Live data from Hacker News

Zoom zero-day discovery

blog.malwarebytes.com

161–170 of 246 posts

Re: Zoom zero-day discovery

#161

Can we please edit the headline. This sounds disingenuous, a more appropriate headline would be something like "critical vulnerability in Zoom Video Calls that would have put millions of users at risk has been found". This feels like a straight up PR piece.

Right, isn't this not a Zero Day specifically because it's not known to be exploited out in the wild. How can it be, no one else knows what the vuln is. It is being reported as part of a bug bounty with 90 day disclosure just like anything else would be.

I always get confused reading/talking about the definition of a zero-day with people... But this is what Wikipedia states, which is most consistent with my understanding.

> A zero-day (also known as 0-day) is a computer-software vulnerability unknown to those who should be interested in its mitigation (including the vendor of the target software). Until the vulnerability is mitigated, hackers can exploit it to adversely affect programs, data, additional computers or a network.

Seems like someone knows how to exploit this, and zoom / the general public don't know how to mitigate or perform it. That seems to fit this definition, no?

Re: Zoom zero-day discovery

#162

Earlier quoted context omitted.

We run zoom calls with over 200 participants and no problems. It sounds like their browser experience is poor, I don’t know if that’s a browser limitation or bad design, but their app on Windows and Mac performs quite well. Mistakes were made with security early in their product. It’s clear that has turned a lot of potential users against them. I’m curious why companies like Facebook get more acceptance over terrible…

>Mac performs quite well. This is not my experience at all. Early in the lockdown when Zoom became the darling, I was forced to install their app. Pre-pandemic, Zoom was already panned on this site for crap they were doing, so I pushed back hard against using Zoom before ultimately relenting. Running zoom with a simple 3 person call would bog down my 2017 MBP with fans running full tilt. I've since upgraded hardware…

In my case, Zoom will cause my Mac to heat up quite a lot on each call, using the app.

Re: Zoom zero-day discovery

#163

Earlier quoted context omitted.

Wait, are you saying Zoom isn't hated? It's crap. I refuse to install its PoS app and all of the security holes it came with (don't care if they are fixed or not). Launching a zoom meeting in my browser totally bogs the browser down. The zoom site is so slow that proving I'm a human is at least 10x slower than on other sites. In my use case, nobody on the zoom call is even using video, yet it still runs this badly.

Zoom has a history of nasty security issues, does shady business with China and bought and killed Keybase. It's a shitty company not even considering their software.

Which goes to tell you how good their software is. It is better than anything other companies have to offer for video conference calls with many participants and screen sharing, which is why our university is using it after we had evaluated all competitors last year in April.

Re: Zoom zero-day discovery

#164
post #131
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

Using Zoom on Linux is a fun way to get everything to crash; and may as well flip a coin to see if I'll get connected / anyone will be able to hear me. Google Meet, Slack calls, literally everything else works perfectly. With screenshare. On Wayland. I just call in to Zooms now.

My wife has been doing a ton of Zoom on an Ubuntu system on a Dell laptop, using their native app. She hasn't had problems.

Clearly your experience differs, not sure why.

Of the proprietary video meeting apps, they all have problems, but Zoom sucks less than Teams, Webex, or Skype and is a lot easier for non-technical folks to use.

Re: Zoom zero-day discovery

#165

Earlier quoted context omitted.

We run zoom calls with over 200 participants and no problems. It sounds like their browser experience is poor, I don’t know if that’s a browser limitation or bad design, but their app on Windows and Mac performs quite well. Mistakes were made with security early in their product. It’s clear that has turned a lot of potential users against them. I’m curious why companies like Facebook get more acceptance over terrible…

I also like zoom over the alternatives. Does it have problems, yes but what software doesn’t. I have been using zoom for years (my school switched early) compared to previous tools it just worked and worked well. Yes I know they lied and deceived but again marketing is always full of BS and guess who makes the blurbs we read on the internet about a company. Again the constantly changing UI is annoying but what is bet…

There's a difference between software having problems, and the problems that zoom had/has. The fiasco of creating a method to run any command with escalated sudo privelages just because they wanted to make the install easier that remains after install was absolutely mind blowing. Those kinds of things are unforgivable.

