not protected from Zoom itself.

True end-to-end encryption requires local encryption keys that ensure only meeting participants can decrypt the content, a level of security that Zoom currently lacks. A Zoom spokesperson defends the company's terminology by stating that "end to end" simply refers to the connection between Zoom endpoints, rather than absolute user privacy. Despite this defense, the only feature that actually uses true end-to-end encryption is the in-meeting text chat.

Because Zoom has the technical ability to access unencrypted meeting content, the service could theoretically be compelled to hand over recordings to law enforcement or government agencies. This revelation follows recent criticism regarding Zoom's undisclosed data sharing practices with Facebook, which the company addresses by removing the Facebook log-in feature. Additionally, security researcher Patrick Wardle discloses two previously unknown zero-day vulnerabilities that impact the Zoom application.

Read More at the original source →