Live data from Hacker News

How the Zoom macOS installer does its job without you clicking ‘install’

twitter.com

231–240 of 334 posts

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#231
post #32

Earlier quoted context omitted.

We just had a corporate presentation with around 250 people. Normally we use Teams or Slack for internal communication, this was also stated by management, that Zoom should only be used for 'big' meetings like this. I think they know the other solutions will not work as well for bigger groups. I've not had issues with using either solution for small group meetings. Actually I have to go out of my way to run Zoom in t…

Why not use Teams Live for this? We have been using zoom and Teams alternately and Teams performance and ease of use has been much better in my experience, but we have yet to do a 200+ all hands so I was curious if there were some footguns with teams live that you may know about. Teams live works on a lot of platforms and also has a web version.

My employer has used Teams Live for all-hands meetings from home the last couple weeks and it worked great for ~350 attendees.

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#232

Zoom's got a tradition of being, let's put it like this, way too clever for everyone's own good. See previous “lets install a server on this Mac that is not removed when you uninstall the app and leaves your camera open to the entire internet” for more examples. I use it on a VM, I suggest you do it too.

It's very Dropbox-esque…

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#233
post #114

1) If Zoom can do this then it's a MacOS security bug. 2) UX matters. Users don't care about the technical details, they want a smooth experience and that can be the difference between a billion-dollar business or a failed startup. And yes the desktop version is more stable than the web-based UI. 3) Malware is defined by what it does, not how it's installed.

I mean, it's not really a security bug. Installer.app displays a dialog box that says "Hey, this package wants to run arbitrary code to check if it's compatible with your system. Is that OK?" The user is explicitly opting into the code execution. Zoom's "compatibility check" installs the app and kills the installer window. That's certainly unexpected behavior, but I don't think it's an exploit in any real sense. Whil…

It's really Apple's fault. "This package will run a program to determine if the software can be installed." Is just fundamentally a very strange statement to make, loaded with vagueness.

Think about your average user... they are running an installer program... which alerts them that they need to run another program... to determine if they can install the program.... (Which the user thought they were already doing)

The loaded expectation of the user to realize they are granting privileges to a program to determine whether they can install a program is just totally unreasonable.

It just sounds more and more ridiculous written out like this.

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#234

Earlier quoted context omitted.

It should be impossible with SIP enabled, as in OS X 10.14 Apple protected the files in /var/db/dslocal where the user shadow files are stored so that root could not read them (unless triggered by an Apple signed executable, like Software Update). If you are running with SIP disabled you've taken the risk of it happening, and if you are on a corporate laptop (or 99% of personal machines) it is engaged. https://apple.…

Think a little harder. With root, you can install a keylogger.

You'd still need to bypass TCC.

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#235
post #228

Earlier quoted context omitted.

A botnet agent is designed to take control and run a bot, so yes it's malware. It doesn't have to be actively doing it at that moment to be considered such.

Zoom does report usage to Facebook whether you have an account or not - and that data is used to stitch together a web profile of the user that is of no benefit to the user. Zoom is bordering on malware, just... malware that comes with a useful app that allows video conferencing.

They removed that Facebook sdk after complaints.

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#236

Zoom's got a tradition of being, let's put it like this, way too clever for everyone's own good. See previous “lets install a server on this Mac that is not removed when you uninstall the app and leaves your camera open to the entire internet” for more examples. I use it on a VM, I suggest you do it too.

Best zoom alternative?

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#237
post #110

Earlier quoted context omitted.

The script asks for root which subsequently pops up an OS password prompt. Zoom never sees your password. How is this different from the way e.g. Virtualbox gets root?

It's not making the proper privilege escalation call, it's faking the box entirely. There's even a typo in the dialog box.

No, they're using the (deprecated) Authorization Services API from the (renamed) BLAuthentication.

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#238

Earlier quoted context omitted.

Zoom doesn’t just work. If the students want privacy, they are just helpless. Edit: downvoted for speaking up for student rights. Sorry if it is inconvenient for the teachers

> If the students want privacy, they are just helpless. This isn't true actually. As a student, send the following email: "Hi Professor, I just read this webpage [link], which outlines some privacy concerns with Zoom. I know some other classes are running Software X, could we try that instead?" My university isn't mandating Zoom. Indeed, they recommended several software packages, of which their top recommendation wa…

> "Hi Professor, I just read this webpage [link], which outlines some privacy concerns with Zoom. I know some other classes are running Software X, could we try that instead?"

Hi [Student],

I appreciate your concern; however, our university has conducted a thorough audit of this software and found that it satisfies our needs. We will continue using it for our lectures.

Regards, Dr. [Professor]

Senior tenured chair of [Department], distinguished lecturer, [University]

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#239
post #10

Earlier quoted context omitted.

I'm still curious why everyone thinks Zoom "just works" while others don't. Because in an enterprise context it is often hard to download an executable and run it with sufficient permissions. While Google and Microsoft both offer a product that "just works" with only a browser. What makes Zoom more "just works" than that?

Zoom has a browser version as a fallback. Most people use the standalone app because indeed it "just works". That's why you don't hear much about its browser client.

> Most people use the standalone app because indeed it "just works".

Most people use the standalone app because Zoom aggressively pushes it.

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#240

Zoom's got a tradition of being, let's put it like this, way too clever for everyone's own good. See previous “lets install a server on this Mac that is not removed when you uninstall the app and leaves your camera open to the entire internet” for more examples. I use it on a VM, I suggest you do it too.

Best zoom alternative?

Jitsi, Google Meet, bigbluebutton -- anything can runs in a browser tab and is more or less confined within it.
Post reply on HN