Live data from Hacker News

Apple has pushed a silent Mac update to remove hidden Zoom web server

techcrunch.com

511–520 of 552 posts

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#511

Earlier quoted context omitted.

I care far more about the facts than about what's in the article. Zoom is clearly not malware. It just has a bug. Is updating regular third party software documented behaviour of macOS? If so then I agree that it is not abuse. Otherwise Apple has some explaining to do.

I wouldn't call it a bug. Zoom deliberately engineered their app so it opened a security threat, accessible from any website on your browser, on your local machine without the user's knowledge. Then they reinstalled their software after the user had uninstalled it. Again, deliberately engineered that way. That is not a bug

Zoom's intention was not to introduce a security vulnerability. That's why I'm calling it a bug.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#512
post #306

Earlier quoted context omitted.

I don't fully understand the difference. But signed is different from notarized. Notarized means you uploaded the binary to Apple. Previously, you can sign without doing that. I haven't looked enough to understand what is gained by notary. Does Apple want to search your binary for maliciousness or rulebreaking (potentially even at a later date) so that it might revoke the notarization/signature?

In order to avoid repeating myself, from WWDC 2019: "Advances in macOS Security" https://developer.apple.com/videos/play/wwdc2019/701/ "All About Notarization" https://developer.apple.com/videos/play/wwdc2019/703

Thanks.

Some of this stuff seems a tad disingenuous. Like preventing debugging. The debugger APIs on Mac already pop up a password prompt, limiting the usability in malware (and actual use, like trying to debug over ssh). Meanwhile, a culture of producing separate binaries for debug and for end users (debug builds lacking optimization, allowing additional permissions) is in my experience a great way to fail to reproduce legit customer-facing bugs during development and have greater difficulty diagnosing them when they occur on a real live user machine.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#513

Earlier quoted context omitted.

lol they removed what would be called horrific spyware if it wasn’t made by Zoom and you’re over here on some lofty criticism about possible implications years into the future any OS (and many other apps) that update have the power to do what you’re afraid of, and much more. plus i don’t really see a bright line between system level software and an app when apps can access your video cam, mic, all your files - basica…

It's not spyware, this was not something that was intended to be abused, it's insecure software and its very common, you're running plenty of it right now.

It's not spyware but it's user-hostile, insecure, undocumented, uninstallable-by-the-usual-process software.

Most of the insecure software that I run has enough grace to not silently leave behind a web server to automatically re-install itself after I dumped it in the trash can.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#514

Earlier quoted context omitted.

I’m quite happy with it, as I don’t see millions of people removing some hidden directory. No more zoom for me.

The point is precisely NOT to think about only this one case like many others seem to be focusing (or Zoom-ing in...?) on, but to consider how far you are willing to let Apple exercise its power over your computer. Would you let it scan all your files and delete e.g. "suspected images of child abuse" (to use an old cliche)? Suspected copyrighted material or fragments thereof? "Extremist" content, or content which is…

I'd rather put Apple in control of my computer than any other random software vendor. This is exatly why all windows systems are full of crapware and are grinding their disks out of the box

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#515

Earlier quoted context omitted.

This is untrue. The update process was part of Xprotect, the malware definition/signature system built-into macOS that's part of Gatekeeper [1]. It dates back to Mac OS X 10.5 Leopard and was expanded on Mac OS X 10.6 Snow Leopard (the Gatekeeper GUI was introduced in OS X 10.8 Mountain Lion and back ported to Mac OS X 10.7.5 Lion). Updates were historically issued via minor OS updates, but Apple started to do silent…

I understand why Apple did it and the additional context you provide does change my opinion somewhat in Apple's favor, but I disagree about Zoom being malware because malware is made in bad faith to introduce functionality the user never intended to use. What Zoom did was negligent and incompetent, but I don't see that there was malicious intent. I do agree, however, that what they tried to do is unacceptable even if…

I think when you refuse to address a reported security issue related to something you installed (without the users knowledge and without a way for the user to easily remove) as a way to bypass an access control pop-up, and cite that it’s a feature not a bug, until forced by the public/other disclosures to remove it, The intent is malicious.

But even if it weren’t — and we can agree to disagree on the intent — the second the RCE is popped, it becomes a massive security issue and it becomes traditional malware. As I said, I’m convinced Apple would do the same thing if this was something left behind or associated with Java or Flash.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#516

Earlier quoted context omitted.

