Zoom meetings are not as private as advertised: What you should do
Zoom's end-to-end encryption fail
Zoom has seen historic growth this year as the video conferencing service of choice for those who are working remotely in the face of the COVID-19 pandemic. But the company's end-to-end encryption is now being called into question due to a report from The Intercept.
This is hardly the first security incident for Zoom; macOS users will remember the massive security bug from last summer, but a considerably greater amount of attention is on the company given its rising popularity.
While the company touts end-to-end encryption in its marketing and security white paper, Zoom fails to meet the traditional definition of end-to-end encryption in one crucial way.
- Best video conferencing apps and software
- Where to buy a webcam: In stock at select retailers
- Zoom, Google Hangouts attract phishing and malware hackers: how to protect yourself
Yes, Zoom completely encrypts your video conference while it's in transit, meaning no one can intercept the stream and view it. However, Zoom has access to your unencrypted video and audio on its end. This means Zoom staff could potentially view your content or Zoom could be compelled to turn your content over to law enforcement.
Zoom issued this response to The Intercept:
"Zoom takes its users’ privacy extremely seriously. Zoom only collects data from individuals using the Zoom platform as needed to provide the service and ensure it is delivered as effectively as possible. Zoom must collect basic technical information like users’ IP address, OS details and device details in order for the service to function properly."
The company continued, "Zoom has layered safeguards in place to protect our users’ privacy, which includes preventing anyone, including Zoom employees, from directly accessing any data that users share during meetings, including — but not limited to — the video, audio and chat content of those meetings. Importantly, Zoom does not mine user data or sell user data of any kind to anyone."
Stay in the know with Laptop Mag
Get our in-depth reviews, helpful tips, great deals, and the biggest news stories delivered to your inbox.
Clearly, it is in the company's best interest to keep your data private and secure, but as it stands, there are some circumstances where this would not be possible. Whether this concern is enough for you to stop using Zoom is up to you. Many users will likely shrug this off as not a significant worry as the service runs well and meets their needs.
The more troubling aspect is that Zoom was misleading customers with its claims of end-to-end encryption. We hope, at a minimum, to see that language clarified on its website and marketing. Whether the company is also able to address this and move to a true end-to-end encryption model remains to be seen.
For those who are worried about the security implications, some other services that we like that do offer true end-to-end encryption include Cisco's Webex and GoToMeeting.
Sean Riley has been covering tech professionally for over a decade now. Most of that time was as a freelancer covering varied topics including phones, wearables, tablets, smart home devices, laptops, AR, VR, mobile payments, fintech, and more. Sean is the resident mobile expert at Laptop Mag, specializing in phones and wearables, you'll find plenty of news, reviews, how-to, and opinion pieces on these subjects from him here. But Laptop Mag has also proven a perfect fit for that broad range of interests with reviews and news on the latest laptops, VR games, and computer accessories along with coverage on everything from NFTs to cybersecurity and more.