Live data from Hacker News

Zoom zero-day discovery

blog.malwarebytes.com

11–20 of 246 posts

Re: Zoom zero-day discovery

#11
Yet another (relative) win for the browser environment:

"We also know that the method works on the Windows and Mac version of the Zoom software, but does not affect the browser version."

Re: Zoom zero-day discovery

#12
post #3

Is it just me, or does $200k seem far too low for this? I understand that the reward was paid by the event, not Zoom... but it seems to me that Zoom should “pony up” some additional funds for this research.

You are always free to sell the hacks for their """actual""" market value on the black market. Of course you need to launder the money, you might get jailed, you might have to flee the country and so on but at least you get your fair rate.

Or sell it to the NSA (or insert your national intelligence service here) as a defense contractor, which some might call your “patriotic duty”.

Re: Zoom zero-day discovery

#13
post #6

“Makes calls safer”. It fixes this particular no user input RCE vulnerability, but how many others remain? If this type of vulnerability is present at all in Zoom, then it stands to reason more wait to be discovered by sufficiently motivated attackers. These things shouldn’t end with a bounty for the researcher and a patch by the vendor. It should end with a root cause analysis and a plan to fix that type of vulnerab…

What makes you assume no RCA will be done?

Re: Zoom zero-day discovery

#14
Seems fair, through "less insecure" would be generally more appropriate (independent of it being Zoom).

But then I have lost all trust in Zoom due to the history involved with it. And I also don't thing Zoom will regain the trust, because due to the way they lost trust again and again and also acted in-honest it's pretty hard for them to convey that they changed (instead of just pretending they did).

Re: Zoom zero-day discovery

#15
post #3

Is it just me, or does $200k seem far too low for this? I understand that the reward was paid by the event, not Zoom... but it seems to me that Zoom should “pony up” some additional funds for this research.

Very few bounty programs offer that much for a single vulnerability. I'm not saying it's worth $200k, but $200k is definitively a huge payout in the security industry.

Re: Zoom zero-day discovery

#16
post #12

Earlier quoted context omitted.

You are always free to sell the hacks for their """actual""" market value on the black market. Of course you need to launder the money, you might get jailed, you might have to flee the country and so on but at least you get your fair rate.

Or sell it to the NSA (or insert your national intelligence service here) as a defense contractor, which some might call your “patriotic duty”.

I doubt the rates are that good tbh..

Re: Zoom zero-day discovery

#17

What percentage of these kind of exploits does hn think are found by these kind of white hat exercises and what percentage are sitting out there in an intelligence service or private entity's 0-day database? I have always been curious.

If I were running an agency...

You don't have to find many zero days. Just have enough. Huge backend of tools and network of contributors surely helps, but if 0-day is gone in Zoom, and say you don't have their explicit cooperation (which you totally can have) and you only have one, then it may not be such a worry if it is commonly used with other software that you can own.

Besides that, there are tiers of 0-days, some of which you would not touch unless the target is exceptionally valuable and you did some homework with oh-just-a-common-malware to learn about their system and response.

There is no system that is secure. There may be systems that are obscure. But if they would be targeted they can be owned with easy because they are not popular and security is really really hard.

This is not just crazy talk anymore, it's reality. It's enough to watch CVEs, think what you could do if you exploit them silently and what that allows you to do in the future. Watch them not only for abstractions on top, but for whole tons of firmware running both on your machine and machines that you trust. Oh and certificates... It's just too easy. Way too easy.

Re: Zoom zero-day discovery

#18
post #6

“Makes calls safer”. It fixes this particular no user input RCE vulnerability, but how many others remain? If this type of vulnerability is present at all in Zoom, then it stands to reason more wait to be discovered by sufficiently motivated attackers. These things shouldn’t end with a bounty for the researcher and a patch by the vendor. It should end with a root cause analysis and a plan to fix that type of vulnerab…

> These things shouldn’t end with a bounty for the researcher and a patch by the vendor. It should end with a root cause analysis and a plan to fix that type of vulnerability across the entire app, or better yet, the whole industry via a research paper.

I'm unsure (and open to discussion) on which classes of bugs make that possible. My initial thought is that finding a stack overflow bug (to randomly choose a bug class) results in "don't goof up memory", which is technically correct, but not actually useful in finding others of that class.

In this hypothetical, maybe the result would some combination of accessing programming language choice, programming practice, and testing tooling? Can't say those are a silver bullet though.

Re: Zoom zero-day discovery

#19
post #10
post #3

Is it just me, or does $200k seem far too low for this? I understand that the reward was paid by the event, not Zoom... but it seems to me that Zoom should “pony up” some additional funds for this research.

> Is it just me, or does $200k seem far too low for this? For two researchers, that sounds like a lot. $100k each in less than a week for this bug sounds just rightly priced.

There is most likely much more than a week of work behind this.

Re: Zoom zero-day discovery

#20
post #6

“Makes calls safer”. It fixes this particular no user input RCE vulnerability, but how many others remain? If this type of vulnerability is present at all in Zoom, then it stands to reason more wait to be discovered by sufficiently motivated attackers. These things shouldn’t end with a bounty for the researcher and a patch by the vendor. It should end with a root cause analysis and a plan to fix that type of vulnerab…

Yes, Zoom calls are now safer in the sense that the nuclear missile program got safer when the nuclear launch codes were changed from 0000000. Except in Zoom's case there isn't a human sitting in between the nuclear device and the world wide web.
Post reply on HN