Move Fast and Roll Your Own Crypto: A Quick Look at the Confidentiality of Zoom Meetings
In response to this confusion, Zoom released a blog post in April 2020 describing their encryption scheme. The weblog publish clarifies that Zoom doesn’t at the moment implement “end-to-end” encryption as most individuals perceive the time period; Zoom used the time period “end-to-end” to explain a state of affairs the place all convention members (besides these dialing in by way of the public switched phone community) are required to make use of transport encryption between their gadgets and Zoom servers. Zoom’s definition of “end-to-end” does not seem to be a standard one, even in the realm of enterprise videoconferencing options. As a result of Zoom doesn’t implement true end-to-end encryption, they’ve the theoretical capability to decrypt and monitor Zoom calls. Nonetheless, Zoom mentions that they haven’t constructed any mechanism to intercept their prospects conferences: “Zoom has never built a mechanism to decrypt live meetings for lawful intercept purposes, nor do we have means to insert our employees or others into meetings without being reflected in the participant list.”