Re: Zoom zero-day discovery

#166

Earlier quoted context omitted.

We run zoom calls with over 200 participants and no problems. It sounds like their browser experience is poor, I don’t know if that’s a browser limitation or bad design, but their app on Windows and Mac performs quite well. Mistakes were made with security early in their product. It’s clear that has turned a lot of potential users against them. I’m curious why companies like Facebook get more acceptance over terrible…

>Mac performs quite well. This is not my experience at all. Early in the lockdown when Zoom became the darling, I was forced to install their app. Pre-pandemic, Zoom was already panned on this site for crap they were doing, so I pushed back hard against using Zoom before ultimately relenting. Running zoom with a simple 3 person call would bog down my 2017 MBP with fans running full tilt. I've since upgraded hardware…

Hard agree. Mac resource use of Zoom is insane. The only machine I've used that feels not bogged way down and blowing it's fans like crazy is my M1 mac and even then it's showing > 50% cpu use. When demoing our app in a screen share on my old iMac 4K the machine would be screaming it's fans and much much slower than normal. Meanwhile Messages screen sharing used less than 10% CPU. IDK what they are doing but it's not right at all.

Re: Zoom zero-day discovery

#167
post #106
post #75

Earlier quoted context omitted.

I don't think that's fair. The Pwn2Own contest rules specifically disallow disclosure. This isn't a "zero day" in any sense but marketing. It's a privately disclosed vulnerability under a managed embargo, just as if it had been reported by Project Zero or whoever. The ding is that, because it was a "public contest", the existence of the vulnerability is known. And that's probably a higher risk scenario in the abstrac…

This. The article should have been less about 0days and more about supporting contests and programs that vulnerability researchers.

It’s actually worded in quite that way (even though it’ll be picked up by larger media differently).

Re: Zoom zero-day discovery

#168
post #133

Earlier quoted context omitted.

We run zoom calls with over 200 participants and no problems. It sounds like their browser experience is poor, I don’t know if that’s a browser limitation or bad design, but their app on Windows and Mac performs quite well. Mistakes were made with security early in their product. It’s clear that has turned a lot of potential users against them. I’m curious why companies like Facebook get more acceptance over terrible…

Also the UI sucks. It doesn't blend nicely with my system. It looks like a sore thumb Windows 3.0 app or quack-age MacOS app in the midst of a futuristic OS.

Yes! Like there's a required two clicks to leave a call, you can't trust if it will start video on or off, the menu bar hides by default! The UX is horrible.

Re: Zoom zero-day discovery

#169
post #30
post #25

Earlier quoted context omitted.

I'm still upset they try to force you to use their plugin. These would be less scary if it were jst a web app.

You can force it to use a web app by declining permission to run locally. The web-app has fewer capabilities (no gallery view, last I used it), but works great. Also, Meet is fully-featured and runs entirely in-browser.

On macOS my experience with Zoom in the browser is that the gallery mode works in Chrome, however in Chrome it has problems with the camera (it reports that the camera is in use, or will hog the cpu and work at about 1 frame per second). On Firefox the camera works fine, but there is no gallery mode. On Safari the gallery mode and camera both work, but audio does not work! So I need to choose whether to do without video, audio, or gallery mode, or I can connect to the meeting twice with two different browsers.

Re: Zoom zero-day discovery

#170

Can we please edit the headline. This sounds disingenuous, a more appropriate headline would be something like "critical vulnerability in Zoom Video Calls that would have put millions of users at risk has been found". This feels like a straight up PR piece.

Agree, but instead of "that would have put" it should be "that could be putting", we don't know if there are people currently exploiting the vulnerability and without a patch very well could be happening now.
Post reply on HN