40 ms·
Ask HN: Why does Zoom Desktop examine all processes and arguments?
Looking at syscalls, I see Zoom desktop reads all processes and arguments.
[pid 3844872] stat("/proc/1", {st_mode=S_IFDIR|0555, st_size=0, ...}) = 0
[pid 3844872] openat(AT_FDCWD, "/proc/1/stat", O_RDONLY) = 4
[pid 3844872] openat(AT_FDCWD, "/proc/1/cmdline", O_RDONLY) = 4
[pid 3844872] readlink("/proc/1/exe", 0x20c0520, 1024) = -1 EACCES (Permission denied)
[pid 3844872] stat("/proc/2", {st_mode=S_IFDIR|0555, st_size=0, ...}) = 0
[pid 3844872] openat(AT_FDCWD, "/proc/2/stat", O_RDONLY) = 4
[pid 3844872] openat(AT_FDCWD, "/proc/2/cmdline", O_RDONLY) = 4
[pid 3844872] stat("/proc/3", {st_mode=S_IFDIR|0555, st_size=0, ...}) = 0
[pid 3844872] openat(AT_FDCWD, "/proc/3/stat", O_RDONLY) = 4
[pid 3844872] openat(AT_FDCWD, "/proc/3/cmdline", O_RDONLY) = 4
...
Why would it do that? Is there any way to prevent it?
- gigatexal 5y agoIm on a Mac so I can’t issue the same … did you use strace on Linux? This is enough for me to remove the app and just use it in the browser.
- saurik 5y ago> Im on a Mac so I can’t issue the same... dtruss
- lsllc 5y agoSadly running dtruss on (modern) macOS requires disabling system integrity protection.
- MrWiffles 5y agoI don't remember the option off-hand, but there's a way to leave SIP enabled, but still allow dtruss too on modern MacOS. You'd have to Google it up, but that option does exist (I just can't remember the name off hand). Saw it about ~4 weeks ago while doing some research.
- beaugunderson 5y agoLooks like you're referring to this, from June: https://poweruser.blog/using-dtrace-with-sip-enabled-3826a352e64b https://poweruser.blog/using-dtrace-with-sip-enabled-3826a35... Sadly it's a little more involved (a chroot which removes all codesigning bits) than a simple option, but I'm glad to have found a way to do it all.
- deleted 5y ago[deleted]
- ianlevesque 5y agoZoom is basically malware with video chat.
- barbazoo 5y agoElaborate please
- infamouscow 5y agoThis really should be self-evident
- miles 5y ago‘Zoom is malware’: why experts worry about the video conferencing platform https://www.theguardian.com/technology/2020/apr/02/zoom-technology-security-coronavirus-video-conferencing https://www.theguardian.com/technology/2020/apr/02/zoom-tech... Zoom banned from New York City schools due to privacy and security flaws https://www.fastcompany.com/90486586/zoom-banned-from-new-york-city-schools-due-to-privacy-and-security-flaws https://www.fastcompany.com/90486586/zoom-banned-from-new-yo... Google Told Its Workers That They Can’t Use Zoom On Their Laptops Anymore https://www.buzzfeednews.com/article/pranavdixit/google-bans-zoom https://www.buzzfeednews.com/article/pranavdixit/google-bans... Elon Musk's SpaceX bans Zoom over privacy concerns https://www.reuters.com/article/us-spacex-zoom-video-commn/elon-musks-spacex-bans-zoom-over-privacy-concerns-memo-idUSKBN21J71H https://www.reuters.com/article/us-spacex-zoom-video-commn/e... Zoom lied to users about end-to-end encryption for years, FTC says https://arstechnica.com/tech-policy/2020/11/zoom-lied-to-users-about-end-to-end-encryption-for-years-ftc-says/ https://arstechnica.com/tech-policy/2020/11/zoom-lied-to-use... Zoom security issues: Here's everything that's gone wrong (so far) https://www.tomsguide.com/news/zoom-security-privacy-woes https://www.tomsguide.com/news/zoom-security-privacy-woes Maybe we shouldn’t use Zoom after all https://techcrunch.com/2020/03/31/zoom-at-your-own-risk/ https://techcrunch.com/2020/03/31/zoom-at-your-own-risk/ Attackers can use Zoom to steal users’ Windows credentials with no warning https://arstechnica.com/information-technology/2020/04/unpatched-zoom-bug-lets-attackers-steal-windows-credentials-with-no-warning/ https://arstechnica.com/information-technology/2020/04/unpat...
- wins32767 5y agoIf I had to guess it's for screen sharing.
- sithadmin 5y agoThis. It enables single-app share, instead of just capturing entire displays.
- akira2501 5y agoUnless I'm missing something.. all of the required information is available through the X11 protocol. Reading the command lines of the processes is unnecessary and provides data that isn't useful in the window sharing context.
- jraph 5y agoThis would not work on Wayland, though.
- bonzini 5y agoWayland is even more strict, you ask it for screen sharing and it gives you the stream. If the compositor doesn't support screen sharing you're out of luck, there's just no way to read the contents of a window. With X11 if the window manager doesn't have the relevant support you can always ask the server.
- mnd999 5y agoZoom doesn’t support screen sharing on Wayland, except through some propriety Gnome API. It also doesn’t run at all for me on sway, just crashes at startup.
- yjftsjthsd-h 5y agoHow would that work? I would expect it to enumerate X clients, not PIDs
- laurensr 5y agoAlso note the news and discussion at https://news.ycombinator.com/item?id=28210076 https://news.ycombinator.com/item?id=28210076
- tryauuum 5y ago(incompetence here) Maybe it's like discord, it does the same to display messages like "$username is playing terraria right now"
- wwweston 5y agoDiscord leaks which apps you're using to other people?
- Osiris 5y agoIt's a feature.
- dcdc123 5y agoYeah, I highly recommend disabling it.
- egypturnash 5y agoSo does Steam. It’s... a little creepier when it’s taken beyond “advertise which games you’re playing so your friends can potentially join you”, though.
- delusional 5y agoAre you sure? I think steam only does it for programs launched through it.
- spockz 5y agoSteam only does this when you launch an app through steam and only when it is enabled though. That is quite a difference from broadcasting the name of any binary it recognises.
- LegitShady 5y agoby default, even.
- humaniania 5y ago
- akira2501 5y ago> Is there any way to prevent it? Put it into it's own namespace, and only allow it to connect to your X11 session over TCP.
- mishafb 5y agoI think only Wayland has real security, X11 lets you do anything
- phendrenad2 5y agoDoes that prevent it from reading from `/proc`?
- jraph 5y agoIn a PID namespace [1], it will be able to read /proc, but will see nothing interesting other than a strangely empty system. The process is isolated from the rest of the system as far as processes and PIDs are concerned. [1] https://www.redhat.com/sysadmin/pid-namespace https://www.redhat.com/sysadmin/pid-namespace
- zzo38computer 5y agoIf you want to prevent programs from accessing other windows, then (in addition to using its own namespace and file access) you would also need to proxy the X server, or run it in a nested X server (which does not have access to the one outside).
- yjftsjthsd-h 5y agoSpecifically, Xephyr is generally the go-to option, although there are others.
- kamray23 5y agoFor a more general solution, firejail.
- luke2m 5y ago> Is there any way to prevent it? Use a flatpak
- phendrenad2 5y ago> Is there any way to prevent it? Maybe run it in a chroot?
- jagged-chisel 5y ago> Is there any way to prevent it? Hook the stat, openat, readlink functions within the zoom process, experiment with blocking (returning failure) based on arguments.
- deleted 5y ago[deleted]
- dllthomas 5y agoOr just don't let it run pidof.
- MattGaiser 5y agoAnd for people giving ways to prevent it, can you please provide some context for those of us who aren't OS experts?
- dsr_ 5y agoIf you must use zoom, use it in a browser; uninstall their app.
- elliekelly 5y agoI must have uninstalled their app on my Macbook ten times now but somehow it keeps coming back. I’ll click a link to join a meeting and the app launches.
- agustif 5y ago> https://news.ycombinator.com/item?id=28210076 https://news.ycombinator.com/item?id=28210076 They recover the app from your backups if available when launching. Try appCleaner or something like that, and you might need to delete it from any TimeMachine backups too, lol
- GekkePrutser 5y agoThis is exactly the kind of dickery I hate zoom for. The same thing with installing a backdoor and then blatantly refusing to remove it when found out. Luckily Apple did the job for them :P Their attitude is so wrong. I don't understand how people still use it.
