Earlier quoted context omitted.
The same forces that require several levels of management make it increasingly difficult to enforce ethical decisions. Basically, when no one person can keep track of all the moving pieces you get splits around what individuals think is acceptable behavior. The larger organizations grows the more things tend to diverge, with different branches often having wildly different perspectives. This tends to further degrade…
> make it increasingly difficult to enforce ethical decisions Nonsense - this is a solved problem. You simply need to remove the ability to make defined classes of bad decisions by binding the company's future decision making capability with a Ulysses pact[1]. Cory Doctorow gave a good talk[2] about using Ulysses pacts in the tech industry. >> It's not that you don't want to lose weight when you raid your Oreo stash…
Apple has pushed a silent Mac update to remove hidden Zoom web server
491–500 of 552 posts
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#492I imagine Apple has known about this daemon for a long time from it's OS analytics.
What OS analytics? Apple gathers various anonymous metrics, yes, but I don't think they collect information on arbitrary web servers running on Macs.
What do you think the anonymous metrics are if the process list and open sockets are excluded?
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#493Earlier quoted context omitted.
> Apple also apparently didn't even notice Do they have any information about enterprise apps? As I understand it, Apple never phones home with app info (such as the identifier, name, etc) when verifying or installing enterprise-signed apps, so the only thing they know is probably the IP address requesting to verify the enterprise-signed app and the frequency of how often Apple devices do this certificate verificatio…
Going forwards, Apple will require that companies provide their enterprise apps to be audited.
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#494Earlier quoted context omitted.
This is effectively a press release to the Russian and Chinese governments that Apple could unilaterally remove all VPN software from Macs in a territory if they were compelled to. If you don't think that's scary then you're just incapable of long term thinking.
What? The blowback from that would be huge . Why would they do that? Yes, they can do that. So can Microsoft with Windows. So can Google with Android. Will any of them do that? Hopefully not, at the very least. Will all of them do that? Probably not- there's money to be made being the last company standing that actively protects privacy.
For the same reason Apple removed VPN apps from the Chinese iOS app store and multiple news organisations. Because they feel that the money from China is worth obeying oppressive regimes. I really don't think the backlash would be any worse.
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#495I figured.. this has probably evolved already to an acceptable situation.
So the calendar invite came in, I started up zoom to see what it would do. There's an update available, where zoom says they're abandoning the local web server.
Upgraded, should be good for tomorrow.
Came here, noticed the "softwareupdate -i MRTConfigData_10_14-1.45 --include-config-data" command and ran it. Checked last update -- back in June, to 1.42 ...
Updated that, ready to go.
Business continues, maybe I'll delete zoom another day, but not just yet.
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#496Earlier quoted context omitted.
I still think Apple products are built on human rights abuses. I am currently trying to parse their most recent conflict minerals disclosure. It doesn't explicitly say "yes" but also doesn't clearly say "conflict-free" either.
I’m sure you also love to complain about the problems at the Foxconn ‘Apple factory’. Which in reality builds products for all manufacturers.
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#497Earlier quoted context omitted.
I am also getting this error, and suspect it is because I’m on 10.12.6. If you do system_profiler SPInstallHistoryDataType |grep -A5 MRTConfigData you should see your latest version. For me, it’s 1.42. Not sure how to get the update yet though. Will update this comment once I figure that out. Update: According to this macworld article, there is a Zoom patch out that fixes this. https://www.macworld.com/article/340776…
What do the chmod do there? Removing files count as writes to the directory at least in Linux, so chmodding the dummy file wouldn't do much I'm thinking.
I would also set the ‘user immutable’ flag. If you want even better, set the ‘system immutable’ flag (see ‘man chflags’)
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#498Earlier quoted context omitted.
I still have a lot of trouble seeing how Apple removing a critical vulnerability - a completely mundane act with plenty of precedent from both Apple and others - is some clarion call that, if left unheeded, will have Siri judging everyone's hentai collection next. Why this - preventing myriads of users from becoming campeople - of all things? Why not, say, every Chrome autoupdate ever?
The problem is that Apple appears to have made an exception to its own rules in this particular case. If I understand correctly, they used a first party system update mechanism to change third party software. It's like Google making an ad hoc decision to use Chrome autoupdate to silently patch a particularly bad vulnerability in Microsoft Word just because they can. So what is the principle behind this kind of except…
There were a few instances in the last few years where the repos or built-in update systems of legitimate programs were compromised and bundled malware (and in one case, ransomware) along with their apps. In those cases, Apple also silently updated XProtect to remove the malware.
In this case, just because this was a webserver and not something more traditional like a trojan doesn't mean that it isn't still malware. The Risky Business podcast asserted the existence of the RCE before Apple jumped into action that it says Zoom knew about for months. Given that the only way to remove the webserver is to update Zoom (something that won't help any user that has already uninstalled Zoom, which kindly left the insecure webserver behind), this type of update makes perfect sense -- especially since Zoom itself is removing the server from its own application bundle.
This was malware, pure and simple. It wasn't third party software. It was malware left behind/included with a third-party app. It's not as if Apple removed the Zoom app -- it removed the piece of malware Zoom was including alongside its app. The fact that Zoom was including this malware as a way of bypassing Apple's access control in Safari (God forbid the user have to click a button confirming they want to open a meeting) is beside the point -- this was malware.
Additionally, users can turn off the auto system updates and they can disable Gatekeeper entirely.
I understand the broader concern of an OS maker being able to remove files a user chose to install -- but this is a very unambiguous case of malware. Just because the RCE wasn't actively exploited doesn't mean it wasn't malware.
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#499Earlier quoted context omitted.
The problem is that Apple appears to have made an exception to its own rules in this particular case. If I understand correctly, they used a first party system update mechanism to change third party software. I don't see anything in the article that suggests this - as I read it, it pretty much says the opposite. What else have you read that outlined these rules and the exception Apple made?
The article says "Apple said the update does not require any user interaction and is deployed automatically." As far as I know, there is no system-wide update mechanism for third party software not distributed through the Mac App Store that does not require any user interaction. So apparently they (ab)used the system update mechanism.
Re: Apple has pushed a silent Mac update to remove hidden Zoom web server
#500Earlier quoted context omitted.
As nice as that sounds, I think it requires an impossibly perfect prediction of future events. You face ethical decisions whenever you have power or limited resources.
No. You can bend your business model towards transactions you are comfortable with, without perfect future vision, or even a clear strategic understanding of how that might happen. In fact, the world around you will bend to meet your values whether you’re even aware of it. And that includes any companies you run. The world does extend beyond your knowledge of it.