Apple has pushed a silent Mac update to remove hidden Zoom web server
21–30 of 552 posts
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#22Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#23Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#24Disturbs me somewhat that Apple has a way to silently push changes to laptops without user interaction.
It's no different than a virus scanner auto-updating its signatures.
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#25i tried etrecheck on a lark. at the time i found it unremarkable. oh, i have this leftover dingle here, thanks etrecheck, i'll just remove it then. but otherwise i wasn't screaming etrecheck from on high.
now i am!!
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#26> Apple said the update does not require any user interaction and is deployed automatically. I think this scares me just as much. #singlePointOfFailure #rootKit
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#27Earlier quoted context omitted.
Of note, Apple has had its own malware detection and removal system in place since the Mountain Lion - Snow Leopard timeframe. Since this article speaks to removal, it's sounding like the Zoom local server may have had its signature added to that system.
So the local server is not a regular price of software with a vulnerability, it is now considered malware?
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#28It's been really interesting to see how quickly the original Zoom response of "there's nothing wrong with this, everybody does it" ended up being reversed. I wonder if there's a known exploit for the Zoom server specifically, or if Apple discovered one while looking into it. It seems strange for them to go to these lengths in this case when it sounds like other software has been using a similar technique too. Maybe i…
> Zoom spokesperson Priscilla McCarthy told TechCrunch: “We’re happy to have worked with Apple on testing this update. We expect the web server issue to be resolved today. We appreciate our users’ patience as we continue to work through addressing their concerns.”
Yeah, I bet.
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#29How do these kinds of silent updates work?
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#30Earlier quoted context omitted.
Of note, Apple has had its own malware detection and removal system in place since the Mountain Lion - Snow Leopard timeframe. Since this article speaks to removal, it's sounding like the Zoom local server may have had its signature added to that system.
So the local server is not a regular price of software with a vulnerability, it is now considered malware?
That makes this server at least doubly malware. And "vulnerability" understates the case: a negligent implementation that utterly disregarded any security concerns should be considered beyond the pale. That times 1000 for a major software vendor like Zoom.