Apple has pushed a silent Mac update to remove hidden Zoom web server
techcrunch.com
techcrunch.com
softwareupdate -ia --include-config-data
It will show up as MRTConfigData if you look under Apple Menu->About This Mac->System Report->Software->Installations. The latest version is 1.45 and was updated today which includes the Zoom mitigations.
softwareupdate -i MRTConfigData_10_14-1.45 --include-config-dataIf I'm correct MRT stands for Malware Removal Tool.
I'd feel pretty bad if anything I worked on had to be uninstalled by that.
MRTConfigData_10_14-1.45: No such update No updates are available.
Update: According to this macworld article, there is a Zoom patch out that fixes this. https://www.macworld.com/article/3407764/zoom-mac-app-flaw-c...
There are also commands at the bottom to manually kill the zoom localhost and disable it. I have opted to run those commands regardless:
pkill ZoomOpener;rm -rf ~/.zoomus;touch ~/.zoomus &&chmod 000 ~/.zoomus;
pkill "RingCentralOpener";rm -rf ~/.ringcentralopener;touch ~/.ringcentralopener &&chmod 000 ~/.ringcentralopener;# softwareupdate -l --include-config-data
To list available updates, then adjust the command with the MRTConfigData version Apple provides for you.Is there a book you can recommend? Or did you pick these up over the years
system_profiler SPInstallHistoryDataType |grep -A5 MRTConfigData>To help distinguish Gatekeeper and XProtect updates from other updates in the software update feed, Apple marks them as being ConfigData updates.
>Marking these updates as ConfigData cues the App Store to not display these as available software updates in the App Store’s list of software updates. These updates are meant to be under Apple’s control and to be as invisible as possible.
[1] https://derflounder.wordpress.com/2014/12/27/managing-automa...
MRTConfigData 1.45 2019-07-11, 13:10:59 softwareupdated
Apple: Hey, your app poses a threat to macOS security. We're going to remove your server app with the built-in macOS anti-virus.
Zoom: Oh crap. Okay, give us 2 sprints to release a new version that removes it.
Apple: We're killing it in 48 hours.
...
Zoom, after an all-nighter: HEyyy users, we have a patch for youu
The loading modal would come up, but the app window would never open and I would have to force kill the app entirely, since I couldn't close the modal.
I suspect that Apple had already closed the possibility of the loophole on Catalina, which is why it wasn't working.
So I suspect they had probably noticed it weeks ago.
rm -rf ~/.zoomusSource: https://medium.com/bugbountywriteup/zoom-zero-day-4-million-...
The who found the Vulnerability where at least talking to the people at chrome and firefox: Quote from there Blogpost (https://medium.com/bugbountywriteup/zoom-zero-day-4-million-...) "Apr 10, 2019 — Vulnerability disclosed to Chromium security team.
Apr 19, 2019 — Vulnerability disclosed to Mozilla FireFox security team."
So, not entirely unrealistic that the other Browser manufacturer also got a notice.
Makes me happy to be a customer. Hope they keep enforcing their own rules and protecting their users' privacy and security in this fearless manner.
Apple definitely does make some commendable decisions, but I think it's also important to distinguish between bravery and what Ben Thompson calls "Strategy Credits" (https://stratechery.com/2013/strategy-credit/):
> Strategy Credit: An uncomplicated decision that makes a company look good relative to other companies who face much more significant trade-offs.
Do they have any information about enterprise apps? As I understand it, Apple never phones home with app info (such as the identifier, name, etc) when verifying or installing enterprise-signed apps, so the only thing they know is probably the IP address requesting to verify the enterprise-signed app and the frequency of how often Apple devices do this certificate verification.
Considering FB and Google have many employees in all different parts of the world, it wouldn't be too suspicious to see a good amount of diversity between GeoIP regions.
Correct me if i'm wrong about what info Apple collects about enterprise apps.
Anyway I wholehartedly agree with you here and I think Apple genuinely had no knowledge of this activity until news outlets reported on it. Or if they did, it did not make its way to the higher-ups that revoke developer certs.
We should still reward/praise companies who make decisions that are morally superior to their competitors, regardless of whether the morality itself was a primary motivation.
