Live data from Hacker News

Apple has pushed a silent Mac update to remove hidden Zoom web server

techcrunch.com

21–30 of 552 posts

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#24
post #18

Disturbs me somewhat that Apple has a way to silently push changes to laptops without user interaction.

This has been in place since 10.6 Snow Leopard. It's part of their built-in anti-malware system (MRT + XProtect + Gatekeeper).

It's no different than a virus scanner auto-updating its signatures.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#25
ertecheck found this for me maybe 2 months ago. coincidentally right in the disclosure window!

i tried etrecheck on a lark. at the time i found it unremarkable. oh, i have this leftover dingle here, thanks etrecheck, i'll just remove it then. but otherwise i wasn't screaming etrecheck from on high.

now i am!!

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#26
post #20

> Apple said the update does not require any user interaction and is deployed automatically. I think this scares me just as much. #singlePointOfFailure #rootKit

This isn't an "update" in the traditional sense and you can turn this off from System Preferences.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#27
post #6

Earlier quoted context omitted.

Of note, Apple has had its own malware detection and removal system in place since the Mountain Lion - Snow Leopard timeframe. Since this article speaks to removal, it's sounding like the Zoom local server may have had its signature added to that system.

So the local server is not a regular price of software with a vulnerability, it is now considered malware?

That's Apple's closed garden, even when they allow you to sideload application, they still have the ultimate decision. Of course it's not malware, but probably enough users have vulnerable software which could be remotely exploited, that they decided to blacklist it.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#28
post #7

It's been really interesting to see how quickly the original Zoom response of "there's nothing wrong with this, everybody does it" ended up being reversed. I wonder if there's a known exploit for the Zoom server specifically, or if Apple discovered one while looking into it. It seems strange for them to go to these lengths in this case when it sounds like other software has been using a similar technique too. Maybe i…

After that PR spin in response to threat disclosure in the original article, I am very skeptical of Zoom's PR machine.

> Zoom spokesperson Priscilla McCarthy told TechCrunch: “We’re happy to have worked with Apple on testing this update. We expect the web server issue to be resolved today. We appreciate our users’ patience as we continue to work through addressing their concerns.”

Yeah, I bet.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#30
post #6

Earlier quoted context omitted.

Of note, Apple has had its own malware detection and removal system in place since the Mountain Lion - Snow Leopard timeframe. Since this article speaks to removal, it's sounding like the Zoom local server may have had its signature added to that system.

So the local server is not a regular price of software with a vulnerability, it is now considered malware?

Beyond the unsolicited reinstallation (== malware) behavior other commenters rightly mentioned, the entire existence of the vulnerable server was a hack to work around a Safari security feature. Zoom wanted to eliminate an extra user click, required by Safari to confirm that it was OK to invoke a local application based on the public zoom link. This server was an implementation of that security "workaround".

That makes this server at least doubly malware. And "vulnerability" understates the case: a negligent implementation that utterly disregarded any security concerns should be considered beyond the pale. That times 1000 for a major software vendor like Zoom.

Post reply on HN