8 ms·
The positive "tilt" in this article is honestly amusing and unusual for such articles "zero-day discovery makes calls safer" "Understandably, Zoom has not yet
by bezoz 5y ago
The positive "tilt" in this article is honestly amusing and unusual for such articles
"zero-day discovery makes calls safer"
"Understandably, Zoom has not yet had the time to issue a patch for the vulnerability"
"This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work"
Imagine if that was your run of the mill well-hated big corp
"Yet another security vulnerability leaves millions at risk"
"XYZ Corp shows its incompetence once again exposing users' private data to hackers"
etc etc
No specific point here. I am just amused!
- vxNsr 5y agoThis is a PR piece. People do hate zoom, this is zoom trying to rehabilitate their image through their security partner.
- FreshFries 5y agoPeople hate zoom? Like "Teams is so much better" or "online meeting are bad"? For me it one of the more enjoyable online meeting options and it leaves Teams, Skype, webex and what have you, far behind.
- Throwaway234285 5y agoLike "Zoom is an unethical company". See: Privacy concerns, lying about encryption, connections to china, bad security.
- cstejerean 5y agoThat might be “people on HN hate zoom”.
- Throwaway234285 5y agoFair point. Possibly "people on HN hate zoom, and then use it anyways because it's forced."
- rijoja 5y agoOr how about people on HN are educated about zoom and therefore hate it.
- dylan604 5y agoThat doesn't make them wrong though
- Throwaway234285 5y agoIt doesn't, but it's worth noting that the general populace doesn't feel that way.
- hashkb 5y agoBecause they don't realize how bad Zoom's bad acts could be for them. People didn't feel that cigarettes were bad for them. People don't feel like McDonald's is bad for them.
- vxNsr 5y agoI work for a large MSP, one of our partners announced recently that effective basically immediately they are no longer supporting any zoom integrations due to the China connection.
- kyawzazaw 5y agoa lot of college students do not worry about this
- Taylor_OD 5y agoIts possible to hate zoom without liking one of the alternatives. I know a lot of people hate zoom because they associate it without meeting burning due to this year and security issues.
- chociej 5y agoNever used Teams. Skype, which I last used years ago, was certainly better as far as downloadable chat clients go. Google Meet runs circles around Zoom, and I don't have to install anything.
- chapium 5y agoTo be fair, Zoom is universally well-hated at this point, at least by anyone with an interest in security.
- anoncake 5y agoZoom is pretty well-liked by those who would be stuck with Teams otherwise.
- Moodles 5y agoWhich was also hacked in pwn2own but that's not a big story for some reason https://www.bleepingcomputer.com/news/security/microsofts-windows-10-exchange-and-teams-hacked-at-pwn2own/ https://www.bleepingcomputer.com/news/security/microsofts-wi...
- pydry 5y ago>Imagine if that was your run of the mill well-hated big corp Microsoft seems to be the one banging the "zoom is insecure" drum hardest and teams had, like, 4 zero days and paid < 30K for them IIRC.
- Moodles 5y ago... including an RCE in the very same competition https://www.bleepingcomputer.com/news/security/microsofts-windows-10-exchange-and-teams-hacked-at-pwn2own/ https://www.bleepingcomputer.com/news/security/microsofts-wi...
- mtmail 5y agoZDNet's headline is "Critical Zoom vulnerability triggers remote code execution without user input"
- rijoja 5y agoWhich is more akin to what a person who actually knows what a 0-day exploit is would phrase it.
- dylan604 5y agoWait, are you saying Zoom isn't hated? It's crap. I refuse to install its PoS app and all of the security holes it came with (don't care if they are fixed or not). Launching a zoom meeting in my browser totally bogs the browser down. The zoom site is so slow that proving I'm a human is at least 10x slower than on other sites. In my use case, nobody on the zoom call is even using video, yet it still runs this badly.
- rijoja 5y agoDidn't they route calls through China for no apparent reason as well?
- titzer 5y agoNot without improving the speed of light.
- codefreakxff 5y agoWe run zoom calls with over 200 participants and no problems. It sounds like their browser experience is poor, I don’t know if that’s a browser limitation or bad design, but their app on Windows and Mac performs quite well. Mistakes were made with security early in their product. It’s clear that has turned a lot of potential users against them. I’m curious why companies like Facebook get more acceptance over terrible security, but other companies are never forgiven
- IHLayman 5y agoIf browser performance is bad but app performance is good (and I agree that my experience with the app is actually pretty good), then it is a bad sign that the exploit is in the app, and not the browser version.
