Zoom fixes major Mac webcam security flaw with emergency patch
31–40 of 151 posts
Re: Zoom fixes major Mac webcam security flaw with emergency patch
#32Tech executive changes stance after very public embarrassment that could impact their bottom line. If they didn't get the backlash, they would have kept their course. There's not really much "willing to accept responsibility" here as far as I'm concerned.
Exactly. My company is actively shopping for a conferencing tool, and Zoom just ensured that it's eliminated.
Do we want a world of people who change their ways, even if for somewhat impure reasons, or a world in which no one ever does because it's pointless?
Re: Zoom fixes major Mac webcam security flaw with emergency patch
#33Glad to see the company is changing course, but I’m not sure it would have happened without the public shaming. I want companies to fix things because something is insecure and it endangers the public, not because they have their feet to the fire. I know companies don’t always respond right the first time, I know I haven’t, but Zoom had over 90 days to consider their responses and possible options / software changes.…
Re: Zoom fixes major Mac webcam security flaw with emergency patch
#34Earlier quoted context omitted.
Exactly. My company is actively shopping for a conferencing tool, and Zoom just ensured that it's eliminated.
Anger is certainly justified, but it should give way to reconciliation once the offending party truly repents. Do we want a world of people who change their ways, even if for somewhat impure reasons, or a world in which no one ever does because it's pointless?
Re: Zoom fixes major Mac webcam security flaw with emergency patch
#35Earlier quoted context omitted.
Will shenanigans like this (declaring a security breach as not a security breach) be caught and fined under GDPR? According to the regulation, companies need to declare breaches in under 72 hours without any unduly delay, but Zoom left this unpatched for months!
As a non-lawyer forum commentator I can say with absolute correctness that it will (or will not) maybe apply. More seriously: I would guess no, as the GDPR is concerned with data collection and compromise, but I can’t imagine they store all the video they forward. Of course I wouldn’t be surprised if someone sues them in the US (but given that the US sees companies as people for rights, but not punishment I imagine t…
Re: Zoom fixes major Mac webcam security flaw with emergency patch
#36This is why full disclosure is so effective. Nothing else works quite like dropping a full PoC and details of an exploit publicly to light a fire under their ass to fix it.
Well it’s an argument for responsible disclosure - you tell them, give them plenty of time to fix it, and publish. But responsible disclosure absolutely does not mean “no disclosure”. It means give them a chance to fix it. If they choose not to you disclose so that people know that they need to take steps to protect themselves. The important thing is that the disclosure must become public. It doesn’t matter that they…
https://blogs.technet.microsoft.com/ecostrat/2010/07/22/coor...
Re: Zoom fixes major Mac webcam security flaw with emergency patch
#37RingCentral Meetings still vulnerable: lsof -i :19424 https://www.ringcentral.com/whyringcentral/company/pressrele...
Re: Zoom fixes major Mac webcam security flaw with emergency patch
#38The exploit can then be divulged to the public, automatically, on the expiration of the 90-day window, regardless of whether it's fixed or not, as that may also be educational.
For example, after this Zoom issue other companies will hesitate to use a localhost webserver, but if the issue had quietly been fixed by Zoom other companies may still have been tempted to use similar approach.
Re: Zoom fixes major Mac webcam security flaw with emergency patch
#39I wonder if instead of the usual 90-day notice a slightly better approach would be an initial partial public disclosure of the issue, without divulging the actual exploit, and the fact that it had been communicated to the company so that a public countdown of the 90-day window can happen. The exploit can then be divulged to the public, automatically, on the expiration of the 90-day window, regardless of whether it's…
Re: Zoom fixes major Mac webcam security flaw with emergency patch
#40I wonder if instead of the usual 90-day notice a slightly better approach would be an initial partial public disclosure of the issue, without divulging the actual exploit, and the fact that it had been communicated to the company so that a public countdown of the 90-day window can happen. The exploit can then be divulged to the public, automatically, on the expiration of the 90-day window, regardless of whether it's…
More often than not announcing the existence of a vulnerability is enough to motivate people to find it. It’s much easier to find something that you know is there than to just experiment blindly.
Even if we don't do that, I think we should at least reveal the issue after it's been fixed in all the cases so that other entities can learn from that.