5 ms·
Can we please edit the headline. This sounds disingenuous, a more appropriate headline would be something like "critical vulnerability in Zoom Video Calls that
by vthallam 6y ago
Can we please edit the headline. This sounds disingenuous, a more appropriate headline would be something like "critical vulnerability in Zoom Video Calls that would have put millions of users at risk has been found".
This feels like a straight up PR piece.
- rijoja 6y agoSeconded! Only a PR person would dream of saying that a 0 day exploit is a good thing. I expect that most HN readers just finds this hillarious, but still people read HN since it has a good standard. Saying that a 0 day exploit is a good thing goes against this needless to say. Especially since they've faced serious accusations earlier on.
- brundolf 6y agoIt's very clearly sarcasm and not a serious PR move, though I agree it makes the article confusing and hard to follow. Changing it to a different source link seems appropriate.
- rijoja 6y agoI don't really think a communication from Malwarebytes is the place for sarcastic comments. Lets say if you are working with a US government this could have enormous implications. I've talked to a lot of clients who ditched Zoom for Microsoft Teams due to their earlier mistakes. Also I find it funny that the heading "Not patched yet" is solved by the headline "Security done right". Lets say if you are working with a company that deals with say healthcare information a 0-day certainly doesn't make things safer and since it is not patched yet this is definitely not done right.
- okamiueru 6y agoHow can it be very clearly something, and at the same time confusing and hard to follow?
- dylan604 6y ago>Only a PR person would dream of saying that a 0 day exploit is a good thing Depends on your perspective. a 0-day is a very good thing if you are an advesary trying to get in. so maybe to the alphabet soup of groups CCP, FBI, NSA, etc, woohoo!!!
- toomanyducks 5y agoWell, as is previously mentioned, it's not _quite_ a 0-day, and finding it and responsibly disclosing it is a very good thing *compared to alternatives*. I do agree, though, that the tone is needlessly confusing, and it feels like PR over clarity.
- charcircuit 5y agoHaving critical zero days being reported is always a good thing.
- HenryBemis 5y agoBut I thought we call them "zero day" when they are already being abused. I didn't get from the article that this vulnerability has been discovered and abused by the baddies. Thus it is NOT a "zero day" but a "critical vulnerability". Sod the clickbait-y titles!
- jacobr1 5y agoIt doesn't need to be exploited to be a zero-day, just not yet mitigated.
- JaggedJax 5y agoRight, isn't this not a Zero Day specifically because it's not known to be exploited out in the wild. How can it be, no one else knows what the vuln is. It is being reported as part of a bug bounty with 90 day disclosure just like anything else would be.
- nixpulvis 5y agoI always get confused reading/talking about the definition of a zero-day with people... But this is what Wikipedia states, which is most consistent with my understanding. > A zero-day (also known as 0-day) is a computer-software vulnerability unknown to those who should be interested in its mitigation (including the vendor of the target software). Until the vulnerability is mitigated, hackers can exploit it to adversely affect programs, data, additional computers or a network. Seems like someone knows how to exploit this, and zoom / the general public don't know how to mitigate or perform it. That seems to fit this definition, no?
- charcircuit 5y agoA zero day just means that the vulnerability hasn't been patched.
- tptacek 5y agoThe term "zero day" has nothing to do with in-the-wild exploit observation.
- javierbyte 5y agoAgree, but instead of "that would have put" it should be "that could be putting", we don't know if there are people currently exploiting the vulnerability and without a patch very well could be happening now.
- interestica 5y agoI really wish there was a changelog for headlines. Too often I see a critique like this and I have to figure out if the comment is referring to the current headline or a previous version. And, if the headline has already unknowingly been 'corrected', it leaves me wasting time trying to figure it out within that framing. And it shouldn't be the responsibility of the poster necessarily to quote it -- because there's no verifiability there.
- swsieber 5y ago> And it shouldn't be the responsibility of the poster necessarily to quote it -- because there's no verifiability there. Although there's no verifiability there, I would assume that most people on here comment in good faith.
- vngzs 5y agoThe original title was the article title: Zoom zero-day discovery makes calls safer, hackers $200,000 richer
- chrononaut 5y agoExactly. It would be nice if there was a little arrow (or other icon) next to the title of an article that simply showed the previous titles that article used -- much like previous gaming handles on Steam profiles; Simple yet effective.
- mssundaram 5y agoHackerNews is pretty opaque with its moderation
- EE84M3i 5y agoLike https://hackernewstitles.netlify.app/ https://hackernewstitles.netlify.app/ ?
- Black101 5y agoa change log of everything the admins do would be nice, because they control a lot of the content that you and me see... they move threads to other posts, they hide posts... etc... they don't like to let nature take its course.