Live data from Hacker News

Vulnerability in the Mac Zoom client allows malicious websites to enable camera

medium.com

291–300 of 473 posts

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#291

On my Mac, I have uBlockOrigin installed in my browser and I have it configured to always block 3rdparty and 3rdparty frames and it prevents both the POCs completely. I have one browser that I use for work email and video conference, where system grants access to camera/microphone to the browser and browser allows Google Meet to access camera. I have another browser where system does not grant access to any of the de…

and I am in the crowd of mac users who tape over their camera. when it comes to video conferences at most I have ever seen the desktop shared. what type of work do you do that uses the video for portions other than the presentation?

You weren't asking me, but I run into this same thing.

In my business -- project management software -- I'm in online meetings a LOT (say, 20 hours a week?) because everyone in my company is remote. We have never, ever used video. It just doesn't come up. Nobody wants it internally, and none of our customers ask for it in external meetings. I don't think any of them use it internally, either (and many of our customers are large, distributed organizations with offices all over the place).

This seems normal to me.

My neighbor is an IT VP for a health care concern. She travels a lot (30-40%), and when she's home she's in online meetings pretty much all the time. And in her company, video is ALWAYS included. I have no idea why, and neither does she; it's a cultural thing.

The upshot, though, is that I work in t-shirts and cargo shorts, and she has to be "office ready" even though she works at home. However, I will note that, if I run into her outside when she's walking the dog, it's not unusual to see her in a nice blouse, hair and makeup done, but wearing yoga pants or whatever. Which is its own kind of hilarious.

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#292

Hi I'm the author, AMA Or come hang out in the party chat! Use the exploit to join: https://jlleitschuh.org/zoom_vulnerability_poc/zoompwn_ifram...

> You can confirm this server is present by running lsof -i :19421 in your terminal.

Might be good to specify what the output would be if the vulnerability is present or not, like this:

"If the server is running on your machine, you'll get a line specifying which process is listening to that port. If the command returns empty, your machine is not vulnerable."

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#294
Can’t Zoom add their own simple prompt to the local server which gets confirmation from the user that they want to join the meeting? Just one more click and not “nasty”.

It could even be 4 different Join buttons:

- Video & Audio

- Video Only

- Audio Only

- No Video or Audio

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#295
post #154

Hosting a web server on localhost is the equivalent of adding a backdoor on your customer's machines. How does a product team even reach this decision?

By being blind to the implications.

The most charitable interpretation of the Superhuman read-receipt problem is kinda the same thing: they had an idea, thought it was good, and then did some deeply shitty things to make it work. And nobody at Zoom or at Superhuman had the organizational power to stop it.

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#298

Can’t Zoom add their own simple prompt to the local server which gets confirmation from the user that they want to join the meeting? Just one more click and not “nasty”. It could even be 4 different Join buttons: - Video & Audio - Video Only - Audio Only - No Video or Audio

Without the local webserver, they fall back to Safari's URL handler, which asks whether or not you wan't to start the application in question.

They went through a lot of trouble to implement this ridiculous solution to avoid the kind of thing you describe.

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#299
post #264
post #230

Earlier quoted context omitted.

It wasn't bad habits, up to Windows XP which introduced user separation on consumer oriented Windows (NT and 2K were meant for businesses and businesses who had networked PCs were really meant to use those) all personal computers were fully controlled by their users without any notion of privilege separation - this is a behavior that traces its lineage back to the original Altair 8800. Computers weren't networked and…

I’ve had viruses and anti viruses years before I had internet. Getting a virus was trivial in the 90’s when windows had no security and any program could do anything.

Your comment is a bit ambiguous. Are you saying that even retail software could be considered a virus just because of what it can do on the system? Or was virus software making it onto the machine in other ways?
Post reply on HN