Live data from Hacker News

Apple has pushed a silent Mac update to remove hidden Zoom web server

techcrunch.com

131–140 of 552 posts

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#131

Earlier quoted context omitted.

> Some other comments here suggest that the installation of this update is controlled by a setting described as being for system related updates, which a user would expect to leave his/her third-party software alone. The setting is called "Install system data files and security updates": it's not just system components.

I suppose that depends on the application of the transitive property of English grammar: "Install (system) (data files and security updates)" or "Install (system data files) and (security updates)"

Removing a malware app is installing a system security update.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#132
post #18

Disturbs me somewhat that Apple has a way to silently push changes to laptops without user interaction.

Windows update does the same, no?

When I was at Microsoft, Windows' policy was only to kill applications like this with the explicit consent of the manufacturer (i.e. they were usually asking us to do it because they are unable to patch themselves, not the other way around), and only with a very specific version range.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#133

They are basically solving a self-inflicted problem. The real issue there is the fact that macOS doesn't provide a standarized way to completely uninstall an app.

Which is completely frustrating, because Mac is totally in the position of using its built-in capabilities to deal with this. The Mac Bundle (.app) format could solve this entirely. All application specific data should be written inside of the bundle folder, so that when you delete the app, you delete the thing entirely. I mean, maybe you need a "user data" bundle of sorts tied to the specific application. If you del…

> The default installer and bundle runners should be controlling the process. "XYZ App is attempting to write data files outside of its bundle location. These may not be cleaned up if you delete the application. Do you want to continue?"

If you do that, the entire system stops working. Everyone will just click "ok" and then still gets mad when uninstalling doesn't fully clean things up.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#134
post #44

The bigger question -- what other desktop apps have similar, latent daemons hanging around? I'm always wary of installing stuff like this (e.g. zoom, go2meeting, teamviewer). Anyone know of other sneaky apps to avoid?

I had toyed with using Little Snitch, https://www.obdev.at/products/littlesnitch/index.html, to let me know what connections each program is making but after like a day it was just too complex to get going.

Wonder if the LitteSnitch list of procs had the Zoom Daemon.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#135
post #97
post #83

Earlier quoted context omitted.

Funny, it is also self-inflicted because Safari inspired Zoom to do this hack by breaking the correct behavior of protocol links. > This is a workaround to a change introduced in Safari 12 that requires a user to confirm that they want to start the Zoom client prior to joining every meeting. The local web server enables users to avoid this extra click before joining every meeting. https://blog.zoom.us/wordpress/2019/…

I don’t understand how a “you’re about to jump out of the app” confirm panel is breaking protocol links. I actually want this behavior for zoom and any other app...

It adds an extra, confusing step, that is not necessary most of the time.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#136
post #81

Earlier quoted context omitted.

I would say true morals lead to structuring your company in such a way that you don’t have to rely on business people making ethical decisions moment to moment, because they won’t.

As nice as that sounds, I think it requires an impossibly perfect prediction of future events. You face ethical decisions whenever you have power or limited resources.

No. You can bend your business model towards transactions you are comfortable with, without perfect future vision, or even a clear strategic understanding of how that might happen.

In fact, the world around you will bend to meet your values whether you’re even aware of it. And that includes any companies you run.

The world does extend beyond your knowledge of it.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#137

It's been rather disturbing to see this whole thing play out --- I'm not taking sides here, but Apple "flexing its arms" in this manner shows that it is willing and has the power to go beyond policing its App Store and such (which while I do not like, I feel it does have the right to) and involve itself in the affairs of third-party software which it did not originally install. (This is subtly different from updating…

That's why the only safe OS is indeed Linux. Say, Xubuntu or Fedora. Microsoft has turned the masses into unpaid QA along with extracting their digital wealth. Mac/iOS is a dictatorial wasteland. And Android is adtechs wet dream.

It's weird to call Linux "safe" because it lacks an optional anti-malware service.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#138

Earlier quoted context omitted.

Neither does Windows or Linux. I don't think you can have such a standardized way on a flexible general-purpose OS.

What apple should do though is provide an API that developers can hook into, where in when the user drags the app to the trash, it can also uninstall anything else the app placed elsewhere on the system.

They do! The app developers didn't follow the guidelines.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#139
post #97
post #83

Earlier quoted context omitted.

Funny, it is also self-inflicted because Safari inspired Zoom to do this hack by breaking the correct behavior of protocol links. > This is a workaround to a change introduced in Safari 12 that requires a user to confirm that they want to start the Zoom client prior to joining every meeting. The local web server enables users to avoid this extra click before joining every meeting. https://blog.zoom.us/wordpress/2019/…

I don’t understand how a “you’re about to jump out of the app” confirm panel is breaking protocol links. I actually want this behavior for zoom and any other app...

The first time you use that protocol, of course a warning is appropriate. To prompt the user on _every_ external protocol click seems.. hostile to the concept of linking

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#140

It's been rather disturbing to see this whole thing play out --- I'm not taking sides here, but Apple "flexing its arms" in this manner shows that it is willing and has the power to go beyond policing its App Store and such (which while I do not like, I feel it does have the right to) and involve itself in the affairs of third-party software which it did not originally install. (This is subtly different from updating…

If you can't see a difference between deleting files not authorized by the person who bought, installed, and uses the OS, and deleting files not authorized by third parties, I don't know what to tell you.
Post reply on HN