Humans might have too short lifespans, memories and limited rationality for the long term benefit of morality to be strongly in our individual self interest though... one of the possible benefits of anti-aging and cognitive enhancement tech is it might incentivize us to be more moral all other things equal as a side effect.
1) Public sentiment is hammering companies for perceived privacy violations
2) Our business model does not rely heavily on selling user data
3) Make public statements about how much we value privacy at literally no cost to us
4) Get in a good dig at our competition at the same time
1. Lists of people who have purchased [music genre] from iTunes & listened on Pandora is for sale by data brokers, and
2. App developers (they specifically call out Pandora) who use the MediaFramework API have access to iTunes library metadata that they can then collect.
I haven’t looked at Apple’s Developer Agreement recently but I suspect Pandora (and potentially others) hasn’t complied with the terms.
We recently went back to PC's and it was immediately obvious we needed wall to wall antivirus protection which was not always the case on macs.
"We are not going to keep any data at all about you unless we are forced to do so legally. We are bound by that contract with you when you purchase our device."
Then followed that with
"We're going to make it as hard as humanly possible for anyone else to collect and keep data about you if you own one of our devices. Including both legal and technical solutions and we will sue them for breach."
As it is, we're praising "least worse" which is effing awful. Apple's excrement stinks less than some others, eat it up!
But of course Apple literally wrote the book on selling their customers as product to third parties. They've been wildly successful at it. Microsoft, IBM look on in envy at how they've managed to get away with it.
Since it has been massively profitable for them to turn their customers into their product, they see no reason to change and I guess why should they? Profit maximisation is their business, yours and my health and welfare is only of interest in service to maximising profit. If they did anything else they might be guilty of securities fraud(!) So yeah, they can be completely horrific and still win the PR battle because others seem even worse.
I see these statements of fact are always jarring for people to notice for the first time, especially if they quite like the machines (I do), and quite like liberal democracy and free market economics (again I do!) and more so that this utter hideousness is our best option right now because there is no option even remotely on the same planet as good. It is thoroughly depressing all round.
Sure, Apple has more leverage, considering their size, but that also comes with its own set of problems. Plus, their customers have nowhere to go to in protest - all other phones are full of conflict minerals too.
I feel sick when apple says they are deeply committed to upholding human rights, while they continue manufacturing electronics, because I need authenticity. I would like Apple to use more of their resources to figure out how to do conflict-free consumer electronics.
Apple charges $1k for their monitor stands. I think they can afford to build their stuff at a factory that doesn't use modern slavery.
Apple certainly wasn't looking out for their users' privacy and security when they let an iTunes bug go unfixed for 3 years (see http://www.telegraph.co.uk/technology/apple/8912714/Apple-iT... for more). That bug was said to allowed government spying. Apple's iPhone back door lets Apple delete a user's apps (per http://www.telegraph.co.uk/technology/3358134/Apples-Jobs-co...) but Steve Jobs said it was okay because we can trust Apple ("Hopefully we never have to pull that lever, but we would be irresponsible not to have a lever like that to pull."). Back doors aren't moral, they exist to grant another party over the device the user bought and should own.
The root of all of this is the power of proprietary software (software the user can't inspect, share, or modify, and in some particularly restrictive cases can't always run). Proprietary software is unjust power over the user. There's nothing moral about proprietary software.
And in any case, there is a checkbox in the software update preferences labelled "Install system data files and security updates" which presumably allows you to opt out of these critical security updates.
And if you really wanted to have the zoom backdoor server run on your system, you could probably just strip the code signature and run it manually. Apple isn't stopping you from running whatever software you want on the Mac. Apple is helping all those users that don't follow Hacker News to keep their Mac safe.
That seems highly unlikely to me. Do you have evidence to support that assertion.
On first use "Do you want us to automatically remove apps we think might damage your system: Y/n."
Don't users need a notification, at least, to inform their choices when installing software.
I guess Apple Computers would rather you just mindlessly relied on them, however, so anything that lets users know that Apple's system exposed them from risk is going to be avoided.
Every relative who never installs updates. I ask them why they are on an old version with major security holes that were on the news, but they just don't care. They always click "later".
