Live data from Hacker News

How the Zoom macOS installer does its job without you clicking ‘install’

twitter.com

261–270 of 334 posts

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#261
post #184

Earlier quoted context omitted.

> I'm still curious why everyone thinks Zoom "just works" while others don't. I'm also curious. I subscribed to Whereby ( https://whereby.com/ ), where I can send people a URL, which they click and land in my conference room. There is ZERO software they need to install. [For all the "well, actually" folks: yes, it "only" works in every modern browser out there, and it works "only" for up to 12 people. Fine with me.]…

To be more specific, whereby seems to be free for up to 4 people, but then they claim to be able to support 50. Never tested it with 50

Some of my teachers use jitsi, which works on the same principle. The teacher sends a link, you click it, and that's it. Works very well, and no limit.

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#262

I installed Zoom on macOS yesterday and I thought that the install was crashing because this is not the expected behavior. I would double click the download, try to install, and then the installation program would "crash", so I'd try it again. Did that a few times before I realized it was installed. Until now I thought it had somehow gotten far enough in the installation process before crashing that I could at least…

I too don't get how Zoom is considered "the superior software". Maybe the calls don't drop, but the experience is bad (at least on macOS).

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#263

Earlier quoted context omitted.

> 3) Malware is defined by what it does, not how it's installed. Well, from the tweet thread: > If the App is already installed but the current user is not admin, they use a helper tool called "zoomAutenticationTool" [sic] and the AuthorizationExecuteWithPrivileges API to spawn a password prompt identifying as "System" (!!) to gain root (including a typo).

It's not malicious, and you have to give it permissions somehow to finish the install. Dropbox (used to?) patch system files to integrate with Office better, and that wasn't considered malware either.

> It's not malicious

By the time you're lying to the user, you are malicious.

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#264
post #262

I installed Zoom on macOS yesterday and I thought that the install was crashing because this is not the expected behavior. I would double click the download, try to install, and then the installation program would "crash", so I'd try it again. Did that a few times before I realized it was installed. Until now I thought it had somehow gotten far enough in the installation process before crashing that I could at least…

I too don't get how Zoom is considered "the superior software". Maybe the calls don't drop, but the experience is bad (at least on macOS).

Said this on Reddit the other day and got downvoted.

It _is_ bad on macOS. It used to be one of the better platforms to stream video content to others, but now it just lacks in many areas compared to most of its competitors.

The worst bug I had was it essentially started muting random people on a call, but only for me. I could see their mouth moving, and thought it was a problem their side but turns out everyone else could hear them apart from me. I could hear everyone else too apart from them.

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#265

Zoom's got a tradition of being, let's put it like this, way too clever for everyone's own good. See previous “lets install a server on this Mac that is not removed when you uninstall the app and leaves your camera open to the entire internet” for more examples. I use it on a VM, I suggest you do it too.

It's very Dropbox-esque…

As a Dropbox user, care to elaborate please?

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#266
post #265

Earlier quoted context omitted.

It's very Dropbox-esque…

As a Dropbox user, care to elaborate please?

https://applehelpwriter.com/2016/08/29/discovering-how-dropb..., and the associated Hacker News discussion: https://news.ycombinator.com/item?id=12463338

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#268

Earlier quoted context omitted.

Best zoom alternative?

Google Duo have raised the people per meeting from 4 to 12.

But can they raise the expected product lifespan from 4 years to 12?

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#269
post #13

Earlier quoted context omitted.

they work for your use case. hangouts can’t handle many users (is it 10 the limit?), which is a deal breaker for me. we’ve tried and people couldn’t join the call. if by microsoft you mean teams, i’m not aware of it working without accounts (not an issue for google as most people have google accounts).

> hangouts can’t handle many users (is it 10 the limit?), which is a deal breaker for me. we’ve tried and people couldn’t join the call. My company had a 17 person Hangouts (Meet) meeting on Monday. Actually, we switched to Hangouts from Slack because Slack has a 15 person limit. Is the limit maybe different for "Hangouts" vs Hangouts Meet?

That’s probably the issue. We were using the free version.

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#270
post #114

Earlier quoted context omitted.

I mean, it's not really a security bug. Installer.app displays a dialog box that says "Hey, this package wants to run arbitrary code to check if it's compatible with your system. Is that OK?" The user is explicitly opting into the code execution. Zoom's "compatibility check" installs the app and kills the installer window. That's certainly unexpected behavior, but I don't think it's an exploit in any real sense. Whil…

It's really Apple's fault. "This package will run a program to determine if the software can be installed." Is just fundamentally a very strange statement to make, loaded with vagueness. Think about your average user... they are running an installer program... which alerts them that they need to run another program... to determine if they can install the program.... (Which the user thought they were already doing) Th…

On top of this, a standard install asks for permissions, but doesn't disclose who/what is asking for it (certified in some way) or what permissions it wants, if these are temporary for the install or permanent for the application, or what it is going to do during the install (what goes where, what gets changed etc).

It is long past time for Apple to improve this process.

Post reply on HN