Live data from Hacker News

Apple has pushed a silent Mac update to remove hidden Zoom web server

techcrunch.com

471–480 of 552 posts

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#471

Earlier quoted context omitted.

> OmniDiskSweeper is great for finding this stuff. iTrash [1] is also worth mentioning. It uses the Levenshtein distance algorithm [2] to find all of the junk related to an app. [1] http://www.osxbytes.com [2] https://en.wikipedia.org/wiki/Levenshtein_distance

I've been using AppCleaner [1] for years and it's awesome. And it's free. https://freemacsoft.net/appcleaner/

That's a cool little app. But at some point, I became very wary of running free, closed-source binaries from the Internet.

What do you think about this one?

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#472

Earlier quoted context omitted.

This also install a lot of stuff people may not want to. You can install only the designated package with : softwareupdate -i MRTConfigData_10_14-1.45 --include-config-data

Software Update Tool MRTConfigData_10_14-1.45: No such update No updates are available.

I am also getting this error, and suspect it is because I’m on 10.12.6. If you do system_profiler SPInstallHistoryDataType |grep -A5 MRTConfigData you should see your latest version. For me, it’s 1.42. Not sure how to get the update yet though. Will update this comment once I figure that out.

Update: According to this macworld article, there is a Zoom patch out that fixes this. https://www.macworld.com/article/3407764/zoom-mac-app-flaw-c...

There are also commands at the bottom to manually kill the zoom localhost and disable it. I have opted to run those commands regardless:

  pkill ZoomOpener;rm -rf ~/.zoomus;touch ~/.zoomus &&chmod 000 ~/.zoomus;

  pkill "RingCentralOpener";rm -rf ~/.ringcentralopener;touch ~/.ringcentralopener &&chmod 000 ~/.ringcentralopener;#

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#473

Earlier quoted context omitted.

Requiring user confirmation for updating malware signatures would make them a lot less effective. And in any case, there is a checkbox in the software update preferences labelled "Install system data files and security updates" which presumably allows you to opt out of these critical security updates. And if you really wanted to have the zoom backdoor server run on your system, you could probably just strip the code…

>Requiring user confirmation for updating malware signatures would make them a lot less effective. That seems highly unlikely to me. Do you have evidence to support that assertion. On first use "Do you want us to automatically remove apps we think might damage your system: Y/n." Don't users need a notification, at least, to inform their choices when installing software. I guess Apple Computers would rather you just m…

You can turn it off if you don't like it. If one doesn't know enough to turn it off, one probably shouldn't be turning it off.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#474
post #152
post #147

Earlier quoted context omitted.

That's it right there. This isn't some gray area, questionable thing like that time they pushed a David Bowie song onto people's iTunes. Remember that? People completely lost their minds over it, and I agree with the sentiment. This isn't third-party anything. No one even knew this was running on their machine and it was demonstrably abusable. Good riddance!

a David Bowie song It was an entire U2 album, a far greater offense.

If it was a Bowie song, people probably would've been happy.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#475
post #13

If you would like to force this update you can do so via the terminal: softwareupdate -ia --include-config-data It will show up as MRTConfigData if you look under Apple Menu->About This Mac->System Report->Software->Installations. The latest version is 1.45 and was updated today which includes the Zoom mitigations.

This also install a lot of stuff people may not want to. You can install only the designated package with : softwareupdate -i MRTConfigData_10_14-1.45 --include-config-data

You are correct, the -a flag will install all updates that are available from Apple. Thanks!

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#476

Earlier quoted context omitted.

I’m quite happy with it, as I don’t see millions of people removing some hidden directory. No more zoom for me.

The point is precisely NOT to think about only this one case like many others seem to be focusing (or Zoom-ing in...?) on, but to consider how far you are willing to let Apple exercise its power over your computer. Would you let it scan all your files and delete e.g. "suspected images of child abuse" (to use an old cliche)? Suspected copyrighted material or fragments thereof? "Extremist" content, or content which is…

You have to extend some goodwill to a company that invested millions of dollars and absolutely critical space in its handheld tech simply for security (I'm referring, of course, to the secure enclave).

Point to me any other manufacturer who has gone to those lengths to protect their users. There was no reason for Apple to develop that tech. No one else in that space, but they developed it anyway.

Can they do all this stuff? Sure, but I don't think they will. It does not seem to be in their interest.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#477

Earlier quoted context omitted.

It is enabled by default and if you don’t like that you can disable this behavior. https://support.apple.com/en-us/HT204536

We still have not heard anything officially from Apple. Based on other comments here, this removal happened via Malware Removal Tool (MRT) which itself is a hidden tool. If yes, then Apple needs to declare Zoom as Malware. For reference, Apple defines Malware here - https://support.apple.com/en-in/guide/mac-help/mh27449/10.14... . On the other hand, Apple itself is guilty of not addressing gatekeeper vulnerability in…

> We cannot commend them > Why are we dependent

Why are you using "we"? I for one am quite happy how Apple manages Gatekeeper.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#478

Huh? Why is it ok for Apple or anyone to do silent installs on my computer? As a customer, why am I getting this information from YC/Techcrunch and not Apple? What else have they pushed like this? Is there a transparent log? Can we verify if their track record is clean? How many times have they silently broken and fixed their own things? How do we know they won't abuse this? Isn't this the same dark pattern that we c…

I don't want to come across as confrontational, but I find this kind of response exhausting. I do not want control of everything on my computer. I don't have time or expertise to decide on whether to accept each and every security update, particularly ones that involve a web server which was installed by stealth and which isn't removed when the app is uninstalled. I want to outsource these kinds of decisions to peopl…

It's the same response like the one when dropbox released. "It's trivial to spin up a server, set up a file sync, blah blah blah, why do we need dropbox".

I'm the same as you. The whineyness exhausts me. Let the market decide. I just want shit to work.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#479

Earlier quoted context omitted.

I still think Apple products are built on human rights abuses. I am currently trying to parse their most recent conflict minerals disclosure. It doesn't explicitly say "yes" but also doesn't clearly say "conflict-free" either.

I’m sure you also love to complain about the problems at the Foxconn ‘Apple factory’. Which in reality builds products for all manufacturers.

So "everyone else does it" is a valid defense?

Apple charges $1k for their monitor stands. I think they can afford to build their stuff at a factory that doesn't use modern slavery.

Re: Apple has pushed a silent Mac update to remove hidden Zoom web server

#480

Earlier quoted context omitted.

Software Update Tool MRTConfigData_10_14-1.45: No such update No updates are available.

I am also getting this error, and suspect it is because I’m on 10.12.6. If you do system_profiler SPInstallHistoryDataType |grep -A5 MRTConfigData you should see your latest version. For me, it’s 1.42. Not sure how to get the update yet though. Will update this comment once I figure that out. Update: According to this macworld article, there is a Zoom patch out that fixes this. https://www.macworld.com/article/340776…

What do the chmod do there? Removing files count as writes to the directory at least in Linux, so chmodding the dummy file wouldn't do much I'm thinking.
Post reply on HN