Live data from Hacker News

Tell HN: Cisco WebEx on OS X uses the same pre-installer tricks as Zoom

news.ycombinator.com

81–90 of 181 posts

Re: Tell HN: Cisco WebEx on OS X uses the same pre-installer tricks as Zoom

#81
post #74

I believe this is not hard to detect. Apple should detect this and report such an installer as particularly risky. Chances are the majority of installers working this way actually are malware, legitimate apps like Zoom and WebEx probably are exceptions.

That's extremely unlikely. Malware on macOS isn't prevalent. There is no market for anti-virus vendors on macOS, and Apple have been repeatedly tightening the approval process for macOS software. Gatekeeper only ever gets more aggressive, not less. Meanwhile videocall software is widespread, it's rapidly become a necessity for a large part of the world's population. I wouldn't be surprised if on macOS it's now in sec…

> the usability of macOS software installation is terrible and no, the App Store is not an acceptable alternative. macOS software install UX is worse than Windows. It's worse than Android and iOS. It's better than Linux but that doesn't say much.

Sounds questionable in all the parts.

Mac: Just click-mount an installation disk image and drag an app icon to the Applicationss folder - isn't this a perfect install UX? If an app installed this way wants to handle some URLs it should declare that in its metadata. No app should be allowed to modify files outside its dedicated directories unless modifying those files is its actual mission.

Linux: just type "sudo apt install app_name" - what can be more handy?

Windows: let every app you install do anything it wants with all the system files, leaving traces after uninstallation is a norm.

The only problems with iOS are it removes a user's right to program his own device freely and demands too much money from 3rd party devs.

Re: Tell HN: Cisco WebEx on OS X uses the same pre-installer tricks as Zoom

#82

This is apples fault. Not for not blocking it but for not making the download-and-installed as streamlined as it needs to be. Being forced to drag something to a folder is not the UX you expect.

Would distribution via the App Store work? I mean that is the easiest and most trustworthy way - from a consumer's point of view - to install software.

Re: Tell HN: Cisco WebEx on OS X uses the same pre-installer tricks as Zoom

#83
Why aren't more apps like Zoom and this one distributed via the app store? I mean besides the installer hackery they are legitimate and free apps right?

Or would that mean that their premium services would require paying the fees to Apple, which they avoid this way?

Re: Tell HN: Cisco WebEx on OS X uses the same pre-installer tricks as Zoom

#84

Earlier quoted context omitted.

Another reason could be to ensure that you have at most one copy of the application ever, since you can force it to install stuff always at the same location. On an unrelated product we learned that users ended up with many different copies of the app scattered throughout the system, if they were allowed to use the traditional bundle + DMG distribution method. Spotlight would then helpfully pick one random copy, with…

yes, it's a total pain. users send you a crash log, you see that they're on an old version, ask them to update. They say they do, you get the next crash log, and it's still the old version. And then you get a screenshot and you see 12 different versions of your .app, in the desktop, in ~/Applications, in /Applications...

Even worse when they don't copy it off the DMG. Just leave the DMG mounted.. forever.

Re: Tell HN: Cisco WebEx on OS X uses the same pre-installer tricks as Zoom

#85
post #74

I believe this is not hard to detect. Apple should detect this and report such an installer as particularly risky. Chances are the majority of installers working this way actually are malware, legitimate apps like Zoom and WebEx probably are exceptions.

That's extremely unlikely. Malware on macOS isn't prevalent. There is no market for anti-virus vendors on macOS, and Apple have been repeatedly tightening the approval process for macOS software. Gatekeeper only ever gets more aggressive, not less. Meanwhile videocall software is widespread, it's rapidly become a necessity for a large part of the world's population. I wouldn't be surprised if on macOS it's now in sec…

>>> Malware on macOS isn't prevalent.

I'd beg to differ on that. If anything, I'd bet MacOS is now be the platform with the most malware (adware specifically).

