Having closed the accounts of activists a few days ago, at the request of China and specifically Beijing, Zoom decided that it needed a system that would allow it to comply with the laws of each country, so that activities that may be considered illegal by a country are not carried out. In addition, with this system, the restrictions imposed by a country will not affect citizens of other countries. The company stated on its official blog that this system would allow it to comply with the requests of local authorities when they determine that activity on platform is illegal within their borders. However, it will be able to protect conversations involving people outside of the respective borders. Zoom also pointed out that it should have foreseen the need for such a system earlier. In addition, the company seems to have understood that requests from Beijing could have even more unpleasant results. Thus, Zoom will no longer allow requests from the Chinese government to affect people who are not in China.
The video conferencing company said it had shut down one Hong Kong account and two U.S. accounts after being notified by Beijing last month that activist conferences were scheduled to take place on the anniversary of the June 4 Tiananmen Square crackdown. Beijing demanded that the company end the conferences and close the accounts that organized them, saying their activities were illegal, even though they involved users who did not live in China. Zoom also said it did not hand over user information or conference content to China, while its employees reviewed data , such as IP addresses, of conference participants to determine which meetings were attended by users from China.
The company recently announced that meetings would feature end-to-end encryption only for paying customers, with CEO Eric Yuanstating that his goal is to end the platform’s free tier to enable cooperation with U.S. law enforcement. However, this opens the door to “bad actors.”

In March, Zoom came under fire for misleading claims that it uses end-to-end encryption, stating that while it never intended to defraud any of its customers, it recognizes that there is a difference between what is commonly accepted as end-to-end encryption and how it uses it. The company also noted that its goal is to leverage encryption best practices to provide maximum security.
Citizen Lab found that the app provided encryption keys from servers in China to participants outside the country. A company that primarily targets North American customers sometimes distributes encryption keys through servers in China is concerning, given that Zoom may be legally obligated to disclose those keys to Chinese authorities.
Zoom accidentally added two of its Chinese data centers to a long list of allowed “bridges,” potentially allowing non-Chinese customers – in extremely limited cases – to connect to them when the main non-Chinese servers were unavailable.
Last year, the company was accused of using a local web server on Mac instances to avoid an extra click for users. That server was found to contain a remote code execution vulnerability
When the issue first came to light, Zoom defended its use of the web server, telling ZDNet that it was “a legitimate solution to a poor user experience,” allowing users of the platform to seamlessly connect with one click to join meetings. The next day, Zoom said it would revert to supporting the local web server with a code update, stressing that its change of course was a response to customer feedback and not a security issue. The company said at the time that no remote code execution vulnerability had ever been identified, adding that it decided to remove the web server based on feedback from the security community and its users.
