Live data from Hacker News

Zoom fixes major Mac webcam security flaw with emergency patch

theverge.com

51–60 of 151 posts

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#51
post #28

The security flaw isnt even the outrageous part. It was secretly installing webservers that dont even remove themselves when you uninstall the app that makes them scum.

Dropbox also does this, so does a lot of other popular programs.

do `lsof -i | grep LISTEN` to find out what server is running on your machine.

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#52
post #21

Earlier quoted context omitted.

Well it’s an argument for responsible disclosure - you tell them, give them plenty of time to fix it, and publish. But responsible disclosure absolutely does not mean “no disclosure”. It means give them a chance to fix it. If they choose not to you disclose so that people know that they need to take steps to protect themselves. The important thing is that the disclosure must become public. It doesn’t matter that they…

Responsible disclosure doesn’t mean anything. It’s an obsolete term. You’re referring to coordinated disclosure. https://blogs.technet.microsoft.com/ecostrat/2010/07/22/coor...

This case is actually a really great demonstration of why this often-repeated claim is false. This was responsible, but not coordinated, disclosure.

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#53
post #45
post #33

Earlier quoted context omitted.

And this is why anyone who trusts that organization in any way moving forward is a fool.

Nah leadership can change, see Microsoft and apple

The Microsoft telemetry spyware was completely opaque and they kept changing it to work around users blocking it until they were shamed into publishing almost everything they collect. One still can't turn it off.

Apple usually needs to be shamed into admitting to and repairing any broken hardware design. They had to be sued in multiple countries to stop misleading customers to buy AppleCare and allow them to use the warranty guaranteed by law.

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#54
post #45
post #33

Earlier quoted context omitted.

And this is why anyone who trusts that organization in any way moving forward is a fool.

Nah leadership can change, see Microsoft and apple

That’s more of a reason not to trust anything ever. If leaders change for the worse, your investment in the company gets screwed no matter how well they’d done previously. And that investment can be stocks or it can be data, to give an example which you can’t just pull.

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#55
post #45

Earlier quoted context omitted.

Nah leadership can change, see Microsoft and apple

That’s more of a reason not to trust anything ever. If leaders change for the worse, your investment in the company gets screwed no matter how well they’d done previously. And that investment can be stocks or it can be data, to give an example which you can’t just pull.

Leaders influence company culture but it's also a self-feedback loop where leaders that fit the company culture end up being leaders in the first place. To break that feedback loop and change course is usually a conscious choice for a company. Even then leadership change and direction at the top is only one of the many signals. It's entirely possible for Zoom's CEO to be a security minded person and the PM/Infosec person who reviewed the security report decided it's not a flaw worth patching.

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#56
post #37

RingCentral Meetings still vulnerable: lsof -i :19424 https://www.ringcentral.com/whyringcentral/company/pressrele...

For those unaware, RingCentral white-labels the zoom.us product as their meeting solution.

Ironically, RingCentral's convention schwag includes a stick-on laptop lens shutter.

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#57
post #2

Tech executive changes stance after very public embarrassment that could impact their bottom line. If they didn't get the backlash, they would have kept their course. There's not really much "willing to accept responsibility" here as far as I'm concerned.

Exactly. My company is actively shopping for a conferencing tool, and Zoom just ensured that it's eliminated.

[deleted]

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#58

Glad to see the company is changing course, but I’m not sure it would have happened without the public shaming. I want companies to fix things because something is insecure and it endangers the public, not because they have their feet to the fire. I know companies don’t always respond right the first time, I know I haven’t, but Zoom had over 90 days to consider their responses and possible options / software changes.…

What's scary is that they have a bounty program but it comes with a gag catch.

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#59
post #34
post #32

Earlier quoted context omitted.

Anger is certainly justified, but it should give way to reconciliation once the offending party truly repents. Do we want a world of people who change their ways, even if for somewhat impure reasons, or a world in which no one ever does because it's pointless?

They haven’t repented yet, though. Read their response.

I don't understand, is there something specific you're referring to? From the article it looks like they're even removing the local web server.

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#60
The more a think about it, the more a I come to the conclusion that we need a mixed computing paradigm.

For many tasks (probably most and certainly for most people) the iOS model is the best.

It is, however way too restrictive for a number of use cases. Prohibitively so.

Imagine two very different and isolated environments. Terminal, compilers, file managers in one, most other software in the other. With perhaps shared folders between them.

Post reply on HN