- MattGaiser 5y agoI didn't know that Zoom allowed that. Thank you.
- dheera 5y agoYou have to pretend that Zoom doesn't work and then it eventually gives you the "join from browser" link. When you click on a Zoom meeting, it will prompt you to launch xdg-open -- cancel it. Then hit launch again -- cancel the xdg-open again -- and then the "Join from browser" link should pop up after a few times. Sometimes it tries to capture you, I had to click on trucks and trains for 15 minutes before it let me in, and then had to apologize for being 15 minutes late to the meeting.
- reilly3000 5y agoZoom has a popular feature which allows for screen sharing a single application window instead of the entire desktop. I assume this is how its discovering running applications with GUI windows open in a cross-platform manner. Perhaps there is a better API for this? Its not a common use-case that an app would need to know all of the other open windows, but it seems like a perfectly valid use case, and frankly handy for sharing a PPT without fear of an embarrassing email showing up in during a meeting.
- sails 5y agoDoes Teams do this in the same way? They offer the same feature
- sniperjzp 5y agoNot sure about Teams, but Google Meet allow you to share a specific browser tab, I don't know how to implement it without reading all the opened tabs.
- meibo 5y agoThere is a JavaScript API that abstracts this, so Google Meet/whatever asked can only read the "final" video stream of what you selected and not everything that's going on, which stays in your local browser.
- Flame 5y agoTeams lets you share an application window or your display(s).
- saikan 5y agoand "Window sharing isn't available for Linux users." https://support.microsoft.com/en-us/office/share-content-in-a-meeting-in-teams-fcc2bf59-aecd-4481-8f99-ce55dd836ce8 https://support.microsoft.com/en-us/office/share-content-in-...
- 5y ago
- dng88 5y agoWould it be better if run in a vm?
- fsflover 5y ago> Is there any way to prevent it? I prevent it by running Zoom in a VM on Qubes OS.
- ezekg 5y agoOr just run it in a browser...
- fsflover 5y agoCan you run it in a browser without an account?
- forgotpwd16 5y agoIf the meeting is open (join by invite link), yes. It's basically how Zoombombing happens.
- MichaelGroves 5y ago> Is there any way to prevent it? Do what I do: Run it on a burner computer connected to your guest network.
- 0xbadcafebee 5y agoHah! Only a fool would run it outside of a completely sound-isolated windowless underground faraday cage. Otherwise The Men In Black will find out about your blockers in your stand-up meeting!
- dllthomas 5y agoI'm more worried about our jokes.
- gwbas1c 5y agoJokes aside, you can probably get close to that by running Zoom in a VM with NAT. Unfortunately, sound and camera tend to be sketchy in a VM.
- fsflover 5y agoWorks fine for me on Qubes OS.
- jlgaddis 5y ago> Is there any way to prevent it? Mounting /proc with "hidepid=2" should prevent it from seeing processes owned by other users, although it would still be able to see your processes. Alternatively, it shouldn't be too hard to create an AppArmor profile that blocks access to /proc. Other options might include things like SELinux, seccomp-bpf, namespaces, cgroups, etc., depending on what's available on your host. Or you could just, you know, obliterate it from your system altogether. That's almost certainly the best option.
- hdjjhhvvhga 5y agoI don't understand why anyone who is forced to use it doesn't use it in a browser (I have a separate Firefox container for that, same for Teams).
- vbernat 5y agoFor me: more CPU usage (and more battery usage), not able to see other participants when sharing screen. But I am running Zoom in a Flatpak to avoid the kind of issues reported here. BTW, the same happens with Discord and it's not possible to disable it.
- rocqua 5y agoDiscord does it to detect which game you are running, so it can display "user is playing X" to your friends.
- avel 5y agoThe browser edition of zoom lacks a lot of features and also lacks in performance. It's not like BlueJeans which has a web version pretty much aligned with the desktop client.
- maxk42 5y agoThat's what they're counting on.
