9 ms·
From the article, this sounds like it was a GateKeeper change, de-whitelisting the signature, rather than an update, per se.
by sparky_ 7y ago
From the article, this sounds like it was a GateKeeper change, de-whitelisting the signature, rather than an update, per se.
- saidajigumi 7y agoOf note, Apple has had its own malware detection and removal system in place since the Mountain Lion - Snow Leopard timeframe. Since this article speaks to removal, it's sounding like the Zoom local server may have had its signature added to that system.
- bredren 7y agoSo the local server is not a regular price of software with a vulnerability, it is now considered malware?
- sieabahlpark 7y agoYes because even if you purposely uninstalled the application it would reinstall if you went to a link even by accident without really notifying you that it did so. So yes, malware.
- olliej 7y agoThe server was intentionally left behind, and running, by the "uninstaller". The server would respond to requests by reinstalling the intentionally uninstalled software. That's malware. The server itself was deliberately added to work around a Safari security feature, that was designed specifically to prevent what they wanted: allowing arbitrary web content to open an app without user consent. They literally added an always on, persistent server, to avoid a security dialog
- javagram 7y ago> The server was intentionally left behind, and running, by the "uninstaller FWIW, I don’t think there was a uninstaller? What I’ve seen people describe is that dragging the .App file to the trash wouldn’t remove the server, since it was installed in a different folder. There was no uninstaller until the Zoom update this week added an uninstall option to the menu.
- fastball 7y agoI think that is the point. MacOS users expect an app that does not come bundled with an uninstaller to be "uninstalled" by dragging the .app bundle to the trash. This generally leaves behind metadata, but that is not a big deal as it is just data - not code. Leaving behind code that continues to execute after the user has removed the application without an option to uninstall it is obviously something that never should have shipped in the first place from a customer trust perspective.
- javagram 7y agoFWIW I am not sure how dragging the .app to the trash would uninstall other things installed by the app. If I drag photoshop to my trash instead of using Adobe’s uninstaller, I’m pretty sure that leaves Creative Cloud junk running on my machine. Now, zoom did mess up by not having a proper uninstaller shipped with their app, I think a lot of other Mac apps do fail at this too though.
- fastball 7y agoYes, as is, dragging apps to the trash cannot do that. Apple should probably implement an API that allows developers to tell the OS what other stuff should be removed if the app is dragged to the trash. To prevent devs from removing other people's stuff, you could require that the subcomponents need to be cryptographically signed with the same key as the main app bundle. edit: or, even simpler solution (potentially) - have a fairly basic API via which devs can install subprograms elsewhere on the system. When you use this API to install something, it adds the thing installed to an OS-level registry. When the user drags the app to the trash, the OS checks the registry and removes anything that was added by the application.
- javagram 7y agoI think your edit is describing a package manager :D Or the Mac App Store... (But yes, it would be good if this feature were available for apps that can’t come through the App Store)
- vbezhenar 7y agoThat's Apple's closed garden, even when they allow you to sideload application, they still have the ultimate decision. Of course it's not malware, but probably enough users have vulnerable software which could be remotely exploited, that they decided to blacklist it.
- scarface74 7y agoA program that surreptitiously reinstalls software when you uninstall it is by definition malware. A piece of software that lets any website activate your camera without your permission is a security vulnerability.
- vbezhenar 7y agoMalware is a software written to harm user. Their purpose was not to harm user, they wanted to make their service more convenient for users. Bugs are bugs, every product have bugs and many products have security bugs. That does not make them malware.
- scarface74 7y agoIntent doesn’t matter only results. The result is that unless you like for random websites to be able to activate your camera without your permission, it did harm users. It wasn’t a “bug”. They purposefully hacked around a security feature. Do you really think it was a “bug” that it reinstalled itself?
- vbezhenar 7y ago> Intent doesn’t matter only results. Then you should call Chrome a malware because there were vulnerabilities with remote code execution (and there will be similar vulnerabilities), so every website could install anything. But that is absurd. > The result is that unless you like for random websites to be able to activate your camera without your permission, it did harm users. First of all, you need a hard data that this vulnerability was exploited in the wild. Otherwise it did not harm users, it only opened a way for malicious websites to harm users. And, again, every vulnerability could be counted as a malware by that definition which makes malware term meaningless. > Do you really think it was a “bug” that it reinstalled itself? It is intended behaviour. And I don't see anything drastically bad with it. If you're opening their website with corresponding link, you want to use that service. In order to use that service, you have to run additional software and they are making it easier for you to run it. Only a few years ago every browser supported Java Applets and with Java Applets every website could run arbitrary code on your machine. And that feature was actually used a lot. Does it make all services which used that feature to overcome browser weaknesses malware? I don't think so. They probably should have communicated better about that aspect and provide proper uninstaller software for security-concerned users. And not making those vulnerabilities in the first place, of course. But world is not perfect.
- saidajigumi 7y agoBeyond the unsolicited reinstallation (== malware) behavior other commenters rightly mentioned, the entire existence of the vulnerable server was a hack to work around a Safari security feature. Zoom wanted to eliminate an extra user click, required by Safari to confirm that it was OK to invoke a local application based on the public zoom link. This server was an implementation of that security "workaround". That makes this server at least doubly malware. And "vulnerability" understates the case: a negligent implementation that utterly disregarded any security concerns should be considered beyond the pale. That times 1000 for a major software vendor like Zoom.
- msbarnett 7y agoMore likely this was done via a signature update to xprotect, which is essentially a background antivirus process in macOS.
- snuxoll 7y agoDoesn't appear so, current XProtect version remains at 2103 which was released a couple months ago now.
- saagarjha 7y agoThe update from today updates the MRT configuration data.
- msbarnett 7y agoI haven’t checked, but are you looking at the version of the binary itself, or the MRT signature files it uses
- snuxoll 7y agoChecked XProtect.meta.plist inside the app bundle, forcing an update check with softwareupdate has no impact either. Perhaps it’s a staged rollout, but at least on my iMac there’s no sign of updated signatures.
- msbarnett 7y agoYeah you’re just looking at the version of the xprotect binary, not the malware signature data files, which don’t live in the bundle and get updated more regularly. They also ship silently via system_installd, you’re not going to see anything in the software update GUI
- snuxoll 7y agoThe signature files also live inside the XProtect.app bundle, unless in true Apple fashion they’ve got other stuff that’s lurking elsewhere in /System that I can’t locate.
- ddeville 7y agoLooks like the ZoomOpener app is still present on my machine but it’s not running anymore and it shows as unticked in the Login Items preferences.