Zoom Reaches FTC Settlement Over Misleading Encryption Promises

Video conferencing platform Zoom agrees to implement a stronger security program and undergo regular assessments after the FTC accuses it of falsely claiming to offer end-to-end encryption.

Video conferencing company Zoom agrees to implement a comprehensive information security program and submit to third-party assessments every two years as part of a settlement with the Federal Trade Commission. The FTC accuses Zoom of misleading users since 2016 by falsely claiming to provide end-to-end, 256-bit encryption for secure communications.

True end-to-end encryption ensures that only the sender and intended recipients can read the content, but the FTC alleges that Zoom actually retains the cryptographic keys needed to access customer meeting data. Furthermore, the agency states that Zoom secures its meetings with a lower level of encryption than it promises to its users.

Dissenting Democratic commissioners criticize the settlement as too lenient, arguing that it fails to provide affected consumers with notice, refunds, or a way to exit long-term contracts. Commissioner Rohit Chopra specifically questions the effectiveness of mandatory third-party assessments and urges the agency to focus on tangible help for individual consumers and small businesses rather than additional paperwork.

Read More at the original source →