Live data from Hacker News

Apple has pushed a silent Mac update to remove hidden Zoom web server

techcrunch.com

261–270 of 552 posts

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#261

Earlier quoted context omitted.

any OS (and many other apps) that update have the power to do what you’re afraid of, and much more. There's an ocean of difference between can and will . plus i don’t really see a bright line between system level software and an app when apps can access your video cam, mic, all your files - basically your whole computer. The setting ostensibly refers to the operating system , i.e. macOS, which I have no problems with…

I’m quite happy with it, as I don’t see millions of people removing some hidden directory. No more zoom for me.

The point is precisely NOT to think about only this one case like many others seem to be focusing (or Zoom-ing in...?) on, but to consider how far you are willing to let Apple exercise its power over your computer.

Would you let it scan all your files and delete e.g. "suspected images of child abuse" (to use an old cliche)? Suspected copyrighted material or fragments thereof? "Extremist" content, or content which is contrary to current social norms? How authoritarian does it have to get before you start being creeped out?

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#262
post #42

This means there might have been another side to this story: Zoom's change of heart might have been forced by Apple, not the public backlash. Apple: Hey, your app poses a threat to macOS security. We're going to remove your server app with the built-in macOS anti-virus. Zoom: Oh crap. Okay, give us 2 sprints to release a new version that removes it. Apple: We're killing it in 48 hours. ... Zoom, after an all-nighter:…

[deleted]

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#263

Earlier quoted context omitted.

I’m quite happy with it, as I don’t see millions of people removing some hidden directory. No more zoom for me.

The point is precisely NOT to think about only this one case like many others seem to be focusing (or Zoom-ing in...?) on, but to consider how far you are willing to let Apple exercise its power over your computer. Would you let it scan all your files and delete e.g. "suspected images of child abuse" (to use an old cliche)? Suspected copyrighted material or fragments thereof? "Extremist" content, or content which is…

You can take any capability and stretch it out to some absurd extreme. What if apt-get whatnot trashed your entire computer? What if buses started hunting pedestrians for sport? It's a line of inquiry that prioritizes handwringing over insight.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#264

It's been rather disturbing to see this whole thing play out --- I'm not taking sides here, but Apple "flexing its arms" in this manner shows that it is willing and has the power to go beyond policing its App Store and such (which while I do not like, I feel it does have the right to) and involve itself in the affairs of third-party software which it did not originally install. (This is subtly different from updating…

I'm actually quite happy to have Apple police its App Store and offer patches that eliminate security holes and malware. There's nothing wrong with Apple trying to make your computer safer and less prone to exploitation, in my opinion.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#265

It's been rather disturbing to see this whole thing play out --- I'm not taking sides here, but Apple "flexing its arms" in this manner shows that it is willing and has the power to go beyond policing its App Store and such (which while I do not like, I feel it does have the right to) and involve itself in the affairs of third-party software which it did not originally install. (This is subtly different from updating…

Jesus Christ, literally do you work for Zoom? This isn't a hot take, this is a fundamental lack of understanding about how macOS, any OS works.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#266

Earlier quoted context omitted.

The point is, all of those files are generally still left behind on Windows as well. Uninstalling a program in Windows is roughly equivalent to dragging it into the trash in macOS.

> all of those files are generally still left behind on Windows as well. Citation needed. That was the case in the 90s, these days most apps (device drivers aside) uninstall fairly cleanly with only settings/configurations stored in the registry still resident afterwards. Startup programs remaining after an uninstall is straight-up a bug.

> these days most apps (device drivers aside) uninstall fairly cleanly

Citation needed.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#267
post #168

Earlier quoted context omitted.

I’m sure Apple is as upset as anyone else. It effectively breaks their sandbox model so they’ll probably be working hard on a way to plug that hole gracefully.

> It effectively breaks their sandbox model The sandbox only applies to software devs that want to use it or those that wish to sell through the Mac App Store. I don't think Zoom is in the MAS at all (I don't see it in a quick search anyway), and a standalone installer is free to do whatever it wants and can convince users to go along with (up to and including, in principle, bypassing SIP though since that significan…

Not after Catalina.

Future versions of macOS will require signed software (notarized as per Apple terminology), even outside of the store.

What is new in security at WWDC.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#268
Huh? Why is it ok for Apple or anyone to do silent installs on my computer? As a customer, why am I getting this information from YC/Techcrunch and not Apple?

What else have they pushed like this? Is there a transparent log? Can we verify if their track record is clean? How many times have they silently broken and fixed their own things? How do we know they won't abuse this?

Isn't this the same dark pattern that we criticized zoom for? Did I consent to Apple doing silent editorial changes to my system?

For having exercised this editorial privilege, will Apple take accountability for every thing that is done by every app on my computer?

It seems like we are being slow-boiled into accepting outrageous things as normal.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#269

Earlier quoted context omitted.

I’m sure Apple is as upset as anyone else. It effectively breaks their sandbox model so they’ll probably be working hard on a way to plug that hole gracefully.

There is no real sandbox model on Macs if you don’t go through the Mac App Store, only code signing to detect that the app hasn’t been tampered with and to validate the author.

Until Catalina, which will more aggressively use permissions and require all software to be notarized.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#270

That's pretty epic. Apple continues to make big, brave moral gestures (like when they yanked Facebook and Google's enterprise certs earlier this year, or killed long-term tracking cookies in Safari overnight). Makes me happy to be a customer. Hope they keep enforcing their own rules and protecting their users' privacy and security in this fearless manner.

Apple or anyone cannot silently pushing changes to my computer without my explicit consent – especially on unrelated things.

What Apple did here is also a dark pattern. We cannot commend them and normalize this behavior.

This is a dictatorial one-sided decision by Apple. What else can they do? Can nation state governments compel Apple to push stuff silently? Can this system be abused by hackers?

Why are we dependent on the good moral behavior of Apple business decision makers for the well-being of our digital lives? Haven't we learnt anything at all from all the incidents in the recent past w.r.t trust in corporate benevolence?

Post reply on HN