8 ms·
Zoom responded to this point [1]: > This is a workaround to a change introduced in Safari 12 that requires a user to confirm that they want to start the Zoom c
by muzzio 7y ago
Zoom responded to this point [1]:
> This is a workaround to a change introduced in Safari 12 that requires a user to confirm that they want to start the Zoom client prior to joining every meeting. The local web server enables users to avoid this extra click before joining every meeting. We feel that this is a legitimate solution to a poor user experience problem, enabling our users to have faster, one-click-to-join meetings. We are not alone among video conferencing providers in implementing this solution.
Presumably they're both doing the janky web server solution for the same reason. Either way, I'm not sold, that browser behavior exists for for a reason.
[1]: https://blog.zoom.us/wordpress/2019/07/08/response-to-video-on-concern/ https://blog.zoom.us/wordpress/2019/07/08/response-to-video-...
- prophesi 7y agoThey were probably also against Window's UAC popups.
- komali2 7y agoEveryone I knew was against UAC popups, including security professionals. They were likened to California Prop 65 warnings: so prolific as to be ignored, and arguably causing more harm than good, because just as apparently since EVERYTHING causes cancer one can't make decisions about avoiding things that actually do, so to does EVERYTHING trigger a UAC popup and so who gives a fuck, one more thing to quickly ignore and click through.
- chrisfinazzo 7y agoUAC is the correct idea (elevated user privilege levels), but implemented in the worst way possible. As I understand it, things have gotten MUCH less annoying since Vista, but it still left a bad taste in people's mouths.
- syn0byte 7y agoIt pops up with exactly as much frequency as a normal user account in most Posix-like systems would require "su" of one form or another. For exactly the same reasons. It's just expected behavior for those systems, but completely unacceptable for Windows. And we wonder why Microsoft sucks so bad at securing Windows.
- munchbunny 7y agoIt was the collision of Microsoft trying to limit "run as admin" and Windows developers taking users running as admin for granted for too long. There had to be a period of pain as "if it ain't broken don't fix it" developers got around to not asking for unnecessary permissions. These days you mostly see the prompt when you're installing or updating an app, which makes a lot of sense. What I mean is, this is Microsoft's fault so far as users got in the habit of running in admin in the first place, but I doubt you would've been able to do better given where Microsoft was with its software ecosystem going into Vista.
- prophesi 7y agoYeah, that makes sense. And I can't think of any way to accomplish it better :/ Every app you install can potentially cause computer 'cancer'. As a sister comment mentions, it's akin to warning the user whenever they run a command under su/sudo.
- AgloeDreams 7y agoWow that is really damning, trashing user security in trade to remove a single click that makes it clear as to what is happening. This totally breaks Apple's Developer Terms right?
- vbezhenar 7y agoHow is it trashing user security?
- ghostpepper 7y agoBy running a web server with the ability to circumvent installation? It could almost be considered a backdoor
- vbezhenar 7y agoUser willingly installs their software, they are not backdooring it. There are plenty of services running on every computer, including TCP servers and web servers. If you're going to call them backdoors, you've got a long list.
- ghostpepper 7y agoIf I think I have installed your software and it's secretly running a web server with the ability to reinstall itself, I am calling it a backdoor. I think that list is pretty short, but perhaps I am wrong.
- goerz 7y agoI don't think I understand the security implications of this either. Seems distasteful, but how could it be exploited?
- sabbour 7y agohttps://www.wired.com/story/zoom-bug-webcam-hackers/ https://www.wired.com/story/zoom-bug-webcam-hackers/
- peterwwillis 7y agoMove fast, break security
- LeoNatan25 7y agoGAAS—garbage as a service 99% of software world these days fits this description, sadly.
- kstrauser 7y agoI resisted the urge to vote you down simply because their response you quoted pissed me off so much. I'm going to remind my CTO of this when our contract expires and it's time to evaluate alternatives. Signed, Unamused CISO