Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Zoom’s HIPAA product documentation does define Zoom’s “end-to-end encryption” as:

https://zoom.us/docs/doc/Zoom-hipaa.pdf

> Meeting data transmitted across the network is protected using a unique Advanced Encryption Standard (AES) with a 256-bit key generated and securely distributed to all participants at the start of each session.

It does not guarantee that the key is withheld from the server, which is unsurprising given that e.g. the recording and chat history features are implemented server-side.

EDIT: For comparison, the Australian government provides a telehealth platform that clearly states it does not allow the server to inspect the call video/audio:

https://help.vcc.healthdirect.org.au/about-healthdirect-vide...

> Data shared in actual calls between participants is only ever available in decrypted form to the participating endpoints of the call. All other intermediaries that forward the call can only see encrypted data.

For those looking to hold Zoom accountable, the question to ask is: “Does your country’s law permit Zoom’s servers to be considered an ‘endpoint’ capable of decrypting a telehealth call?”.



As a note, to be HIPAA compliant you also need to sign a BAA with Zoom. This, interestingly, disables cloud capture and a bunch of other things.

https://support.zoom.us/hc/en-us/articles/207652183-HIPAA-Bu...


I'm not sure a company can make their own definition of "end-to-end encryption" and say they're E2E because they meet their own definition of the term.

Sure, they're legally in the green perhaps. But this is not E2E, it is not the decades-long definition of E2E, and this is ultimately deceptive marketing.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: