Live data from Hacker News

Zoom zero-day discovery

blog.malwarebytes.com

81–90 of 246 posts

Re: Zoom zero-day discovery

#81
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

Wait, are you saying Zoom isn't hated? It's crap. I refuse to install its PoS app and all of the security holes it came with (don't care if they are fixed or not). Launching a zoom meeting in my browser totally bogs the browser down. The zoom site is so slow that proving I'm a human is at least 10x slower than on other sites. In my use case, nobody on the zoom call is even using video, yet it still runs this badly.

We run zoom calls with over 200 participants and no problems. It sounds like their browser experience is poor, I don’t know if that’s a browser limitation or bad design, but their app on Windows and Mac performs quite well.

Mistakes were made with security early in their product. It’s clear that has turned a lot of potential users against them.

I’m curious why companies like Facebook get more acceptance over terrible security, but other companies are never forgiven

Re: Zoom zero-day discovery

#82
post #63

Earlier quoted context omitted.

Seconded! Only a PR person would dream of saying that a 0 day exploit is a good thing. I expect that most HN readers just finds this hillarious, but still people read HN since it has a good standard. Saying that a 0 day exploit is a good thing goes against this needless to say. Especially since they've faced serious accusations earlier on.

It's very clearly sarcasm and not a serious PR move, though I agree it makes the article confusing and hard to follow. Changing it to a different source link seems appropriate.

How can it be very clearly something, and at the same time confusing and hard to follow?

Re: Zoom zero-day discovery

#83
post #6

“Makes calls safer”. It fixes this particular no user input RCE vulnerability, but how many others remain? If this type of vulnerability is present at all in Zoom, then it stands to reason more wait to be discovered by sufficiently motivated attackers. These things shouldn’t end with a bounty for the researcher and a patch by the vendor. It should end with a root cause analysis and a plan to fix that type of vulnerab…

Yes, Zoom calls are now safer in the sense that the nuclear missile program got safer when the nuclear launch codes were changed from 0000000. Except in Zoom's case there isn't a human sitting in between the nuclear device and the world wide web.

Oh the link actually says that it is not patched. So now everyone with an interest in nuclear devices knows that the code is something really easy to guess. The silver lining in this moving the nuclear warning system a few minutes closer to 12 is that the guy who pointed it out got a bonus and a raise!

Re: Zoom zero-day discovery

#84
post #70
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

ZDNet's headline is "Critical Zoom vulnerability triggers remote code execution without user input"

Which is more akin to what a person who actually knows what a 0-day exploit is would phrase it.

Re: Zoom zero-day discovery

#85
post #47
post #43

Earlier quoted context omitted.

False dichotomy. There's a (likely) third option where they do not have sufficient engineering effort to do everything at once. Most users are on the app so that's where effort is applied. Yes, this means the webapp loses even more market share but thems the breaks.

Given that Facebook removed functionality from the mobile web view that was present in earlier versions and is still there in the desktop view (messages, cough), I think that it's a very fair question to raise about Zoom's choice to not allow gallery view in the web app.

I can still get FB Messages in the mobile web view by telling my browser to use Desktop view and ensuring the URL starts with "www" rather than "m." It's painful but it works.

I deleted the FB app from my phone years ago (with difficulty because Samsung makes it undeletable by non-hackers) because the app gives FB far too much info about me.

Re: Zoom zero-day discovery

#86
post #77

Earlier quoted context omitted.

It's very clearly sarcasm and not a serious PR move, though I agree it makes the article confusing and hard to follow. Changing it to a different source link seems appropriate.

I don't really think a communication from Malwarebytes is the place for sarcastic comments. Lets say if you are working with a US government this could have enormous implications. I've talked to a lot of clients who ditched Zoom for Microsoft Teams due to their earlier mistakes. Also I find it funny that the heading "Not patched yet" is solved by the headline "Security done right". Lets say if you are working with a…

Teams is exploitable too.

Re: Zoom zero-day discovery

#87
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

Wait, are you saying Zoom isn't hated? It's crap. I refuse to install its PoS app and all of the security holes it came with (don't care if they are fixed or not). Launching a zoom meeting in my browser totally bogs the browser down. The zoom site is so slow that proving I'm a human is at least 10x slower than on other sites. In my use case, nobody on the zoom call is even using video, yet it still runs this badly.

The browser experience is pretty decent IMO. And unlike, say, MS Teams, at least it works on all platforms with a reasonably modern browser.

Re: Zoom zero-day discovery

#88

Earlier quoted context omitted.

Wait, are you saying Zoom isn't hated? It's crap. I refuse to install its PoS app and all of the security holes it came with (don't care if they are fixed or not). Launching a zoom meeting in my browser totally bogs the browser down. The zoom site is so slow that proving I'm a human is at least 10x slower than on other sites. In my use case, nobody on the zoom call is even using video, yet it still runs this badly.

We run zoom calls with over 200 participants and no problems. It sounds like their browser experience is poor, I don’t know if that’s a browser limitation or bad design, but their app on Windows and Mac performs quite well. Mistakes were made with security early in their product. It’s clear that has turned a lot of potential users against them. I’m curious why companies like Facebook get more acceptance over terrible…

If browser performance is bad but app performance is good (and I agree that my experience with the app is actually pretty good), then it is a bad sign that the exploit is in the app, and not the browser version.

Re: Zoom zero-day discovery

#89

Earlier quoted context omitted.

It's very clearly sarcasm and not a serious PR move, though I agree it makes the article confusing and hard to follow. Changing it to a different source link seems appropriate.

How can it be very clearly something, and at the same time confusing and hard to follow?

What's clear to A can be confusing to B. Sarcasm or satire is a common example.

Re: Zoom zero-day discovery

#90

Earlier quoted context omitted.

It's very clearly sarcasm and not a serious PR move, though I agree it makes the article confusing and hard to follow. Changing it to a different source link seems appropriate.

How can it be very clearly something, and at the same time confusing and hard to follow?

It's clear that it's not serious, but once you get the joke you then have to mentally transform every statement as you go along in order to get the base facts. That hurts clarity.
Post reply on HN