Live data from Hacker News

Zoom fixes major Mac webcam security flaw with emergency patch

theverge.com

141–150 of 151 posts

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#141
post #114

Earlier quoted context omitted.

I don't want the web server running when Zoom is running either. Video conferencing has nothing to do with a web server or any server listening to ports. When I install a video conferencing client its only function should be me initiating a connection.

Then why don’t you switch to webex?

I have never been in the position to choose other than voicing my opinion, all video conferencing sucks for some reason or another, and it has never been anywhere near the most important thing.

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#142
post #65

Earlier quoted context omitted.

> It was secretly installing webservers that dont even remove themselves when you uninstall the app that makes them scum. To be fair, dragging an "app" to Trash does not constitute un-installation. It was a poor design decision to implement features using a local web server, but let's not be so quick to attribute covert, malicious intentions.

> To be fair, dragging an "app" to Trash does not constitute un-installation. Dragging an app to Trash MUST constitute uninstallation. If it doesn't, it is a bug. Leaving configuration files in home folder for easier on-boarding after a reinstall is not the same thing as leaving a self replicating rootkit running all the time. > It was a poor design decision to implement features using a local web server, but let's n…

There are plenty of Mac apps where dragging the app to the trash doesn’t uninstall them.

Unlike windows which has the add/remove programs control panel there isn’t really a standardized way to uninstall things on Mac. (I think you can make a .pkg uninstaller but it’s rare to see that)

I went through the launch agents and launch daemons on my personal computer a few months ago and found plenty of obsolete stuff that was hanging around even after I no longer had whatever the associated app was installed.

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#143
post #115

Earlier quoted context omitted.

But for what? My caveat is that a helper service is acceptable when it is doing something necessary for the basic function of the software. Virus scanners, file sync, and things which are obviously servers fit the bill. Not much else I can think of does.

Libreoffice has an agent that preloads java bins to make the startup time comparable to MS Office. There are valid uses for startup agents, please get over yourself

I don't want that.

I don't want installing an office suite to permanently take away a percentage of my computer's resources.

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#144
post #106

Earlier quoted context omitted.

I want an operating system with a permissions model which specifically forbids this kind of thing. My Linux desktops are also always full of processes which I have to dig to figure the purpose, unless I build my own distribution it's hard to make anything work which feels satisfactorily under control.

So how does your OS differenate between Apache and a local helper?

Non-OS provided applications are installed as packages and given package-level permissions which are easily audited and revokable (without forcing uninstall).

Apache has permission to start at boot, run in the background, and listen to 0.0.0.0:80,443. Photoshop has permission to write to files in $HOME, and connect to network services while the application is running optionally with explicit permissions for each access. Adobe's update service can be disabled with a click.

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#145

Earlier quoted context omitted.

MacOS as a whole forces confirmation on deeplinks. The old solution skipped the OS confirmation dialog.

Hmm..but I'm not getting a confirmation prompt on Firefox or Chrome? Visiting a zoom link in either of those browsers takes me directly into the meeting

Safari 12 forces the confirmation, not all browsers.

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#146
post #105
post #97

Earlier quoted context omitted.

Running a local helper to take control from the browser is absolutely a bad architectural choice. The browser doesn't allow websites to open local programs without going through a user confirmation process for damned good reasons, and Zoom decided to put a lot of effort into circumventing that security measure to save users a click and so boost their conversion rates by a few percentage points.

It really sounds like what we need is: “Always allow zoom.us to open ‘Zoom’” within browsers. Even Spotify runs a local web server for this.

This is inherently a security problem because web sites can open URLs without user awareness or deceive users about the content of said URLs.

On Ubuntu, xdg-open phrases the checkbox as something like "always allow X program to handle foo:// URLs?", which is probably not comprehensible to the average user; more accurate phrasing would be "always allow websites to open X program?" Which I think indicates why I'm so skeptical that this is a good option to give to users.

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#147

Stories like this are wonderful evidence of the effectiveness of public disclosure of security vulnerabilities, and are always heartwarming to see. Remember, 90-day disclosure windows are just a courtesy .

Mmm. This post by Matthew Garrett is good on this: https://mjg59.dreamwidth.org/52432.html

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#148
post #127

This is why I love the appstore and forced sandboxing. I hope adobe will finally use the appstore for once. Glas that office is using it. No more buggy updater apps

Adobe has been using the App Store for years[1], but not for the Creative Suite apps. [1]: https://apps.apple.com/us/developer/adobe-inc/id331646274

For iOS because they have no other choice. I’m talking about macOS and their crapware updater and licensing apps

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#149
post #2

Tech executive changes stance after very public embarrassment that could impact their bottom line. If they didn't get the backlash, they would have kept their course. There's not really much "willing to accept responsibility" here as far as I'm concerned.

Let us be quite clear here:

"Farley maintains that the relative security risk of the vulnerabilities that security researcher Jonathan Leitschuh disclosed yesterday were not as severe as Leitschuh made them out to be."

That's the CIO still unwilling to accept what a poor decision it was to subversively install a web server on users' computers. They need to shut the fuck up unless the words coming out of their mouth are "we're sorry and we'll do better in the future".

Re: Zoom fixes major Mac webcam security flaw with emergency patch

#150
post #32

Earlier quoted context omitted.

Exactly. My company is actively shopping for a conferencing tool, and Zoom just ensured that it's eliminated.

Anger is certainly justified, but it should give way to reconciliation once the offending party truly repents. Do we want a world of people who change their ways, even if for somewhat impure reasons, or a world in which no one ever does because it's pointless?

I've seen no evidence of true repentance here.
Post reply on HN