Live data from Hacker News

Apple has pushed a silent Mac update to remove hidden Zoom web server

techcrunch.com

191–200 of 552 posts

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#191
post #113

Earlier quoted context omitted.

How do you feel about Windows Defender?

I think the difference here is that apple explicitly does not have an "anti malware" configuration section of the MacOS control panel. There's configuration for automated system updates, which most technical people understand to mean security patches and things that are equivalent to windows hotfixes and servicepacks. I am with the "two wrongs don't make a right" people here. Zoom was reckless and their casual disreg…

If Apple removed a piece of ransomware that you installed would you have a problem with that?

Do you think anyone would have installed Zoom if they knew that it would allow any random website to activate your camera?

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#192

It's been rather disturbing to see this whole thing play out --- I'm not taking sides here, but Apple "flexing its arms" in this manner shows that it is willing and has the power to go beyond policing its App Store and such (which while I do not like, I feel it does have the right to) and involve itself in the affairs of third-party software which it did not originally install. (This is subtly different from updating…

I agree that this entire thing has been disturbing. Leaving behind a web server after you perform an uninstall by Zoom is unbelievable in my opinion. It's not even the fact that there was a vulnerability that makes me angry, it's the idea that you say uninstall, and it knowingly leaves a web server running on your machine.

Then, Apple, can push a silent update to simply kill software on your machine which as I understand it wasn't installed through the app store.

In this case I may be happy that it's no longer running, but the whole thing is disturbing. Looking at the Security & Privacy settings on my MacBook, I see nothing about running any anti-virus or anti-malware. The closest setting I can see that might be this is under software update, where I have the option to install automatically the system data files and security updates.

It's kind of a stretch for me to consider the ability to kill some software Apple might construe as malware at anytime the same thing as a "security update". To me, a security update would patch Apple code which had a vulnerability.

Where do I tell Apple to whitelist software in the future they might not like which I've chosen to install not going through the App Store?

It's actually news to me that I'm running Anti-X on my Mac, I didn't think I was.

Considering the fact that I have to learn new places for all the buttons every time Microsoft gets bored and changes things for the "better" I'm really disappointed.

System76 is looking better and better.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#193
post #158

Earlier quoted context omitted.

The same forces that require several levels of management make it increasingly difficult to enforce ethical decisions. Basically, when no one person can keep track of all the moving pieces you get splits around what individuals think is acceptable behavior. The larger organizations grows the more things tend to diverge, with different branches often having wildly different perspectives. This tends to further degrade…

Yes, and all of those are decisions you can go along with or reject. Deciding how big an organization you will join is one of many ways you apply your ethics.

That’s another issue. As an organization is viewed as less ethical, only less ethical people join creating a downward spiral.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#194

It's been rather disturbing to see this whole thing play out --- I'm not taking sides here, but Apple "flexing its arms" in this manner shows that it is willing and has the power to go beyond policing its App Store and such (which while I do not like, I feel it does have the right to) and involve itself in the affairs of third-party software which it did not originally install. (This is subtly different from updating…

I was waiting for this comment.

> You may agree with its decision this time, but will you always agree?

Yes, I will. At least I am not going to lose sleep over it until Apple does abuse that power.

I am actually even more happy to be an Apple user knowing that the mothership said hell naw to the naw naw naw naw to this horseshit Zoom has been pulling.

If I were Apple, I'd be taking this as a personal slight against my entire user base.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#195

Earlier quoted context omitted.

>The real issue there is the fact that macOS doesn't provide a standarized way to completely uninstall an app. reply And Windows does? Uninstallers are completely at the behest of application developers. No consumer OS but iOS actually provides any sort of true app level sandboxing.

> And Windows does? Control Panel “add and remove programs” usually works? There’s no equivalent on Mac. Yes, dragging the app to the trash is a thing but that leaves behind content in ~/Library/caches, ~/Library/Application Support, and ~/Library/Preferences . It’s been somewhat of an issue with Mac ever since they first put a hard drive on the original ones back in the 80s... Edit: I literally cleared several GB of…

Control Panel “add and remove programs” usually works?

All that does is launch the app’s uninstall process. The app is free to leave whatever crap it wants to on your system.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#196

Earlier quoted context omitted.