Sorry, but this is absurd. Automatic security updates are necessity. And no user read through all changelogs of all updated software (except extremely critical systems).
Maybe you wanted to argue for ability to downgrade and disable updates?
It should be up to the user to decide whether to take on updates, regardless of what you think because that's their computer and not yours and you each deserve control over the computers you own. Just as freedom of speech means sometimes people will say things you disagree with, free software computers means not everyone will keep up with the updates. But not offering software freedom is unethical and neither Zoom nor Apple are distributing software freedom. Apple has a clear record of using the power of a proprietor to expose their users to harm (more examples at https://www.gnu.org/proprietary/malware-apple.html ) and this story is an example of how Zoom apparently does as well.
What you and other posters are tellingly refusing to address is the immorality of software nonfreedom. As I wrote before, this is the core of the issue.
Which is why the user can CHOOSE to have automatic updates. Or not to. The default when buying a new Mac is that automatic updates are enabled, because that’s the product Apple wants to sell and that they believe most of their users want to buy. It’s secure, it’s practical, it’s fun.
If you want to be your own IT department you simply deactivate all or some automatic updates. If you want a secure computer and trust Apple you leave it on.
I don’t see how this is a big moral question at all. Let people organize their computing needs in a way that’s safe and practical for them, not in the way that’s safe and practical for you.
There's nothing accurate about this description.
The user can turn off all update checking, or use the granular permissions to just turn off silent security updates.
>To allow macOS to update automatically, go to System Preferences > Software Update, then check Automatically keep my Mac up to date. The Mac offers some more granular update options than iOS. If you click Advanced…, you see a number of options:
https://www.intego.com/mac-security-blog/everything-you-need...
If you only want to turn off silent security updates, the option to uncheck is "Install system data files and security updates".
What Apple did here is also a dark pattern. We cannot commend them and normalize this behavior.
This is a dictatorial one-sided decision by Apple. What else can they do? Can nation state governments compel Apple to push stuff silently? Can this system be abused by hackers?
Why are we dependent on the good moral behavior of Apple business decision makers for the well-being of our digital lives? Haven't we learnt anything at all from all the incidents in the recent past w.r.t trust in corporate benevolence?
"By using the Apple Software, you agree that Apple may download and install automatic updates onto your computer and your peripheral devices. You can turn off automatic updates altogether at any time by changing the automatic updates settings found within System Preferences."
On the other hand, Apple itself is guilty of not addressing gatekeeper vulnerability in time (is still yet to fix this bug): https://9to5mac.com/2019/05/25/macos-gatekeeper-vulnerabilit...
You may agree with its decision this time, but will you always agree? Apple's wielding of power in this way is likely to attract the attention of groups such as copyright/IP lobbyists, which have an immense desire to have all "non-authorised" files/software erased from all user's machines.
As the saying goes, "two wrongs don't make a right".
In any case, the idea of the OS/platform vendor meddling with third-party software that it doesn't like just feels wrong. I know Apple has historically held tight control over its mobile platforms, but the Mac is meant to be different.
I am not an Apple customer, and I now feel even more reluctant to become one.
any OS (and many other apps) that update have the power to do what you’re afraid of, and much more.
plus i don’t really see a bright line between system level software and an app when apps can access your video cam, mic, all your files - basically your whole computer.
This isn't third-party anything. No one even knew this was running on their machine and it was demonstrably abusable. Good riddance!
There's an ocean of difference between can and will.
plus i don’t really see a bright line between system level software and an app when apps can access your video cam, mic, all your files - basically your whole computer.
The setting ostensibly refers to the operating system, i.e. macOS, which I have no problems with Apple modifying if you've enabled that option, and which their EULA probably has a clause about. But from a legal perspective, modifying a third-party application which Apple does not own and did not install seems an overreach; unless their EULA explicitly grants them the right to do anything they want with the files of the system it's installed on, they could find themselves in legal trouble. (That notorious CFAA and the like.)
If you don't think that's scary then you're just incapable of long term thinking.
Apple didn’t flex anything here, it removed malware from its users computers.
https://twitter.com/riskybusiness/status/1148824808236318721
> You may agree with its decision this time, but will you always agree?
