Live data from Hacker News

Zoom zero-day discovery

blog.malwarebytes.com

111–120 of 246 posts

Re: Zoom zero-day discovery

#111
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

Wait, are you saying Zoom isn't hated? It's crap. I refuse to install its PoS app and all of the security holes it came with (don't care if they are fixed or not). Launching a zoom meeting in my browser totally bogs the browser down. The zoom site is so slow that proving I'm a human is at least 10x slower than on other sites. In my use case, nobody on the zoom call is even using video, yet it still runs this badly.

Zoom has a history of nasty security issues, does shady business with China and bought and killed Keybase. It's a shitty company not even considering their software.

Re: Zoom zero-day discovery

#113
post #62

Zoom is entirely banned at the two companies that are my day job, and probably 90% of partners. If you do any work adjacent to anything that's ITAR controlled you should also not be surprised to see the same policy from partner companies. This has been in place for quite some time since the initial security problem that was so egregiously bad apple had to resort to using the malware removal tool to remove zoom's bina…

Do these issues hold true for the FedRAMP'd "Zoom For Government"?

No, but that's not available to anybody but the govt.

Re: Zoom zero-day discovery

#116

Naive question. I'm forced to use Zoom by my University, so I run it from a dedicated user (on Linux). That's fairly safe, right?

"Safe" in security is always relative. Safe from a military hacking attack? Probably never. Safe from random scriptkiddies? Yeah, probably even if you don't run Zoom with a separate user, as long as you got the rest of your shit together. Safe from people buying/using 0days? Seems so, since this issue was never actually disclosed (yet) so it's not really a 0day, so it'll be harder to for people to exploit.

You'd need to understand who/what are your threats to understand if you're "safe" or not.

Re: Zoom zero-day discovery

#118

Naive question. I'm forced to use Zoom by my University, so I run it from a dedicated user (on Linux). That's fairly safe, right?

"Safe" in security is always relative. Safe from a military hacking attack? Probably never. Safe from random scriptkiddies? Yeah, probably even if you don't run Zoom with a separate user, as long as you got the rest of your shit together. Safe from people buying/using 0days? Seems so, since this issue was never actually disclosed (yet) so it's not really a 0day, so it'll be harder to for people to exploit. You'd need…

What I mean is: am I safe from those who have a Zoom 0day, if Zoom is running on a separate user; assuming they do not also have a Linux 0day.

Re: Zoom zero-day discovery

#120

Earlier quoted context omitted.

My biggest gripe about Teams is what a memory hog it is. Mine is currently sitting idle (been on vacation all week) at nearly 1GB. Compare this to Zoom, which is idling at just over 100MB. Teams is literally taking up 10 times more RAM than Zoom just running in the background.

In Microsoft’s defense Teams is an electron (or electronesque) app and offers quite a bit more than Zoom in terms of features. The fact that it uses so much RAM is expected when you consider it as another copy of chrome.

It boggles me to no end that Microsoft is switching to electron apps even for Windows. You would think that they could write native applications that wouldn't sacrifice stability, performance or functionality the way Teams does for their own operating system.
Post reply on HN