4 ms·
The videoconferencing industry seems to believe it's necessary to bypass regular OS protections to make the UX "better". For example: https://www.theverge.com/
by rainforest 7y ago
The videoconferencing industry seems to believe it's necessary to bypass regular OS protections to make the UX "better".
For example: https://www.theverge.com/2019/7/8/20687014/zoom-security-flaw-video-conference-websites-hijack-mac-cameras https://www.theverge.com/2019/7/8/20687014/zoom-security-fla... By design, instead of using a URL handler, they run a HTTP server on your machine to bypass the "open with" dialog. There are good reasons not to trust the binaries they ask you to run.
Here, it turns out they offer a web client after all, which is nice and sandboxed, but they default to trying to run a binary on your machine where you have less control over what it does.
- kristianc 7y ago> Update, 5:15PM ET July 9th: Zoom has published a blog post detailing its response to this vulnerability, including how it will patch its software and uninstall the webserver it has installed on Macs. More details here, and original story follows. Seems like they don't, and haven't since July.
- ilogik 7y agothe used to do it, but there was a huge backlash. I think even apple pushed a patch to block their behaviour
- rainforest 7y agoThis is an example. Why would you trust an organisation that engineers "solutions" to security measures but does so without due care and attention leading to a widespread critical security bug?