Live data from Hacker News

Vulnerability in the Mac Zoom client allows malicious websites to enable camera

medium.com

471–473 of 473 posts

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#472
post #454

Earlier quoted context omitted.

Yeah, when I read this, I said WAT. How on earth does Apple allow this ? I'm not excusing Zoom, but this is Apples fault.

I'm not sure how this can be construed as Apple's fault (and I've never owned any Apple products). A general purpose OS runs what the user installs. This is purely on zoom for backdooring the system. I'm not sure how many Mac users bother running ps every once in a while, but it seems like it wouldn't be that hard to detect either. That said I have to say zoom's the only businessy meeting client I've used that doesn'…

Apple only lets you install verified applications by default. Zoom is in the damn AppStore.

The whole point of making the AppStore a walled garden is such that these things don't happen. If an AppStore App can install a server in your machine that remains there and reinstalls the App after it has been deleted, and can be used to spy you via the camera or DDoS you. Then... the AppStore sucks.

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#473
Apologies in advance if someone has already commented about this, but it would appear that Zoom removed that local web server feature for the MacOS version a few days ago:

---

Current Release July 9, 2019 Version 4.4.53932.0709

New and Enhanced Features

-General Features

--Option to uninstall Zoom Zoom users can now uninstall the Zoom application and all of its components through the settings menu.

-Resolved Issues

--Removal of the local web server Zoom will be discontinuing the use of a local web server on Mac and will be completely removed from the Zoom installation. --Minor Bug Fixes (https://support.zoom.us/hc/en-us/articles/201361963-New-Upda...)

Post reply on HN