So last week Zoom bought Keybase. If you haven't heard of Keybase, don't feel bad — it's a small encrypted messaging and file-sharing outfit that's been quietly doing its thing since 2014, the kind of company most people only hear about when a bigger company buys it. Which is exactly what happened here. Zoom picked them up specifically to build real end-to-end encryption into Zoom calls, and I've been chewing on this all week because I am, at this point, contractually obligated to have opinions about Zoom.
I'm on it four, sometimes five times a day right now. Team standup at 9:15, a client call at 11, my kid's "virtual show and tell" at 2 because apparently that's a thing now, and then some optional-but-not-really happy hour at 5:30 that I mostly mute myself through while I do dishes. So when Zoom does anything, I notice, because it directly affects whether my Tuesday is pleasant or a small daily indignity.
Quick recap for anyone who tuned this out: back in April, after the whole "zoombombing" mess where randos were dropping into unsecured meetings and screen-sharing awful stuff, Eric Yuan (Zoom's CEO) announced a 90-day freeze on new features so the company could just focus on fixing security and privacy. Waiting rooms got turned on by default, passwords got required, Zoom 5.0 shipped with AES 256-bit GCM encryption instead of the weaker 128-bit ECB stuff they were using before (which, incredible that it took a PR crisis to fix that one). Buying Keybase is the next move in that same plan. The stated goal is a proper end-to-end encrypted mode where not even Zoom's own servers can see your call content.
Here's my actual opinion, not just a rundown: I think this is a genuinely good and slightly overdue move, and I also don't think it's going to work the way people are hoping. End-to-end encryption and "let's dial into a meeting with 40 people, some of whom joined by phone, and some of whom need transcription and cloud recording" are in tension with each other. A lot of the features that make Zoom actually usable for the average office depend on the server being able to see and process the stream. You can have real E2E encryption or you can have all of Zoom's convenience features, and squaring that circle for something as feature-heavy as Zoom is a much bigger lift than turning on GCM by default. I'd bet money this ships as an opt-in mode with a bunch of asterisks next to it, not something that just quietly becomes how all my calls work.
And honestly, my day-to-day complaint about Zoom isn't even encryption, it's the waiting room UX. My company's Zoom Pro plan is $14.99 a month per host, and I still watch coworkers get stuck in a waiting room limbo because whoever scheduled the call forgot they're not the host and can't admit anyone. Happened twice this week alone. There's something almost funny about a company spending real money and doing an acquisition to fix cryptography while the actual daily friction point is "nobody knows who's supposed to click the green checkmark."
The other thing nagging at me is that Keybase wasn't just an encryption toolkit, it had its own little community built around it — people used it for identity verification, for encrypted git repos, for tying your online handles together in a verifiable way. I don't know yet what happens to that side of the product once it gets folded into a video conferencing company that mostly cares about the encryption tech underneath. Acquisitions like this have a pretty consistent track record of the acquired product either dying quietly or getting stripped for parts within a year or two. I'd genuinely like to be wrong about that one.
Anyway. If your whole workday is also five Zoom calls stacked back to back like mine, I don't think anything changes for you this week, or probably this month. But it's worth keeping an eye on, if only because Zoom is one of maybe three pieces of software that basically the entire white-collar workforce is now using every single day, whether they picked it or not.