Live data from Hacker News

Apple has pushed a silent Mac update to remove hidden Zoom web server

techcrunch.com

541–550 of 552 posts

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#541

It's been rather disturbing to see this whole thing play out --- I'm not taking sides here, but Apple "flexing its arms" in this manner shows that it is willing and has the power to go beyond policing its App Store and such (which while I do not like, I feel it does have the right to) and involve itself in the affairs of third-party software which it did not originally install. (This is subtly different from updating…

I'll never understand this argument: > Apple's wielding of power in this way... the idea of the OS/platform vendor meddling with third-party software... This is THEIR app store for THEIR operating system. Why in the world would they not be allowed to control their software's features or third party integrations? It reminds me of the ridiculous argument over Windows setting IE as its default browser (and I've been a w…

> This is THEIR app store for THEIR operating system.

On MY computer.

> Why in the world would they not be allowed to control their software's features or third party integrations?

Because it is not THEIR computer but MY computer.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#542
post #372

Earlier quoted context omitted.

No, it prioritizes thinking about clear boundaries ahead of time, while you're able to think clearly about the issues. "Hard cases make bad law" as the lawyers say. Ethicists do this sort of thing all the time. There's a line between the OS and third-party software. There's a line between malicious software and accidentally vulnerable. Apple has just shown that it is willing to cross both those lines. Where is the li…

Lets ask a reasonable question: who wants the zoom webserver running on their systems providing a backdoor.

I didn't want my window to be broken. I still wasn't happy when my landlord came in and fixed it without giving me any notice.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#543
post #541

Earlier quoted context omitted.

I'll never understand this argument: > Apple's wielding of power in this way... the idea of the OS/platform vendor meddling with third-party software... This is THEIR app store for THEIR operating system. Why in the world would they not be allowed to control their software's features or third party integrations? It reminds me of the ridiculous argument over Windows setting IE as its default browser (and I've been a w…

> This is THEIR app store for THEIR operating system. On MY computer. > Why in the world would they not be allowed to control their software's features or third party integrations? Because it is not THEIR computer but MY computer.

> On MY computer.

But Apple didn't install macOS on your computer. You chose to use THEIR platform.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#544

Earlier quoted context omitted.

I wouldn't call it a bug. Zoom deliberately engineered their app so it opened a security threat, accessible from any website on your browser, on your local machine without the user's knowledge. Then they reinstalled their software after the user had uninstalled it. Again, deliberately engineered that way. That is not a bug

Zoom's intention was not to introduce a security vulnerability. That's why I'm calling it a bug.

Their intention was to bypass an inbuilt security measure. So no, maybe they didn't mean to add a vulnerability but they did mean to reduce the security of the system as a whole

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#545
post #490
post #328

Earlier quoted context omitted.

The large majority of devs that buy Macs aren't UNIX FOSS devs, rather devs that care about Apple platform.

My experience has been the opposite. Of all the people I've worked with using Macs, all of them were developing cross-platform open source software. I've yet to meet a single developer making MacOS applications.

They would better off sponsoring OEMs that try to keep BSDs and GNU/Linux hardware alive then.

On my Mac circle it is all about store apps and Web apps (Java/.NET Core based).

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#546

That's pretty epic. Apple continues to make big, brave moral gestures (like when they yanked Facebook and Google's enterprise certs earlier this year, or killed long-term tracking cookies in Safari overnight). Makes me happy to be a customer. Hope they keep enforcing their own rules and protecting their users' privacy and security in this fearless manner.

Glad to see that Cook hasn't altered this as Apple always had security as focus. It was one of the reasons I got my wife into using macs years ago, I never had to support her or worry about what website has managed to install ad malware.

We recently went back to PC's and it was immediately obvious we needed wall to wall antivirus protection which was not always the case on macs.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#547
post #163

Please, Apple, give me a way to disconnect my microphone and webcam on an OS level so apps can't randomly access it.

Doesn’t that already exist under Preferences > Security & Privacy? Afk rn so i might be misremembering the name of the setting.

TIL! Thanks! This is exactly what I wanted.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#548
post #540

Earlier quoted context omitted.

>the users themselves having no knowledge or any say about it. This is not true. You can disable all the automatic updates in System Preferences.

This is a nuclear option and the issue isn't getting updates, the issue is being silent and not offering any control over that. See my other replies about Windows Defender about what i meant with that.

What do you mean? They're silent because they're malware updates. You can turn those off.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#549

Earlier quoted context omitted.

You're saying that an application can't write user specific information into the bundle and sort that out? There's no difference between these two (hypothetical) file paths: /Applications/SomeApp.app/users/taftster/user.specific.data /Users/taftster/Library/Application Support/SomeApp/user.specific.data These two file paths are effectively the same. And when the "global" application gets deleted, I most definitely wa…

You're trading one problem for another. What if I want to delete a user instead? Now I have that user's crap in every application bundle. However, the OS should perhaps insist on a particular location within "Application Support/" that each app can write to, and when the application bundle is deleted, provide a way to delete those support files as well, either for that user alone or for all users within permission (c…

I would argue, I think most systems have more quantity and churn of applications than users. Meaning, it would be better to pay some overhead to deal with "user's crap" in every application bundle than to deal with "application crap" in every user's home.

Your second paragraph though is probably closer to a realistic solution. That is, the OS provisions an Application Support directory and restricts the application to using it exclusively. Any application uninstalls can (via admin prompting or configuration settings) then also delete the support directories as well.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#550

ertecheck found this for me maybe 2 months ago. coincidentally right in the disclosure window! i tried etrecheck on a lark. at the time i found it unremarkable. oh, i have this leftover dingle here, thanks etrecheck, i'll just remove it then. but otherwise i wasn't screaming etrecheck from on high. now i am!!

Everything about the etrecheck website screams "system optimizer scam!" and this comment does nothing but reinforce that feeling.

If you try EtreCheck, you’ll find that it has nothing in common with system optimization scams. EtreCheck has no (or very few) magic “fix it” buttons. It only finds issues that appear to be problematic and (optionally) gives the user instructions on how to fix those issues. EtreCheck is definitely an end-user tool. It is designed for people who don’t know what software they have installed. It will even provide people with anti-scam tips if it detects that they might have installed scam apps in the past. For other users, it could still be helpful in listing partially uninstalled software like what is being discussed with the Zoom issue.

The latest version of EtreCheckPro 6.0.2 has more features that might appeal to very tech-savvy users. It has a storage analysis feature to help find how your disk is being used since Apple’s own tools are notoriously bad at this. It also has a graphical view of the analytics data that macOS automatically collects. You won’t find this analytics display in any other tool.

Post reply on HN