Discord introduced the DAVE protocol , a custom end-to-end encryption (E2EE) protocol, to protect voice and video calls on the platform.

DAVE was created with the help of cybersecurity experts.
End-to-end encryption will cover audio and video calls between users (two people) in private channels, as well as calls in small group chats , server-based voice channels used for larger group chats, and real-time streaming
“You will be able to confirm when calls are end-to-end encrypted and verify other members on those calls,” the platform says.
See also: GSMA: End-to-end encryption plans for RCS messaging
Introducing end-to-end encryption to Discord can significantly enhance the security of user data and privacy.
End-to-end encryption is a data protection method that allows for the secure transmission of information over the internet. In this technology, data is encrypted at the source and decrypted only at the destination, ensuring that only the recipient can see the information. The idea is to protect data from prying eyes during transmission, preventing it from being intercepted, monitored , or modified by third parties.
Additionally, the popular platform has decided to make the protocol and supporting libraries open source, which means security researchers can audit the code to identify potential bugs.
Discord: DAVE protocol for end-to-end encryption
DAVE allows media frames (audio and video) to be encrypted after encoding and before being packetized for transmission. The receiver decrypts the frames and then decodes them. Only codec-specific metadata, such as headers and reserved sequences, remain unencrypted.
In terms of key management, the Messaging Layer Security (MLS) protocol is used for secure group key exchanges, with each participant having a “per-sender symmetric media encryption key.” The Elliptic Curve Digital Signature Algorithm (ECDSA) is used to generate identity key pairs.
See also: Chrome switches to ML-KEM quantum encryption
When the composition of a group changes (a member leaves or a new member joins), changes are made to the encryption, with the creation of new keys.

Finally, with regard to user verification, methods are used, such as comparing verification codes called "voice privacy codes" and derived from the team's MLS epoch state.
Persistent tracking is prevented by using ephemeral identity, as users are assigned a new key for each call.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Discord has already started migrating all appropriate communication channels to the DAVE protocol, and users will be able to confirm whether their calls are protected by end-to-end encryption (there is a relevant indication).
See also: How to encrypt your emails?
However, the platform explains that the feature will be rolled out gradually. All users need to do is upgrade to the latest version of the service.
The presence of end-to-end encryption on Discord aligns with the growing demand for privacy and security in online communication. It demonstrates the platform’s commitment to protecting user data and respecting their privacy rights, which can help build trust among users and attract those who prioritize privacy when choosing a messaging platform.
Source: www.bleepingcomputer.com