Yes, I will. At least I am not going to lose sleep over it until Apple does abuse that power.
I am actually even more happy to be an Apple user knowing that the mothership said hell naw to the naw naw naw naw to this horseshit Zoom has been pulling.
If I were Apple, I'd be taking this as a personal slight against my entire user base.
What if Apple abuses that power in ways that not everyone sees as "abuse", yet they are affected by it?
The reason you are not already seeing this act as abuse is because you happen to agree with it. What if you didn't agree? What if you were in the minority? What if the reason you where in the minority was that the majority simply didn't had the necessary understanding, experience and/or knowledge to see the issue you see?
If something can be abused, it will be abused, there isn't a matter of if, it is a matter of when. And with that in mind it is better to try and avoid being abused than wait for the abuse to happen and see what you can do after the fact.
I love this. This is why I'll keep buying Apple.
To be honest I'm kinda sick of this argument. Someone brings this argument up _every single time_ a tech company takes action against something malicious. It's a strawman argument at best and at worst a way to give people an out on acting against something that could harm the user.
> Apple's wielding of power in this way is likely to attract the attention of groups such as copyright/IP lobbyists, which have an immense desire to have all "non-authorised" files/software erased from all user's machines.
This will never happen.
This seems like overreach to me. It's annoying but it's not like the Zoom app was silently letting people watch me for hours through my webcam without anyone noticing - the app opens a full screen video sharing GUI for goodness sake. Is being joined to a VC without me wanting it when I click a link annoying? Sure. It also serves the attacker no real purpose and thus has never actually happened in the wild. It's also easily fixed. This is a storm in a teacup.
Moreover it seems from the last discussion of this on HN that videocall firms do this for a good reason - lots of users get confused by bad Safari permissions GUIs and end up locking themselves out of the app by cancelling the URL open prompt without thinking (which is apparently persistent!) Then they can't join the call. So the only reason these firms are using such a bad workaround to begin with is because Apple screwed up their user interfaces: why is this not on Apple to fix?
This appears to send a message to Mac devs that a single troublemaking blogger can cause Apple to kneejerkingly nuke features in your app overnight, regardless of whether you are fixing them, whether they're serious or not or whether it will result in legions of confused and stuck Mac users. Not a great message.
The argument isn't about taking action against something malicious, the argument is about the implications of being able to take that action and what sort of power the company has and if they should have it in light of past abuses (not necessarily but that company, but this is totally irrelevant since companies are made up of people that come and go, they do not have a single "brain" or morality).
> This will never happen.
You cannot guarantee that.
The setting is called "Install system data files and security updates": it's not just system components.
And it is a security update meant to annihilate a serious malware threat, not to mess with legitimate third party software.
I am an Apple customer, and I now feel even happier about being one.
You shouldn't want. But at the same time i do not think it is a good idea to want Apple to be able to silently remove arbitrary applications they had nothing to do with from your computer.
At the very least they should ask the user about it or quarantine the software and inform the user about it. AFAIK this is what Windows Defender does when it finds malicious files.
Then, Apple, can push a silent update to simply kill software on your machine which as I understand it wasn't installed through the app store.
In this case I may be happy that it's no longer running, but the whole thing is disturbing. Looking at the Security & Privacy settings on my MacBook, I see nothing about running any anti-virus or anti-malware. The closest setting I can see that might be this is under software update, where I have the option to install automatically the system data files and security updates.
It's kind of a stretch for me to consider the ability to kill some software Apple might construe as malware at anytime the same thing as a "security update". To me, a security update would patch Apple code which had a vulnerability.
Where do I tell Apple to whitelist software in the future they might not like which I've chosen to install not going through the App Store?
It's actually news to me that I'm running Anti-X on my Mac, I didn't think I was.
Considering the fact that I have to learn new places for all the buttons every time Microsoft gets bored and changes things for the "better" I'm really disappointed.
System76 is looking better and better.
Real principles would involve switching now.
Oh, and a company that defended the insecure web server up until the moment the public outrage exploded and/or the RCE it had willfully ignored was about to be revealed.