I understand why Apple did it and the additional context you provide does change my opinion somewhat in Apple's favor, but I disagree about Zoom being malware because malware is made in bad faith to introduce functionality the user never intended to use. What Zoom did was negligent and incompetent, but I don't see that there was malicious intent. I do agree, however, that what they tried to do is unacceptable even if…

I think when you refuse to address a reported security issue related to something you installed (without the users knowledge and without a way for the user to easily remove) as a way to bypass an access control pop-up, and cite that it’s a feature not a bug, until forced by the public/other disclosures to remove it, The intent is malicious. But even if it weren’t — and we can agree to disagree on the intent — the sec…

Malicious intent is the only thing that separates malware from a regular security issue. So if we disagree on intent we have to keep disagreeing on whether or not it's malware.

But I will admit that I'm starting to see the question of Zoom's intent a bit differently after thinking about what you have said.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#517

Earlier quoted context omitted.

This is untrue. The update process was part of Xprotect, the malware definition/signature system built-into macOS that's part of Gatekeeper [1]. It dates back to Mac OS X 10.5 Leopard and was expanded on Mac OS X 10.6 Snow Leopard (the Gatekeeper GUI was introduced in OS X 10.8 Mountain Lion and back ported to Mac OS X 10.7.5 Lion). Updates were historically issued via minor OS updates, but Apple started to do silent…

I understand why Apple did it and the additional context you provide does change my opinion somewhat in Apple's favor, but I disagree about Zoom being malware because malware is made in bad faith to introduce functionality the user never intended to use. What Zoom did was negligent and incompetent, but I don't see that there was malicious intent. I do agree, however, that what they tried to do is unacceptable even if…

It's not.. it is malicious. They want to circumvent os/browser behavior / user protection (the prompt to open zoom). To hack around this they install malware to get things done. It is exactly the same as using doing something that wouldn't pass the appstore checks.

It is actually very competent of them, except for the security part.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#518

Earlier quoted context omitted.

Requiring user confirmation for updating malware signatures would make them a lot less effective. And in any case, there is a checkbox in the software update preferences labelled "Install system data files and security updates" which presumably allows you to opt out of these critical security updates. And if you really wanted to have the zoom backdoor server run on your system, you could probably just strip the code…

>Requiring user confirmation for updating malware signatures would make them a lot less effective. That seems highly unlikely to me. Do you have evidence to support that assertion. On first use "Do you want us to automatically remove apps we think might damage your system: Y/n." Don't users need a notification, at least, to inform their choices when installing software. I guess Apple Computers would rather you just m…

> Do you have evidence to support that assertion.

Every relative who never installs updates. I ask them why they are on an old version with major security holes that were on the news, but they just don't care. They always click "later".

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#519

Earlier quoted context omitted.

I understand why Apple did it and the additional context you provide does change my opinion somewhat in Apple's favor, but I disagree about Zoom being malware because malware is made in bad faith to introduce functionality the user never intended to use. What Zoom did was negligent and incompetent, but I don't see that there was malicious intent. I do agree, however, that what they tried to do is unacceptable even if…

I think when you refuse to address a reported security issue related to something you installed (without the users knowledge and without a way for the user to easily remove) as a way to bypass an access control pop-up, and cite that it’s a feature not a bug, until forced by the public/other disclosures to remove it, The intent is malicious. But even if it weren’t — and we can agree to disagree on the intent — the sec…

[deleted]

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#520

Earlier quoted context omitted.

I think when you refuse to address a reported security issue related to something you installed (without the users knowledge and without a way for the user to easily remove) as a way to bypass an access control pop-up, and cite that it’s a feature not a bug, until forced by the public/other disclosures to remove it, The intent is malicious. But even if it weren’t — and we can agree to disagree on the intent — the sec…

Malicious intent is the only thing that separates malware from a regular security issue. So if we disagree on intent we have to keep disagreeing on whether or not it's malware. But I will admit that I'm starting to see the question of Zoom's intent a bit differently after thinking about what you have said.

Lying to users about the uninstallation is pretty icky intent. It's weird to make this about the sanctity of user choice and just repeatedly ignore that bit on top of coming up with a throughly inaccurate narrative about the nature of Apple's response.
Post reply on HN