Last week, I wrote a piece about Zoom's security and its 90-day plan to combat occurrences like Zoombombing. Zoom's Founder and CEO, Eric Yuan, announced in April, the company would enact a 90-day plan to combat its security flaws. Two weeks after making that announcement, Zoom reached a monumental milestone on its timeline to sharpen security for its influx of new users, launching version 5.0.
[caption id="attachment_21567" align="alignright" width="200"]
Eric Yuan[/caption]
Zoom recently reached another significant milestone on its 90-day quest to clean up its security for users, with the acquisition of Keybase. The team of developers designed a secure messaging and file-sharing service that relies on the company's expertise in encryption and security and have been around since 2014.
Yuan said he wanted to turn Zoom into the most broadly-used enterprise end-to-end encryption offering. And the acquisition of Keybase could bring the company one step closer, he acknowledged in a statement:
"This acquisition marks a key step for Zoom as we attempt to accomplish the creation of a truly private video communications platform that can scale to hundreds of millions of participants"
Today's Zoom Encryption
According to Zoom, audio and video content that travels between Zoom clients gets encrypted 'at each sending client device.' The company wrote in a recent blog post, "it is not decrypted until it reaches the recipients’ devices."
The launch of Zoom 5.0 means that system-wide account enablement of AES 256-bit GCM encryption will occur May 30, 2020. Only Zoom clients on version 5.0 or later, including Zoom Rooms, can join Zoom Meetings starting that day. These encryption keys get generated by Zoom’s servers, however.
Some features widely used by Zoom clients, like support for attendees to call into a phone bridge, or the use of in-room meeting systems offered by other companies, will always require Zoom to keep some encryption keys in the cloud, Zoom said in a statement.
Zoom of the Near Future
Yuan said Zoom will soon offer end-to-end encrypted meetings on all paid accounts. "Logged-in users will generate public cryptographic identities that are stored in a repository on Zoom’s network and can be used to establish trust relationships between meeting attendees."


Max Krohn[/caption]

