Live data from Hacker News

Zoom zero-day discovery

blog.malwarebytes.com

91–100 of 246 posts

Re: Zoom zero-day discovery

#91
post #42

Related, the two other $200k entries from Pwn2Own 2021:[1] - DEVCORE targeting Microsoft Exchange in the Server category (The DEVCORE team combined an authentication bypass and a local privilege escalation to complete take over the Exchange server.) - The researcher who goes by OV targeting Microsoft Teams in the Enterprise Communications category (OV combined a pair of bugs to demonstrate code execution on Microsoft…

I wonder if the OS world will move towards lightweight but unforgiving sandboxing like OpenBSD's `pledge` and `unveil` system calls. It's crazy to me that most software is still completely fine to run around and set things as fire the instant it's compromised!

This is about the implementation in the SerenityOS but it's my favourite explanation so far: https://awesomekling.github.io/pledge-and-unveil-in-Serenity...

Re: Zoom zero-day discovery

#92

Earlier quoted context omitted.

Wait, are you saying Zoom isn't hated? It's crap. I refuse to install its PoS app and all of the security holes it came with (don't care if they are fixed or not). Launching a zoom meeting in my browser totally bogs the browser down. The zoom site is so slow that proving I'm a human is at least 10x slower than on other sites. In my use case, nobody on the zoom call is even using video, yet it still runs this badly.

We run zoom calls with over 200 participants and no problems. It sounds like their browser experience is poor, I don’t know if that’s a browser limitation or bad design, but their app on Windows and Mac performs quite well. Mistakes were made with security early in their product. It’s clear that has turned a lot of potential users against them. I’m curious why companies like Facebook get more acceptance over terrible…

>Mac performs quite well.

This is not my experience at all. Early in the lockdown when Zoom became the darling, I was forced to install their app. Pre-pandemic, Zoom was already panned on this site for crap they were doing, so I pushed back hard against using Zoom before ultimately relenting. Running zoom with a simple 3 person call would bog down my 2017 MBP with fans running full tilt. I've since upgraded hardware and zoom is not allowed to be installed on this computer.

>I’m curious why companies like Facebook get more acceptance

Is there anyone on this site that agrees with that comment? I certainly don't. There are multiple billions of FB users, so I'm quite sure the readers of HN is just a mere rounding error level of numbers.

Re: Zoom zero-day discovery

#93

Earlier quoted context omitted.

Like "Zoom is an unethical company". See: Privacy concerns, lying about encryption, connections to china, bad security.

That might be “people on HN hate zoom”.

That doesn't make them wrong though

Re: Zoom zero-day discovery

#94
post #75
post #49

The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work" Imagine if that was your run of the mill well-hated big corp "Yet another security vulnerabi…

I don't think that's fair. The Pwn2Own contest rules specifically disallow disclosure. This isn't a "zero day" in any sense but marketing. It's a privately disclosed vulnerability under a managed embargo, just as if it had been reported by Project Zero or whoever. The ding is that, because it was a "public contest", the existence of the vulnerability is known. And that's probably a higher risk scenario in the abstrac…

finally, someone who uses 0day more correct than nearly every else. My remaining sanity thanks you!

Re: Zoom zero-day discovery

#95
post #63

Can we please edit the headline. This sounds disingenuous, a more appropriate headline would be something like "critical vulnerability in Zoom Video Calls that would have put millions of users at risk has been found". This feels like a straight up PR piece.

Seconded! Only a PR person would dream of saying that a 0 day exploit is a good thing. I expect that most HN readers just finds this hillarious, but still people read HN since it has a good standard. Saying that a 0 day exploit is a good thing goes against this needless to say. Especially since they've faced serious accusations earlier on.

>Only a PR person would dream of saying that a 0 day exploit is a good thing

Depends on your perspective. a 0-day is a very good thing if you are an advesary trying to get in. so maybe to the alphabet soup of groups CCP, FBI, NSA, etc, woohoo!!!

Re: Zoom zero-day discovery

#96

I sometimes wonder if we're destined for a world where software companies decide they should employ QA staff. Or if we're destined for a world where the majority of QA gets oursourced to competitions.

Software companies used to have QA staff. But developers said "we can write our own tests and you can get rid of those expensive QA people who we hate" and here we are, in the land of forever-crappy software.

It's our own damn fault for becoming over-reliant on CI to find all the bugs.

Re: Zoom zero-day discovery

#97

Earlier quoted context omitted.

Same here, zoom is on our 'ban' list. And MS teams is getting there, what a load of crap that is, it is so buggy it is embarrassing.

My biggest gripe about Teams is what a memory hog it is. Mine is currently sitting idle (been on vacation all week) at nearly 1GB. Compare this to Zoom, which is idling at just over 100MB. Teams is literally taking up 10 times more RAM than Zoom just running in the background.

In Microsoft’s defense Teams is an electron (or electronesque) app and offers quite a bit more than Zoom in terms of features. The fact that it uses so much RAM is expected when you consider it as another copy of chrome.

Re: Zoom zero-day discovery

#98

Earlier quoted context omitted.

My biggest gripe about Teams is what a memory hog it is. Mine is currently sitting idle (been on vacation all week) at nearly 1GB. Compare this to Zoom, which is idling at just over 100MB. Teams is literally taking up 10 times more RAM than Zoom just running in the background.

I have never used Teams but is 1GB of memory usage really an issue in 2021, when most laptops have at least 16-32 gigs of memory? It's been years since the last time I actually worried about how much memory some software on my laptop was using.

is 1GB of memory usage really an issue in 2021

It isn't if you're on a laptop from 2021. But that vast majority of people aren't. Companies don't provision new computers to their employees every time a new computer comes out. At the companies I've worked for, the minimum refresh time is 3-5 years, depending on tax laws, and financial ability.

It's also not a big deal if the computer is only used for Zoom. Most people, whether office drones or developers, run many programs at once.

Re: Zoom zero-day discovery

#100
post #79

Earlier quoted context omitted.

Wait, are you saying Zoom isn't hated? It's crap. I refuse to install its PoS app and all of the security holes it came with (don't care if they are fixed or not). Launching a zoom meeting in my browser totally bogs the browser down. The zoom site is so slow that proving I'm a human is at least 10x slower than on other sites. In my use case, nobody on the zoom call is even using video, yet it still runs this badly.

Didn't they route calls through China for no apparent reason as well?

Not without improving the speed of light.
Post reply on HN