Live data from Hacker News

Apple has pushed a silent Mac update to remove hidden Zoom web server

techcrunch.com

451–460 of 552 posts

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#451
post #13

If you would like to force this update you can do so via the terminal: softwareupdate -ia --include-config-data It will show up as MRTConfigData if you look under Apple Menu->About This Mac->System Report->Software->Installations. The latest version is 1.45 and was updated today which includes the Zoom mitigations.

Thank you for this. HN comments always make me realize I don’t know enough about MacOS command line. My primary system is Linux so I miss out in these MacOS specific commands day to day. But I would love to pick up a few, if there’s a book or document.

Is there a book you can recommend? Or did you pick these up over the years

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#452

They are basically solving a self-inflicted problem. The real issue there is the fact that macOS doesn't provide a standarized way to completely uninstall an app.

Which is completely frustrating, because Mac is totally in the position of using its built-in capabilities to deal with this. The Mac Bundle (.app) format could solve this entirely. All application specific data should be written inside of the bundle folder, so that when you delete the app, you delete the thing entirely. I mean, maybe you need a "user data" bundle of sorts tied to the specific application. If you del…

> All application specific data should be written inside of the bundle folder, so that when you delete the app, you delete the thing entirely

Not even Apple follows that ideology though, I can't be the only one who has had to delete the gigs of Garageband data from ~/Library/Application Support on an under-specced company laptop 128GB SSD

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#453

Earlier quoted context omitted.

> Intent doesn’t matter only results. Then you should call Chrome a malware because there were vulnerabilities with remote code execution (and there will be similar vulnerabilities), so every website could install anything. But that is absurd. > The result is that unless you like for random websites to be able to activate your camera without your permission, it did harm users. First of all, you need a hard data that…

First of all, you need a hard data that this vulnerability was exploited in the wild So would it also be okay for a credit bureau to post all of your information to a website? Would that be okay until it was “exploited in the wild”? Are you really saying it’s okay to run knowingly insecure software until there are reports of it being exploited? Only a few years ago every browser supported Java Applets and with Java A…

> So would it also be okay for a credit bureau to post all of your information to a website? Would that be okay until it was “exploited in the wild”?

I'm not saying that it's okay. I'm just saying that it's an overreaction to call their software malware.

> Are you really saying it’s okay to run knowingly insecure software until there are reports of it being exploited?

Yes, it's okay. When Windows security team receives some vulerability report, they do not shut down all Windows systems in the world until the bug is fixed. Those systems continue to work insecurely until they got update.

> Java applets ran in a sandbox.

Signed Java applets do not run in a sandbox and have full access to the computer. That's why they were widely used for things that JavaScript did not have access to, e.g. using USB secure tokens for website authentication.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#454
post #392

Earlier quoted context omitted.

> You may agree with its decision this time, but will you always agree? To be honest I'm kinda sick of this argument. Someone brings this argument up _every single time_ a tech company takes action against something malicious. It's a strawman argument at best and at worst a way to give people an out on acting against something that could harm the user. > Apple's wielding of power in this way is likely to attract the…

> Someone brings this argument up _every single time_ a tech company takes action against something malicious. The argument isn't about taking action against something malicious, the argument is about the implications of being able to take that action and what sort of power the company has and if they should have it in light of past abuses (not necessarily but that company, but this is totally irrelevant since compan…

   > > This will never happen

   > You cannot guarantee that.
Can you guarantee that it will happen within the next, say, 5, 10, 15, or 20 years? Somewhere within there, the devices we're currently using will likely be replaced, and the landscape will have changed.

What I personally care about, privacy-wise, is the present and near future- will my family be safe on the internet with what I've set up for the next five years? Probably. Will the computer I'm using to type this reply on be replaced within a decade? Probably so. Will my family get a new PC within the next ten years? Yes.

Can you 100% guarantee that the Government of the United States will be intact in twenty years? No, the threats from Russia and China (both nuclear countries) and North Korea (armed or not, they're still dangerous), and space asteroids and epidemics and terrorists and politics and civil wars are not zero.

Can you 100% guarantee that California won't sink into the ocean in 100 years? That would make for some really bad real estate investments, yet people still buy and sell and build there.

People are still living in California, trading with each other, the US Government is still stable, and Apple is currently upholding and protecting user privacy. Also, we still have electricity and the internet. Now is a great time to be alive.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#455

Earlier quoted context omitted.

