Live data from Hacker News

Zoom zero-day discovery

blog.malwarebytes.com

171–180 of 246 posts

Re: Zoom zero-day discovery

#171

Earlier quoted context omitted.

We run zoom calls with over 200 participants and no problems. It sounds like their browser experience is poor, I don’t know if that’s a browser limitation or bad design, but their app on Windows and Mac performs quite well. Mistakes were made with security early in their product. It’s clear that has turned a lot of potential users against them. I’m curious why companies like Facebook get more acceptance over terrible…

>Mac performs quite well. This is not my experience at all. Early in the lockdown when Zoom became the darling, I was forced to install their app. Pre-pandemic, Zoom was already panned on this site for crap they were doing, so I pushed back hard against using Zoom before ultimately relenting. Running zoom with a simple 3 person call would bog down my 2017 MBP with fans running full tilt. I've since upgraded hardware…

I've been involved with zoom sessions of up to 50 connections and it has exceptionally flawless on my work macOS laptop from approx 2017. Compared to every other video conference software I've tried, zoom is unfortunately by far the best on macos, Windows and even Linux for video conferencing with large number of participants. I am baffled as to why it performs so poorly—this is not my observation on the machine I have and I also know it works well with on many of my colleagues Macs so it is not just the one Mac I use.

Re: Zoom zero-day discovery

#172

Zoom is entirely banned at the two companies that are my day job, and probably 90% of partners. If you do any work adjacent to anything that's ITAR controlled you should also not be surprised to see the same policy from partner companies. This has been in place for quite some time since the initial security problem that was so egregiously bad apple had to resort to using the malware removal tool to remove zoom's bina…

I use the zoom web client, never the desktop app. I prefer everything to be via the browser since it provides good sandboxing. Up until we have good sandboxing mechanisms via OS's - it will be the browser for me.

Re: Zoom zero-day discovery

#174
post #108
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

> Imagine if that was your run of the mill well-hated big corp I don't know what the general perception of Zoom is. Our opinions of it never really come up at work. The discussion I see of it online largely focuses upon the security issues so that is going to be negative. There is one thing I am grateful for though: it seems as though the masses settled on a product with decent cross-platform support for once . You r…

Indeed. It is really nice to be able to participate in group and conference calls from Linux without having to reboot into windows or macos. Also performs well in all the platforms I've used it in which is not something I can say for teams and Google meets.

Re: Zoom zero-day discovery

#175

Can we please edit the headline. This sounds disingenuous, a more appropriate headline would be something like "critical vulnerability in Zoom Video Calls that would have put millions of users at risk has been found". This feels like a straight up PR piece.

I really wish there was a changelog for headlines. Too often I see a critique like this and I have to figure out if the comment is referring to the current headline or a previous version. And, if the headline has already unknowingly been 'corrected', it leaves me wasting time trying to figure it out within that framing.

And it shouldn't be the responsibility of the poster necessarily to quote it -- because there's no verifiability there.

Re: Zoom zero-day discovery

#176
post #30
post #25

Earlier quoted context omitted.

I'm still upset they try to force you to use their plugin. These would be less scary if it were jst a web app.

You can force it to use a web app by declining permission to run locally. The web-app has fewer capabilities (no gallery view, last I used it), but works great. Also, Meet is fully-featured and runs entirely in-browser.

Meet performs quite poorly with large number of participants (the tipping point being around 10 or so for me) in a meeting. I tried various browsers and found Chrome to be the worst performer and surprisely Firefox was somewhat better but still needed a refresh every now and then. Macos on a 2017 MacBook. This is one of many reasons keeping my $employer on Zoom. We just haven't found a decent video conferencing software that manages 25+ videos flawlessly. I know of colleagues using Teams successfully but many people we meet with outside our organisation expects Zoom nowdays. I suspect any alternative will have to be very good to take over Zoom as the preferred platform. That has yet to appear.

Re: Zoom zero-day discovery

#177

Can we please edit the headline. This sounds disingenuous, a more appropriate headline would be something like "critical vulnerability in Zoom Video Calls that would have put millions of users at risk has been found". This feels like a straight up PR piece.

I really wish there was a changelog for headlines. Too often I see a critique like this and I have to figure out if the comment is referring to the current headline or a previous version. And, if the headline has already unknowingly been 'corrected', it leaves me wasting time trying to figure it out within that framing. And it shouldn't be the responsibility of the poster necessarily to quote it -- because there's no…

> And it shouldn't be the responsibility of the poster necessarily to quote it -- because there's no verifiability there.

Although there's no verifiability there, I would assume that most people on here comment in good faith.

Re: Zoom zero-day discovery

#178
post #42

Related, the two other $200k entries from Pwn2Own 2021:[1] - DEVCORE targeting Microsoft Exchange in the Server category (The DEVCORE team combined an authentication bypass and a local privilege escalation to complete take over the Exchange server.) - The researcher who goes by OV targeting Microsoft Teams in the Enterprise Communications category (OV combined a pair of bugs to demonstrate code execution on Microsoft…

I wonder if the OS world will move towards lightweight but unforgiving sandboxing like OpenBSD's `pledge` and `unveil` system calls. It's crazy to me that most software is still completely fine to run around and set things as fire the instant it's compromised! This is about the implementation in the SerenityOS but it's my favourite explanation so far: https://awesomekling.github.io/pledge-and-unveil-in-Serenity...

Just last week we were talking about a zero-click bug in Apple Mail (https://mikko-kenttala.medium.com/zero-click-vulnerability-i...) that didn't even need to bypass Apple's built-in sandboxing—simply overwriting Mail.app's config files was enough to trigger a devastating information disclosure.

Re: Zoom zero-day discovery

#179
post #164
post #131

Earlier quoted context omitted.

Using Zoom on Linux is a fun way to get everything to crash; and may as well flip a coin to see if I'll get connected / anyone will be able to hear me. Google Meet, Slack calls, literally everything else works perfectly. With screenshare. On Wayland. I just call in to Zooms now.

My wife has been doing a ton of Zoom on an Ubuntu system on a Dell laptop, using their native app. She hasn't had problems. Clearly your experience differs, not sure why. Of the proprietary video meeting apps, they all have problems, but Zoom sucks less than Teams, Webex, or Skype and is a lot easier for non-technical folks to use.

I'm in the same boat. I use Zoom frequently on Linux and it's performance is quite acceptable. I use Zoom successfully on other platforms as well. It compares well to altneratives such as Google Meets which in my experience starts to fall apart past a certain number of participants on a call. Quite interesting to see the variance of experiences as it doesn't match what I've observed personally as well as comments I've heard from colleagues who have tried various systems. I hear lots of praise for Zoom and Teams but Meets is either loved or hated.

Re: Zoom zero-day discovery

#180

Zoom is entirely banned at the two companies that are my day job, and probably 90% of partners. If you do any work adjacent to anything that's ITAR controlled you should also not be surprised to see the same policy from partner companies. This has been in place for quite some time since the initial security problem that was so egregiously bad apple had to resort to using the malware removal tool to remove zoom's bina…

For some reason my fortune pays for Teams but has all of their big meetings on zoom. Makes no fucking sense and I would rather not have to download their app.
Post reply on HN