Live data from Hacker News

Zoom zero-day discovery

blog.malwarebytes.com

141–150 of 246 posts

Re: Zoom zero-day discovery

#141

Earlier quoted context omitted.

What I mean is: am I safe from those who have a Zoom 0day, if Zoom is running on a separate user; assuming they do not also have a Linux 0day.

Depends on a lot of things. If the 0day is an RCE they would need another privilege escalation exploit. How easy that would be depends a lot on how your system is setup. But the short answer is probably not. Unless you are running Qubes or something, if someone can exploit an RCE then they can probably own your system.

I'd be really interested in a longer answer. I'm running Void Linux. What would exactly would Qubes add in this respect?

Re: Zoom zero-day discovery

#142
post #107
post #87

Earlier quoted context omitted.

The browser experience is pretty decent IMO. And unlike, say, MS Teams, at least it works on all platforms with a reasonably modern browser.

I was shocked to find that on Windows, Teams refuses to run in any browser except Edge. On Linux, it runs quite happily under Chromium. It's the worst sort of anti-competitive behavior, in my view.

I use it in Firefox regularly, and just checked and it runs in chrome too. Weird...

Re: Zoom zero-day discovery

#143
post #131
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

Using Zoom on Linux is a fun way to get everything to crash; and may as well flip a coin to see if I'll get connected / anyone will be able to hear me. Google Meet, Slack calls, literally everything else works perfectly. With screenshare. On Wayland. I just call in to Zooms now.

I've read that AV is a dumpster fire on Linux and you're lucky if anything runs and Linux has never solved it and no resolution in sight.

Re: Zoom zero-day discovery

#144

This reminds me of the Skype 'vuln' where you could see weird VPS/colocation servers scooping up links when you send them via their chat feature. /Nobody/ except the recipient and you should be visiting that link, yet it's still an issue. At first I thought it just wanted to generate a 'link preview' but it's more sinister than that. Some random surveillant is looking at every link.

How long ago was this going on?

Re: Zoom zero-day discovery

#145

Earlier quoted context omitted.

Wait, are you saying Zoom isn't hated? It's crap. I refuse to install its PoS app and all of the security holes it came with (don't care if they are fixed or not). Launching a zoom meeting in my browser totally bogs the browser down. The zoom site is so slow that proving I'm a human is at least 10x slower than on other sites. In my use case, nobody on the zoom call is even using video, yet it still runs this badly.

We run zoom calls with over 200 participants and no problems. It sounds like their browser experience is poor, I don’t know if that’s a browser limitation or bad design, but their app on Windows and Mac performs quite well. Mistakes were made with security early in their product. It’s clear that has turned a lot of potential users against them. I’m curious why companies like Facebook get more acceptance over terrible…

I also like zoom over the alternatives. Does it have problems, yes but what software doesn’t. I have been using zoom for years (my school switched early) compared to previous tools it just worked and worked well. Yes I know they lied and deceived but again marketing is always full of BS and guess who makes the blurbs we read on the internet about a company. Again the constantly changing UI is annoying but what is better? If someone has something better that even my grandma can use I will give it a shot.

Re: Zoom zero-day discovery

#147
post #42

Related, the two other $200k entries from Pwn2Own 2021:[1] - DEVCORE targeting Microsoft Exchange in the Server category (The DEVCORE team combined an authentication bypass and a local privilege escalation to complete take over the Exchange server.) - The researcher who goes by OV targeting Microsoft Teams in the Enterprise Communications category (OV combined a pair of bugs to demonstrate code execution on Microsoft…

I wonder if the OS world will move towards lightweight but unforgiving sandboxing like OpenBSD's `pledge` and `unveil` system calls. It's crazy to me that most software is still completely fine to run around and set things as fire the instant it's compromised! This is about the implementation in the SerenityOS but it's my favourite explanation so far: https://awesomekling.github.io/pledge-and-unveil-in-Serenity...

I don't see how the large majority of security problems could be solved by any OS design. Human failures would just account for 95% of breaches instead of the current 85% (made up numbers). Not saying the OS improvements aren't useful nevertheless..

Re: Zoom zero-day discovery

#148
post #59
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

To be fair, Zoom is universally well-hated at this point, at least by anyone with an interest in security.

Zoom is pretty well-liked by those who would be stuck with Teams otherwise.

Re: Zoom zero-day discovery

#149

Zoom is entirely banned at the two companies that are my day job, and probably 90% of partners. If you do any work adjacent to anything that's ITAR controlled you should also not be surprised to see the same policy from partner companies. This has been in place for quite some time since the initial security problem that was so egregiously bad apple had to resort to using the malware removal tool to remove zoom's bina…

As if other vendors are certainly more secure. Those bans seem more based on media exposure than known technical facts and evaluations.

Re: Zoom zero-day discovery

#150
post #59

Earlier quoted context omitted.

To be fair, Zoom is universally well-hated at this point, at least by anyone with an interest in security.

Zoom is pretty well-liked by those who would be stuck with Teams otherwise.

Which was also hacked in pwn2own but that's not a big story for some reason https://www.bleepingcomputer.com/news/security/microsofts-wi...
Post reply on HN