That's pretty epic. Apple continues to make big, brave moral gestures (like when they yanked Facebook and Google's enterprise certs earlier this year, or killed long-term tracking cookies in Safari overnight). Makes me happy to be a customer. Hope they keep enforcing their own rules and protecting their users' privacy and security in this fearless manner.
I don't think killing those enterprise cert was a moral gesture. They were just enforcing their walled garden.
Apple has pushed a silent Mac update to remove hidden Zoom web server
61–70 of 552 posts
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#62Earlier quoted context omitted.
So the local server is not a regular price of software with a vulnerability, it is now considered malware?
That's Apple's closed garden, even when they allow you to sideload application, they still have the ultimate decision. Of course it's not malware, but probably enough users have vulnerable software which could be remotely exploited, that they decided to blacklist it.
A piece of software that lets any website activate your camera without your permission is a security vulnerability.
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#63I always wondered why the zoom app required root permissions, which is why I never installed it in the first place. What would a video conferencing app ever need root permissions for?! Now we know: a backdoor. Thank god for Apple putting down the law. This is why I happily pay premium prices...
I can't verify since I don't have it installed but I see no reason why this webserver would need root permissions. If it's asking for root it must be for something else.
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#64Earlier quoted context omitted.
So the local server is not a regular price of software with a vulnerability, it is now considered malware?
The server was intentionally left behind, and running, by the "uninstaller". The server would respond to requests by reinstalling the intentionally uninstalled software . That's malware. The server itself was deliberately added to work around a Safari security feature, that was designed specifically to prevent what they wanted: allowing arbitrary web content to open an app without user consent. They literally added a…
FWIW, I don’t think there was a uninstaller? What I’ve seen people describe is that dragging the .App file to the trash wouldn’t remove the server, since it was installed in a different folder.
There was no uninstaller until the Zoom update this week added an uninstall option to the menu.
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#65Seriously though, they should have owned the mistake, apologised and reversed their decision rather than handling it with a PR spin. It is a great product but somehow it has left me with little trust for zoom. It's probably still not too late.
Does anyone know if bluejeans et all are also removing this? Or does it require public shaming, like the zoom case?
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#66The bigger question -- what other desktop apps have similar, latent daemons hanging around? I'm always wary of installing stuff like this (e.g. zoom, go2meeting, teamviewer). Anyone know of other sneaky apps to avoid?
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#67ertecheck found this for me maybe 2 months ago. coincidentally right in the disclosure window! i tried etrecheck on a lark. at the time i found it unremarkable. oh, i have this leftover dingle here, thanks etrecheck, i'll just remove it then. but otherwise i wasn't screaming etrecheck from on high. now i am!!
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#68I always wondered why the zoom app required root permissions, which is why I never installed it in the first place. What would a video conferencing app ever need root permissions for?! Now we know: a backdoor. Thank god for Apple putting down the law. This is why I happily pay premium prices...
I can't verify since I don't have it installed but I see no reason why this webserver would need root permissions. If it's asking for root it must be for something else.
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#69That's pretty epic. Apple continues to make big, brave moral gestures (like when they yanked Facebook and Google's enterprise certs earlier this year, or killed long-term tracking cookies in Safari overnight). Makes me happy to be a customer. Hope they keep enforcing their own rules and protecting their users' privacy and security in this fearless manner.
Apple definitely does make some commendable decisions, but I think it's also important to distinguish between bravery and what Ben Thompson calls "Strategy Credits" (https://stratechery.com/2013/strategy-credit/):
> Strategy Credit: An uncomplicated decision that makes a company look good relative to other companies who face much more significant trade-offs.
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#70From the article, this sounds like it was a GateKeeper change, de-whitelisting the signature, rather than an update, per se.