Oh, and a public company at that, that’s trying to convince businesses to use its product as it primary video chat system.
Apple worked with Zoom insofar as Apple cleaned up Zoom’s mess because of Zoom’s poor/unethical software practices.
For example if you classify possibly unwanted programs from annoying toolbars to randomware on a scale of 1-3 it might be reasonable to provide a checkbox to allow the user to switch between being warned of a negative program and being given the option to uninstall and having this happen automatically for non critical situations.
If the default is to on then 99% of users will be protected.
Arguably stuff like ransomware shouldn't be optional lest the malware set the option.
Apple made the right call for this instance, especially after the completely insufficient excuses given by Zoom’s CIO.
> Apple's wielding of power in this way... the idea of the OS/platform vendor meddling with third-party software...
This is THEIR app store for THEIR operating system. Why in the world would they not be allowed to control their software's features or third party integrations? It reminds me of the ridiculous argument over Windows setting IE as its default browser (and I've been a web dev since the late 90s).
On MY computer.
> Why in the world would they not be allowed to control their software's features or third party integrations?
Because it is not THEIR computer but MY computer.
It reminds me of the ridiculous argument over Windows setting IE as its default browser
What do you mean by that? Instead you reminded me that saying "$our_competitor's product is not secure, so we've helpfully removed it and recommend you use $our_equivalent instead" is likely to run afoul of antitrust laws.
At this point it is up to the user to decide what to do and most non-technical users will leave it at that (and wont know what else to do) which should keep them safe.
That said, in the context of my original comment, AVs are a bit of a special case because their sole and expected purpose is to detect and remove software they don't like.
[1] https://www.csoonline.com/article/3216765/security/heres-why...
[2] https://stackoverflow.com/questions/22926360/malwarebytes-gi...
I am with the "two wrongs don't make a right" people here. Zoom was reckless and their casual disregard for the initial security report left a very bad taste in my mouth. I'm now highly unlikely to use one of their products willingly. But having Apple initiate unattended removal of software that a person willingly installed on their own workstation machine is also unacceptable, unless they specifically opted in and checked "enable" on something that is very similar to windows defender.
Yes, Apple does have the power to change every bit on your hard disk if you let it. Things like EULAs are supposed to govern to what extent they can use that power.
I wonder if there's a known exploit for the Zoom server specifically, or if Apple discovered one while looking into it. It seems strange for them to go to these lengths in this case when it sounds like other software has been using a similar technique too. Maybe it's just the reinstallation aspect that makes Zoom's case exceptional?
"Additionally, if you’ve ever installed the Zoom client and then uninstalled it, you still have a localhost web server on your machine that will happily re-install the Zoom client for you, without requiring any user interaction on your behalf besides visiting a webpage. This re-install ‘feature’ continues to work to this day."
> Zoom spokesperson Priscilla McCarthy told TechCrunch: “We’re happy to have worked with Apple on testing this update. We expect the web server issue to be resolved today. We appreciate our users’ patience as we continue to work through addressing their concerns.”
Yeah, I bet.
It looked like they decided to remove the server themselves (or at least, as a response to pressure), but maybe they didn't actually have a choice at all.
Zoom also didn't reverse their decision until there was a huge amount of public backlash.
There is, though it's not public yet.
Thank god for Apple putting down the law. This is why I happily pay premium prices...
They have a bunch of cool little apps (that are free) like BlockBlock that let you know when things are happening you wouldn't have otherwise allowed.
For example, BlockBlock warned me randomly about 30 minutes ago about an app that was being silently installed in the background.. something I hadn't seen before called MRT.app.
Turns out - that was Apple silently updating the OS to protect against Zoom. Wouldn't have known if it weren't for these apps.
The "nice folks" at Objective-See is Patrick Wardle, a former NSA rootkit expert who would like nothing more than to install various close-sourced components on your computer.
Funny how both companies have "objective" in their names.
Occam's Razor, asking for root was probably just the path of least resistance for the Zoom developers.
What else have they pushed like this? Is there a transparent log? Can we verify if their track record is clean? How many times have they silently broken and fixed their own things? How do we know they won't abuse this?
Isn't this the same dark pattern that we criticized zoom for? Did I consent to Apple doing silent editorial changes to my system?
