Live data from Hacker News

Zoom fixes major Mac webcam security flaw with emergency patch

theverge.com

1–10 of 151 posts

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#2
Tech executive changes stance after very public embarrassment that could impact their bottom line. If they didn't get the backlash, they would have kept their course.

There's not really much "willing to accept responsibility" here as far as I'm concerned.

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#4
There's not a single reason to use zoom over the n other existing meeting software. They just got big because of marketing. My office has recently switched from Skype business to zoom and I find it just as shitty. First of all there's absolutely no use for video, because who the fuck wants to see each other's faces in a work related call? Then there's the whole UI thing to consider. I haven't yet figured out how to initiate a call. I always copy the link and email it to the person I want to talk to. Then they see the email and click it. Compare that to Skype's simple call button. All in all, zoom is hyped up by their marketing and provides less than zero value over existing solutions.

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#6
This is why no researcher should sign an NDA after to doing volunteer work for a for-profit Corp.

If the reporter had agreed to the NDA required for the bug bounty, Zoom could have - and based on their earlier responses, would have - continued to ship this malware. But now because of the researcher signed an NDA they wouldn’t be able to inform the at risk public.

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#7
post #2

Tech executive changes stance after very public embarrassment that could impact their bottom line. If they didn't get the backlash, they would have kept their course. There's not really much "willing to accept responsibility" here as far as I'm concerned.

Exactly. My company is actively shopping for a conferencing tool, and Zoom just ensured that it's eliminated.

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#9
post #6

This is why no researcher should sign an NDA after to doing volunteer work for a for-profit Corp. If the reporter had agreed to the NDA required for the bug bounty, Zoom could have - and based on their earlier responses, would have - continued to ship this malware. But now because of the researcher signed an NDA they wouldn’t be able to inform the at risk public.

Will shenanigans like this (declaring a security breach as not a security breach) be caught and fined under GDPR? According to the regulation, companies need to declare breaches in under 72 hours without any unduly delay, but Zoom left this unpatched for months!

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#10
post #9
post #6

This is why no researcher should sign an NDA after to doing volunteer work for a for-profit Corp. If the reporter had agreed to the NDA required for the bug bounty, Zoom could have - and based on their earlier responses, would have - continued to ship this malware. But now because of the researcher signed an NDA they wouldn’t be able to inform the at risk public.

Will shenanigans like this (declaring a security breach as not a security breach) be caught and fined under GDPR? According to the regulation, companies need to declare breaches in under 72 hours without any unduly delay, but Zoom left this unpatched for months!

Someone would have to prove that their personal information was stolen or misused for GDPR enforcement to be relevant.
Post reply on HN