- 5y ago
- 3r8Oltr0ziouVDM 5y agoWhen you run proprietary software, you basically give full control over your computer to a third party. For the best security use a separate physical machine for stuff like this. Or a separate operating system (in such case your primary system should be encrypted and have a protected boot loader). Or at least a VM.
- the8472 5y ago> Is there any way to prevent it? Firejail[0] allows cobbling together various linux sandboxing features, including namespaces which should result in an isolated proc filesystem which doesn't see the other processes. But I don't know if the default profile for zoom does that, you have to test it or write your own. [0] https://github.com/netblue30/firejail https://github.com/netblue30/firejail
- als0 5y agoJust checked the default profile and it looks sufficiently isolated
- guerrilla 5y agoSELinux being another. Smack too, if people still use that.
- kamray23 5y agoAUR has a package for "zoom-firejail" which ships zoom binaries with a ready-made configuration and .desktop for launching it in firejail. Goes to show how little people trust Zoom.
- andrewlevi 5y agoDoes Teams or Discord do anything similar?
- P9TXJYG0TENG 5y agoDiscord does. It makes some sense, since Discord has a feature to broadcast what game you're currently playing (or anything you want), but I found it was scanning /proc even when I turned this off. I didn't like that, and I spent a lot of time and effort working out various ways to keep it out of /proc (or anywhere else while I was at it- mostly with AppArmor) and ultimately ended up running it in a container with systemd-nspawn. This is still a little bit fiddly, but seems to work reliably and without any issues.
- lathiat 5y agoThe discord snap blocks this with apparmor by default unless you connect process-control. But it also fills your kernel log with audit denials.
- P9TXJYG0TENG 5y agoI think I tried one of those alternative app distribute-y things at the time, but I don't remember which, and I came away disappointed. If memory serves, I couldn't establish whether it actually did any sandboxing, or what it did by default (like intentionally opening up this exact hole), and certainly not how to configure it, and gave up shortly in favor of something I'd at least seen before. It might have been Snap. I don't like Snap.
- orangea 5y agoWouldn't it be easier to just run it in a browser?
- P9TXJYG0TENG 5y agoThat's probably the better answer, yeah. I think there's a couple of features that don't work very well in the browser (push to talk?), but the actual answer is that it probably simply didn't occur to me at the time. I use both these days.
- GekkePrutser 5y agoI know a really good way to prevent it. Don't use zoom :) Seriously they've done so many things that show they don't care about privacy. Like that backdoor on Macs. But if you really must, use the web version only. If you can avoid it, jitsi is a great alternative. Much smoother video than teams and much lighter
- 99mans 5y agoBecause they can get away with it and use it to make more money from your "experience".
- kevmo 5y agoZoom is pursuing surveillance profits. Shoshanna Zuboff has an excellent book on "surveillance capitalism", if you want to read more on the trend.
- dllthomas 5y agoThey may be, but this case is not related unless someone is paying big bucks to know the pid of gnome-session.
- amelius 5y agoI've used the method of scanning the environment variables of other processes to find the PID of certain applications which advertised themselves using their environment variables. This could be similar?
- dllthomas 5y ago> Why would it do that? We can answer part of that with just a little more reading. What's pid 3844872? For me, the series of queries against /proc happen from a process that, just a bit earlier, called exec. So it's not really zoom reading "all processes and arguments" but ... `pidof gnome-session`, so I guess zoom is looking for the pid of gnome-session. To what nefarious purpose zoom intends to put this knowledge of gnome-session's pid, I can't say - I am not running gnome-session so my trail goes cold; but at least for me, for that particular run, zoom itself doesn't actually see the contents of all of those files.
- thxg 5y ago^ This is the correct answer. I installed the Zoom client just to have a look for myself. The syscalls in question emanate from freshly forked processes that immediately execvp() the command `pidof` (on my system it finds it under /usr/bin, so it's the system command, not anything fishy shipped by Zoom). Actually, the command-line argument to the command is, in succession: gnome-session gnome-panel gnome-shell gnome-session-binary ksmserver cinnamon cinnamon-session mate-panel mate-session xfce-mcs-manage xfce4-panel xfce4-session I suppose Zoom goes through the whole list on my system because it finds none of them. The fact that it stops on parent's system suggests that Zoom stops when it finds one. This hints at a very crude way to determine the desktop environment!
