Live data from Hacker News

Apple has pushed a silent Mac update to remove hidden Zoom web server

techcrunch.com

231–240 of 552 posts

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#231
post #222

Earlier quoted context omitted.

Thanks for the reply, really good stuff. But what I don't get, why even have an "Application Support" directory at all. There is absolutely nothing of value added to me (as a user) to have files stored there. It's just one more place I have to look to clean up after an application is deleted. So dumb and adds zero value. I'll put my files into Documents (or whatever). And you (as an application developer) put your fi…

Mac OS is a multi-user operating system. Most applications that are installed are global to the system although each user also has their own Applications folder. The Application Support folder resides in the user's Library folder and contains information that the app needs when running for that particular user. Storing information in the .app bundle would affect every user on that computer.

You're saying that an application can't write user specific information into the bundle and sort that out? There's no difference between these two (hypothetical) file paths:

  /Applications/SomeApp.app/users/taftster/user.specific.data
  /Users/taftster/Library/Application Support/SomeApp/user.specific.data
These two file paths are effectively the same. And when the "global" application gets deleted, I most definitely want all the user data deleted with it as well.

And no, I'm not talking about saved output (documents, etc.) that are generated by the application. I'm saying there is just no need for Application Support at all; it adds no value and is just used by convention.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#232
post #63

Earlier quoted context omitted.

Quite a few apps ask for root during installation. But now you have me wondering which apps ask for root and which don't. Would be neat if there was a huge app registry website that could show this. Name and shame the ones that ask for root..

Let me introduce you to the nice folks over at Objective See.. https://objective-see.com/products.html They have a bunch of cool little apps (that are free) like BlockBlock that let you know when things are happening you wouldn't have otherwise allowed. For example, BlockBlock warned me randomly about 30 minutes ago about an app that was being silently installed in the background.. something I hadn't seen before call…

Wow, neat stuff. Several machines ago, I used to run Little Snitch, but never got past the trial. At some point I searched for free alternatives but didn't find anything. LuLu seems to be very similar, so I'm giving it a try!

Funny how both companies have "objective" in their names.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#233
post #63

Earlier quoted context omitted.

Quite a few apps ask for root during installation. But now you have me wondering which apps ask for root and which don't. Would be neat if there was a huge app registry website that could show this. Name and shame the ones that ask for root..

Let me introduce you to the nice folks over at Objective See.. https://objective-see.com/products.html They have a bunch of cool little apps (that are free) like BlockBlock that let you know when things are happening you wouldn't have otherwise allowed. For example, BlockBlock warned me randomly about 30 minutes ago about an app that was being silently installed in the background.. something I hadn't seen before call…

> Let me introduce you to the nice folks over at Objective See.. https://objective-see.com/products.html

The "nice folks" at Objective-See is Patrick Wardle, a former NSA rootkit expert who would like nothing more than to install various close-sourced components on your computer.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#234

Has anyone checked that `dpkg --purge zoom` does the right thing, on debian/ubuntu?

Keep in mind dpkg never removes user data.

So that said, I checked, and it removes everything zoom installs that isn't in a user directory, plus (there is an extra script that does this):

    remove_folder "/opt/zoom"
    remove_folder "$HOME/.zoom/logs"
    remove_folder "$HOME/.cache/zoom"
Which is stupid since it's removing this from root, who probably never ran zoom.

Note it removes logs from .zoom, but not the directory itself. Which is good, since there might be user data in there (chat logs, and recordings).

Unlike Macs, there is no hidden webserver.

There is also (yes, it's commented out):

    #logged_in_users=$(who -q | head -n 1)
    #sorted_users=$(echo "$logged_in_users"|tr " " "\n"|sort|uniq|tr "\n" " ")
    #for user in $sorted_users;do
    #       echo "removing $(grep -w ^$user /etc/passwd | cut -d ":" -f6)""/.zoom..."
    #       remove_folder "$(grep -w ^$user /etc/passwd | cut -d ":" -f6)""/.zoom"
    #       echo "removing $(grep -w ^$user /etc/passwd | cut -d ":" -f6)""/.config/zoomus.conf..."
    #       remove_file "$(grep -w ^$user /etc/passwd | cut -d ":" -f6)""/.config/zoomus.conf"

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#235

Earlier quoted context omitted.

