Live data from Hacker News

Apple has pushed a silent Mac update to remove hidden Zoom web server

techcrunch.com

31–40 of 552 posts

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#31
post #12

Earlier quoted context omitted.

More likely this was done via a signature update to xprotect, which is essentially a background antivirus process in macOS.

Doesn't appear so, current XProtect version remains at 2103 which was released a couple months ago now.

The update from today updates the MRT configuration data.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#32
post #12

Earlier quoted context omitted.

More likely this was done via a signature update to xprotect, which is essentially a background antivirus process in macOS.

Doesn't appear so, current XProtect version remains at 2103 which was released a couple months ago now.

I haven’t checked, but are you looking at the version of the binary itself, or the MRT signature files it uses

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#33
post #13

If you would like to force this update you can do so via the terminal: softwareupdate -ia --include-config-data It will show up as MRTConfigData if you look under Apple Menu->About This Mac->System Report->Software->Installations. The latest version is 1.45 and was updated today which includes the Zoom mitigations.

Thank you!

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#34
post #7

It's been really interesting to see how quickly the original Zoom response of "there's nothing wrong with this, everybody does it" ended up being reversed. I wonder if there's a known exploit for the Zoom server specifically, or if Apple discovered one while looking into it. It seems strange for them to go to these lengths in this case when it sounds like other software has been using a similar technique too. Maybe i…

Other software used similar techniques for starting calls, but I believe that Zoom is unique in that calls can turn the camera on without any user interaction.

Zoom also didn't reverse their decision until there was a huge amount of public backlash.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#35
That's pretty epic. Apple continues to make big, brave moral gestures (like when they yanked Facebook and Google's enterprise certs earlier this year, or killed long-term tracking cookies in Safari overnight).

Makes me happy to be a customer. Hope they keep enforcing their own rules and protecting their users' privacy and security in this fearless manner.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#36
post #18

Disturbs me somewhat that Apple has a way to silently push changes to laptops without user interaction.

You can disable it in Preferences -> Software Update -> Advanced -> Install system data files and security updates

From there you can manage the updates manually from the command line with the `softwareupdate` command. e.g. `softwareupdate --list --include-config-data` will show available updates, `softwareupdate -ia --include-config-data` will install them, etc.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#37
post #7

It's been really interesting to see how quickly the original Zoom response of "there's nothing wrong with this, everybody does it" ended up being reversed. I wonder if there's a known exploit for the Zoom server specifically, or if Apple discovered one while looking into it. It seems strange for them to go to these lengths in this case when it sounds like other software has been using a similar technique too. Maybe i…

After that PR spin in response to threat disclosure in the original article, I am very skeptical of Zoom's PR machine. > Zoom spokesperson Priscilla McCarthy told TechCrunch: “We’re happy to have worked with Apple on testing this update. We expect the web server issue to be resolved today. We appreciate our users’ patience as we continue to work through addressing their concerns.” Yeah, I bet.

Yeah, I'm quite curious now if Zoom's reversal and decision to remove the server was because Apple informed them they were going to forcibly remove it like this.

It looked like they decided to remove the server themselves (or at least, as a response to pressure), but maybe they didn't actually have a choice at all.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#38

I wonder what happens now to the Product Owner who decided it was OK to install hidden web server on user machines?

Probably nothing, and mutual lamentation from product and marketing people about the loss of their easiest customer retention strategy.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#39
post #7

It's been really interesting to see how quickly the original Zoom response of "there's nothing wrong with this, everybody does it" ended up being reversed. I wonder if there's a known exploit for the Zoom server specifically, or if Apple discovered one while looking into it. It seems strange for them to go to these lengths in this case when it sounds like other software has been using a similar technique too. Maybe i…

In the news segment of this week's episode of Risky Business[0], one of the hosts mentions (starting around 3:40) he has some information that there was an RCE disclosed to Zoom back "some months ago". He further says that @Jlleitschuh (the person reporting the web server issue earlier this week) got 90% of the way to finding it. So...yeah, speculation only, but maybe Apple became aware of this and dropped the hammer.

[0]: https://www.risky.biz/RB547/

Post reply on HN