Zoom Meetings Not End-to-End Encrypted, Flaw Exposes Email Address and Photos of Users: Reports

Only the text-based conversation on Zoom is end-to-end encrypted.

Advertisement
By Nadeem Sarwar | Updated: 1 April 2020 16:57 IST
Highlights
  • Zoom’s ‘Company Directory’ is at fault for the privacy concern
  • Zoom has blacklisted a few domains to solve the issue
  • The company can access unencrypted meeting content

Zoom maintains a directory of email addresses with identical domain names

Photo Credit: Zoom

Zoom has lately become the go-to video conferencing platform (sorry Skype and Hangouts) as more people are now working remotely while they practise self-isolation during the coronavirus lockdown. However, Zoom has also been mired in some worrying security issues in the past few days. And despite the company assuring users that the platform is secure, there are a few lapses due to mismanagement of user data than can expose the personal information of users. Also, Zoom seems to indicate that it offers end-to-end encryption for everything, but in reality, only text chats are end-to-end encrypted on its platform.

Zoom's folly, user's tragedy

Multiple users have pointed out that they can see the email address of random people and even their photos on their respective Zoom profiles. Exposing email address to strangers is an open invitation to spam in your inbox, but there is a more worrying aspect here. One can actually start a video call with a random person whose profile appears in their contacts, without never actually knowing them. So, how did this happen?

Advertisement

Zoom actually maintains something called ‘Company Directory' where are all email addresses with the same domain name (save for generic ones like Gmail and Yahoo) are listed together. Zoom apparently perceives similar domain name endings as people working in the same company, but apparently, this method has its own flaws. If your email address has been added to one such ‘company directory', mistaking you as a colleague of hundred others, random strangers can see your photos and even call you.

When Zoom was made aware of the issue, the company blacklisted those domains. “Zoom maintains a blacklist of domains and regularly proactively identifies domains to be added. With regards to the specific domains that you highlighted in your note, those are now blacklisted”, a Zoom spokesperson was quoted as saying. Moreover, if your email address has also been compromised by a faulty listing in Zoom's directory, you can actually request Zoom to get it removed. Zoom says on its website that owners or admins can also choose to turn off the directory inclusion feature.

Advertisement

No, Zoom video calls are not end-to-end encrypted

“Zoom's solution and security architecture provides end-to-end encryption and meeting access controls so data in transit cannot be intercepted” says Zoom on its website. The statement makes one believe that Zoom calls are end-to-end encrypted, but that's not really the case. “Currently, it is not possible to enable E2E encryption for Zoom video meetings.

Zoom video meetings use a combination of TCP and UDP. TCP connections are made using TLS and UDP connections are encrypted with AES using a key negotiated over a TLS connection,” a Zoom spokesperson was quoted as saying by The Intercept. The only content that is end-to-end encrypted on Zoom is the text in chats.

Advertisement

What this means is Zoom can access the unencrypted video and audio content of users' meetings. This is not the definition of end-to-end encryption. End-to-end encryption is when the content of a text or multimedia conversation can only be accessed and decrypted by the sender and receiver because they have the decryption keys, and not the service provider itself.

This is what happens when you use apps such as Signal and WhatsApp, but that is not the case with Zoom. In broad terms, a third-party can't eavesdrop on your Zoom video or audio conversation, but the company itself can access the contents. Of course, Zoom claims to abide by the privacy norms put in place, but the way Zoom explains the security aspect of the platform on its website is a bit misleading.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Zoom
Advertisement

Related Stories

Popular Mobile Brands
  1. Here's How Much the Poco X8 Pro Series Could Cost in India
  2. Samsung Galaxy M17e 5G Debuts With 6,000mAh Battery at This Price in India
  3. OnePlus Nord 6 Series India Launch Teased as New Model Surfaces Online
  4. Vivo, iQOO to Reportedly Raise Prices of Their Phones Due to This Reason
  5. Poco X8 Pro Series Camera, Display Features Revealed a Day Before Launch
  6. Nvidia Brings NemoClaw as the Security Layer for OpenClaw Agents
  7. Samsung Galaxy A37, Galaxy A57 Spied in Leaked Hands-on Videos
  8. Claude Is Doubling the Usage Limits for the Next Two Weeks: Details
  9. iQOO Z11 Surfaces on Benchmarking Site Ahead of Its Launch in China
  10. Apple Launches AirPods Max 2 With New H2 Chip, Improved ANC: See Details
  1. Nvidia Unveils DLSS 5 Graphics Upscaler, Issues Clarification After Backlash Over 'AI Slop Filter'
  2. Samsung Galaxy M17e 5G Launched in India With 6,000mAh Battery, 50-Megapixel Camera: Price, Features
  3. Nvidia Introduces NemoClaw, an AI Stack to Make OpenClaw Agents More Secure
  4. Oppo Find X9 Ultra Specifications Leaked in Detail Ahead of Global Launch
  5. OnePlus 15, OnePlus 13s Receive Latest OxygenOS 16 Update in India With March 2026 Security Fixes
  6. Poco X8 Pro Series Price in India Leaked Alongside Storage Variants Hours Ahead of Launch
  7. Vivo, iQOO Smartphones to Get More Expensive in China as Component Prices Continue to Rise: Report
  8. iQOO Z11 With MediaTek Dimensity 8500 SoC Surfaces on Geekbench Ahead of China Launch
  9. AirPods Max 2 Launched in India With H2 Chip, Adaptive Audio, and 20-Hour Battery Life: Price, Specifications
  10. Arc Raiders' AI Voice Lines Were Re-Recorded by Human Actors After Launch, Says Embark CEO
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.