3 ms·
> In a meeting with E2EE enabled, nobody except each participant – not even Zoom’s servers – has access to the encryption keys being used to encrypt the meeting
by nemonemo 6y ago
> In a meeting with E2EE enabled, nobody except each participant – not even Zoom’s servers – has access to the encryption keys being used to encrypt the meeting.
> Zoom’s end-to-end encryption (E2EE) offering will be available as a technical preview, which means we’re proactively soliciting feedback from users for the first 30 days.
It is a commendable step forward, but I wonder what their concerns are about this feature with such a careful rollout schedule. The difference seems only about who generates/manages the key, so unless they were decrypting the packets in transit, they should not be concerned about this.
- donor20 6y agoThey made their entire business work because people could easily call into these conference calls - they have on click call ins in the invite. And before the whole meeting password stuff, it was really easy. So ease of use was priority. Existing solutions are out there for folks with high security needs (that are in some cases darn hard to use with bigger non tech groups). Your POTS phone call to a bridge is not e2e to all the other recipients. The phone system doesn't have support for E2E in many cases. And zoom still has people using phones to connect. Additionally, they have in the past done mixing and other things on the server for very large broadcast type events. Ie, instead of doing 10 streams to 4,000 people (40,000 streams) you do 10 streams, mix, then one stream to 4,000 people.
- nemonemo 6y agoSo there's trade-off between the security and the conference call quality, and this option weighs toward more security. That sounds great for customers in general. I'd wish they choose the E2E option to be the default for small meetings and non-E2E to be the default for larger meetings with some clear notification for attendees.