For having exercised this editorial privilege, will Apple take accountability for every thing that is done by every app on my computer?
It seems like we are being slow-boiled into accepting outrageous things as normal.
If you want complete control over your computer you have the choice of getting yourself a PC with some flavour of *nix, and combing through each update as it comes. I really don't like the future of Apple that you seem to want. Apple has made missteps, sure - like that idiotic U2 album - but I actively want things like this to happen, and I imagine the vast majority of Apple users do too (if they actually ever think about it).
When it comes to public-facing servers that we run it's a different matter of course, but then I'm performing (and delegating) the same task that I want Apple to perform for my MacBook Pro.
I'm the same as you. The whineyness exhausts me. Let the market decide. I just want shit to work.
Yes.
sh-3.2# softwareupdate --history
Display Name Version Date
------------ ------- ----
Safari Technology Preview 87 07/10/2019, 21:40:18
Gatekeeper Configuration Data 171 07/03/2019, 14:00:23
Safari Technology Preview 86 07/02/2019, 01:27:12
MRTConfigData 1.42 06/29/2019, 11:52:13
Gatekeeper Configuration Data 170 06/29/2019, 11:50:33
Safari Technology Preview 85 06/13/2019, 14:48:10
Safari Technology Preview 84 06/10/2019, 00:51:57
TCC Configuration Data 17.0 06/05/2019, 07:04:21
Gatekeeper Configuration Data 167 06/04/2019, 04:17:26
Safari Technology Preview 83 05/30/2019, 19:48:10
iTunes Device Support Update 05/15/2019, 16:27:15
Safari Technology Preview 82 05/15/2019, 16:27:15
macOS 10.14.5 Update 05/15/2019, 16:27:15
Gatekeeper Configuration Data 166 05/14/2019, 02:36:07
Safari Technology Preview 81 05/03/2019, 00:47:53
MRTConfigData 1.41 05/02/2019, 06:36:59
XProtectPlistConfigData 2103 05/02/2019, 06:36:37
And the list goes all the way back to when I bought my Mac. Among the list above, only the Safari Technology Preview updates and the macOS 10.14.5 update are initiated manually, as far as I can remember.You can view the history of these installs by running softwareupdate --history | grep -E "^MRT|^Gatekeeper"
I see an average of 2 updates per month.
FWIW Apple can also mark something as visible (but install automatically) with a certain config file key. A blog mentions this as being done for patching the NTP bug from a while back:
> Marking these updates as ConfigData cues the App Store to not display these as available software updates in the App Store’s list of software updates. These updates are meant to be under Apple’s control and to be as invisible as possible.
> Meanwhile, an automatically installed software update like OS X NTP Security Update 1.0 shows up as a normal software update, but has extra keys in its catalog listing to mark it as a critical update whose automatic installation is set to occur as soon as possible.
https://derflounder.wordpress.com/2014/12/27/managing-automa...
You can turn off silent security updates from System Preferences without affecting software update checks for other components.
The option is called "Automatically: Install system data files and security updates" in the Software Update advanced settings.
Because as opposed to what Zoom did, this is a feature that you can turn off if you want in "Updates" preference pane.
Makes the story MUCH worse in my opinion. An unpatched RCE that they left open until someone else got 90% of the way there and went public with it.
Being my OS or hardware vendor does not entitle you to permanent RCE on the machine that now belongs to me.
Unless of course this is just a XProtect rules update or a Gatekeeper CRL update, then ignore what I said.
That makes this server at least doubly malware. And "vulnerability" understates the case: a negligent implementation that utterly disregarded any security concerns should be considered beyond the pale. That times 1000 for a major software vendor like Zoom.
That's malware.
The server itself was deliberately added to work around a Safari security feature, that was designed specifically to prevent what they wanted: allowing arbitrary web content to open an app without user consent. They literally added an always on, persistent server, to avoid a security dialog
So yes, malware.
Seriously though, they should have owned the mistake, apologised and reversed their decision rather than handling it with a PR spin. It is a great product but somehow it has left me with little trust for zoom. It's probably still not too late.
