Zoom ändrar sig: Erbjuder alla kryptering
Videokonferenstjänsten Zoom fick en hel del kritik när man för en tid sedan aviserade att man skulle rulla ut så kallad end-to-end-kryptering till enbart betalande användare. Andra användare skulle få nöja sig med en mindre robust kryptering.
Men nu har Zoom ändrat sig, och uppger att man kommer att erbjuda samtliga kunder end-to-end-kryptering. För icke betalande användare som vill utnyttja den starkare krypteringen kommer man att kräva verifiering.
End-to-end-kryptering
Wikipedia (en)
End-to-end encryption (E2EE) is a system of communication where only the communicating users can read the messages. In principle, it prevents potential eavesdroppers – including telecom providers, Internet providers, and even the provider of the communication service – from being able to access the cryptographic keys needed to decrypt the conversation.In many messaging systems, including email and many chat networks, messages pass through intermediaries and are stored by a third party, from which they are retrieved by the recipient. Even if the messages are encrypted, they are only encrypted 'in transit', and are thus accessible by the service provider, regardless of whether server-side disk encryption is used. This allows the third party to provide search and other features, or to scan for illegal and unacceptable content, but also means they can be read and misused by anyone who has access to the stored messages on the third party system, whether this is by design or via a backdoor. This can be seen as a concern in many cases where privacy is very important, such as persons living under repressive governments, whistleblowing, mass surveillance, businesses whose reputation depends on its ability to protect third party data, negotiations and communications that are important enough to have a risk of targeted 'hacking', and where sensitive subjects such as health, and information about minors are involved.
End-to-end encryption implements TLS which is intended to prevent data being read or modified, other than by the true sender and recipient(s). The messages are encrypted by the sender but the third party should not have a means to decrypt them.
No third parties should be able to decipher the data being communicated over TL, E2EE concepts must extend to data storage also, for example, companies that use E2EE are unable to hand over plain text data of their customers' to the authorities.
Omni är politiskt obundna och oberoende. Vi strävar efter att ge fler perspektiv på nyheterna. Har du frågor eller synpunkter kring vår rapportering? Kontakta redaktionen