Live data from Hacker News

Zoom zero-day discovery

blog.malwarebytes.com

41–50 of 246 posts

Re: Zoom zero-day discovery

#41
post #10
post #3

Is it just me, or does $200k seem far too low for this? I understand that the reward was paid by the event, not Zoom... but it seems to me that Zoom should “pony up” some additional funds for this research.

> Is it just me, or does $200k seem far too low for this? For two researchers, that sounds like a lot. $100k each in less than a week for this bug sounds just rightly priced.

[deleted]

Re: Zoom zero-day discovery

#42
Related, the two other $200k entries from Pwn2Own 2021:[1]

- DEVCORE targeting Microsoft Exchange in the Server category (The DEVCORE team combined an authentication bypass and a local privilege escalation to complete take over the Exchange server.)

- The researcher who goes by OV targeting Microsoft Teams in the Enterprise Communications category (OV combined a pair of bugs to demonstrate code execution on Microsoft Teams.)

It would be kind of funny if Slack had one too...

[1] https://www.zerodayinitiative.com/blog/2021/4/2/pwn2own-2021...

Re: Zoom zero-day discovery

#43
post #30

Earlier quoted context omitted.

You can force it to use a web app by declining permission to run locally. The web-app has fewer capabilities (no gallery view, last I used it), but works great. Also, Meet is fully-featured and runs entirely in-browser.

Is the lack of a gallery view a genuine technical constraint, or an artificial one introduced to get users to use the plugin?

False dichotomy. There's a (likely) third option where they do not have sufficient engineering effort to do everything at once. Most users are on the app so that's where effort is applied. Yes, this means the webapp loses even more market share but thems the breaks.

Re: Zoom zero-day discovery

#44

Seems fair, through "less insecure" would be generally more appropriate (independent of it being Zoom). But then I have lost all trust in Zoom due to the history involved with it. And I also don't thing Zoom will regain the trust, because due to the way they lost trust again and again and also acted in-honest it's pretty hard for them to convey that they changed (instead of just pretending they did).

Same here, zoom is on our 'ban' list. And MS teams is getting there, what a load of crap that is, it is so buggy it is embarrassing.

Re: Zoom zero-day discovery

#45
post #30
post #25

Earlier quoted context omitted.

I'm still upset they try to force you to use their plugin. These would be less scary if it were jst a web app.

You can force it to use a web app by declining permission to run locally. The web-app has fewer capabilities (no gallery view, last I used it), but works great. Also, Meet is fully-featured and runs entirely in-browser.

Yes, but they keep pushing the binary anyway.

Re: Zoom zero-day discovery

#46

Seems fair, through "less insecure" would be generally more appropriate (independent of it being Zoom). But then I have lost all trust in Zoom due to the history involved with it. And I also don't thing Zoom will regain the trust, because due to the way they lost trust again and again and also acted in-honest it's pretty hard for them to convey that they changed (instead of just pretending they did).

Exactly. I run zoom on my iOS devices because it's hard to avoid and at least there's the combination of stricter sandboxing/less critical material on the device, but I refuse to run it on my computers because there's so much bad history with the company I don't feel I can trust them.

Re: Zoom zero-day discovery

#47
post #43

Earlier quoted context omitted.

Is the lack of a gallery view a genuine technical constraint, or an artificial one introduced to get users to use the plugin?

False dichotomy. There's a (likely) third option where they do not have sufficient engineering effort to do everything at once. Most users are on the app so that's where effort is applied. Yes, this means the webapp loses even more market share but thems the breaks.

Given that Facebook removed functionality from the mobile web view that was present in earlier versions and is still there in the desktop view (messages, cough), I think that it's a very fair question to raise about Zoom's choice to not allow gallery view in the web app.

Re: Zoom zero-day discovery

#48
It sounds like a great deal for Zoom... Zoom would have paid far more for this research in any other scenario.

The InfoSec community seems to be quite happy giving away their hard work, while the large security vendors make mountains of cash on snake oil solutions to enterprises. For context, Zoom certainly paid many multiples of $200k during any given month for firewall licensing.

Re: Zoom zero-day discovery

#49
The positive "tilt" in this article is honestly amusing and unusual for such articles

"zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work"

Imagine if that was your run of the mill well-hated big corp

"Yet another security vulnerability leaves millions at risk" "XYZ Corp shows its incompetence once again exposing users' private data to hackers" etc etc

No specific point here. I am just amused!

Re: Zoom zero-day discovery

#50

Seems fair, through "less insecure" would be generally more appropriate (independent of it being Zoom). But then I have lost all trust in Zoom due to the history involved with it. And I also don't thing Zoom will regain the trust, because due to the way they lost trust again and again and also acted in-honest it's pretty hard for them to convey that they changed (instead of just pretending they did).

Same here, zoom is on our 'ban' list. And MS teams is getting there, what a load of crap that is, it is so buggy it is embarrassing.

My biggest gripe about Teams is what a memory hog it is. Mine is currently sitting idle (been on vacation all week) at nearly 1GB. Compare this to Zoom, which is idling at just over 100MB. Teams is literally taking up 10 times more RAM than Zoom just running in the background.
Post reply on HN