Live data from Hacker News

Zoom zero-day discovery

blog.malwarebytes.com

71–80 of 246 posts

Re: Zoom zero-day discovery

#71
>The fact that the researchers came out on the second day of the Pwn2Own event with this vulnerability does not mean they figured it out in those two days. They will have put in months of research to find the different flaws and combine them into an RCE attack.

I really appreciate the article author mentioning this. It gives hope to all beginners and shows that "overnight success" is a result of months and years of learning and research

Re: Zoom zero-day discovery

#72
post #30

Earlier quoted context omitted.

You can force it to use a web app by declining permission to run locally. The web-app has fewer capabilities (no gallery view, last I used it), but works great. Also, Meet is fully-featured and runs entirely in-browser.

I've wondered whether things like the gallery view limitation were actual technical hurdles, or just the modern equivalent of nagware to boost the app download metrics.

At the start of the pandemic, the web client had gallery view.

Re: Zoom zero-day discovery

#73
post #63

Can we please edit the headline. This sounds disingenuous, a more appropriate headline would be something like "critical vulnerability in Zoom Video Calls that would have put millions of users at risk has been found". This feels like a straight up PR piece.

Seconded! Only a PR person would dream of saying that a 0 day exploit is a good thing. I expect that most HN readers just finds this hillarious, but still people read HN since it has a good standard. Saying that a 0 day exploit is a good thing goes against this needless to say. Especially since they've faced serious accusations earlier on.

It's very clearly sarcasm and not a serious PR move, though I agree it makes the article confusing and hard to follow. Changing it to a different source link seems appropriate.

Re: Zoom zero-day discovery

#74
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

Wait, are you saying Zoom isn't hated? It's crap. I refuse to install its PoS app and all of the security holes it came with (don't care if they are fixed or not). Launching a zoom meeting in my browser totally bogs the browser down. The zoom site is so slow that proving I'm a human is at least 10x slower than on other sites. In my use case, nobody on the zoom call is even using video, yet it still runs this badly.

Re: Zoom zero-day discovery

#75
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

I don't think that's fair. The Pwn2Own contest rules specifically disallow disclosure. This isn't a "zero day" in any sense but marketing. It's a privately disclosed vulnerability under a managed embargo, just as if it had been reported by Project Zero or whoever.

The ding is that, because it was a "public contest", the existence of the vulnerability is known. And that's probably a higher risk scenario in the abstract I guess. But I think it's clear to all that Pwn2Own and similar activities are a net benefit to global software security nonetheless.

Re: Zoom zero-day discovery

#76

Earlier quoted context omitted.

People hate zoom? Like "Teams is so much better" or "online meeting are bad"? For me it one of the more enjoyable online meeting options and it leaves Teams, Skype, webex and what have you, far behind.

Like "Zoom is an unethical company". See: Privacy concerns, lying about encryption, connections to china, bad security.

a lot of college students do not worry about this

Re: Zoom zero-day discovery

#77
post #63

Earlier quoted context omitted.

Seconded! Only a PR person would dream of saying that a 0 day exploit is a good thing. I expect that most HN readers just finds this hillarious, but still people read HN since it has a good standard. Saying that a 0 day exploit is a good thing goes against this needless to say. Especially since they've faced serious accusations earlier on.

It's very clearly sarcasm and not a serious PR move, though I agree it makes the article confusing and hard to follow. Changing it to a different source link seems appropriate.

I don't really think a communication from Malwarebytes is the place for sarcastic comments. Lets say if you are working with a US government this could have enormous implications. I've talked to a lot of clients who ditched Zoom for Microsoft Teams due to their earlier mistakes.

Also I find it funny that the heading "Not patched yet" is solved by the headline "Security done right".

Lets say if you are working with a company that deals with say healthcare information a 0-day certainly doesn't make things safer and since it is not patched yet this is definitely not done right.

Re: Zoom zero-day discovery

#78

Earlier quoted context omitted.

Same here, zoom is on our 'ban' list. And MS teams is getting there, what a load of crap that is, it is so buggy it is embarrassing.

My biggest gripe about Teams is what a memory hog it is. Mine is currently sitting idle (been on vacation all week) at nearly 1GB. Compare this to Zoom, which is idling at just over 100MB. Teams is literally taking up 10 times more RAM than Zoom just running in the background.

I have never used Teams but is 1GB of memory usage really an issue in 2021, when most laptops have at least 16-32 gigs of memory? It's been years since the last time I actually worried about how much memory some software on my laptop was using.

Re: Zoom zero-day discovery

#79
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

Wait, are you saying Zoom isn't hated? It's crap. I refuse to install its PoS app and all of the security holes it came with (don't care if they are fixed or not). Launching a zoom meeting in my browser totally bogs the browser down. The zoom site is so slow that proving I'm a human is at least 10x slower than on other sites. In my use case, nobody on the zoom call is even using video, yet it still runs this badly.

Didn't they route calls through China for no apparent reason as well?

Re: Zoom zero-day discovery

#80

Earlier quoted context omitted.

That might be “people on HN hate zoom”.

Fair point. Possibly "people on HN hate zoom, and then use it anyways because it's forced."

Or how about people on HN are educated about zoom and therefore hate it.
Post reply on HN