Live data from Hacker News

Zoom zero-day discovery

blog.malwarebytes.com

51–60 of 246 posts

Re: Zoom zero-day discovery

#51
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

This is a PR piece. People do hate zoom, this is zoom trying to rehabilitate their image through their security partner.

Re: Zoom zero-day discovery

#52
Not related, but: the other day I joined a Zoom call for the first time. I had no interest in using a native client, but when you first try to join the call and Zoom tries to download the client, Microsoft Edge warned me that it was “harmful to my device”. For once SmartScreen and I are in agreement.

Re: Zoom zero-day discovery

#53
post #47
post #43

Earlier quoted context omitted.

False dichotomy. There's a (likely) third option where they do not have sufficient engineering effort to do everything at once. Most users are on the app so that's where effort is applied. Yes, this means the webapp loses even more market share but thems the breaks.

Given that Facebook removed functionality from the mobile web view that was present in earlier versions and is still there in the desktop view (messages, cough), I think that it's a very fair question to raise about Zoom's choice to not allow gallery view in the web app.

Putting aside that Zoom is not Facebook, "Zoom's choice to not allow gallery view" sounds very much like, "How long have you been beating your wife?" Zoom has not implemented gallery view. We know nothing about the whys, hows, and whats of the matter.

Look, I prefer webapps when possible and keep mobile apps to a very minimum on my mobile (and preferably from F-Droid, at that). But I also understand that you can only do so much in a release and if your engineering team expertise, backlog, users, sales, EVERYTHING, is centered around native apps. Then damn it, you're going to make your native app look stellar because otherwise your competitors will get a leg up over you.

Re: Zoom zero-day discovery

#54
post #13
post #6

“Makes calls safer”. It fixes this particular no user input RCE vulnerability, but how many others remain? If this type of vulnerability is present at all in Zoom, then it stands to reason more wait to be discovered by sufficiently motivated attackers. These things shouldn’t end with a bounty for the researcher and a patch by the vendor. It should end with a root cause analysis and a plan to fix that type of vulnerab…

What makes you assume no RCA will be done?

I should clarify: public RCA.

Is $200k enough to motivate a company like Zoom to do an RCA after something like this? Maybe? I personally doubt it but don’t have any real reasoning for it one way or another.

Re: Zoom zero-day discovery

#55
Zoom is entirely banned at the two companies that are my day job, and probably 90% of partners. If you do any work adjacent to anything that's ITAR controlled you should also not be surprised to see the same policy from partner companies. This has been in place for quite some time since the initial security problem that was so egregiously bad apple had to resort to using the malware removal tool to remove zoom's binaries from Macos clients.

Entirely aside from their many past security holes which have been handled poorly , they have straight up lied about end to end crypto and what exact crypto it's using. That's before we get into the ownership of the company, its management and the location of most of the developers.

Re: Zoom zero-day discovery

#56
post #51
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

This is a PR piece. People do hate zoom, this is zoom trying to rehabilitate their image through their security partner.

People hate zoom? Like "Teams is so much better" or "online meeting are bad"?

For me it one of the more enjoyable online meeting options and it leaves Teams, Skype, webex and what have you, far behind.

Re: Zoom zero-day discovery

#57
Can we please edit the headline. This sounds disingenuous, a more appropriate headline would be something like "critical vulnerability in Zoom Video Calls that would have put millions of users at risk has been found".

This feels like a straight up PR piece.

Re: Zoom zero-day discovery

#58

Earlier quoted context omitted.

Same here, zoom is on our 'ban' list. And MS teams is getting there, what a load of crap that is, it is so buggy it is embarrassing.

My biggest gripe about Teams is what a memory hog it is. Mine is currently sitting idle (been on vacation all week) at nearly 1GB. Compare this to Zoom, which is idling at just over 100MB. Teams is literally taking up 10 times more RAM than Zoom just running in the background.

Try disabling GPU acceleration. It seems to speed things up a lot for some reason.

Re: Zoom zero-day discovery

#59
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

To be fair, Zoom is universally well-hated at this point, at least by anyone with an interest in security.

Re: Zoom zero-day discovery

#60

Zoom is entirely banned at the two companies that are my day job, and probably 90% of partners. If you do any work adjacent to anything that's ITAR controlled you should also not be surprised to see the same policy from partner companies. This has been in place for quite some time since the initial security problem that was so egregiously bad apple had to resort to using the malware removal tool to remove zoom's bina…

this was the case here too, but just yesterday got on a usaf hosted zoom that said 'gov' and hosted in CONUS so they seem to have some offering at least DoD is ok with now, appears to only be fedramp

https://www.zoomgov.com/

Post reply on HN