Live data from Hacker News

Microsoft Teams: 1 feature, 4 vulnerabilities

positive.security

161–170 of 264 posts

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#161

Earlier quoted context omitted.

I don't know about the number of participants, luckily I've never been in a mammoth call. As for the background blur, it may be related to a missing feature in Electron. I seem to remember that another conferencing app (might have been zoom, not sure) didn't support this while running on Chrome/Linux, so I figure it's related. To me, the main missing feature on Linux is the "native notifications" feature (as opposed…

There's a lot of missing features like those mentioned above, is the reply option with a quote already working in Linux? Been using MacOS since the MBP14" came out and haven't booted by PopOS desktop since I'm not at home

> is the reply option with a quote already working in Linux?

Yes, and it has for a while. I don't use it that often, though, so I can't comment since when it works.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#162
post #151

Teams has a bunch of anti-features that I have to click off, including this one. The micro update also tend to break something. For example a November patch broke list in chat, a futher one broke list in general. I have to enter the edit mode every time I want to enter a list. I think the ability to use ''' to enter code snippets was also broken a while ago, and in another patch the indentation of such code block was…

Ah and I thought it was my fault that lists stopped working all of a sudden.

No it wasn't haha. I really wish Teams is not force updated bit I guess it's not a choice.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#163

Earlier quoted context omitted.

I don't know about the number of participants, luckily I've never been in a mammoth call. As for the background blur, it may be related to a missing feature in Electron. I seem to remember that another conferencing app (might have been zoom, not sure) didn't support this while running on Chrome/Linux, so I figure it's related. To me, the main missing feature on Linux is the "native notifications" feature (as opposed…

As a long time Linux user and one that has suffered through multiple versions of teams/slack/zoom/Google Meet I was pleasantly surprised with Google Meet (in chromium) for video calls. It worked flawlessly, adapted really well to a super wide monitor (actually used the space well), and had the background blurring/replacement features that get stripped from most linux clients, the only downside was that it didn't like…

This is interesting. I've actually had a very jarring experience with Google meet. My webcam image, for some reason, would be squished, like it attempted to constrain it to 4:3 when it's 16:9. But the end image wasn't 4:3, there would be vertical bands on the sides. However, while waiting in the lobby for a meeting, the preview worked fine. This happened on both Firefox and Chrome (actual Chrome, not Chromium), and with multiple people.

The exact same setup worked perfectly in Teams, Zoom and OBS.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#164

Reading through these vulnerabilities, it feels like a handful of these are low priority or non-issues. This might be a controversial opinion, but it’s not clear to me why these issues ought to be prioritized and fixed expediently. For example, it’s not clear to me why an IP address leak is considered problematic. And breaking chat or crashing on reload seems more akin to a bug a la iMessage link bugs like https://ww…

I did not seen micropenis nor Gates jokes on HN.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#165
post #17

In 2020 a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft led to a company-wide prohibition on using anything other than Teams "for security reasons" where i worked. This was, I am almost certain, inspired by Microsoft corporate sales getting their hooks into management. This was largely because of news stories like "end to end encryption doesnt really work as advertised" and "if you leav…

> In 2020 a rash of anti-zoom propaganda

The security issues like end-to-end encryption not actually being end-to-end encryption (unless you consider the man in the middle to be two ends, forwarding messages between the other two ends) were not propaganda - they really existed. It isn't even propaganda to say Zoom published very questionable statements (or if I allow myself to be slightly less charitable: the occasional outright lie) about those issues, because it is demonstrably true that this happened.

> that I'm almost certain was driven by Microsoft

You might need to present some evidence for that rather bold claim.

> [comparison with past MS security issues]

Teams is far from perfect, I am not a fan of it at all, and that security issue was real too IIRC, but you are using some very selective reasoning bringing it up at the same time as downplaying the serious flaws present in Zoom in the same period.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#166

I have a hard time understanding why MS is investing so much into VS Code yet so little progress is made on MS Teams (which in theory should be more important to them as it has broader usage?).

