-
A single group key generated by the server, ECB block cipher mode. This is nearly as far away from what we call end-to-end encryption as ROT-13 would be. Note: This doesn't mean that Zoom can't be used, just that it doesn't provide real encryption. Do your own risk mitigation. @citizenlab/1246016180139315200
-
If @zoom_us wanted to fix this, I am still a fan of MLS (protocol.messaginglayersecurity.rocks/). I have no idea what the implication would be on many of the server-side features, but even with a server instance joining such a group, it's a whole lot better than in-house roll-your-own crypto.
-
Since I was asked: Personally, I still use Zoom (and the various other native video meeting clients) on an old, physically separate laptop running (an up-to-date) Windows 10 and Office, and nothing else.