Live data from Hacker News

Vulnerability in the Mac Zoom client allows malicious websites to enable camera

medium.com

401–410 of 473 posts

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#401

I've lost all trust in Zoom at this point

It's a fantastic piece of software I use daily, so I'm inclined to give them the benefit of the doubt before joining an internet pitchfork mob.

If you qualify software that performs such a blatantly awful/wrong practice as fantastic, then you I'm afraid you need to redefine your views of what constitutes software.

This is a truly heinous design and should be lambasted as such

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#402

Earlier quoted context omitted.

> All first-time Zoom users, upon joining their first meeting from a given device, are asked whether they would like their video to be turned OFF. For subsequent meetings, users can configure their client video settings to turn OFF video when joining a meeting. > Additionally, system administrators can pre-configure video settings for supported devices at the time of install or change the configuration at anytime. TB…

That part just doesn’t seem very responsive. Unless Zoom is recommending that everyone should turn it OFF, and urgently releasing a patch to make OFF the default, why does it matter that the vulnerability is in an optional feature rather than a mandatory one?

The Zoom admin for an org can switch to cameras default Off

I agree it should be the default, though if you're worried you can open your Zoom app and change the default as well

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#403

Earlier quoted context omitted.

I do NOT appear to have the web server running, but I did have the ~/.zoomus folder and the ZoomOpener app there. Is this because I'm scrupulous about killing LaunchAgents and LaunchDaemons?

Run this: ps aux | grep zoom You'll probably see "ZoomOpener" there. It is running but it's not in the "Force Quit" menu. Then, to kill it run: killall zoom Then you can follow the other directions indicated by the previous poster who gave information about how to lock your ~/.zoomus directory down to root so that it can't install itself again.

I do not have ZoomOpener running.

My feeling is that removing the startup item probably cripples this, no? I mean, fuck them for doing this, and get rid of all of it, but I think the StartupItem is required for their hack to work.

Right?

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#404
post #374

Earlier quoted context omitted.

> Zoom invited the researcher to join our private paid bug bounty program, which he declined because of non-disclosure terms. It is common industry practice to require non-disclosure for private bug bounty programs. Is an NDA really "common industry practice" for bug bounty programs? I know NDAs are common for pen-testing but it seems like an odd (and kind of dishonest) requirement for a bug bounty program.

Some kind of NDA terms are not unheard-of. Like a 1-3 month period in which to work on things during which disclosures won't go out. That said, there's a slight disconnect between Zoom's two statements here. The first is that the researcher declined out of concerns over Zoom's NDA. The second is that NDAs are common. What this doesn't say is that Zoom's NDA is cookie-cutter or what the specific terms are. If I were t…

I'd have to guess this as well. I have dealt with a number of public and private bounties, and not one of the researchers has ever rejected an NDA or not allowed us time to remediate before they could disclose this information to 3rd parties. Unless you count Tavis tweeting critical findings I guess.

And to be fair, none of the times I've engaged a private bounty have been due to some massively critical bug that impacted privacy or could hijack parts of client systems. I could see that if the researcher worked with Zoom and didn't feel like they took it seriously they would refuse this and just disclose it due to the impact it has.

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#405
post #374

Earlier quoted context omitted.

Some kind of NDA terms are not unheard-of. Like a 1-3 month period in which to work on things during which disclosures won't go out. That said, there's a slight disconnect between Zoom's two statements here. The first is that the researcher declined out of concerns over Zoom's NDA. The second is that NDAs are common. What this doesn't say is that Zoom's NDA is cookie-cutter or what the specific terms are. If I were t…

I'd have to guess this as well. I have dealt with a number of public and private bounties, and not one of the researchers has ever rejected an NDA or not allowed us time to remediate before they could disclose this information to 3rd parties. Unless you count Tavis tweeting critical findings I guess. And to be fair, none of the times I've engaged a private bounty have been due to some massively critical bug that impa…

The researcher makes it clear that they rejected the NDA because it was a permanent gag on any discussion (even after patching). With that in mind, and this clearly being an intentional design, I can see why it might come off as Zoom not taking the issue seriously.

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#406
Zoom’s UX has always come off as invasive. An application default that allows hosts to enable automatic camera join is an overstep, and the lengths they go to facilitate this while ignoring long standing, industry standard appsec guidelines to prevent XSS is relatively unsurprising yet hopefully not inconsequential to their enterprise customers.

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#407

I asked Zoom support about this and they sent me to this page: https://blog.zoom.us/wordpress/2019/07/08/response-to-video-... The key thing here is they think this is a fair trade-off because Safari asks if you want to open Zoom. > This is a workaround to a change introduced in Safari 12 that requires a user to confirm that they want to start the Zoom client prior to joining every meeting. The local web server enabl…

I realised I had a paid account, so I've cancelled that too. And I've also reported them to Apple, after seeing that the ZoomOpener app reinstalls the client - which is completely and utterly unacceptable.

Yeah, this seems like it must violate some Apple TOS, right? The uninstaller leaves behind a local webserver, that can't possibly be allowed.

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#408

Earlier quoted context omitted.

I realised I had a paid account, so I've cancelled that too. And I've also reported them to Apple, after seeing that the ZoomOpener app reinstalls the client - which is completely and utterly unacceptable.

Yeah, this seems like it must violate some Apple TOS, right? The uninstaller leaves behind a local webserver, that can't possibly be allowed.

[deleted]

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#409

Zoom’s response to this[1] is a wonderful example of how not to respond to security issues. It includes the classic tropes: * Our users don’t care about security. > Our video-first platform is a key benefit to our users around the world, and our customers have told us that they choose Zoom for our frictionless video communications experience. * We have no way of knowing if this has been exploited in the wild, so it’s…

> All first-time Zoom users, upon joining their first meeting from a given device, are asked whether they would like their video to be turned OFF. For subsequent meetings, users can configure their client video settings to turn OFF video when joining a meeting. > Additionally, system administrators can pre-configure video settings for supported devices at the time of install or change the configuration at anytime. TB…

That is a pre-existing feature, and while it mitigates one specific aspect of the issue, it doesn't represent a security-focused response. Yes, I am saying that's not good enough: an appropriate, non-dismissive response would commit to writing code to deal with the issue raised, subject to the industry standard 90-day embargo. Depending on how much importance they place on their user's security.

Re: Vulnerability in the Mac Zoom client allows malicious websites to enable camera

#410
This is thoroughly disappointing, given that Zoom is among the few popular conferencing programs that aren't complete garbage for Linux users. Thankfully the Linux client doesn't appear to be affected AFAICT, but this is trust-shattering nonetheless.
Post reply on HN