PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

Zoom's Encryption Keys Are Sometimes Being Sent to China, Report Finds

In end-to-end encryption, normally the key is generated and stored on your smartphone or laptop. However, Zoom will manage the keys over the company's servers, a few of which are based in China, according to Citizen Lab.

 & Michael Kan Principal Reporter

Our team tests, rates, and reviews more than 1,500 products each year to help you make better buying decisions and get more from technology.

Our Expert
LOOK INSIDE PC LABS HOW WE TEST
65 EXPERTS
43 YEARS
41,500+ REVIEWS

Zoom says it offers end-to-end encryption on your video conferences to help ward off spying, but don’t believe it. The San Jose-based company is not only holding on to the encryption keys, but also sending them to China in some cases, according to a watchdog group.

Citizen Lab tested the video-conferencing service to see where the encryption keys were being generated. “During multiple test calls in North America, we observed keys for encrypting and decrypting meetings transmitted to servers in Beijing, China,” researchers Bill Marczak and John Scott-Railton wrote in a Friday report.

The keys are likely being sent to China because Zoom has subsidiary offices in the country. The company’s own SEC filing shows the company employs 700 staffers in China for research and development purposes. 


Citizen Lab graphic on how the Zoom encryption keys are generated

Of course, bad actors can easily spy on your Zoom meetings if you've made the session public or failed to guard their passwords. The lack of security has resulted in a wave of Zoom-bombing incidents, prompting the FBI to warn the public about the phenomenon.

Encryption, on the other hand, can protect your messages from prying eyes as they get hosted in a database or sent over a network. In a true end-to-end encryption system, the key is generated and stored on your smartphone or laptop, which prevents the provider itself (or law enforcement) from decrypting your messages. However, in Zoom’s case, the company manages the keys from its own servers. 

“A scan shows a total of five servers in China and 68 in the United States that apparently run the same Zoom server software as the Beijing server,” the researchers said in the report. 

According to Citizen Lab, Zoom likely has company offices in China to help it cut down on labor costs. But it also means those offices fall under the jurisdiction of the Chinese government, which has the power to pressure domestic companies to hand over information.

So far, Zoom hasn’t commented on the report. But on Wednesday, it addressed the controversy over its approach to encryption. While Zoom does hold on to encryption keys, it has no system in place to readily decrypt the video sessions, according to Oded Gal, Zoom's chief product officer.

“Zoom has never built a mechanism to decrypt live meetings for lawful intercept purposes, nor do we have means to insert our employees or others into meetings without being reflected in the participant list,” Gal wrote in a blog post. 


Encrypted a picture in ECB mode and how it can still reveal the image

Still, Citizen Lab pokes some significant holes in the company’s encryption claims. The same report notes Zoom is using a weaker encryption standard, AES-128, in what’s called ECB mode. This is a bad idea, according to Citizen Lab, because encrypted video sessions will still retain patterns in the data. This can allow you to view rough outlines to video images, despite the encryption in place. 

The researchers have also found a serious vulnerability in Zoom's waiting room feature, which can be used to prevent unwanted guests from entering your meetings. "We are not currently providing public information about the issue to prevent it from being abused," the researchers wrote. "In the meantime, we advise Zoom users who desire confidentiality to not use Zoom Waiting Rooms. Instead, we encourage users to use Zoom’s password feature, which appears to offer a higher level of confidentiality than waiting rooms."

The report’s main takeaway: Zoom is fine to use for casual conversations and online teaching. But if you’re relying on the service to talk about sensitive information, such as company or government business, you should consider a more secure video conferencing tool, or messaging app such as Signal.

Zoom has said it's working on letting users store the encryption keys locally on their own hardware. But the option won't arrive until later this year and appears to be geared toward enterprises, not average consumers. Due to the coronavirus, use of Zoom has skyrocketed to 200 million daily users, up from a mere 10 million back in December. 

Further Reading

Security Reviews

Security Best Picks

About Our Expert

Michael Kan

Michael Kan

Principal Reporter

My Experience

I've been a journalist for over 15 years. I got my start as a schools and cities reporter in Kansas City and joined PCMag in 2017, where I cover satellite internet services, cybersecurity, PC hardware, and more. I'm currently based in San Francisco, but previously spent over five years in China, covering the country's technology sector.

Since 2020, I've covered the launch and explosive growth of SpaceX's Starlink satellite internet service, writing 600+ stories on availability and feature launches, but also the regulatory battles over the expansion of satellite constellations, fights with rival providers like AST SpaceMobile and Amazon, and the effort to expand into satellite-based mobile service. I've combed through FCC filings for the latest news and driven to remote corners of California to test Starlink's cellular service.

I also cover cyber threats, from ransomware gangs to the emergence of AI-based malware. In 2024 and 2025, the FTC forced Avast to pay consumers $16.5 million for secretly harvesting and selling their personal information to third-party clients, as revealed in my joint investigation with Motherboard.

I also cover the PC graphics card market. Pandemic-era shortages led me to camp out in front of a Best Buy to get an RTX 3000. I'm now following how the AI-driven memory shortage is impacting the entire consumer electronics market. I'm always eager to learn more, so please jump in the comments with feedback and send me tips.

The Best Tech I've Had:

  • My first video game console: a Nintendo Famicom
  • I loved my Sega Saturn despite PlayStation's popularity.
  • The iPod Video I received as a gift in college
  • Xbox 360 FTW
  • The Galaxy Nexus was the first smartphone I was proud to own.
  • The PC desktop I built in 2013, which still works to this day.

Read full bio