Earlier quoted context omitted.
Never attribute to malice what is adequately explained by laziness. I can easily believe somebody just wrote a chunk of naive code that grabbed all the running processes, and it worked, and they moved on.
or it’s spyware, maybe not as bad as a keylogger, but it can be mining your active usage behavior
Ask HN: Why does Zoom Desktop examine all processes and arguments?
111–120 of 277 posts
Re: Ask HN: Why does Zoom Desktop examine all processes and arguments?
#112Earlier quoted context omitted.
"Doing something" seems like a really low bar when that "something" is basically useless for the intended use case.
Honestly, I kind of agree with this downvoted post. The MacOS permissions prompts are starting to drive me apeshit. Average user is going to start ignoring them and just click yes to everything anyways. Just like everybody already does on their phones. Reminds me of when Windows Vista came out and they started prompting for permissions like crazy. Everybody hated it. Maybe it was just ahead of its time. I already gra…
Re: Ask HN: Why does Zoom Desktop examine all processes and arguments?
#113Earlier quoted context omitted.
Be careful with this. In some orgs you can get a bit of a bad reputation for being technically incompetent if you can't get zoom to run. Zoom is very invasive / flexible - so it's actually somewhat hard to have it NOT work. People will suggest you try connecting on your phone or dialing in if you really can't figure it out (note that it has a fallback to browser option if you get stuck trying to start meeting as well…
You can avoid this reputation by saying “our security analysts block Zoom because they think it might be untrustworthy spyware.”
That said, a fair number of folks don't credibly have "security analysts". Unless you are interviewing / working for some sort of high security / security analyst type job the world may move on pretty quickly without you.
Re: Ask HN: Why does Zoom Desktop examine all processes and arguments?
#114Earlier quoted context omitted.
OS X already requires that the user open Settings and give the app elevated permissions to be able to share the screen. One can argue about the granularity, but you can’t argue that Apple hasn’t already done something.
"Doing something" seems like a really low bar when that "something" is basically useless for the intended use case.
The user chose to install an application, then had to use admin permissions to choose to give that application more access after installation.
How much additional nanny protection should a user get?
Re: Ask HN: Why does Zoom Desktop examine all processes and arguments?
#115Earlier quoted context omitted.
or it’s spyware, maybe not as bad as a keylogger, but it can be mining your active usage behavior
This could be verified by inspecting their analytics requests. If I have time I may take a peek at those later.
Re: Ask HN: Why does Zoom Desktop examine all processes and arguments?
#116Earlier quoted context omitted.
Elaborate please
‘Zoom is malware’: why experts worry about the video conferencing platform https://www.theguardian.com/technology/2020/apr/02/zoom-tech... Zoom banned from New York City schools due to privacy and security flaws https://www.fastcompany.com/90486586/zoom-banned-from-new-yo... Google Told Its Workers That They Can’t Use Zoom On Their Laptops Anymore https://www.buzzfeednews.com/article/pranavdixit/google-bans... Elon M…
Thank you. These will make for some interesting reading.
Re: Ask HN: Why does Zoom Desktop examine all processes and arguments?
#117Re: Ask HN: Why does Zoom Desktop examine all processes and arguments?
#118Earlier quoted context omitted.
> handy for sharing a PPT without fear of an embarrassing email showing up in during a meeting. When you share a single window in Zoom, notifications are still visible to others in the meeting when they overlap with the window you're sharing. That's the case for e.g. Slack notifications.
They are grayed out for everyone else, so they can’t actually read the contents. Caveat being if you move the window around really fast sometimes it’s possible to catch a glimpse.
Re: Ask HN: Why does Zoom Desktop examine all processes and arguments?
#119> Is there any way to prevent it? Hook the stat, openat, readlink functions within the zoom process, experiment with blocking (returning failure) based on arguments.
Re: Ask HN: Why does Zoom Desktop examine all processes and arguments?
#120Zoom has a paid feature to view processes of other meeting attendees. Yes. Scary.