Encryption in Zoom calls verified by NGI-supported Verifpal

Users of the freemium videoconferencing platform Zoom raised issues of privacy and security, among others about whether the end-to-end encryption for audio and video calls actually worked as promised. Nadim Kobeissi, the lead developer for Verifpal, helped Zoom's team test more than 8 Verifpal models which during the development of Zoom's protocols helped identify a non-obvious attack on some of the proposals considered for Zoom's encryption. "This helps engineers such as the ones at Zoom to identify weaknesses in protocol design proposals very early on." Other projects and tools that recently started using Verifpal to make their software more secure include the private messaging app Delta Chat and the end-to-end encrypted signalling protocol SaltyRTC. Last year Verifpal was one of the first technology projects funded by the Next Generation Internet initiative, a programme initiated by the European Commission to re-imagine and re-engineer a more trustworthy internet. With a recent grant from NGI Zero to expand its feature set, Verifpal is now able to further prove that its verification of protocols is sound using the Coq theorem prover, automatically generate implementations from verified Verifpal-models for real-world testing and integrate into development environments like Visual Studio Code. NGI Zero is proud to support open source software and open hardware projects that address online security and privacy on all layers, from improving fundamental components to developing human-centric middleware and trustworthy end user apps.

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source