Live data from Hacker News

How the Zoom macOS installer does its job without you clicking ‘install’

twitter.com

271–280 of 334 posts

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#271

Earlier quoted context omitted.

In my experience I’ve seen even technical users (Who were used to windows) struggle with the idea of dragging an .app from an open disk image to the Applications folder. They would end up running the app from the disk image and then getting confused when it disappears after restart.

This system worked so much better when the Applications folder was placed in the Dock by default, and everyone used that folder launch applications (which weren't common enough to keep in the Dock directly). It was actually a really beautiful synergy—you install applications by copying them to a folder, and launch them from that folder. Same way you'd acquire and open files. Lovely. Then Apple ruined it in Lion with…

In even earlier days, applications didn't need to be installed at all. You just ran them from wherever they were. Of course, it made sense to store them somewhere together, and you could cause yourself problems if you put applications onto disks you then ejected. But the current system is clearly influenced by the UNIX underpinnings, and I'm not sure that the average user fully "gets it".

though preferences files were a bit of a mess.

I vaguely remember if early Macintosh System versions you would be prompted to insert the disk (with the correct disk name in the message) if you tried to open a file belonging to an application which was on an ejected disk.

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#272

As someone who's never used or seen Zoom in action, what's pulling people into Zoom that's not already available in other tools (Hangouts Meet, MS Teams) and even works without installing anything (such as Jitsi)? Based on what I've seen, there's just so much hostile behaviour by the company (including lying about meeting HIPAA e2e requirements!) and the fact that their _official client_ had parts removed by the macO…

My experience (beyond Zoom) is with WebEx, Hangouts, and Teams. Zoom has a better UI for large meetings, and the audio quality is significantly improved. We just switched recently from WebEx to Zoom at the office and it's been refreshing. A few days ago was the last time I tried to use Teams, but the "only four people on the screen at a time" limitation was a no-go for our family's virtual gathering. Everyone was much happier with Zoom's video grid, and we noticed that the audio was significantly improved -- in particular how it handles multiple people trying to talk at the same time.

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#273
post #108

Earlier quoted context omitted.

I use Zoom, Hangouts, Slack and WebEx. Out of those Zoom has the best call quality, and it is the only solution out of the 4 on which huge meetings (50+ persons) are workable.

I've been in Google Meet meetings with 100 to 150 participants, it worked fine.

Was just on a Zoom call with 656 participants, it it was remarkably better than any other solutions we've tried in the past.

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#275

Earlier quoted context omitted.

> 3) Malware is defined by what it does, not how it's installed. Well, from the tweet thread: > If the App is already installed but the current user is not admin, they use a helper tool called "zoomAutenticationTool" [sic] and the AuthorizationExecuteWithPrivileges API to spawn a password prompt identifying as "System" (!!) to gain root (including a typo).

It's not malicious, and you have to give it permissions somehow to finish the install. Dropbox (used to?) patch system files to integrate with Office better, and that wasn't considered malware either.

Malicious behaviour does not inherently make something malware. That said, The work arounds Dropbox used in the past should also be considered shady or malicious, and do not serve as a convincing defense in any way.

Yes, zoom does need the user’s password to complete the install in the scenario described. So why isn’t there a proper installer that behaves like installers on macOS should. Why do they ask for the users password on the behalf of ‘system’?

Oh, and zoom was just busted for sending user data to Facebook (regardless of whether or not you had a Facebook account and without disclosure AFAIK) so I reverse my previous statement. It is malware.

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#277
Can someone explain to me what the problem is? If you run the installer, isn't that consent to install the software? That's the whole point of it. I guess this isn't the "Mac way" but this is exactly how I would write an install script if I was slapping together support for other platforms. In fact this is the same way most installers work: it unzips an archive somewhere, then creates the links for remove/launch/etc.

What is the typical install process for software on a Mac?

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#278
post #262

I installed Zoom on macOS yesterday and I thought that the install was crashing because this is not the expected behavior. I would double click the download, try to install, and then the installation program would "crash", so I'd try it again. Did that a few times before I realized it was installed. Until now I thought it had somehow gotten far enough in the installation process before crashing that I could at least…

I too don't get how Zoom is considered "the superior software". Maybe the calls don't drop, but the experience is bad (at least on macOS).

Yes. My experience is really bad too in mac OS. I thought may be something wrong with my setup.

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#279
post #87

Earlier quoted context omitted.

I would highly recommend checking all installers on macOS through Suspicious Package. It will give you a complete picture of all the installer scripts that will be run and all the files that will be written. I did just that for zoom and decided against installing it.

https://mothersruin.com/software/SuspiciousPackage/ for those curious

Pacifist is also handy https://www.charlessoft.com/

Re: How the Zoom macOS installer does its job without you clicking ‘install’

#280

Earlier quoted context omitted.

https://mothersruin.com/software/SuspiciousPackage/ for those curious

Oooh this is good. A few years ago I came home drunk and wanted to watch this old film that wasn't on any channels. I found it on some dubious website, which required me to install a player .dmg. I drunkenly typed in my password, and then an hour later was like: dafuq did I just do?!? Next day I re-imaged my mac because I'm both paranoid and don't know enough about secops. SuspiciousPackage wouldn't have helped comba…

If you don’t trust SuspiciousPackage just run it through SuspiciousPackage.
Post reply on HN