4 ms·
> So yeah, Zoom is (ab)using flaws in macOS to get itself installed with minimum fuss, but it isn't doing it with evil intent. But... why? What other software
by rainforest 7y ago
> So yeah, Zoom is (ab)using flaws in macOS to get itself installed with minimum fuss, but it isn't doing it with evil intent.
But... why? What other software vendors look at the OS security model from a viewpoint of 'how do we bypass this as much as possible?' If it's not evil intent, what is it, incompetence?
- javagram 7y agoIt’s about making your software as easy to use as possible. Users don’t like UAC or having to click through a dozen dialogs. They just want to get into their virtual meeting.
- my123 7y agoThen Zoom should just make them join the meeting via the web browser! Zoom does this somehow and doesn't make joining from the web frictionless when they pretty much could have.
- lonelappde 7y agoZoom could be honest about what it doing instead of going to extreme lengths to conceal it
- xenophonf 7y ago/Applications is writable by admins. There is no O/S security model to bypass.
- rainforest 7y agoIt has a pre-flight script (which isn't supposed to change anything) that installs it (and its browser extensions, and a kernel extension at some point in the past) in the most widely available place the current user has privileges to (it installs in their home directory if they aren't an admin). So yes, there is some blame to be laid at the OS for running binaries with the privileges the current user has, but it's clear that the installer doesn't behave like a regular installer would.