Live data from Hacker News

Apple has pushed a silent Mac update to remove hidden Zoom web server

techcrunch.com

401–410 of 552 posts

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#401
Once again, a popular site that is completely GDPR non-complient. To opt out of tracking you have to go through six layers of obfuscation. And don't take the wrong turn, or you will just come to walls of text, meant to do nothing but make you throw up your hands and give up. Or you can just opt in to everything with one click.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#402
post #42

This means there might have been another side to this story: Zoom's change of heart might have been forced by Apple, not the public backlash. Apple: Hey, your app poses a threat to macOS security. We're going to remove your server app with the built-in macOS anti-virus. Zoom: Oh crap. Okay, give us 2 sprints to release a new version that removes it. Apple: We're killing it in 48 hours. ... Zoom, after an all-nighter:…

I've been on the Catalina Beta since the week of WWDC, and Zoom hasnt worked for me until the update today. The loading modal would come up, but the app window would never open and I would have to force kill the app entirely, since I couldn't close the modal. I suspect that Apple had already closed the possibility of the loophole on Catalina, which is why it wasn't working. So I suspect they had probably noticed it w…

I had the same experience on Catalina, couldn't launch. Explains why I couldn't reproduce the bug from the Medium article too. Uninstalled it before the update.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#403
post #365

Earlier quoted context omitted.

Note that conflict-free at this time is so hard to be practically impossible. Fairphone, a company and phone founded explicitly with the goal of producing a phone without conflict minerals, still isn't conflict-free, and it's not for lack of trying. Sure, Apple has more leverage, considering their size, but that also comes with its own set of problems. Plus, their customers have nowhere to go to in protest - all othe…

I understand it's hard to make conflict-free computers. I feel sick when apple says they are deeply committed to upholding human rights, while they continue manufacturing electronics, because I need authenticity. I would like Apple to use more of their resources to figure out how to do conflict-free consumer electronics.

> I would like Apple to use more of their resources to figure out how to do conflict-free consumer electronics.

I would like that as well, but I understand how that's difficult for them to do, too: making public that you're working on that, is also making public the deficiencies you have in that area currently - something many consumers are not aware of, and of which they may think it applies only to you.

That's why initiatives like Fairphone's are good. That said, I've followed their blog [1] for a while, and occasionally they've been part of initiatives of which other phone manufacturers have been part as well (I recall something about Nokia and Congo). I think they just don't publicise that for the reasons I outlined above.

[1] https://www.fairphone.com/en/blog/

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#404
post #308

Earlier quoted context omitted.

Which are a very tiny percentage of typical Mac users.

As it should be. The vast majority of users should only run signed software. That leaves the ones who know what they are doing a way to bypass it.

You mean those that after doing that just perform "curl | sh" as it has become trendy among the younger UNIX generation?

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#405
post #303

Earlier quoted context omitted.

Watch the security talk. macOS is on the path to adopt iOS permissions model and long term roadmap is to apply the sandbox to everything, with the option to explicitly disable it on per-case basis. A path similar to how Windows 10 is now converging the Win32 and UWP sanbox models, or how ChromeOS sandboxes GNU/Linux processes.

> macOS is on the path to adopt iOS permissions model and long term roadmap is to apply the sandbox to everything I do not see where this is mentioned.

[deleted]

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#406
post #267

Earlier quoted context omitted.

Not after Catalina. Future versions of macOS will require signed software (notarized as per Apple terminology), even outside of the store. What is new in security at WWDC.

Notarized≠signed. I suggest you watch the videos that you've posted; they go into detail about the changes in macOS Catalina and when they apply.

On the go now, I will post the video minutes and slide pages afterwards.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#407
post #303

Earlier quoted context omitted.

Watch the security talk. macOS is on the path to adopt iOS permissions model and long term roadmap is to apply the sandbox to everything, with the option to explicitly disable it on per-case basis. A path similar to how Windows 10 is now converging the Win32 and UWP sanbox models, or how ChromeOS sandboxes GNU/Linux processes.

> macOS is on the path to adopt iOS permissions model and long term roadmap is to apply the sandbox to everything I do not see where this is mentioned.

I will show it later then.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#408
post #13

If you would like to force this update you can do so via the terminal: softwareupdate -ia --include-config-data It will show up as MRTConfigData if you look under Apple Menu->About This Mac->System Report->Software->Installations. The latest version is 1.45 and was updated today which includes the Zoom mitigations.

This also install a lot of stuff people may not want to. You can install only the designated package with :

    softwareupdate -i MRTConfigData_10_14-1.45 --include-config-data

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#409
post #399
post #391

Earlier quoted context omitted.

But they didn't uninstall 'a program'. The product itself was unaffected. And, again, this was done in consultation with the makers of the 'program' who had screwed up badly enough to be unable to fix the problem themselves. Nothing happened here that doesn't regularly happen when all sorts of things update.

These are unimportant details, the issue is with Apple modifying people's computers silently and the users themselves having no knowledge or any say about it. Replace this instance with something that you disagree about (imagine Apple removing VPN software from Chinese customers due to demands from China or "fixing" existing VPN software with backdoors that enable Chinese authorities to wiretap Chinese people) and se…

You brought up the details, inaccurately, to now tell me the details don't matter. You can understand, I hope, how this starts to feel like an exercise in eel juggling.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#410
post #389

Earlier quoted context omitted.

I was waiting for this comment. > You may agree with its decision this time, but will you always agree? Yes, I will. At least I am not going to lose sleep over it until Apple does abuse that power. I am actually even more happy to be an Apple user knowing that the mothership said hell naw to the naw naw naw naw to this horseshit Zoom has been pulling. If I were Apple, I'd be taking this as a personal slight against m…

> At least I am not going to lose sleep over it until Apple does abuse that power. What if Apple abuses that power in ways that not everyone sees as "abuse", yet they are affected by it? The reason you are not already seeing this act as abuse is because you happen to agree with it. What if you didn't agree? What if you were in the minority? What if the reason you where in the minority was that the majority simply did…

This same line of reasoning could apply to any Windows or Mac OS update that disables and removes known viruses and malware.

Is it appropriate for Microsoft and Apple to push updates that disable and remove those from infected computers? If so, what is the significant difference?

Post reply on HN