Live data from Hacker News

Zoom zero-day discovery

blog.malwarebytes.com

121–130 of 246 posts

Re: Zoom zero-day discovery

#121
post #75
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

I don't think that's fair. The Pwn2Own contest rules specifically disallow disclosure. This isn't a "zero day" in any sense but marketing. It's a privately disclosed vulnerability under a managed embargo, just as if it had been reported by Project Zero or whoever. The ding is that, because it was a "public contest", the existence of the vulnerability is known. And that's probably a higher risk scenario in the abstrac…

Maybe the zero-day isn't disclosed from this pwn2own itself, but importantly, we now know it exists, which means we should consider how many bad actors are already independently aware of it and are exploiting it.

Responsibe disclosure processes are just as much about closing the vectors that we can't prove are under active exploit.

Re: Zoom zero-day discovery

#122
post #42

Related, the two other $200k entries from Pwn2Own 2021:[1] - DEVCORE targeting Microsoft Exchange in the Server category (The DEVCORE team combined an authentication bypass and a local privilege escalation to complete take over the Exchange server.) - The researcher who goes by OV targeting Microsoft Teams in the Enterprise Communications category (OV combined a pair of bugs to demonstrate code execution on Microsoft…

I wonder if the OS world will move towards lightweight but unforgiving sandboxing like OpenBSD's `pledge` and `unveil` system calls. It's crazy to me that most software is still completely fine to run around and set things as fire the instant it's compromised! This is about the implementation in the SerenityOS but it's my favourite explanation so far: https://awesomekling.github.io/pledge-and-unveil-in-Serenity...

Most desktop OSes came about (or at least have their roots in) a pre-internet world, where you install software from discs you purchased at the store, or if you're feeling gutsy, from media your friend hands you in real-life. They assume you have a great amount of trust in every piece of code you run on your computer (and anyway, how will malware exfiltrate your data without an always-on network connection?).

Things like Windows Defender and Snap and the recent macOS hardening efforts are patchwork solutions to try and cope with the modern world, but they'll never really be enough because these systems can't be fundamentally re-thought; they have to keep doing everything everybody already expects them to do. Only brand new OSes really get the chance to do things right, and only the mobile ones really had the opportunity to gain wide adoption.

Re: Zoom zero-day discovery

#123
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

[deleted]

Re: Zoom zero-day discovery

#124
post #75

Earlier quoted context omitted.

I don't think that's fair. The Pwn2Own contest rules specifically disallow disclosure. This isn't a "zero day" in any sense but marketing. It's a privately disclosed vulnerability under a managed embargo, just as if it had been reported by Project Zero or whoever. The ding is that, because it was a "public contest", the existence of the vulnerability is known. And that's probably a higher risk scenario in the abstrac…

Maybe the zero-day isn't disclosed from this pwn2own itself, but importantly, we now know it exists, which means we should consider how many bad actors are already independently aware of it and are exploiting it. Responsibe disclosure processes are just as much about closing the vectors that we can't prove are under active exploit.

the Pwn2Own exploits have generally not already been out there. There have been a long history of these, including some incredible chrome exploits! So the disclosure process tends to work out OK.

Re: Zoom zero-day discovery

#127

Can we please edit the headline. This sounds disingenuous, a more appropriate headline would be something like "critical vulnerability in Zoom Video Calls that would have put millions of users at risk has been found". This feels like a straight up PR piece.

Right, isn't this not a Zero Day specifically because it's not known to be exploited out in the wild. How can it be, no one else knows what the vuln is. It is being reported as part of a bug bounty with 90 day disclosure just like anything else would be.

Re: Zoom zero-day discovery

#128
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

Wait, are you saying Zoom isn't hated? It's crap. I refuse to install its PoS app and all of the security holes it came with (don't care if they are fixed or not). Launching a zoom meeting in my browser totally bogs the browser down. The zoom site is so slow that proving I'm a human is at least 10x slower than on other sites. In my use case, nobody on the zoom call is even using video, yet it still runs this badly.

Same. The whole interface is god awful. And it almost always dishonors my OS audio input/output preferences by default. The web client always downgrades my camera resolution for some reason, and messes up its aspect ratio. Plus the security problems.

Re: Zoom zero-day discovery

#129

Earlier quoted context omitted.

Wait, are you saying Zoom isn't hated? It's crap. I refuse to install its PoS app and all of the security holes it came with (don't care if they are fixed or not). Launching a zoom meeting in my browser totally bogs the browser down. The zoom site is so slow that proving I'm a human is at least 10x slower than on other sites. In my use case, nobody on the zoom call is even using video, yet it still runs this badly.

We run zoom calls with over 200 participants and no problems. It sounds like their browser experience is poor, I don’t know if that’s a browser limitation or bad design, but their app on Windows and Mac performs quite well. Mistakes were made with security early in their product. It’s clear that has turned a lot of potential users against them. I’m curious why companies like Facebook get more acceptance over terrible…

Having to download and use an executable at all is ridiculous and half the reason they have so many security problems.

Re: Zoom zero-day discovery

#130
post #51

Earlier quoted context omitted.

This is a PR piece. People do hate zoom, this is zoom trying to rehabilitate their image through their security partner.

People hate zoom? Like "Teams is so much better" or "online meeting are bad"? For me it one of the more enjoyable online meeting options and it leaves Teams, Skype, webex and what have you, far behind.

Never used Teams. Skype, which I last used years ago, was certainly better as far as downloadable chat clients go. Google Meet runs circles around Zoom, and I don't have to install anything.
Post reply on HN