Does anyone know if bluejeans et all are also removing this? Or does it require public shaming, like the zoom case?
Apple has its share of evil. Another example is preventing people from repairing their own Apple devices.
--
[1] https://www.vice.com/en_us/article/ywyjmw/history-will-not-b...
No. What gave you this idea? iMessage is end-to-end encrypted. The keys are managed by the devices themselves. There is no facility to backdoor or intercept the messages.
Apple acts as a registration server, notifying your devices when a new device signed in as you joins the pool but the devices themselves tell you when this has happened. That’s all client-side. If the server didn’t tell the client about a new peer it would never encrypt a copy of the message for that peer and that peer wouldn’t get the messages.
That is only a half-truth. Apple controls the key infrastructure; they may replace your keys with arbitrary ones at the demand, coercion or compromise by any number of bad actors. The software is closed source, making it impossible to verify any actual claims made otherwise. If they truly valued privacy, why not open source iMessage, allow users to verify iMessage keys, hire an independent third party to audit their infrastructure, or all of the above?
Moreover, Apple has moved iCloud infrastructure to Chinese data centers to enable spying on millions of innocent people. They have removed apps from their store which circumvent Chinese censorship. These are truly shameful acts which has appropriately drawn criticism from human rights watch organizations.
https://techcrunch.com/2018/02/25/apple-moves-icloud-encrypt...
https://www.cnbc.com/2018/02/24/apple-moves-to-store-icloud-...
https://www.nytimes.com/2017/07/29/technology/china-apple-ce...
https://blog.cryptographyengineering.com/2013/06/26/can-appl...
I would say that what Zoom did was have their app intentionally install malware that bypassed this normal uninstall.
I do think that it would be great to have a more thoroughly sandboxed idea of what an “app” is on the desktop, though.
Even the regular Linux package managers like apt, dnf, pacman track which files were installed by which packages, so they can be removed when the package is uninstalled. The downside to these is they don't track files created at runtime so a lot of the config or cache files created can be left over if the package itself doesn't remove them.
> Even the regular Linux package managers like apt, dnf, pacman track which files were installed by which packages, so they can be removed when the package is uninstalled.
Technically speaking, Zoom could have abused dpkg post-install scripts, or pulled similar tricks, to install their malware server and leave it behind after the package was removed. Linux distributions aren't invincible to these shenanigans.
How would this work with apps that create things that a user would expect to persist, like downloads (kept after uninstalling a browser) or office documents (kept after uninstalling the office suite), or media production apps, IDEs, etc.?
It could have some rule like "let it be if it's in the user home directory" or "only remove stuff in these system directories" but it seems kind of fragile, like what if you use a text editor to create a system config file and then uninstall the text editor?
Does the ZoomOpener app have malicious intentions towards you, your computing resources, or your data? Not just “could it be unintentionally exploited” - note the unintentionality! - but specifically “this was intended to harm”.
If not, then you need to reconsider your use of the word “malware” - a word shortened from “malicious software” - and find a better way to describe software design patterns that aren’t compatible with “drag it to the trash” but also aren’t intended to harm.
Adobe Creative Cloud, any $$$$ audio software DRM, and HP printer drivers all use similar patterns of “can’t just drag it to the trash”, and are all similarly annoying to remove - but they are not malware, any more than this ZoomOpener is.
And Windows does? Uninstallers are completely at the behest of application developers. No consumer OS but iOS actually provides any sort of true app level sandboxing.
Control Panel “add and remove programs” usually works?
There’s no equivalent on Mac. Yes, dragging the app to the trash is a thing but that leaves behind content in ~/Library/caches, ~/Library/Application Support, and ~/Library/Preferences . It’s been somewhat of an issue with Mac ever since they first put a hard drive on the original ones back in the 80s...
Edit: I literally cleared several GB of junk out of my application support folder left behind by just one app today, so it’s fresh on my mind. OmniDiskSweeper is great for finding this stuff.
All that does is launch the app’s uninstall process. The app is free to leave whatever crap it wants to on your system.
Also, Add/Remove only works if the program adds itself there. And remove only works if the program added an uninstaller. Also, even then, it still leaves crap behind.
iTrash [1] is also worth mentioning. It uses the Levenshtein distance algorithm [2] to find all of the junk related to an app.
