5 ms·
Not the first time Zoom abuses privilege. A few years back, there was something about gaining root on MacOS via Zoom due to shady execution on their end. They
by rmellow 21d ago
Not the first time Zoom abuses privilege.
A few years back, there was something about gaining root on MacOS via Zoom due to shady execution on their end.
They've lost my trust since then, and I'll only run it sandboxed: https://gist.github.com/cielavenir/02f322e322a2a3555dbf2b38f2fedd59 https://gist.github.com/cielavenir/02f322e322a2a3555dbf2b38f...
I always ask (1) why does an app require installation and (2) why would it require root?
There are valid answers for both, but realistically, all a videoconferencing app should need (apart from audio and video and maybe screen sharing) is to store a config file.
There's no legitimate use for it accessing privileged or private paths.
- mcintyre1994 21d agoOut of interest why do you still use the app and not just use it in the browser? I feel much more secure having it in the browser sandbox and everything I care about works in the browser.
- rmellow 21d ago99% of the time I use the browser. However, the video quality in the browser is worse, so depending on the use case I might have to use the app (via sandbox). It's been years since I've had to though.
- 3eb7988a1663 21d agoNot parent, but the web player used to be a down-graded experience from the native app. If you need Zoom for a professional setting, those functions could be important. Do not know if this is still true, but at one point, the web player would only let you see one speaker at a time, while the app would show multiple people at once.
- DANmode 21d agoSo the web is a better experience!
- hdgvhicv 21d agoI always turn off incoming video on teams. Waste of bandwidth and cpu, so I don’t see the loss there.
- c-hendricks 21d agoI've been using the web client for over a year and that hasn't been the case the whole time, gallery view is an option.
- 3eb7988a1663 21d agoWell this was back in COVID, sometime fresh after the always-open-port news had surfaced. Can easily believe the experience has been improved since then.
- asveikau 21d agoI notice the browser version is a little resource intensive. I use it on freebsd and I need to renice the browser to -10 for it to be somewhat stable. (This is an improvement because I remember 6 years ago it didn't work on freebsd.) I ran it on a Mac last week and it spun the fan more than I'd expect.
- DANmode 21d agoClose it when you’re done with the meeting.
- MrDrMcCoy 20d agoBy that time, your battery may already be dead.
- lxgr 21d agoLast time I looked at their web client, it was indeed doing absurd things (I think it used TCP and web sockets to carry video instead of WebRTC and shipped a WASM video codec that obviously can’t be GPU/hardware accelerated). Not sure if that’s malice (to nudge people towards using their invasive desktop app) or incompetence.
- asveikau 20d agoThat explains a lot. I would guess incompetence.
- zdc1 21d agoI recently had to use the browser and was shocked to find there was no option for Gallery View. You were just stuck with one square in the middle that would bounce between different faces. I feel like they have the worst web experience out of all the meeting apps.
- duskdozer 21d agoI always try to use browser versions of things, but zoom just hasn't worked for me in it for changes. No error messages or anything, just insistence on downloading the app. I assumed they got rid of it but I guess not.
- dotancohen 21d agoThe link is just smaller, and I think the text is now something to the effect of "Can't Download App" or similar.
- wolvoleo 21d agoYes Apple even blocked their app because they refused to fix it. Eventually they did and unfortunately they were allowed again. It wasn't really root as much as an open backdoor on a TCP port as far as I recall.
