Is it just me, or does $200k seem far too low for this? I understand that the reward was paid by the event, not Zoom... but it seems to me that Zoom should “pony up” some additional funds for this research.
> Is it just me, or does $200k seem far too low for this? For two researchers, that sounds like a lot. $100k each in less than a week for this bug sounds just rightly priced.
Zoom zero-day discovery
41–50 of 246 posts
Re: Zoom zero-day discovery
#42- DEVCORE targeting Microsoft Exchange in the Server category (The DEVCORE team combined an authentication bypass and a local privilege escalation to complete take over the Exchange server.)
- The researcher who goes by OV targeting Microsoft Teams in the Enterprise Communications category (OV combined a pair of bugs to demonstrate code execution on Microsoft Teams.)
It would be kind of funny if Slack had one too...
[1] https://www.zerodayinitiative.com/blog/2021/4/2/pwn2own-2021...
Re: Zoom zero-day discovery
#43Earlier quoted context omitted.
You can force it to use a web app by declining permission to run locally. The web-app has fewer capabilities (no gallery view, last I used it), but works great. Also, Meet is fully-featured and runs entirely in-browser.
Is the lack of a gallery view a genuine technical constraint, or an artificial one introduced to get users to use the plugin?
Re: Zoom zero-day discovery
#44Seems fair, through "less insecure" would be generally more appropriate (independent of it being Zoom). But then I have lost all trust in Zoom due to the history involved with it. And I also don't thing Zoom will regain the trust, because due to the way they lost trust again and again and also acted in-honest it's pretty hard for them to convey that they changed (instead of just pretending they did).
Re: Zoom zero-day discovery
#45Earlier quoted context omitted.
I'm still upset they try to force you to use their plugin. These would be less scary if it were jst a web app.
You can force it to use a web app by declining permission to run locally. The web-app has fewer capabilities (no gallery view, last I used it), but works great. Also, Meet is fully-featured and runs entirely in-browser.
Re: Zoom zero-day discovery
#46Seems fair, through "less insecure" would be generally more appropriate (independent of it being Zoom). But then I have lost all trust in Zoom due to the history involved with it. And I also don't thing Zoom will regain the trust, because due to the way they lost trust again and again and also acted in-honest it's pretty hard for them to convey that they changed (instead of just pretending they did).
Re: Zoom zero-day discovery
#47Earlier quoted context omitted.
Is the lack of a gallery view a genuine technical constraint, or an artificial one introduced to get users to use the plugin?
False dichotomy. There's a (likely) third option where they do not have sufficient engineering effort to do everything at once. Most users are on the app so that's where effort is applied. Yes, this means the webapp loses even more market share but thems the breaks.
Re: Zoom zero-day discovery
#48The InfoSec community seems to be quite happy giving away their hard work, while the large security vendors make mountains of cash on snake oil solutions to enterprises. For context, Zoom certainly paid many multiples of $200k during any given month for firewall licensing.
Re: Zoom zero-day discovery
#49"zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work"
Imagine if that was your run of the mill well-hated big corp
"Yet another security vulnerability leaves millions at risk" "XYZ Corp shows its incompetence once again exposing users' private data to hackers" etc etc
No specific point here. I am just amused!
Re: Zoom zero-day discovery
#50Seems fair, through "less insecure" would be generally more appropriate (independent of it being Zoom). But then I have lost all trust in Zoom due to the history involved with it. And I also don't thing Zoom will regain the trust, because due to the way they lost trust again and again and also acted in-honest it's pretty hard for them to convey that they changed (instead of just pretending they did).
Same here, zoom is on our 'ban' list. And MS teams is getting there, what a load of crap that is, it is so buggy it is embarrassing.