Live data from Hacker News

Zoom zero-day discovery

blog.malwarebytes.com

181–190 of 246 posts

Re: Zoom zero-day discovery

#181

Earlier quoted context omitted.

My biggest gripe about Teams is what a memory hog it is. Mine is currently sitting idle (been on vacation all week) at nearly 1GB. Compare this to Zoom, which is idling at just over 100MB. Teams is literally taking up 10 times more RAM than Zoom just running in the background.

In Microsoft’s defense Teams is an electron (or electronesque) app and offers quite a bit more than Zoom in terms of features. The fact that it uses so much RAM is expected when you consider it as another copy of chrome.

[deleted]

Re: Zoom zero-day discovery

#182

Can we please edit the headline. This sounds disingenuous, a more appropriate headline would be something like "critical vulnerability in Zoom Video Calls that would have put millions of users at risk has been found". This feels like a straight up PR piece.

I really wish there was a changelog for headlines. Too often I see a critique like this and I have to figure out if the comment is referring to the current headline or a previous version. And, if the headline has already unknowingly been 'corrected', it leaves me wasting time trying to figure it out within that framing. And it shouldn't be the responsibility of the poster necessarily to quote it -- because there's no…

The original title was the article title:

Zoom zero-day discovery makes calls safer, hackers $200,000 richer

Re: Zoom zero-day discovery

#183

Earlier quoted context omitted.

this was the case here too, but just yesterday got on a usaf hosted zoom that said 'gov' and hosted in CONUS so they seem to have some offering at least DoD is ok with now, appears to only be fedramp https://www.zoomgov.com/

Note that the DoD Authorization only covers Zoom for public , not even FOUO, data. For sensitive data, only Cisco and Microsoft are allowed.

yes of course, good point to emphasize it's probably never going to even reach CUI approval lol

Re: Zoom zero-day discovery

#184
post #63

Can we please edit the headline. This sounds disingenuous, a more appropriate headline would be something like "critical vulnerability in Zoom Video Calls that would have put millions of users at risk has been found". This feels like a straight up PR piece.

Seconded! Only a PR person would dream of saying that a 0 day exploit is a good thing. I expect that most HN readers just finds this hillarious, but still people read HN since it has a good standard. Saying that a 0 day exploit is a good thing goes against this needless to say. Especially since they've faced serious accusations earlier on.

Having critical zero days being reported is always a good thing.

Re: Zoom zero-day discovery

#185

Can we please edit the headline. This sounds disingenuous, a more appropriate headline would be something like "critical vulnerability in Zoom Video Calls that would have put millions of users at risk has been found". This feels like a straight up PR piece.

Right, isn't this not a Zero Day specifically because it's not known to be exploited out in the wild. How can it be, no one else knows what the vuln is. It is being reported as part of a bug bounty with 90 day disclosure just like anything else would be.

A zero day just means that the vulnerability hasn't been patched.

Re: Zoom zero-day discovery

#186
I use the zoom web client, when I have to use zoom. It has fewer features, but I'm more comfortable running badly written software in an environment designed for hostile code.

Just change the /j/ in the url to /wc/, and insert /join after the meeting id.

https://devforum.zoom.us/t/launch-zoom-client-from-browser-w...

Re: Zoom zero-day discovery

#187

Can we please edit the headline. This sounds disingenuous, a more appropriate headline would be something like "critical vulnerability in Zoom Video Calls that would have put millions of users at risk has been found". This feels like a straight up PR piece.

I really wish there was a changelog for headlines. Too often I see a critique like this and I have to figure out if the comment is referring to the current headline or a previous version. And, if the headline has already unknowingly been 'corrected', it leaves me wasting time trying to figure it out within that framing. And it shouldn't be the responsibility of the poster necessarily to quote it -- because there's no…

Exactly. It would be nice if there was a little arrow (or other icon) next to the title of an article that simply showed the previous titles that article used -- much like previous gaming handles on Steam profiles; Simple yet effective.

Re: Zoom zero-day discovery

#188

I use the zoom web client, when I have to use zoom. It has fewer features, but I'm more comfortable running badly written software in an environment designed for hostile code. Just change the /j/ in the url to /wc/, and insert /join after the meeting id. https://devforum.zoom.us/t/launch-zoom-client-from-browser-w...

handy, thanks

Re: Zoom zero-day discovery

#189

Earlier quoted context omitted.

My biggest gripe about Teams is what a memory hog it is. Mine is currently sitting idle (been on vacation all week) at nearly 1GB. Compare this to Zoom, which is idling at just over 100MB. Teams is literally taking up 10 times more RAM than Zoom just running in the background.

I have never used Teams but is 1GB of memory usage really an issue in 2021, when most laptops have at least 16-32 gigs of memory? It's been years since the last time I actually worried about how much memory some software on my laptop was using.

Most laptops do not have 16-32gb of ram, even in the high-end range.

Re: Zoom zero-day discovery

#190
post #63

Earlier quoted context omitted.

Seconded! Only a PR person would dream of saying that a 0 day exploit is a good thing. I expect that most HN readers just finds this hillarious, but still people read HN since it has a good standard. Saying that a 0 day exploit is a good thing goes against this needless to say. Especially since they've faced serious accusations earlier on.

Having critical zero days being reported is always a good thing.

But I thought we call them "zero day" when they are already being abused. I didn't get from the article that this vulnerability has been discovered and abused by the baddies.

Thus it is NOT a "zero day" but a "critical vulnerability".

Sod the clickbait-y titles!

Post reply on HN