I think the difference here is that apple explicitly does not have an "anti malware" configuration section of the MacOS control panel. There's configuration for automated system updates, which most technical people understand to mean security patches and things that are equivalent to windows hotfixes and servicepacks. I am with the "two wrongs don't make a right" people here. Zoom was reckless and their casual disreg…

If Apple removed a piece of ransomware that you installed would you have a problem with that? Do you think anyone would have installed Zoom if they knew that it would allow any random website to activate your camera?

No, and I'm 100% in agreement with the need for it to be removed, it was clearly malware.

The question I see is really that Apple doesn't inform its users of the existence of this feature, unless you really search for it. Having something as simple as a functional-equivalent to Windows Defender with its own icon in Control Panel, which is fully enabled in the default operating system installation, should be sufficient.

Personally, unless I am specifically aware of the existence and enabled status of some anti-malware application, I don't think it's a good precedent to set for operating system vendors to start silently removing software from peoples' machines. Really all it should take is apple making people aware of the feature's existence.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#197
post #178
post #13

If you would like to force this update you can do so via the terminal: softwareupdate -ia --include-config-data It will show up as MRTConfigData if you look under Apple Menu->About This Mac->System Report->Software->Installations. The latest version is 1.45 and was updated today which includes the Zoom mitigations.

Any details about --include-config-data? Doesn't seem to be documented in the help message.

This blog post[1] has a good explanation of ConfigData updates. The flag would appear to force the install of new Gatekeeper configuration updates.

>To help distinguish Gatekeeper and XProtect updates from other updates in the software update feed, Apple marks them as being ConfigData updates.

>Marking these updates as ConfigData cues the App Store to not display these as available software updates in the App Store’s list of software updates. These updates are meant to be under Apple’s control and to be as invisible as possible.

[1] https://derflounder.wordpress.com/2014/12/27/managing-automa...

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#198
post #83

They are basically solving a self-inflicted problem. The real issue there is the fact that macOS doesn't provide a standarized way to completely uninstall an app.

Funny, it is also self-inflicted because Safari inspired Zoom to do this hack by breaking the correct behavior of protocol links. > This is a workaround to a change introduced in Safari 12 that requires a user to confirm that they want to start the Zoom client prior to joining every meeting. The local web server enables users to avoid this extra click before joining every meeting. https://blog.zoom.us/wordpress/2019/…

I think "breaking the correct behavior" might be a bit of misleading term -- it's obvious that in some contexts we would want to be warned about the context switch and in others we'd be annoyed by it. I could totally understand why Zoom would, for frequent users, want the users not to get an annoying dialogue. On the other hand, if I'm a rare user or don't know a program is installed on my system, the context switch dialogue would be super useful alerting me that something is happening.

So I think you could argue Apple might want to let you override that, I don't know what the language is and whether there's a "click here to skip this next time" box on the dialogue. It's possible they got the annoyance versus security tradeoff wrong.

But imho they didn't break the correct behavior any more than Microsoft "broke the correct behavior" of privilege escalation by adding a dialogue box with UAC in Windows 7 .

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#199

Earlier quoted context omitted.

>The real issue there is the fact that macOS doesn't provide a standarized way to completely uninstall an app. reply And Windows does? Uninstallers are completely at the behest of application developers. No consumer OS but iOS actually provides any sort of true app level sandboxing.

> And Windows does? Control Panel “add and remove programs” usually works? There’s no equivalent on Mac. Yes, dragging the app to the trash is a thing but that leaves behind content in ~/Library/caches, ~/Library/Application Support, and ~/Library/Preferences . It’s been somewhat of an issue with Mac ever since they first put a hard drive on the original ones back in the 80s... Edit: I literally cleared several GB of…

Why do they put that stuff in there instead of keeping it in the .app folder?

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#200
post #139
post #97

Earlier quoted context omitted.

I don’t understand how a “you’re about to jump out of the app” confirm panel is breaking protocol links. I actually want this behavior for zoom and any other app...

The first time you use that protocol, of course a warning is appropriate. To prompt the user on _every_ external protocol click seems.. hostile to the concept of linking

So then you have a protocol link to a .vbs file and you tell all of your contacts how much you love them.....
Post reply on HN