4 ms·
My understanding of how these E2E products often do their (video) call encryption is not that they use a clever communication protocol like the one used in Sign
by kelnage 7y ago
My understanding of how these E2E products often do their (video) call encryption is not that they use a clever communication protocol like the one used in Signal to protect each frame/packet (which would likely introduce huge amounts of delay - not a good user experience!). Instead during call initiation, they do the key negotiation/sharing over the same messaging protocol they use to transmit their normal messages; i.e. effectively they generate the call encryption key on the device, send it as a E2E encrypted message to the call recipient(s), and use the standard call encryption methods (probably based on SRTP?) to actually protect the call.
Thus, assuming the call encryption methods work correctly (which I have no immediate reason to believe they don't), for an adversary to obtain the key (and decrypt the call), they would need to break the E2E encryption used to transmit the messages; therefore the call is E2E encrypted.