To offer end-to-end encryption, Zoom is acquiring Keybase, a provider of secure messaging and file-sharing. Keybase staff will help build an end-to-end encryption system for Zoom’s video conferencing service, which will be available to paid users.
The purchase, announced on Thursday, occurs weeks after Zoom admitted it actually wasn’t offering full encryption as previously advertised. The video conferencing service does encrypt your video sessions—scrambling the content as it's sent over an internet network and decrypting it to make the video data clear once it arrives on your computer. However, the main flaw with Zoom’s system is how the encryption keys are generated and stored on the company’s servers. Although Zoom says it's never mishandled the keys, by holding on to them, the company theoretically has the power to decrypt your video sessions, or transfer the keys to someone else, like a government authority.
To fix this, Zoom is creating an end-to-end system that will generate the encryption keys to video sessions from the meeting host’s computer — not from a company server. “This key will be distributed between clients, enveloped with the asymmetric keypairs and rotated when there are significant changes to the list of attendees,” the company said in today’s announcement. “The cryptographic secrets will be under the control of the host, and the host’s client software will decide what devices are allowed to receive meeting keys, and thereby join the meeting.”
Building this system isn’t easy. So Zoom is enlisting Keybase, which has experience managing encryption keys over the internet. Since 2017, Keybase has been offering its own end-to-end encrypted chat system, which works on PCs and smartphones.
As for Zoom, the company’s proposed end-to-end encryption does have a few limitations: It won’t work for meeting sessions that let people connect via a phone call, or when Zoom’s cloud video recording is switched on. But the system should be applicable to most users, who are connecting via PC and mobile devices.
“We believe this will provide equivalent or better security than existing consumer end-to-end encrypted messaging platforms, but with the video quality and scale that has made Zoom the choice of over 300 million daily meeting participants, including those at some of the world’s largest enterprises,” the company added.
Zoom plans on publishing more details about the end-to-end encryption implementation on May 22, with the goal of getting feedback from the security community and customers. “Once we have assessed this feedback for integration into a final design, we will announce our engineering milestones and goals for deploying to Zoom users,” the company said.
However, the fate of Keybase’s existing products is a bit murky. In a blog post today, Keybase said: “Initially, our single top priority is helping to make Zoom even more secure. There are no specific plans for the Keybase app yet. Ultimately Keybase's future is in Zoom's hands, and we'll see where that takes us.”
Not all Keybase users are happy with the move, pointing to Zoom's repeated stumbles managing the video conferencing service's security. "This is good for Zoom users, probably. They could use your expertise. (But) this is awful for Keybase users. Just deleted my account," tweeted one user. "They (Zoom) have proven time and time again they can't be trusted for calls, can't expect me to trust them with a security product."
Copyright © 2023 Powered by
Zoom acquires secure messaging company to fix video chat encryption-寸地尺天网
sitemap
文章
981
浏览
74988
获赞
12829
Tim Cook calls out 'senseless killing' of George Floyd in WWDC opening remarks
Tim Cook took the stage this morning at Apple's Steve Jobs Theater in Cupertino, California to talkPlanned Parenthood tool will help women navigate state abortion laws
Alabama got the attention of the nation in May when its governor signed a full-on abortion ban intoZoom lets a website turn on your Mac's camera without permission
Video conferencing app Zoom has a major security flaw in its Mac client, letting any website turn onMini Cooper is now electric and just as cute
The tiny British Mini Coopers have been around for decades (six to be exact) -- but on Tuesday the fJameela Jamil posts Instagram about the stretch marks on her boobs
Boob stretch marks. A lot of us have them. But Jameela Jamil has decided to nickname hers "babe markMotorola patent application seeks to track people who switch phones
Think twice before buying your next smartphone. A Motorola Solutions patent application published on15 gifts true fans of 'The Office' need in their lives
Fans of The Officeare loyal as hell, and you know what? It's about time they get rewarded for their'Agent Smith' Android malware infected 25M devices
A new strain of Android malware has infected 25 million devices and modified legitimate apps with aApple could debut its new laptop chip in a Macbook Pro this year
A few weeks after Apple announced it would start developing its own silicon chip for Mac computers,Amazon reveals new Prime Air delivery drone
Amazon has been promising fast drone deliveries for years, and this year was no exception at the comNew FaceTime feature forces you to make eye contact
FaceTime and other forms of video calling are already inherently weird, but Apple seems committed toReddit user allowed to remain anonymous following court ruling
A Reddit user who faced a legal fight to reveal their identity has been allowed to stay anonymous, aGoogle Maps and YouTube Music just made some commutes a little better
Google Maps has featured music controls for Spotify, Apple Music, and Google Play since 2018, but itCongressman implies Facebook's Libra is a 'shitcoin'
Congressman Warren Davidson really wants to talk about shitcoins.The representative from Ohio took pTrump's ridiculous notes have spawned more Sharpie memes
As the impeachment hearings rage on, President Donald Trump is busy scrawling extremely official st