Live data from Hacker News

Apple has pushed a silent Mac update to remove hidden Zoom web server

techcrunch.com

11–20 of 552 posts

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#11
post #6

Earlier quoted context omitted.

Of note, Apple has had its own malware detection and removal system in place since the Mountain Lion - Snow Leopard timeframe. Since this article speaks to removal, it's sounding like the Zoom local server may have had its signature added to that system.

So the local server is not a regular price of software with a vulnerability, it is now considered malware?

The server was intentionally left behind, and running, by the "uninstaller". The server would respond to requests by reinstalling the intentionally uninstalled software.

That's malware.

The server itself was deliberately added to work around a Safari security feature, that was designed specifically to prevent what they wanted: allowing arbitrary web content to open an app without user consent. They literally added an always on, persistent server, to avoid a security dialog

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#12
post #2

From the article, this sounds like it was a GateKeeper change, de-whitelisting the signature, rather than an update, per se.

More likely this was done via a signature update to xprotect, which is essentially a background antivirus process in macOS.

Doesn't appear so, current XProtect version remains at 2103 which was released a couple months ago now.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#13
If you would like to force this update you can do so via the terminal:

softwareupdate -ia --include-config-data

It will show up as MRTConfigData if you look under Apple Menu->About This Mac->System Report->Software->Installations. The latest version is 1.45 and was updated today which includes the Zoom mitigations.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#16
My coworker owes me lunch, I said they would yank the Zoom app for breaking the app stores TOS (close enough hahaha). Apple cant be very happy with public companies breaking their platform, especially in the name of "UX", which is supposed to be (and is) their differentiator.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#17
post #2

From the article, this sounds like it was a GateKeeper change, de-whitelisting the signature, rather than an update, per se.

More likely this was done via a signature update to xprotect, which is essentially a background antivirus process in macOS.

Since the update is called "MRTConfigData" - and that has to do with XProtect according to https://discussions.apple.com/thread/250079600 - you're probably right.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#19
post #7

It's been really interesting to see how quickly the original Zoom response of "there's nothing wrong with this, everybody does it" ended up being reversed. I wonder if there's a known exploit for the Zoom server specifically, or if Apple discovered one while looking into it. It seems strange for them to go to these lengths in this case when it sounds like other software has been using a similar technique too. Maybe i…

Yeah, exactly. Software you've uninstalled gives away permission to use your camera to a remote web page? That's malware, and would get most apps banned permanently.
Post reply on HN