Live data from Hacker News

Linux Zoom client proactively reading everything written to X11 clipboard

hachyderm.io

71–80 of 175 posts

Re: Linux Zoom client proactively reading everything written to X11 clipboard

#72
post #70

Earlier quoted context omitted.

Apple did block the app so the 'working with Apple' didn't exactly earn Zoom a lot of trust with them otherwise they wouldn't have done it. They'd have let Zoom fix it in an update. And just make that update mandatory. They were just looking out for their own customers in limiting the impact, but for them to pull this handbrake means they really saw this as a big risk. 'But Cisco did it too!' is just whataboutism. It…

> 'But Cisco did it too!' is just whataboutism. A whataboutism that makes a legitimate point. It isn't reasonable to dismiss something just because a person makes a comparison. It's valid to consider that Apple might have been applying inconsistent standards and unfairly targeting Zoom for some reason. I doubt they were being unfair but it is a bad practice to dismiss an argument because someone has the temerity to e…

Cisco's one wasn't shown to be exploited though. Even after the news about the zoom one. They must have done something different.

But my point is that this should never have made it into an enterprise level product, even if someone else did it.

Re: Linux Zoom client proactively reading everything written to X11 clipboard

#73
post #53
post #45

Earlier quoted context omitted.

Or just use Google Meet on all browsers , which is more practical to use than Zoom. Zero software to install.

Zoom also works on all browsers. Clearly you had a hot take, people corrected you, and now you're doubling down by suggesting, of all things, a Google product.

To be fair, you have to wrangle it into submission by having the app launch fail.

Re: Linux Zoom client proactively reading everything written to X11 clipboard

#74

Earlier quoted context omitted.

I worked at Zoom during this time. That's not what happened. Zoom used the same technique Cisco Webex did - they ran a webserver with an open port so that local "links" to a meeting could open on your own machine. It wasn't a backdoor. Apple flagged that as a potential security risk, so Zoom worked with Apple on how to safely remove only the webserver without affecting other functionality. We were happy that Apple wo…

Apple did block the app so the 'working with Apple' didn't exactly earn Zoom a lot of trust with them otherwise they wouldn't have done it. They'd have let Zoom fix it in an update. And just make that update mandatory. They were just looking out for their own customers in limiting the impact, but for them to pull this handbrake means they really saw this as a big risk. 'But Cisco did it too!' is just whataboutism. It…

> Ps I'm sorry if I sound harsh Actually, thanks, that did go a long way.

It's not whataboutism, I'm not trying to distract from the point, I'm saying there was _prior art_ in the industry where customers appeared to tolerate this.

There was another PM on the team who felt the same way I did and we basically both wagged our fingers and said "you should have asked people during install", but who cares, it was too late.

Zoom had, I will say, a very... Chinese culture around software security. If you're familiar, Chinese software is often much more interested in just getting the job done in a simple way, and security is... not the job? I've used a lot of Chinese software that just wants full admin everything so no one had to learn about permissions.

Zoom wasn't exactly run that way, but the pool they hired from had a lot of that mentality in it.

I thought Apple's tool was ridiculous though. It's like "oh, some trash blew into our yards from the neighbor's trashcan" so Apple replies "oh, don't worry, I destroyed it with my orbital ion cannon" and the tech community never stops to wonder if maybe it's a little strange that Apple has an orbital ion cannon and maybe we should ask some questions about the ion cannon.

Re: Linux Zoom client proactively reading everything written to X11 clipboard

#77
post #6

Not the first time Zoom abuses privilege. A few years back, there was something about gaining root on MacOS via Zoom due to shady execution on their end. They've lost my trust since then, and I'll only run it sandboxed: https://gist.github.com/cielavenir/02f322e322a2a3555dbf2b38f... I always ask (1) why does an app require installation and (2) why would it require root? There are valid answers for both, but realistic…

Out of interest why do you still use the app and not just use it in the browser? I feel much more secure having it in the browser sandbox and everything I care about works in the browser.

I notice the browser version is a little resource intensive. I use it on freebsd and I need to renice the browser to -10 for it to be somewhat stable. (This is an improvement because I remember 6 years ago it didn't work on freebsd.) I ran it on a Mac last week and it spun the fan more than I'd expect.

Re: Linux Zoom client proactively reading everything written to X11 clipboard

#78

Earlier quoted context omitted.

Apple did block the app so the 'working with Apple' didn't exactly earn Zoom a lot of trust with them otherwise they wouldn't have done it. They'd have let Zoom fix it in an update. And just make that update mandatory. They were just looking out for their own customers in limiting the impact, but for them to pull this handbrake means they really saw this as a big risk. 'But Cisco did it too!' is just whataboutism. It…

> Ps I'm sorry if I sound harsh Actually, thanks, that did go a long way. It's not whataboutism, I'm not trying to distract from the point, I'm saying there was _prior art_ in the industry where customers appeared to tolerate this. There was another PM on the team who felt the same way I did and we basically both wagged our fingers and said "you should have asked people during install", but who cares, it was too late…

Asked people what during install? From my perspective this should have never been designed this way. I understand if you're a PM, but those engineers should've known better, Chinese or not.

As for the ion cannon (signed and notarized apps) people do talk about this and question it. Apple's infamous walled garden. Europe is trying to fix this with the Digital Markets Act (DMA) and the USA is trying to fix this with the right to repair.

But you have to admit, in this instance with Zoom, it was used for a just purpose. Apple protected end-users against bad code from Zoom, which from your post, seemed complacent.

Re: Linux Zoom client proactively reading everything written to X11 clipboard

#79

Earlier quoted context omitted.

Out of interest why do you still use the app and not just use it in the browser? I feel much more secure having it in the browser sandbox and everything I care about works in the browser.

I notice the browser version is a little resource intensive. I use it on freebsd and I need to renice the browser to -10 for it to be somewhat stable. (This is an improvement because I remember 6 years ago it didn't work on freebsd.) I ran it on a Mac last week and it spun the fan more than I'd expect.

Close it when you’re done with the meeting.

Re: Linux Zoom client proactively reading everything written to X11 clipboard

#80

Earlier quoted context omitted.

Out of interest why do you still use the app and not just use it in the browser? I feel much more secure having it in the browser sandbox and everything I care about works in the browser.

Not parent, but the web player used to be a down-graded experience from the native app. If you need Zoom for a professional setting, those functions could be important. Do not know if this is still true, but at one point, the web player would only let you see one speaker at a time, while the app would show multiple people at once.

So the web is a better experience!
Post reply on HN