MS Teams is adopted as part of office. It does not have to be good.

It has to look good at first sight and has to have features higher management needs. But, it is is complete crap for rest of us, it does not matter.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#167
post #17

In 2020 a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft led to a company-wide prohibition on using anything other than Teams "for security reasons" where i worked. This was, I am almost certain, inspired by Microsoft corporate sales getting their hooks into management. This was largely because of news stories like "end to end encryption doesnt really work as advertised" and "if you leav…

> In 2020 a rash of anti-zoom propaganda The security issues like end-to-end encryption not actually being end-to-end encryption (unless you consider the man in the middle to be two ends, forwarding messages between the other two ends) were not propaganda - they really existed. It isn't even propaganda to say Zoom published very questionable statements (or if I allow myself to be slightly less charitable: the occasio…

Zoom’s statements were in fact found by a jury to be false and misleading. If you used Zoom prior to last summer you are entitled to a (small) cash settlement https://www.zoommeetingsclassaction.com/

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#168

Earlier quoted context omitted.

Um, just think of what you're suggesting. At MS some department (marketing, sales, product managers, devs?) somehow coordinated a bunch of press leaks (not sure how these were even determined to be 'leaks'), made sure that media outlets collectively believed that they were problematic, and then used those leaks to influence sales? It's a stretch to attribute to malice what can be attributable to other environmental f…

> At MS some department (marketing, sales, product managers, devs?) somehow coordinated a bunch of press leaks (not sure how these were even determined to be 'leaks'), made sure that media outlets collectively believed that they were problematic, and then used those leaks to influence sales? You’re literally describing a thing that exists which is called public relations. I’ll admit it is unlikely for the call to be…

So we’re suggesting a 3rd-party PR firm likely coordinated public criticism about Zoom, an app that was undergoing hyper growth and entered the public consciousness in 2020 due to WFH and COVID. We don’t think media outlets would likely have wanted to voraciously cover Zoom stories because Zoom became one of the most widely used apps out of nowhere?

The logic appears to be: I saw a lot of news stories about X, therefore X was caused by Y, without recognizing that Z is just as likely a cause for X.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#169
post #164

Reading through these vulnerabilities, it feels like a handful of these are low priority or non-issues. This might be a controversial opinion, but it’s not clear to me why these issues ought to be prioritized and fixed expediently. For example, it’s not clear to me why an IP address leak is considered problematic. And breaking chat or crashing on reload seems more akin to a bug a la iMessage link bugs like https://ww…

I did not seen micropenis nor Gates jokes on HN.

Comments were deleted.

Re: Microsoft Teams: 1 feature, 4 vulnerabilities

#170
post #17

In 2020 a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft led to a company-wide prohibition on using anything other than Teams "for security reasons" where i worked. This was, I am almost certain, inspired by Microsoft corporate sales getting their hooks into management. This was largely because of news stories like "end to end encryption doesnt really work as advertised" and "if you leav…

> In 2020 a rash of anti-zoom propaganda that I'm almost certain was driven by Microsoft led to a company-wide prohibition on using anything other than Teams "for security reasons" where i worked.

It was not propaganda. There was no privacy protection. I work for a K-12 and there was literally no way to configure Zoom such that it wasn't a massive FERPA violation waiting to happen. There was originally no way to gatekeep entrants to a virtual Zoom classroom. It even earned it's own term: Zoombombing [0]. It was completely unsuitable for use. It's like it was designed for the Internet of the 1990s.

The only way we figure that so many districts were using it was:

1. It was free when basically nothing else was.

2. There was no time to evaluate alternatives when the pandemic started.

3. They were hoping nobody was looking too closely.

4. They didn't properly evaluate Zoom or they just didn't tell anyone how Zoom didn't ensure privacy.

[0]: https://en.wikipedia.org/wiki/Zoombombing

Post reply on HN