- blake8086 21d agoI worked at Zoom during this time. That's not what happened. Zoom used the same technique Cisco Webex did - they ran a webserver with an open port so that local "links" to a meeting could open on your own machine. It wasn't a backdoor. Apple flagged that as a potential security risk, so Zoom worked with Apple on how to safely remove only the webserver without affecting other functionality. We were happy that Apple worked with us on this. However, I thought it was very interesting (and strange) that there was almost no reaction from the tech community that Apple had software running on every Mac that allowed them to remove any binary they wished. (Which sure sounds like a backdoor)
- wolvoleo 21d agoApple did block the app so the 'working with Apple' didn't exactly earn Zoom a lot of trust with them otherwise they wouldn't have done it. They'd have let Zoom fix it in an update. And just make that update mandatory. They were just looking out for their own customers in limiting the impact, but for them to pull this handbrake means they really saw this as a big risk. 'But Cisco did it too!' is just whataboutism. It was shown to be exploited (IIRC to open scam websites) which was a real backdoor and a legitimate security risk, not a potential one. This is something that should never have happened in the first place. Even releasing something like this in the first place is really showing no concern for the security of customers at all. What it looks like to me is that zoom wanted to conquer the market by ease of use and was willing to sacrifice security to do it. The zoombombing thing was another example. And yes Apple has an emergency brake for malware outbreaks. And they've only used that one for high profile apps once, for zoom. They didn't do that lightly, especially during the pandemic when people were depending on it. Really I have no good words for the actions of zoom. And there have been more incidents. I was involved in mitigating these screwups in my work, what we did was flag zoom as malware ourselves so it automatically got removed from every company machine. And block it from being installed by the user. This block is still in place. Ps I'm sorry if I sound harsh but zoom has caused several security worries at work and we don't even use it.
- spondyl 21d ago> A few years back, there was something about gaining root on MacOS via Zoom due to shady execution on their end. > There's no legitimate use for it accessing privileged or private paths. Well, that was the whole premise that made Zoom popular in the first place! It was a true one click install which made onboarding frictionless for non-technical users Security wise, it's insane but user experience wise, it was unbeatable and is what solidified their position. It's ironic nowadays that all of those tricks have been stripped away, making it just as painful as any other platform to install on a fresh machine.
- samus 21d agoUnfortunately making software easy to install also makes it easier for Malware to be installed. It's a classic dilemma that is only fixable by making the user think twice about running stuff from the internet: Unix requires making the file executable, Windows at some point started tagging downloaded files with an "untrusted" attribute.
- bmacho 21d ago> They've lost my trust since then, and I'll only run it sandboxed: https://gist.github.com/cielavenir/02f322e322a2a3555dbf2b38f https://gist.github.com/cielavenir/02f322e322a2a3555dbf2b38f... On Linux/X11 even when you run a program sandboxed or as a different user if you use a master Xserver the sandboxed program still can listen and modify all your input/output including keyboard/mouse events and window content of every application.
- rwmj 21d agoThat doesn't change that programs doing this can be shady (or very useful).
- wolfi1 21d agobut sandboxing would be quite useless
- shevy-java 21d agoHow so? If you can break out of a sandbox then by definition it is not a sandbox. There are ways to force sandbox jail. For instance, giving processes only a partial view of the computer system. GoboLinux did this years ago via ViewFS (https://linuxphilia.blogspot.com/2009/07/gobolinux-is-linux-distribution-i-heard.html https://linuxphilia.blogspot.com/2009/07/gobolinux-is-linux-... search for ViewFS). There are many other similar solutions, some probably better.
- wolfi1 21d agoX itself is the problem here, not the process attached to
- imtringued 21d agoYou need to sandbox X11 which requires giving up X11 capabilities just like Wayland did.
- wolfi1 21d ago
- syntaxing 20d agoWow thanks for the link. I have zoom on my personal laptop which isnt ideal. I always wanted to run it sandboxed
- fight4fun 20d agoIt is caused by Qt. Qt 6.8.8 monitors the clipboard, and an official notice has been issued regarding this. https://qt-project.atlassian.net/browse/QTBUG-149610 https://qt-project.atlassian.net/browse/QTBUG-149610
- pjmlp 20d agoI only use their Web client, given that there is hardly any use for it other than some Webminars that insist in using Zoom.
- soltanov 20d agoOld platform limitations do not remove an application’s duty to minimize collection and offer clear controls