Live data from Hacker News

Apple has pushed a silent Mac update to remove hidden Zoom web server

techcrunch.com

491–500 of 552 posts

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#491
post #435
post #158

Earlier quoted context omitted.

The same forces that require several levels of management make it increasingly difficult to enforce ethical decisions. Basically, when no one person can keep track of all the moving pieces you get splits around what individuals think is acceptable behavior. The larger organizations grows the more things tend to diverge, with different branches often having wildly different perspectives. This tends to further degrade…

> make it increasingly difficult to enforce ethical decisions Nonsense - this is a solved problem. You simply need to remove the ability to make defined classes of bad decisions by binding the company's future decision making capability with a Ulysses pact[1]. Cory Doctorow gave a good talk[2] about using Ulysses pacts in the tech industry. >> It's not that you don't want to lose weight when you raid your Oreo stash…

It's easy to talk about "not preserving the option to behave badly" in the abstract, but actually doing it requires perfect foresight (predicting every way anything could be used for evil) and often a lot of implementation difficulty (because you need to completely foreclose on the bad options without impeding good or neutral ones).

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#492
post #50
post #47

I imagine Apple has known about this daemon for a long time from it's OS analytics.

What OS analytics? Apple gathers various anonymous metrics, yes, but I don't think they collect information on arbitrary web servers running on Macs.

Crash reports include running processes.

What do you think the anonymous metrics are if the process list and open sockets are excluded?

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#493

Earlier quoted context omitted.

> Apple also apparently didn't even notice Do they have any information about enterprise apps? As I understand it, Apple never phones home with app info (such as the identifier, name, etc) when verifying or installing enterprise-signed apps, so the only thing they know is probably the IP address requesting to verify the enterprise-signed app and the frequency of how often Apple devices do this certificate verificatio…

Going forwards, Apple will require that companies provide their enterprise apps to be audited.

I see them adding something like the macOS "notarization" requirement to iOS enterprise apps.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#494

Earlier quoted context omitted.

This is effectively a press release to the Russian and Chinese governments that Apple could unilaterally remove all VPN software from Macs in a territory if they were compelled to. If you don't think that's scary then you're just incapable of long term thinking.

What? The blowback from that would be huge . Why would they do that? Yes, they can do that. So can Microsoft with Windows. So can Google with Android. Will any of them do that? Hopefully not, at the very least. Will all of them do that? Probably not- there's money to be made being the last company standing that actively protects privacy.

> What? The blowback from that would be huge. Why would they do that?

For the same reason Apple removed VPN apps from the Chinese iOS app store and multiple news organisations. Because they feel that the money from China is worth obeying oppressive regimes. I really don't think the backlash would be any worse.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#495
I had a prospective client/customer, just today, schedule a Zoom meeting for tomorrow. I was aware of the issue this week, but I wasn't really going to make a lot of noise with someone who was just a prospect.

I figured.. this has probably evolved already to an acceptable situation.

So the calendar invite came in, I started up zoom to see what it would do. There's an update available, where zoom says they're abandoning the local web server.

Upgraded, should be good for tomorrow.

Came here, noticed the "softwareupdate -i MRTConfigData_10_14-1.45 --include-config-data" command and ran it. Checked last update -- back in June, to 1.42 ...

Updated that, ready to go.

Business continues, maybe I'll delete zoom another day, but not just yet.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#496

Earlier quoted context omitted.

I still think Apple products are built on human rights abuses. I am currently trying to parse their most recent conflict minerals disclosure. It doesn't explicitly say "yes" but also doesn't clearly say "conflict-free" either.

I’m sure you also love to complain about the problems at the Foxconn ‘Apple factory’. Which in reality builds products for all manufacturers.

I just wanted to express to rawrmaan that I felt disturbed about his calling apple brave and moral when many aspects of their supply chain don't appeal to my sense of justice.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#497

Earlier quoted context omitted.

I am also getting this error, and suspect it is because I’m on 10.12.6. If you do system_profiler SPInstallHistoryDataType |grep -A5 MRTConfigData you should see your latest version. For me, it’s 1.42. Not sure how to get the update yet though. Will update this comment once I figure that out. Update: According to this macworld article, there is a Zoom patch out that fixes this. https://www.macworld.com/article/340776…

What do the chmod do there? Removing files count as writes to the directory at least in Linux, so chmodding the dummy file wouldn't do much I'm thinking.

