Live data from Hacker News

Apple has pushed a silent Mac update to remove hidden Zoom web server

techcrunch.com

351–360 of 552 posts

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#351

It's been rather disturbing to see this whole thing play out --- I'm not taking sides here, but Apple "flexing its arms" in this manner shows that it is willing and has the power to go beyond policing its App Store and such (which while I do not like, I feel it does have the right to) and involve itself in the affairs of third-party software which it did not originally install. (This is subtly different from updating…

Jesus Christ, literally do you work for Zoom? This isn't a hot take, this is a fundamental lack of understanding about how macOS, any OS works.

Could you please not slide back into breaking the site guidelines like this? I don't want to ban you, but you've done it repeatedly recently.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#352
post #233

Earlier quoted context omitted.

Let me introduce you to the nice folks over at Objective See.. https://objective-see.com/products.html They have a bunch of cool little apps (that are free) like BlockBlock that let you know when things are happening you wouldn't have otherwise allowed. For example, BlockBlock warned me randomly about 30 minutes ago about an app that was being silently installed in the background.. something I hadn't seen before call…

> Let me introduce you to the nice folks over at Objective See.. https://objective-see.com/products.html The "nice folks" at Objective-See is Patrick Wardle, a former NSA rootkit expert who would like nothing more than to install various close-sourced components on your computer.

I'm not necessarily a fan of Patrick Wardle, but his software is open source: https://github.com/objective-see/

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#353
post #330

Earlier quoted context omitted.

Let me introduce you to the nice folks over at Objective See.. https://objective-see.com/products.html They have a bunch of cool little apps (that are free) like BlockBlock that let you know when things are happening you wouldn't have otherwise allowed. For example, BlockBlock warned me randomly about 30 minutes ago about an app that was being silently installed in the background.. something I hadn't seen before call…

That’s funny. Windows’ own tool for these matters is called... MRT.exe

Maybe it stands for Malware Removal Tool on Windows as well.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#354
post #278

Huh? Why is it ok for Apple or anyone to do silent installs on my computer? As a customer, why am I getting this information from YC/Techcrunch and not Apple? What else have they pushed like this? Is there a transparent log? Can we verify if their track record is clean? How many times have they silently broken and fixed their own things? How do we know they won't abuse this? Isn't this the same dark pattern that we c…

Apple has done silent updates for Gatekeeper, the macOS code signing/file quarantine/light anti-malware framework ever since Yosemite. These are done silently unless you explicitly disable all updates and only show up as a visible item when you manually list updates using the softwareupdate command line tool, I think. AFAIK these are just config files and hash databases or similar. You can view the history of these i…

> These are done silently unless you explicitly disable all updates

You can turn off silent security updates from System Preferences without affecting software update checks for other components.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#355
post #13

If you would like to force this update you can do so via the terminal: softwareupdate -ia --include-config-data It will show up as MRTConfigData if you look under Apple Menu->About This Mac->System Report->Software->Installations. The latest version is 1.45 and was updated today which includes the Zoom mitigations.

To check it with fewer mouse clicks:

  system_profiler SPInstallHistoryDataType |grep -A5 MRTConfigData

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#356

It's been rather disturbing to see this whole thing play out --- I'm not taking sides here, but Apple "flexing its arms" in this manner shows that it is willing and has the power to go beyond policing its App Store and such (which while I do not like, I feel it does have the right to) and involve itself in the affairs of third-party software which it did not originally install. (This is subtly different from updating…

> You may agree with its decision this time, but will you always agree? To be honest I'm kinda sick of this argument. Someone brings this argument up _every single time_ a tech company takes action against something malicious. It's a strawman argument at best and at worst a way to give people an out on acting against something that could harm the user. > Apple's wielding of power in this way is likely to attract the…

How is it a strawman? It's not even a hypothetical, has everyone forgotten already the constant dramas from the era in which Steve Jobs insisted iPhone apps would be banned if they weren't of "very good quality" or whatever the BS wording was? And when he went on his personal moral quest against porn?

This seems like overreach to me. It's annoying but it's not like the Zoom app was silently letting people watch me for hours through my webcam without anyone noticing - the app opens a full screen video sharing GUI for goodness sake. Is being joined to a VC without me wanting it when I click a link annoying? Sure. It also serves the attacker no real purpose and thus has never actually happened in the wild. It's also easily fixed. This is a storm in a teacup.

Moreover it seems from the last discussion of this on HN that videocall firms do this for a good reason - lots of users get confused by bad Safari permissions GUIs and end up locking themselves out of the app by cancelling the URL open prompt without thinking (which is apparently persistent!) Then they can't join the call. So the only reason these firms are using such a bad workaround to begin with is because Apple screwed up their user interfaces: why is this not on Apple to fix?

This appears to send a message to Mac devs that a single troublemaking blogger can cause Apple to kneejerkingly nuke features in your app overnight, regardless of whether you are fixing them, whether they're serious or not or whether it will result in legions of confused and stuck Mac users. Not a great message.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#357
post #267

Earlier quoted context omitted.

Not after Catalina. Future versions of macOS will require signed software (notarized as per Apple terminology), even outside of the store. What is new in security at WWDC.

I don't fully understand the difference. But signed is different from notarized. Notarized means you uploaded the binary to Apple. Previously, you can sign without doing that. I haven't looked enough to understand what is gained by notary. Does Apple want to search your binary for maliciousness or rulebreaking (potentially even at a later date) so that it might revoke the notarization/signature?

As far as I understand, notarization is intended to catch malware before it can be distributed. The traditional signing mechanism can protect users against malicious software because Apple can pull certificates used to sign malware.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#358

That's pretty epic. Apple continues to make big, brave moral gestures (like when they yanked Facebook and Google's enterprise certs earlier this year, or killed long-term tracking cookies in Safari overnight). Makes me happy to be a customer. Hope they keep enforcing their own rules and protecting their users' privacy and security in this fearless manner.

Apple or anyone cannot silently pushing changes to my computer without my explicit consent – especially on unrelated things. What Apple did here is also a dark pattern. We cannot commend them and normalize this behavior. This is a dictatorial one-sided decision by Apple. What else can they do? Can nation state governments compel Apple to push stuff silently? Can this system be abused by hackers? Why are we dependent…

It's also on macOS license agreement:

"By using the Apple Software, you agree that Apple may download and install automatic updates onto your computer and your peripheral devices. You can turn off automatic updates altogether at any time by changing the automatic updates settings found within System Preferences."

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#359
post #267
post #168

Earlier quoted context omitted.

> It effectively breaks their sandbox model The sandbox only applies to software devs that want to use it or those that wish to sell through the Mac App Store. I don't think Zoom is in the MAS at all (I don't see it in a quick search anyway), and a standalone installer is free to do whatever it wants and can convince users to go along with (up to and including, in principle, bypassing SIP though since that significan…

Not after Catalina. Future versions of macOS will require signed software (notarized as per Apple terminology), even outside of the store. What is new in security at WWDC.

Notarized≠signed. I suggest you watch the videos that you've posted; they go into detail about the changes in macOS Catalina and when they apply.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#360
post #52

Wasn't there once a company with the motto "Don't be evil."? If that motto is abandoned, Apple should claim it since they genuinely try do their best to live by it.

Not so fast. E.g. have you read "History will not be kind to Jony Ive"[1]?

Apple has its share of evil. Another example is preventing people from repairing their own Apple devices.

--

[1] https://www.vice.com/en_us/article/ywyjmw/history-will-not-b...

Post reply on HN