Malware is a software written to harm user. Their purpose was not to harm user, they wanted to make their service more convenient for users. Bugs are bugs, every product have bugs and many products have security bugs. That does not make them malware.

There is tons of malware that doesn't harm the user. Take crypto mining for example: it raises the temperature and the electricity bill, but those things aren't per se harmful (albeit financially). Or how about a botnet client that harms some other entity but not the user who owns the machine it's on? Or adware? The list goes on and on... calling this nefarious behavior "harm" is a huge stretch but calling it "malwar…

Stealing electricity is harm. It’s theft no different than if someone stole your wallet.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#236
post #224

Earlier quoted context omitted.

A sandboxed macOS app would offer similar protections as what snapd, flatpak, etc provide on Linux. > Even the regular Linux package managers like apt, dnf, pacman track which files were installed by which packages, so they can be removed when the package is uninstalled. Technically speaking, Zoom could have abused dpkg post-install scripts, or pulled similar tricks, to install their malware server and leave it behin…

> Technically speaking, Zoom could have abused dpkg post-install scripts, or pulled similar tricks, to install their malware server and leave it behind after the package was removed. Linux distributions aren't invincible to these shenanigans. This is correct, but such a package should not make it into the distribution's package repositories.

And likewise Zoom didn’t make it to the AppStore...

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#237

That's pretty epic. Apple continues to make big, brave moral gestures (like when they yanked Facebook and Google's enterprise certs earlier this year, or killed long-term tracking cookies in Safari overnight). Makes me happy to be a customer. Hope they keep enforcing their own rules and protecting their users' privacy and security in this fearless manner.

Wouldn't it be EPIC if apple produced a statement saying

"We are not going to keep any data at all about you unless we are forced to do so legally. We are bound by that contract with you when you purchase our device."

Then followed that with

"We're going to make it as hard as humanly possible for anyone else to collect and keep data about you if you own one of our devices. Including both legal and technical solutions and we will sue them for breach."

As it is, we're praising "least worse" which is effing awful. Apple's excrement stinks less than some others, eat it up!

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#238
post #171

It's been rather disturbing to see this whole thing play out --- I'm not taking sides here, but Apple "flexing its arms" in this manner shows that it is willing and has the power to go beyond policing its App Store and such (which while I do not like, I feel it does have the right to) and involve itself in the affairs of third-party software which it did not originally install. (This is subtly different from updating…

They worked with Zoom to kill the zombie servers which were left behind after Zoom is uninstalled. Not really flexing. Zoom accidentally created malware, and Apple killed it using the same mechanisms they would to kill other malware.

That’s being pretty kind to a company that bypassed a system setting designed to respect user permissions by writing an always-running insecure web server —- and then refusing to remove that web server and even reinstalling itself when you remove the app.

Oh, and a company that defended the insecure web server up until the moment the public outrage exploded and/or the RCE it had willfully ignored was about to be revealed.

Oh, and a public company at that, that’s trying to convince businesses to use its product as it primary video chat system.

Apple worked with Zoom insofar as Apple cleaned up Zoom’s mess because of Zoom’s poor/unethical software practices.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#239

Earlier quoted context omitted.

> And Windows does? Control Panel “add and remove programs” usually works? There’s no equivalent on Mac. Yes, dragging the app to the trash is a thing but that leaves behind content in ~/Library/caches, ~/Library/Application Support, and ~/Library/Preferences . It’s been somewhat of an issue with Mac ever since they first put a hard drive on the original ones back in the 80s... Edit: I literally cleared several GB of…

The point is, all of those files are generally still left behind on Windows as well. Uninstalling a program in Windows is roughly equivalent to dragging it into the trash in macOS.

> all of those files are generally still left behind on Windows as well.

Citation needed. That was the case in the 90s, these days most apps (device drivers aside) uninstall fairly cleanly with only settings/configurations stored in the registry still resident afterwards. Startup programs remaining after an uninstall is straight-up a bug.

Post reply on HN