- thxg 5y agoHmmm... maybe Zoom devs too use Stack Overflow? https://stackoverflow.com/questions/3376679/qt-how-to-detect-whether-the-application-is-running-on-gnome-or-kde https://stackoverflow.com/questions/3376679/qt-how-to-detect...
- kamray23 5y agoGod damn it, why do terrible SO suggestions find themselves in every application?
- 5y ago
- aFaid7see0ni 5y agoZoom has a paid feature to view processes of other meeting attendees. Yes. Scary.
- pizza 5y agoCan you explain this? Not sure how to look this up
- phgn 5y agoI don't believe that, would be way too scary. Do you have a link?
- Gene_Parmesan 5y agoThis seems to be a viral inaccuracy: https://www.howtogeek.com/664624/does-zoom-really-monitor-which-apps-youre-using-on-a-call/ https://www.howtogeek.com/664624/does-zoom-really-monitor-wh... That article claims that Zoom does have a feature allowing hosts to see whether people have the zoom window focused while someone is presenting, but it doesn't allow the host to actually see running processes. Note that I can't, nor do I claim to, vouch for the accuracy of the explanation in the link. Just something I found.
- EMM_386 5y ago> That article claims that Zoom does have a feature allowing hosts to see whether people have the zoom window focused while someone is presenting It used to but it was removed. https://support.zoom.us/hc/en-us/articles/115000538083-Attendee-attention-tracking https://support.zoom.us/hc/en-us/articles/115000538083-Atten...
- dmart 5y agoPerhaps a better question to ask would be "why is any process allowed to do this by default in 2021?"
- acatton 5y agoBecause it's a legitimate behaviour. htop needs to do this, it's literally its main feature. You can use hidepid=2 to prevent users from seeing other user's processes list.[1] But I don't want my OS to ask me "do you want to allow htop to access the list of your processes" — à la Windows Vista — every time I want to run htop to see my user processes. The issue here is closed source software with no way to inspect what they do. If one really want to run closed source programs which were not vetted by their distro's maintainers, they should use firejail.[2] [1] https://www.cyberciti.biz/faq/linux-hide-processes-from-other-users/ https://www.cyberciti.biz/faq/linux-hide-processes-from-othe... [2] https://firejail.wordpress.com/ https://firejail.wordpress.com/
- mixmastamyk 5y agoWhitelisting htop would be a simple matter.
- gwbas1c 5y agoI think the nags discourage sketchy behavior. It makes some of the lackluster product managers think twice about unreasonable program behavior.
- OJFord 5y ago> But I don't want my OS to ask me "do you want to allow htop to access the list of your processes" — à la Windows Vista — every time I want to run htop to see my user processes. Why would it be every time? Say yes once to htop, no to Zoom. Sort of like Android/iOS permissions. Or just require root. No way I'd give it to Zoom, htop maybe.
- acatton 5y agoThe issue is that the model on Linux is different. As opposed to walled gardens, the assumption is that applications are cooperative, therefore there is no need for such "authorization systems". The security model on Linux is based on blacklist, with solutions like firejail. Also, what's the points of these nags? Most people will just say "OK" anyway because they want to access the features they were promised.
- xfitm3 5y agoIt not only examines all processes and arguments - it leverages the microphone to act on ultrasonic cues for "integrations". Zoom is a privacy dumpster fire. https://devforum.zoom.us/t/ultrasonic-connection/3318 https://devforum.zoom.us/t/ultrasonic-connection/3318
- acatton 5y agoIt also plays your user-name (when configured by the meeting owner) in the background at a non-audible frequency, so that companies can find out who leaked their meetings by analysing the audio from the leak. https://theintercept.com/2021/01/18/leak-zoom-meeting/ https://theintercept.com/2021/01/18/leak-zoom-meeting/
- IG_Semmelweiss 5y agoI thought this thread was full of sarcasm and then I see the links. I should have known better. I am glad this is getting posted because we need reminders of the reality we live in
- dathinab 5y agoYes there are reasons besides conflicts with US law and they not having German Servers which makes it completely GDPR in-compliant and de-facto legal unusable in the EU. (Not that anyone seem to care.)