According to the article, "Apple said the update does not require any user interaction and is deployed automatically.". There's nothing moral about using "silent updates" (updates the user has no opportunity to decide whether to adopt). Apple certainly wasn't looking out for their users' privacy and security when they let an iTunes bug go unfixed for 3 years (see http://www.telegraph.co.uk/technology/apple/8912714/Ap…

Requiring user confirmation for updating malware signatures would make them a lot less effective. And in any case, there is a checkbox in the software update preferences labelled "Install system data files and security updates" which presumably allows you to opt out of these critical security updates. And if you really wanted to have the zoom backdoor server run on your system, you could probably just strip the code…

>Requiring user confirmation for updating malware signatures would make them a lot less effective.

That seems highly unlikely to me. Do you have evidence to support that assertion.

On first use "Do you want us to automatically remove apps we think might damage your system: Y/n."

Don't users need a notification, at least, to inform their choices when installing software.

I guess Apple Computers would rather you just mindlessly relied on them, however, so anything that lets users know that Apple's system exposed them from risk is going to be avoided.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#456
You can judge how a company functions internally by how they respond externally,

Zoom’s initial response to this incident was shameful. They basically said “that’s how are app works. F U”

I am moving away from Zoom.

Any suggestions? Preferably open source

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#457
post #399

Earlier quoted context omitted.

These are unimportant details, the issue is with Apple modifying people's computers silently and the users themselves having no knowledge or any say about it. Replace this instance with something that you disagree about (imagine Apple removing VPN software from Chinese customers due to demands from China or "fixing" existing VPN software with backdoors that enable Chinese authorities to wiretap Chinese people) and se…

> something something Apple, a US-based company who prides itself on privacy helping China spy on people. Apple engineers go to China . Anything they do to help the Chinese government can immediately affect their own workers. If they did that, and a bunch of people with Apple devices got thrown in jail / whatever, their stock, and moral standing, would suffer some serious blow-back for it. Google Chrome has a thing t…

>terminated my connection and said "Hey, we don't think this is safe" /

That's not equivalent, equivalent would be doing something you don't realise, the point is about user agency: keeping users uninformed and, for those that get the information out-of-band, unable to exercise their own control over the situation.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#458

ertecheck found this for me maybe 2 months ago. coincidentally right in the disclosure window! i tried etrecheck on a lark. at the time i found it unremarkable. oh, i have this leftover dingle here, thanks etrecheck, i'll just remove it then. but otherwise i wasn't screaming etrecheck from on high. now i am!!

Everything about the etrecheck website screams "system optimizer scam!" and this comment does nothing but reinforce that feeling.

it's a very simple tool, to be sure. but come on, it's not like it's steve gibson wares ...

the free version is perfectly adequate. it's simply an information gathering and reporting tool. anyone could write this tool themselves -- the mechanics of it are beyond simple. but like all sysadmin tasks, gathering the requirements is the hard part.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#459

Earlier quoted context omitted.

I’m quite happy with it, as I don’t see millions of people removing some hidden directory. No more zoom for me.

The point is precisely NOT to think about only this one case like many others seem to be focusing (or Zoom-ing in...?) on, but to consider how far you are willing to let Apple exercise its power over your computer. Would you let it scan all your files and delete e.g. "suspected images of child abuse" (to use an old cliche)? Suspected copyrighted material or fragments thereof? "Extremist" content, or content which is…

This is a classic "parade of horribles" argument. I do not find them compelling, personally.

If Apple starts being abusive, they'll get their hand slapped. If they don't, they don't.

There's no better company positioned to do anti-malware than the vendor of the OS itself. Which is why Apple and Microsoft both do it. You can disable updates on both platforms if, for some reason, you don't want anything to change on your system without your explicit action (pros and cons to that, obviously). But for most end users, the tradeoff of control vs. security is a very easy one, since the average user is in no way qualified to secure their own system or audit the code that runs on it.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#460

Earlier quoted context omitted.

It's not spyware, this was not something that was intended to be abused, it's insecure software and its very common, you're running plenty of it right now.

> It's not spyware, this was not something that was intended to be abused Do you have a source for that. It doesn’t peek around my computer a little and/or send back any telemetry? I’m being serious, I’d like to know. I had to install Zoom in school in 2014, I ended up uninstalling it the next week and reformatted after the quarter. I’m with Apple here. It’s shit insecure non-consenting software that wastes battery 9…

> I had to install Zoom in school in 2014

This is a good point; we shouldn't act as though users are necessarily making an informed choice or meaningfully consenting to all the software that's on their computers. Lots of people are forced to install software at economic gunpoint (and probably can ill afford a separate computer to isolate it on).

You can't depend on users and the marketplace to select against insecure software. The market is too distorted to function that way; the people forcing others to use shitty software are often isolated from the consequences themselves, so there's no effective feedback loop to stop it. Having the OS vendor step in is really the only good solution in the short term.

Post reply on HN