Idea is to prevent the Zoom Software from ‘repairing’ the ‘damaged’ app by overwriting it with the malware.

I would also set the ‘user immutable’ flag. If you want even better, set the ‘system immutable’ flag (see ‘man chflags’)

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#498
post #386

Earlier quoted context omitted.

I still have a lot of trouble seeing how Apple removing a critical vulnerability - a completely mundane act with plenty of precedent from both Apple and others - is some clarion call that, if left unheeded, will have Siri judging everyone's hentai collection next. Why this - preventing myriads of users from becoming campeople - of all things? Why not, say, every Chrome autoupdate ever?

The problem is that Apple appears to have made an exception to its own rules in this particular case. If I understand correctly, they used a first party system update mechanism to change third party software. It's like Google making an ad hoc decision to use Chrome autoupdate to silently patch a particularly bad vulnerability in Microsoft Word just because they can. So what is the principle behind this kind of except…

This is untrue. The update process was part of Xprotect, the malware definition/signature system built-into macOS that's part of Gatekeeper [1]. It dates back to Mac OS X 10.5 Leopard and was expanded on Mac OS X 10.6 Snow Leopard (the Gatekeeper GUI was introduced in OS X 10.8 Mountain Lion and back ported to Mac OS X 10.7.5 Lion). Updates were historically issued via minor OS updates, but Apple started to do silent updates to the Xprotect definition list a number of years ago, as a way to target popular/growing strains of malware (which were often installed via cracked apps).

There were a few instances in the last few years where the repos or built-in update systems of legitimate programs were compromised and bundled malware (and in one case, ransomware) along with their apps. In those cases, Apple also silently updated XProtect to remove the malware.

In this case, just because this was a webserver and not something more traditional like a trojan doesn't mean that it isn't still malware. The Risky Business podcast asserted the existence of the RCE before Apple jumped into action that it says Zoom knew about for months. Given that the only way to remove the webserver is to update Zoom (something that won't help any user that has already uninstalled Zoom, which kindly left the insecure webserver behind), this type of update makes perfect sense -- especially since Zoom itself is removing the server from its own application bundle.

This was malware, pure and simple. It wasn't third party software. It was malware left behind/included with a third-party app. It's not as if Apple removed the Zoom app -- it removed the piece of malware Zoom was including alongside its app. The fact that Zoom was including this malware as a way of bypassing Apple's access control in Safari (God forbid the user have to click a button confirming they want to open a meeting) is beside the point -- this was malware.

Additionally, users can turn off the auto system updates and they can disable Gatekeeper entirely.

I understand the broader concern of an OS maker being able to remove files a user chose to install -- but this is a very unambiguous case of malware. Just because the RCE wasn't actively exploited doesn't mean it wasn't malware.

[1]: https://en.wikipedia.org/wiki/Gatekeeper_(macOS)

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#499
post #416

Earlier quoted context omitted.

The problem is that Apple appears to have made an exception to its own rules in this particular case. If I understand correctly, they used a first party system update mechanism to change third party software. I don't see anything in the article that suggests this - as I read it, it pretty much says the opposite. What else have you read that outlined these rules and the exception Apple made?

The article says "Apple said the update does not require any user interaction and is deployed automatically." As far as I know, there is no system-wide update mechanism for third party software not distributed through the Mac App Store that does not require any user interaction. So apparently they (ab)used the system update mechanism.

No, they installed an update to XProtect's signatures to say "this is malware, remove it if detected" -- something the company has done many times in the past.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#500

Earlier quoted context omitted.

As nice as that sounds, I think it requires an impossibly perfect prediction of future events. You face ethical decisions whenever you have power or limited resources.

No. You can bend your business model towards transactions you are comfortable with, without perfect future vision, or even a clear strategic understanding of how that might happen. In fact, the world around you will bend to meet your values whether you’re even aware of it. And that includes any companies you run. The world does extend beyond your knowledge of it.

[deleted]
Post reply on HN