- deleted 5y ago[deleted]
- kamray23 5y agoWell that's easy enough to defeat if oyu know of it.
- agumonkey 5y agoThanks a lot, its now fully trollable.
- deleted 5y ago[deleted]
- mcrmonkey 5y agoI can only think the most direct usage for this info is to feed the performance screen/tab that lives in settings showing CPU and memory usage But some of the info its reading seems a little bit too much cough 'telemetry' cough
- 0xbadcafebee 5y agoIt's not really worth wondering. There are a million potential reasons that you and I don't know or can't come up with, but they may have a specific reason for. You can probably prevent it with capabilities, or selinux, or with a container. Unless you just enjoy the fashion statement of tinfoil hats, it's not worth it.
- sneak 5y agoThe way to prevent it is to not install their poorly engineered spyware and only use the sandboxed web app. You'd have to be crazy to install Zoom given their history.
- sunkenvicar 5y agoBecause it is made in china.
- vishho 5y agoZoom has attention tracking, which when enabled silently, shows an admin if the screen is maximized or if the user is focused on other applications. They don't yet tell admins what other apps the user is active in, just whether the user is active. Another angle for Zoom to do that, is that it is a massive Chinese spyware application, which can target users by meta data or IP, like it did by messing with the calls of activists. A bit like how anti-virus companies are sometimes charged with exfiltrating secret documents.
- bowmessage 5y agoOh, yuck, I didn't know this was a thing but it looks like it has since been removed: https://support.zoom.us/hc/en-us/articles/115000538083-Attendee-attention-tracking https://support.zoom.us/hc/en-us/articles/115000538083-Atten... > As of April 2, 2020, we have removed the attendee attention tracker feature as part of our commitment to the security and privacy of our customers. For more background on this change and how we are pivoting during these unprecedented times, please see a note from our CEO, Eric S. Yuan.
- hashhar 5y agoThat feature got pulled last year and hasn't existed for over a year and a half now.
- gwbas1c 5y agoI'm going to assume this happens when you aren't trying to share your screen. I once worked on a file synchronization application that would scan processes when files were locked. I don't remember if we put the process name in the UI, but we logged detailed information about the other process in case someone contacted support. (Sometimes users ran weird applications that kept files locked.) I believe we had to scan through all processes and inspect their open file handles. I would assume some things like: Maybe there are applications that are known to cause problems for Zoom? Maybe some applications lock the camera or microphone? Maybe some applications hog the CPU and cause encoder problems? If you really want to know more, consider decompiling zoom and/or looking at strings compiled into the binary.
- dllthomas 5y agoIt happens right at startup, and is a result of some calls (via the usual fork/exec dance) to `pidof ...` seemingly trying to identify the window manager being used, possibly for telemetry or possibly to change behavior. Decompiling would be more certain (I don't have ghidra on this computer and it's a little more effort than I want to go to) but the pattern is pretty visible in the strace dump.
- gwbas1c 5y agoMaybe it has to alter behavior based on your distro? IMO, if you can't/won't reverse engineer, maybe see if you can contact Zoom support and see what they say? Obviously the support people won't know, but if you can ask the right way they might pass your question on to the developers. For the file sync client, we got all kinds of oddball questions passed along from support to developers; and we'd make an honest effort to answer reasonable ones.
- dllthomas 5y agoNot a bad thought, though ghidra would be more fun.
- nullc 5y agoHow else would they backup your command-line passed passwords and private keys for you?
- cranekam 5y agoI assume this is a joke comment because I have never heard of passing a private key (the contents of one, not the file name) as a command line argument. It’d be ten times worse than asking what someone’s wifi password was and being told some 40-digit hex string.
- noobermin 5y agoI'll be annoying and say if people used the FOSS alternatives we wouldn't have to be so paranoid about a tool we all use.
- swiley 5y agoYour crap is being exfiltrated. Stop using non-free software if you're doing anything important on that machine.
- egberts 5y agoPolling for all processes is the technique used by some educators’ quiz/test/exam program. Zoom is probably footholding their place as to be able to inform its educator whether their students’ behavior are acceptable or are cheating. Most probably.
- ayush--s 5y agoSo should I move it to docker? Since X11 socket will be shared, I'm assuming screen sharing might work