Live data from Hacker News

Linux Zoom client proactively reading everything written to X11 clipboard

hachyderm.io

81–90 of 175 posts

Re: Linux Zoom client proactively reading everything written to X11 clipboard

#81
I remember a friend installing Zoom on a Linux computer through their software manager. Later, they removed it and found that when they visited the page in the software manager for Zoom, it automatically tried to install Zoom without interaction from them (ie, my friend did not click Install, but viewed the page and a password prompt for installing the package appeared).

I'm not sure if this was behaviour that happened with the software manager on other packages, but was a concern for us.

Re: Linux Zoom client proactively reading everything written to X11 clipboard

#82
post #38

Reason 1492835 to use Qubes OS. Also reason 35892384242892 to not use proprietary software, especially proprietary software with network access.

I mean I agree with you, but the real world just wants to get work done.

Outsource trust more carefully.

Re: Linux Zoom client proactively reading everything written to X11 clipboard

#83
post #59

Earlier quoted context omitted.

Jitsi is an excellent free and open source alternative.

And that is useless if you have meetings with people that "have standardized" on Zoom, and that hold some sort of leverage over you, like clients/customers.

Can’t see enjoying my time on this Earth putting up with that sort of burnout.

Re: Linux Zoom client proactively reading everything written to X11 clipboard

#84

Earlier quoted context omitted.

Srsly, all those neck beards who over simplify the problem with a flippant "don't use zoom", as if everyone has the luxury to skip every job interview and employer meeting that absolutely requires Zoom. I wish I could live in their world where every problem is solved by simply avoiding that problem.

Zoom isn't just a technical problem. It's literally malware. The list of issues they've knowingly caused and sometimes even refused to fix is endless. They have made it clear they absolutely don't care about security in any way and they've built their entire business around that. As I work in cyber security there's no way I'll install that shit on my personal PC. Yes I could spin up a VM but I don't want to. I could…

> I'd refuse and that company's reply should inform me whether I'd want to work there in the first place

This.

Develop sufficient leverage to be able to show basic respect the right way to do things - and yourself.

Re: Linux Zoom client proactively reading everything written to X11 clipboard

#87

Earlier quoted context omitted.

Srsly, all those neck beards who over simplify the problem with a flippant "don't use zoom", as if everyone has the luxury to skip every job interview and employer meeting that absolutely requires Zoom. I wish I could live in their world where every problem is solved by simply avoiding that problem.

Use a dedicated, otherwise empty account for job interviews. Linux is multi-process, _multi-user_ since forever. No need to leave a password manager, online banking, andwhatnot accessible in the background during an interview. And yeah: stop. using. X11. For God's sake!

> And yeah: stop. using. X11. For God's sake!

Why should I stop using software that is superior to the alternatives?

Re: Linux Zoom client proactively reading everything written to X11 clipboard

#88
University of California has licensed zoom accounts with privacy agreements. I install it in Linux. Now I will check if I can replicate this behavior. I am not sure if it is a violation of their agreement or not if they do, but I don't like it.

Re: Linux Zoom client proactively reading everything written to X11 clipboard

#89

Earlier quoted context omitted.

Apple did block the app so the 'working with Apple' didn't exactly earn Zoom a lot of trust with them otherwise they wouldn't have done it. They'd have let Zoom fix it in an update. And just make that update mandatory. They were just looking out for their own customers in limiting the impact, but for them to pull this handbrake means they really saw this as a big risk. 'But Cisco did it too!' is just whataboutism. It…

> Ps I'm sorry if I sound harsh Actually, thanks, that did go a long way. It's not whataboutism, I'm not trying to distract from the point, I'm saying there was _prior art_ in the industry where customers appeared to tolerate this. There was another PM on the team who felt the same way I did and we basically both wagged our fingers and said "you should have asked people during install", but who cares, it was too late…

As an apple user, I am glad that Apple has an orbital ion cannon that blows up lazy and/or malicious things that could affect me.

Re: Linux Zoom client proactively reading everything written to X11 clipboard

#90
post #59

Earlier quoted context omitted.

Jitsi is an excellent free and open source alternative.

And that is useless if you have meetings with people that "have standardized" on Zoom, and that hold some sort of leverage over you, like clients/customers.

I'm pleasantly surprised at how often someone will use jitsi when the alternative is not communicating with me in such a fashion.
Post reply on HN