- dylan604 5y ago>Mac performs quite well. This is not my experience at all. Early in the lockdown when Zoom became the darling, I was forced to install their app. Pre-pandemic, Zoom was already panned on this site for crap they were doing, so I pushed back hard against using Zoom before ultimately relenting. Running zoom with a simple 3 person call would bog down my 2017 MBP with fans running full tilt. I've since upgraded hardware and zoom is not allowed to be installed on this computer. >I’m curious why companies like Facebook get more acceptance Is there anyone on this site that agrees with that comment? I certainly don't. There are multiple billions of FB users, so I'm quite sure the readers of HN is just a mere rounding error level of numbers.
- ajross 5y agoI don't think that's fair. The Pwn2Own contest rules specifically disallow disclosure. This isn't a "zero day" in any sense but marketing. It's a privately disclosed vulnerability under a managed embargo, just as if it had been reported by Project Zero or whoever. The ding is that, because it was a "public contest", the existence of the vulnerability is known. And that's probably a higher risk scenario in the abstract I guess. But I think it's clear to all that Pwn2Own and similar activities are a net benefit to global software security nonetheless.
- grayhatter 5y agofinally, someone who uses 0day more correct than nearly every else. My remaining sanity thanks you!
- teawrecks 5y agoI'm not seeing how your point relates to bezoz's point...
- jms703 5y agoThis. The article should have been less about 0days and more about supporting contests and programs that vulnerability researchers.
- coverband 5y agoIt’s actually worded in quite that way (even though it’ll be picked up by larger media differently).
- whatgoodisaroad 5y agoMaybe the zero-day isn't disclosed from this pwn2own itself, but importantly, we now know it exists, which means we should consider how many bad actors are already independently aware of it and are exploiting it. Responsibe disclosure processes are just as much about closing the vectors that we can't prove are under active exploit.
- 5y ago
- II2II 5y ago> Imagine if that was your run of the mill well-hated big corp I don't know what the general perception of Zoom is. Our opinions of it never really come up at work. The discussion I see of it online largely focuses upon the security issues so that is going to be negative. There is one thing I am grateful for though: it seems as though the masses settled on a product with decent cross-platform support for once. You rarely see that unless the product is intended for a niche market (e.g. science, engineering, software development). Heck, they even package it for Arch.
- kiwijamo 5y agoIndeed. It is really nice to be able to participate in group and conference calls from Linux without having to reboot into windows or macos. Also performs well in all the platforms I've used it in which is not something I can say for teams and Google meets.
- c7DJTLrn 5y agoChernobyl nuclear power plant explodes and paves way for safer reactor design!* *citizens not yet evacuated from radiation zone
- deleted 5y ago[deleted]
- hashkb 5y agoUsing Zoom on Linux is a fun way to get everything to crash; and may as well flip a coin to see if I'll get connected / anyone will be able to hear me. Google Meet, Slack calls, literally everything else works perfectly. With screenshare. On Wayland. I just call in to Zooms now.
- LoneWolf 5y agoThis so much, also eats way too much CPU, and has no support for background blur, just a damn basic chroma.
- toomanyducks 5y agoI use Zoom fairly regularly, and haven't had *too* many issues. (Debian, x11, the app, though the browser version is fairly terrible)
- TwoBit 5y agoI've read that AV is a dumpster fire on Linux and you're lucky if anything runs and Linux has never solved it and no resolution in sight.
- not2b 5y agoMy wife has been doing a ton of Zoom on an Ubuntu system on a Dell laptop, using their native app. She hasn't had problems. Clearly your experience differs, not sure why. Of the proprietary video meeting apps, they all have problems, but Zoom sucks less than Teams, Webex, or Skype and is a lot easier for non-technical folks to use.
- kiwijamo 5y agoI'm in the same boat. I use Zoom frequently on Linux and it's performance is quite acceptable. I use Zoom successfully on other platforms as well. It compares well to altneratives such as Google Meets which in my experience starts to fall apart past a certain number of participants on a call. Quite interesting to see the variance of experiences as it doesn't match what I've observed personally as well as comments I've heard from colleagues who have tried various systems. I hear lots of praise for Zoom and Teams but Meets is either loved or hated.
- lostgame 5y ago>> Imagine if that was your run of the mill well-hated big corp Zoom is one of my, and several of my coder friends', top-five well-hated big corps. This far into the pandemic, I take personal pride that I hadn't installed what for a while was essentially reported as Chinese spyware on my machines. :)