Live data from Hacker News

Apple has pushed a silent Mac update to remove hidden Zoom web server

techcrunch.com

61–70 of 552 posts

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#61
post #51

That's pretty epic. Apple continues to make big, brave moral gestures (like when they yanked Facebook and Google's enterprise certs earlier this year, or killed long-term tracking cookies in Safari overnight). Makes me happy to be a customer. Hope they keep enforcing their own rules and protecting their users' privacy and security in this fearless manner.

I don't think killing those enterprise cert was a moral gesture. They were just enforcing their walled garden.

[deleted]

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#62
post #6

Earlier quoted context omitted.

So the local server is not a regular price of software with a vulnerability, it is now considered malware?

That's Apple's closed garden, even when they allow you to sideload application, they still have the ultimate decision. Of course it's not malware, but probably enough users have vulnerable software which could be remotely exploited, that they decided to blacklist it.

A program that surreptitiously reinstalls software when you uninstall it is by definition malware.

A piece of software that lets any website activate your camera without your permission is a security vulnerability.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#63

I always wondered why the zoom app required root permissions, which is why I never installed it in the first place. What would a video conferencing app ever need root permissions for?! Now we know: a backdoor. Thank god for Apple putting down the law. This is why I happily pay premium prices...

I can't verify since I don't have it installed but I see no reason why this webserver would need root permissions. If it's asking for root it must be for something else.

Quite a few apps ask for root during installation. But now you have me wondering which apps ask for root and which don't. Would be neat if there was a huge app registry website that could show this. Name and shame the ones that ask for root..

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#64
post #11
post #6

Earlier quoted context omitted.

So the local server is not a regular price of software with a vulnerability, it is now considered malware?

The server was intentionally left behind, and running, by the "uninstaller". The server would respond to requests by reinstalling the intentionally uninstalled software . That's malware. The server itself was deliberately added to work around a Safari security feature, that was designed specifically to prevent what they wanted: allowing arbitrary web content to open an app without user consent. They literally added a…

> The server was intentionally left behind, and running, by the "uninstaller

FWIW, I don’t think there was a uninstaller? What I’ve seen people describe is that dragging the .App file to the trash wouldn’t remove the server, since it was installed in a different folder.

There was no uninstaller until the Zoom update this week added an uninstall option to the menu.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#65
I wonder if this was the real reason behind the Zoom backflip. It certainly cannot be good for business if your app gets marked as malware.

Seriously though, they should have owned the mistake, apologised and reversed their decision rather than handling it with a PR spin. It is a great product but somehow it has left me with little trust for zoom. It's probably still not too late.

Does anyone know if bluejeans et all are also removing this? Or does it require public shaming, like the zoom case?

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#66
post #44

The bigger question -- what other desktop apps have similar, latent daemons hanging around? I'm always wary of installing stuff like this (e.g. zoom, go2meeting, teamviewer). Anyone know of other sneaky apps to avoid?

Razer gaming keyboard drivers spin up a webserver for controlling the chroma, which I've always found scary. (Using the much more reasonable community open source drivers that don't do that.)

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#67

ertecheck found this for me maybe 2 months ago. coincidentally right in the disclosure window! i tried etrecheck on a lark. at the time i found it unremarkable. oh, i have this leftover dingle here, thanks etrecheck, i'll just remove it then. but otherwise i wasn't screaming etrecheck from on high. now i am!!

Everything about the etrecheck website screams "system optimizer scam!" and this comment does nothing but reinforce that feeling.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#68

I always wondered why the zoom app required root permissions, which is why I never installed it in the first place. What would a video conferencing app ever need root permissions for?! Now we know: a backdoor. Thank god for Apple putting down the law. This is why I happily pay premium prices...

I can't verify since I don't have it installed but I see no reason why this webserver would need root permissions. If it's asking for root it must be for something else.

They ship a pkg installer package that pretty much always elevates, even if it doesn’t actually need it. While it could in theory install as the user, I don’t even think the Installer app supports this configuration anymore (at least last time I tried I wasn’t able to).

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#69

That's pretty epic. Apple continues to make big, brave moral gestures (like when they yanked Facebook and Google's enterprise certs earlier this year, or killed long-term tracking cookies in Safari overnight). Makes me happy to be a customer. Hope they keep enforcing their own rules and protecting their users' privacy and security in this fearless manner.

I don't think disabling the enterprise certs was particularly moral, Facebook and Google were flagrantly violating the terms of the enterprise program. Apple also apparently didn't even notice (or didn't care) until articles about it started getting a lot of attention.

Apple definitely does make some commendable decisions, but I think it's also important to distinguish between bravery and what Ben Thompson calls "Strategy Credits" (https://stratechery.com/2013/strategy-credit/):

> Strategy Credit: An uncomplicated decision that makes a company look good relative to other companies who face much more significant trade-offs.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#70
post #2

From the article, this sounds like it was a GateKeeper change, de-whitelisting the signature, rather than an update, per se.

Looks like the ZoomOpener app is still present on my machine but it’s not running anymore and it shows as unticked in the Login Items preferences.
Post reply on HN