Zoom fixes major Mac webcam security flaw with emergency patch
1–10 of 151 posts
Re: Zoom fixes major Mac webcam security flaw with emergency patch
#2There's not really much "willing to accept responsibility" here as far as I'm concerned.
Re: Zoom fixes major Mac webcam security flaw with emergency patch
#3Re: Zoom fixes major Mac webcam security flaw with emergency patch
#4Re: Zoom fixes major Mac webcam security flaw with emergency patch
#5lsof -i :19424
https://www.ringcentral.com/whyringcentral/company/pressrele...
Re: Zoom fixes major Mac webcam security flaw with emergency patch
#6If the reporter had agreed to the NDA required for the bug bounty, Zoom could have - and based on their earlier responses, would have - continued to ship this malware. But now because of the researcher signed an NDA they wouldn’t be able to inform the at risk public.
Re: Zoom fixes major Mac webcam security flaw with emergency patch
#7Tech executive changes stance after very public embarrassment that could impact their bottom line. If they didn't get the backlash, they would have kept their course. There's not really much "willing to accept responsibility" here as far as I'm concerned.
Re: Zoom fixes major Mac webcam security flaw with emergency patch
#8Re: Zoom fixes major Mac webcam security flaw with emergency patch
#9This is why no researcher should sign an NDA after to doing volunteer work for a for-profit Corp. If the reporter had agreed to the NDA required for the bug bounty, Zoom could have - and based on their earlier responses, would have - continued to ship this malware. But now because of the researcher signed an NDA they wouldn’t be able to inform the at risk public.
Re: Zoom fixes major Mac webcam security flaw with emergency patch
#10This is why no researcher should sign an NDA after to doing volunteer work for a for-profit Corp. If the reporter had agreed to the NDA required for the bug bounty, Zoom could have - and based on their earlier responses, would have - continued to ship this malware. But now because of the researcher signed an NDA they wouldn’t be able to inform the at risk public.
Will shenanigans like this (declaring a security breach as not a security breach) be caught and fined under GDPR? According to the regulation, companies need to declare breaches in under 72 hours without any unduly delay, but Zoom left this unpatched for months!