Live data from Hacker News

Zoom zero-day discovery

blog.malwarebytes.com

131–140 of 246 posts

Re: Zoom zero-day discovery

#131
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

Using Zoom on Linux is a fun way to get everything to crash; and may as well flip a coin to see if I'll get connected / anyone will be able to hear me.

Google Meet, Slack calls, literally everything else works perfectly. With screenshare. On Wayland. I just call in to Zooms now.

Re: Zoom zero-day discovery

#132

Earlier quoted context omitted.

That doesn't make them wrong though

It doesn't, but it's worth noting that the general populace doesn't feel that way.

Because they don't realize how bad Zoom's bad acts could be for them. People didn't feel that cigarettes were bad for them. People don't feel like McDonald's is bad for them.

Re: Zoom zero-day discovery

#133

Earlier quoted context omitted.

Wait, are you saying Zoom isn't hated? It's crap. I refuse to install its PoS app and all of the security holes it came with (don't care if they are fixed or not). Launching a zoom meeting in my browser totally bogs the browser down. The zoom site is so slow that proving I'm a human is at least 10x slower than on other sites. In my use case, nobody on the zoom call is even using video, yet it still runs this badly.

We run zoom calls with over 200 participants and no problems. It sounds like their browser experience is poor, I don’t know if that’s a browser limitation or bad design, but their app on Windows and Mac performs quite well. Mistakes were made with security early in their product. It’s clear that has turned a lot of potential users against them. I’m curious why companies like Facebook get more acceptance over terrible…

Also the UI sucks. It doesn't blend nicely with my system. It looks like a sore thumb Windows 3.0 app or quack-age MacOS app in the midst of a futuristic OS.

Re: Zoom zero-day discovery

#134
This reminds me of the Skype 'vuln' where you could see weird VPS/colocation servers scooping up links when you send them via their chat feature. /Nobody/ except the recipient and you should be visiting that link, yet it's still an issue. At first I thought it just wanted to generate a 'link preview' but it's more sinister than that. Some random surveillant is looking at every link.

Re: Zoom zero-day discovery

#135
post #131
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

Using Zoom on Linux is a fun way to get everything to crash; and may as well flip a coin to see if I'll get connected / anyone will be able to hear me. Google Meet, Slack calls, literally everything else works perfectly. With screenshare. On Wayland. I just call in to Zooms now.

This so much, also eats way too much CPU, and has no support for background blur, just a damn basic chroma.

Re: Zoom zero-day discovery

#136

Earlier quoted context omitted.

"Safe" in security is always relative. Safe from a military hacking attack? Probably never. Safe from random scriptkiddies? Yeah, probably even if you don't run Zoom with a separate user, as long as you got the rest of your shit together. Safe from people buying/using 0days? Seems so, since this issue was never actually disclosed (yet) so it's not really a 0day, so it'll be harder to for people to exploit. You'd need…

What I mean is: am I safe from those who have a Zoom 0day, if Zoom is running on a separate user; assuming they do not also have a Linux 0day.

Depends on a lot of things. If the 0day is an RCE they would need another privilege escalation exploit. How easy that would be depends a lot on how your system is setup.

But the short answer is probably not. Unless you are running Qubes or something, if someone can exploit an RCE then they can probably own your system.

Re: Zoom zero-day discovery

#137
post #131
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

Using Zoom on Linux is a fun way to get everything to crash; and may as well flip a coin to see if I'll get connected / anyone will be able to hear me. Google Meet, Slack calls, literally everything else works perfectly. With screenshare. On Wayland. I just call in to Zooms now.

I use Zoom fairly regularly, and haven't had *too* many issues. (Debian, x11, the app, though the browser version is fairly terrible)

Re: Zoom zero-day discovery

#138
post #63

Can we please edit the headline. This sounds disingenuous, a more appropriate headline would be something like "critical vulnerability in Zoom Video Calls that would have put millions of users at risk has been found". This feels like a straight up PR piece.

Seconded! Only a PR person would dream of saying that a 0 day exploit is a good thing. I expect that most HN readers just finds this hillarious, but still people read HN since it has a good standard. Saying that a 0 day exploit is a good thing goes against this needless to say. Especially since they've faced serious accusations earlier on.

Well, as is previously mentioned, it's not _quite_ a 0-day, and finding it and responsibly disclosing it is a very good thing *compared to alternatives*. I do agree, though, that the tone is needlessly confusing, and it feels like PR over clarity.

Re: Zoom zero-day discovery

#139

Zoom is entirely banned at the two companies that are my day job, and probably 90% of partners. If you do any work adjacent to anything that's ITAR controlled you should also not be surprised to see the same policy from partner companies. This has been in place for quite some time since the initial security problem that was so egregiously bad apple had to resort to using the malware removal tool to remove zoom's bina…

I think we're a bit naive in the west and most often assume good faith from certain other business cultures. We're not used to companies that engage in calculated perfidy that have their sorry prepared long before you've discovered the problem. To put another way, "It's better to ask for forgiveness than to ask for permission", or to beat around the bush even more: I disagree with Hanlon's razor.

Re: Zoom zero-day discovery

#140
post #107
post #87

Earlier quoted context omitted.

The browser experience is pretty decent IMO. And unlike, say, MS Teams, at least it works on all platforms with a reasonably modern browser.

I was shocked to find that on Windows, Teams refuses to run in any browser except Edge. On Linux, it runs quite happily under Chromium. It's the worst sort of anti-competitive behavior, in my view.

https://docs.microsoft.com/en-us/microsoftteams/get-clients#...

IE11 (ew), old Edge (ew), Chromium Edge and Chrome are fully supported. Newest Safari has limited support, and only Firefox and older Safari versions are the only ones explicitly not supported.

Post reply on HN