Live data from Hacker News

Zoom zero-day discovery

blog.malwarebytes.com

61–70 of 246 posts

Re: Zoom zero-day discovery

#61
post #51

Earlier quoted context omitted.

This is a PR piece. People do hate zoom, this is zoom trying to rehabilitate their image through their security partner.

People hate zoom? Like "Teams is so much better" or "online meeting are bad"? For me it one of the more enjoyable online meeting options and it leaves Teams, Skype, webex and what have you, far behind.

Like "Zoom is an unethical company".

See: Privacy concerns, lying about encryption, connections to china, bad security.

Re: Zoom zero-day discovery

#62

Zoom is entirely banned at the two companies that are my day job, and probably 90% of partners. If you do any work adjacent to anything that's ITAR controlled you should also not be surprised to see the same policy from partner companies. This has been in place for quite some time since the initial security problem that was so egregiously bad apple had to resort to using the malware removal tool to remove zoom's bina…

Do these issues hold true for the FedRAMP'd "Zoom For Government"?

Re: Zoom zero-day discovery

#63

Can we please edit the headline. This sounds disingenuous, a more appropriate headline would be something like "critical vulnerability in Zoom Video Calls that would have put millions of users at risk has been found". This feels like a straight up PR piece.

Seconded! Only a PR person would dream of saying that a 0 day exploit is a good thing. I expect that most HN readers just finds this hillarious, but still people read HN since it has a good standard. Saying that a 0 day exploit is a good thing goes against this needless to say.

Especially since they've faced serious accusations earlier on.

Re: Zoom zero-day discovery

#64
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

>Imagine if that was your run of the mill well-hated big corp

Microsoft seems to be the one banging the "zoom is insecure" drum hardest and teams had, like, 4 zero days and paid < 30K for them IIRC.

Re: Zoom zero-day discovery

#66
post #3

Is it just me, or does $200k seem far too low for this? I understand that the reward was paid by the event, not Zoom... but it seems to me that Zoom should “pony up” some additional funds for this research.

You are always free to sell the hacks for their """actual""" market value on the black market. Of course you need to launder the money, you might get jailed, you might have to flee the country and so on but at least you get your fair rate.

You're overcomplicating, Zerodium exists.

Re: Zoom zero-day discovery

#67

Earlier quoted context omitted.

People hate zoom? Like "Teams is so much better" or "online meeting are bad"? For me it one of the more enjoyable online meeting options and it leaves Teams, Skype, webex and what have you, far behind.

Like "Zoom is an unethical company". See: Privacy concerns, lying about encryption, connections to china, bad security.

That might be “people on HN hate zoom”.

Re: Zoom zero-day discovery

#68

Earlier quoted context omitted.

Like "Zoom is an unethical company". See: Privacy concerns, lying about encryption, connections to china, bad security.

That might be “people on HN hate zoom”.

Fair point.

Possibly "people on HN hate zoom, and then use it anyways because it's forced."

Re: Zoom zero-day discovery

#69
post #51

Earlier quoted context omitted.

This is a PR piece. People do hate zoom, this is zoom trying to rehabilitate their image through their security partner.

People hate zoom? Like "Teams is so much better" or "online meeting are bad"? For me it one of the more enjoyable online meeting options and it leaves Teams, Skype, webex and what have you, far behind.

Its possible to hate zoom without liking one of the alternatives. I know a lot of people hate zoom because they associate it without meeting burning due to this year and security issues.

Re: Zoom zero-day discovery

#70
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

ZDNet's headline is "Critical Zoom vulnerability triggers remote code execution without user input"
Post reply on HN