Live data from Hacker News

Zoom zero-day discovery

blog.malwarebytes.com

211–220 of 246 posts

Re: Zoom zero-day discovery

#212

Can we please edit the headline. This sounds disingenuous, a more appropriate headline would be something like "critical vulnerability in Zoom Video Calls that would have put millions of users at risk has been found". This feels like a straight up PR piece.

I really wish there was a changelog for headlines. Too often I see a critique like this and I have to figure out if the comment is referring to the current headline or a previous version. And, if the headline has already unknowingly been 'corrected', it leaves me wasting time trying to figure it out within that framing. And it shouldn't be the responsibility of the poster necessarily to quote it -- because there's no…

Like https://hackernewstitles.netlify.app/ ?

Re: Zoom zero-day discovery

#213

I use the zoom web client, when I have to use zoom. It has fewer features, but I'm more comfortable running badly written software in an environment designed for hostile code. Just change the /j/ in the url to /wc/, and insert /join after the meeting id. https://devforum.zoom.us/t/launch-zoom-client-from-browser-w...

The zoom web client has extremely buggy audio support. It regularly breaks in all of the browsers on my computer, and I end up listening to meetings only able to contribute via the text chat.

Audio was stuttering for me as well up until at some point late last autumn / early winter when it suddenly started working quite fine to the point I could actually bear using it. On MacOS with Chrome.

Re: Zoom zero-day discovery

#214

I use the zoom web client, when I have to use zoom. It has fewer features, but I'm more comfortable running badly written software in an environment designed for hostile code. Just change the /j/ in the url to /wc/, and insert /join after the meeting id. https://devforum.zoom.us/t/launch-zoom-client-from-browser-w...

You can also click "cancel" when the browser prompts you to open in zoom, then it will show a link to join from the browser.

Re: Zoom zero-day discovery

#215
post #149

Zoom is entirely banned at the two companies that are my day job, and probably 90% of partners. If you do any work adjacent to anything that's ITAR controlled you should also not be surprised to see the same policy from partner companies. This has been in place for quite some time since the initial security problem that was so egregiously bad apple had to resort to using the malware removal tool to remove zoom's bina…

As if other vendors are certainly more secure. Those bans seem more based on media exposure than known technical facts and evaluations.

I wouldn't be surprised if Google Meet is much more secure than Zoom.

Re: Zoom zero-day discovery

#216

Earlier quoted context omitted.

Having critical zero days being reported is always a good thing.

But I thought we call them "zero day" when they are already being abused. I didn't get from the article that this vulnerability has been discovered and abused by the baddies. Thus it is NOT a "zero day" but a "critical vulnerability". Sod the clickbait-y titles!

It doesn't need to be exploited to be a zero-day, just not yet mitigated.

Re: Zoom zero-day discovery

#217

Earlier quoted context omitted.

Oh, really?! But then, why does it suck so much at "window management" (especially the "chat" feature) ??

I don't think Qt has ever pretended to look native. I remember using KDE back in the early 2000s and most Qt apps that didn't explicitly integrate with KDE didn't look "native" either. The other desktop OSes are not even internally consistent -- look at Windows's "settings" vs. "control panel". Which one is native? The answer is they both are, sort of, but there are simply two UI kits bundled with the OS. One is depr…

For me this was never about the look, but about the features. Zoom chat isn't even able to do scrolling properly !!

Re: Zoom zero-day discovery

#218

Earlier quoted context omitted.

I think we're a bit naive in the west and most often assume good faith from certain other business cultures. We're not used to companies that engage in calculated perfidy that have their sorry prepared long before you've discovered the problem. To put another way, "It's better to ask for forgiveness than to ask for permission", or to beat around the bush even more: I disagree with Hanlon's razor.

So people contributing to western business culture don't act exactly like Mark Zuckerberg? There's a lot of this stuff in "the west" too.

Reckless and negligence aren't the same as deliberate deceit. Though agreed there is plenty of deceit around the world.

Re: Zoom zero-day discovery

#219

See also ZDNet article about this: Critical Zoom vulnerability triggers remote code execution without user input https://www.zdnet.com/article/critical-zoom-vulnerability-tr...

Thanks for that link!

"The attack must also originate from an accepted external contact or be a part of the target's same organizational account," Zoom added.

"As a best practice, Zoom recommends that all users only accept contact requests from individuals they know and trust."

Re: Zoom zero-day discovery

#220

I use the zoom web client, when I have to use zoom. It has fewer features, but I'm more comfortable running badly written software in an environment designed for hostile code. Just change the /j/ in the url to /wc/, and insert /join after the meeting id. https://devforum.zoom.us/t/launch-zoom-client-from-browser-w...

The zoom web client has extremely buggy audio support. It regularly breaks in all of the browsers on my computer, and I end up listening to meetings only able to contribute via the text chat.

strange. I exclusively use the web client with chromium and ubuntu and have no issues whatsoever. I use it for probably 20 meetings per week.
Post reply on HN