Live data from Hacker News

Apple has pushed a silent Mac update to remove hidden Zoom web server

techcrunch.com

371–380 of 552 posts

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#371
post #83

Earlier quoted context omitted.

Funny, it is also self-inflicted because Safari inspired Zoom to do this hack by breaking the correct behavior of protocol links. > This is a workaround to a change introduced in Safari 12 that requires a user to confirm that they want to start the Zoom client prior to joining every meeting. The local web server enables users to avoid this extra click before joining every meeting. https://blog.zoom.us/wordpress/2019/…

I think "breaking the correct behavior" might be a bit of misleading term -- it's obvious that in some contexts we would want to be warned about the context switch and in others we'd be annoyed by it. I could totally understand why Zoom would, for frequent users, want the users not to get an annoying dialogue. On the other hand, if I'm a rare user or don't know a program is installed on my system, the context switch…

> But imho they didn't break the correct behavior any more than Microsoft "broke the correct behavior" of privilege escalation by adding a dialogue box with UAC in Windows 7 .

well, it did a shitton didn't it ? to this day, most people I know disable UAC because of how annyoing it is.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#372
post #263

Earlier quoted context omitted.

The point is precisely NOT to think about only this one case like many others seem to be focusing (or Zoom-ing in...?) on, but to consider how far you are willing to let Apple exercise its power over your computer. Would you let it scan all your files and delete e.g. "suspected images of child abuse" (to use an old cliche)? Suspected copyrighted material or fragments thereof? "Extremist" content, or content which is…

You can take any capability and stretch it out to some absurd extreme. What if apt-get whatnot trashed your entire computer? What if buses started hunting pedestrians for sport? It's a line of inquiry that prioritizes handwringing over insight.

No, it prioritizes thinking about clear boundaries ahead of time, while you're able to think clearly about the issues. "Hard cases make bad law" as the lawyers say. Ethicists do this sort of thing all the time.

There's a line between the OS and third-party software. There's a line between malicious software and accidentally vulnerable. Apple has just shown that it is willing to cross both those lines. Where is the line at which Apple will stop?

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#373

Earlier quoted context omitted.

I think the difference here is that apple explicitly does not have an "anti malware" configuration section of the MacOS control panel. There's configuration for automated system updates, which most technical people understand to mean security patches and things that are equivalent to windows hotfixes and servicepacks. I am with the "two wrongs don't make a right" people here. Zoom was reckless and their casual disreg…

If Apple removed a piece of ransomware that you installed would you have a problem with that? Do you think anyone would have installed Zoom if they knew that it would allow any random website to activate your camera?

> Do you think anyone would have installed Zoom if they knew that it would allow any random website to activate your camera?

Yes, I'm quite confident that millions of "normal users" would still have installed Zoom knowing that.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#374

Huh? Why is it ok for Apple or anyone to do silent installs on my computer? As a customer, why am I getting this information from YC/Techcrunch and not Apple? What else have they pushed like this? Is there a transparent log? Can we verify if their track record is clean? How many times have they silently broken and fixed their own things? How do we know they won't abuse this? Isn't this the same dark pattern that we c…

I don't want to come across as confrontational, but I find this kind of response exhausting. I do not want control of everything on my computer. I don't have time or expertise to decide on whether to accept each and every security update, particularly ones that involve a web server which was installed by stealth and which isn't removed when the app is uninstalled. I want to outsource these kinds of decisions to people more qualified than me, and if I don't have to pay extra for those people (beyond the extra expense of buying Apple products) all the better.

If you want complete control over your computer you have the choice of getting yourself a PC with some flavour of *nix, and combing through each update as it comes. I really don't like the future of Apple that you seem to want. Apple has made missteps, sure - like that idiotic U2 album - but I actively want things like this to happen, and I imagine the vast majority of Apple users do too (if they actually ever think about it).

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#375
post #42

This means there might have been another side to this story: Zoom's change of heart might have been forced by Apple, not the public backlash. Apple: Hey, your app poses a threat to macOS security. We're going to remove your server app with the built-in macOS anti-virus. Zoom: Oh crap. Okay, give us 2 sprints to release a new version that removes it. Apple: We're killing it in 48 hours. ... Zoom, after an all-nighter:…

HN 2 hours since story broke:

  rm -rf ~/.zoomus

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#376
post #193

Earlier quoted context omitted.

Yes, and all of those are decisions you can go along with or reject. Deciding how big an organization you will join is one of many ways you apply your ethics.

That’s another issue. As an organization is viewed as less ethical, only less ethical people join creating a downward spiral.

It’s quite clear that you are indulging in the fantasy of the free market correcting itself by the patrons dollar. This rarely plays out in reality. It even more rarely plays out when certain corporations have hegemonic control of technology, culture and the body politic.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#378
post #372
post #263

Earlier quoted context omitted.

You can take any capability and stretch it out to some absurd extreme. What if apt-get whatnot trashed your entire computer? What if buses started hunting pedestrians for sport? It's a line of inquiry that prioritizes handwringing over insight.

No, it prioritizes thinking about clear boundaries ahead of time, while you're able to think clearly about the issues. "Hard cases make bad law" as the lawyers say. Ethicists do this sort of thing all the time. There's a line between the OS and third-party software. There's a line between malicious software and accidentally vulnerable. Apple has just shown that it is willing to cross both those lines. Where is the li…

In what way did Apple cross a line? Platform vendors have automatically removed malware for many years. In this particular case, Apple, in consultation with the vendor, removed a particularly nasty vulnerability. The software itself was left alone. In fact, because the software was written so poorly, the vendor didn't even have the ability to address the problem - only Apple could. It's even odder to bring up ethics - should Apple have knowingly left zillions of users exposed to this?

To make this look scary, you have to misrepresent what Apple actually did and then extrapolate to some frightening hypothetical to end up at nothing more than a risk inherent in all self-updating software.

If the position is 'all self-updating software is an unreasonable risk', fine. But at least argue that unvarnished, and I imagine to most people, extreme and impractical view instead of trying to dress it up as some novel and intricate argument about morality and creeping authoritarianism.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#379
post #324
post #206

Earlier quoted context omitted.

> iMessage is end-to-end encrypted. The keys are managed by the devices themselves. There is no facility to backdoor or intercept the messages. That is only a half-truth. Apple controls the key infrastructure; they may replace your keys with arbitrary ones at the demand, coercion or compromise by any number of bad actors. The software is closed source, making it impossible to verify any actual claims made otherwise.…

I find it disappointing that we blame companies operating in China and not the real forcing function for all this: the Chinese government

The government is bad, so is a trillion dollar American company choosing to collaborate with the government by enabling spying on their users just so they can make even more money. They're enabling a government to track down & torture/murder dissidents

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#380
post #365

Earlier quoted context omitted.

I still think Apple products are built on human rights abuses. I am currently trying to parse their most recent conflict minerals disclosure. It doesn't explicitly say "yes" but also doesn't clearly say "conflict-free" either.

Note that conflict-free at this time is so hard to be practically impossible. Fairphone, a company and phone founded explicitly with the goal of producing a phone without conflict minerals, still isn't conflict-free, and it's not for lack of trying. Sure, Apple has more leverage, considering their size, but that also comes with its own set of problems. Plus, their customers have nowhere to go to in protest - all othe…

I understand it's hard to make conflict-free computers.

I feel sick when apple says they are deeply committed to upholding human rights, while they continue manufacturing electronics, because I need authenticity. I would like Apple to use more of their resources to figure out how to do conflict-free consumer electronics.

Post reply on HN