I've had to check laptops from wife and step family (all apple users) in the past year and they all turned out to be infected with a truckload of mac adware, that they only noticed after it replaced their homepage browser or spammed unending popups on the desktop.

While browsing for help on safari, pages were filled with ads and popups trying to send you more malware. That is, when pages are not right away sending you some executable files (just like pages sending you .apk on android devices). MacOS is as unsafe as everything else nowadays.

Re: Tell HN: Cisco WebEx on OS X uses the same pre-installer tricks as Zoom

#86

This is apples fault. Not for not blocking it but for not making the download-and-installed as streamlined as it needs to be. Being forced to drag something to a folder is not the UX you expect.

As a Mac-user since the mid 2000's, that's exactly what I expect. Whenever I see an installer I know that it's some multiplatform/slightly crapware software I'm about to use.

Re: Tell HN: Cisco WebEx on OS X uses the same pre-installer tricks as Zoom

#87
post #80

I was surprised that when I ran a WebEx exe on windows to join a meeting, after the meeting concluded a window appeared with my calendar information pulled from outlook. It really highlights how on desktop apps can do what they like. Whilst on mobile platforms at least you have to grant specific access.

Webex can sync with your corporate calendar. Its possible by signing into Webex, it checked your corporation calendar and synced that.

There is also a system with Webex, that is separate, and if you have Webex meetings registered against your email, it will provide you those meetings if you are not signed in.

Re: Tell HN: Cisco WebEx on OS X uses the same pre-installer tricks as Zoom

#88

Why aren't more apps like Zoom and this one distributed via the app store? I mean besides the installer hackery they are legitimate and free apps right? Or would that mean that their premium services would require paying the fees to Apple, which they avoid this way?

Because logging in, downloading and installing from the App Store is higher friction than how it works now. Typically Zoom is installed for the first time at the very moment a meeting is starting. Seconds matter.

Re: Tell HN: Cisco WebEx on OS X uses the same pre-installer tricks as Zoom

#89
post #76
post #74

Earlier quoted context omitted.

That's extremely unlikely. Malware on macOS isn't prevalent. There is no market for anti-virus vendors on macOS, and Apple have been repeatedly tightening the approval process for macOS software. Gatekeeper only ever gets more aggressive, not less. Meanwhile videocall software is widespread, it's rapidly become a necessity for a large part of the world's population. I wouldn't be surprised if on macOS it's now in sec…

> 1. Genuine one or two-click install of software from the web, without the App Store being involved and without requiring sandboxing I disagree with this. Why is going via the app store a bad thing? The app store is the solution here. Zoom should be able to tell apple "Hey I'd like to handle zoom://" links, and clicking one will redirect you to either zoom or the app store (without the source of your link knowing wh…

No company that has a choice is going to pay Apple their tax. That's why the MacOS sure is always going to be the same as the Windows store: a home of loser apps. Since another install procedure is available, only losers will use the app store. Ergo, any software available through the app store is a loser app.

Re: Tell HN: Cisco WebEx on OS X uses the same pre-installer tricks as Zoom

#90

I still don’t understand the issue with this: it’s not using this feature as intended, but they’re not exploiting any vulnerabilities or attempting to exploit a privilege escalation bug in macOS. Apple’s installers allow these scripts to do anything (and I believe there’s a prompt along the lines of “this installer will run a script to determine if the package can be installed”).

The thing is that Zoom isn't installing the package either! If you look at the list of installed pkgs after installing Zoom there is no Zoom package.

They are using a .pkg only for the side effect of running a pre installation script that simply copies Zoom.app in the /Application directory. That is to a software develper garbage, why doing so, when all other macOS application require the user a single drag and drop?

Sure, that is probably not malware, but is a very poor practice, gives the user a bad experience, for no reason. These are the things that let's you wonder if the installation is managed in such a poor way how is the rest of the infrastructure.

Post reply on HN