Zoom is even available in Flathub, and that's how I use it.
Android does, too.
I mean, maybe you need a "user data" bundle of sorts tied to the specific application. If you delete the app, it deletes all the user data bundles as well.
The default installer and bundle runners should be controlling the process. "XYZ App is attempting to write data files outside of its bundle location. These may not be cleaned up if you delete the application. Do you want to continue?"
The unix permissions system and the Mac bundle format should completely solve this problem. I honestly just don't get why this still happens. Doesn't iOS at least get this right?
There is already a concept of a "user data" directory for the app, which is determined just like on iOS. There are also other directories for things like caches that the system can clear if it's low on disk space.
Of course they could sandbox Mac apps just like on iOS, and Mac App Store apps essentially already work that way.
I can assure you, though, that any barrier they put in the way of letting non-App Store apps run however they always have will be met by strong resistance. It's easy to point to this occurrence with Zoom and call it unreasonable, but prompts like what you're describing will undoubtedly disrupt what other people see as totally valid use cases and ruining of the UX.
[1] By "things", I mean things like a separate web server process. Apps do store files in app-specific folders like "Application Support" by convention, but not for separate processes.
But what I don't get, why even have an "Application Support" directory at all. There is absolutely nothing of value added to me (as a user) to have files stored there. It's just one more place I have to look to clean up after an application is deleted. So dumb and adds zero value.
I'll put my files into Documents (or whatever). And you (as an application developer) put your files in your app bundle directory. That should be the contract for most (all?) user space applications.
I agree my prompt idea is generally poor and wouldn't work, it was mostly just for discussion purposes. But the mechanics of a fix for this are in place, rogue daemons that can't be deleted are just unacceptable.
If you uninstall a .deb or .rpm or AppImage, the files you wrote into XDG_CONFIG_HOME (defaults to ~/.config) won't magically get cleaned up.
I'd love to be wrong here, BTW! I've had several PhotoStructure users try to reset their configuration by uninstall/reinstall, but that just removes the files in the installer, it doesn't do anything to files in user directories (and I'd be really surprised if that was ever a thing). Can you imagine the havoc from `apt remove vscode` and having it remove user's keybindings, extensions, and anything else?
Isn't this what apt purge appname does ? or is something missing
Form the apt-get docs:
purge - purge is identical to remove except that packages are removed and purged (any configuration files are deleted too).
If you do that, the entire system stops working. Everyone will just click "ok" and then still gets mad when uninstalling doesn't fully clean things up.
Maybe the app bundle runner should be logging files written outside of the bundle folder? Then the uninstall process will wipe those out?
Not even Apple follows that ideology though, I can't be the only one who has had to delete the gigs of Garageband data from ~/Library/Application Support on an under-specced company laptop 128GB SSD
If we are talking about OS updates, OSX has the same thing.
You are not required to use Windows Installer. And even if you do, you are not guaranteed that everything will be removed, be it due to malice or incompetence.
Not even Linux can guarantee that. Something like the Nix package manager would be closer to what's required. Plus a sandbox.
> This is a workaround to a change introduced in Safari 12 that requires a user to confirm that they want to start the Zoom client prior to joining every meeting. The local web server enables users to avoid this extra click before joining every meeting.
https://blog.zoom.us/wordpress/2019/07/08/response-to-video-...
So I think you could argue Apple might want to let you override that, I don't know what the language is and whether there's a "click here to skip this next time" box on the dialogue. It's possible they got the annoyance versus security tradeoff wrong.
But imho they didn't break the correct behavior any more than Microsoft "broke the correct behavior" of privilege escalation by adding a dialogue box with UAC in Windows 7 .
well, it did a shitton didn't it ? to this day, most people I know disable UAC because of how annyoing it is.
The developers in this case didn't bother trying to use it.
Anyone know of other sneaky apps to avoid?
Not as serious as leaving an httpd around and then letting sites to hot mic you with it -- obviously -- but on par in terms of a few select adjectives.
Wonder if the LitteSnitch list of procs had the Zoom Daemon.
For cripes sake...
So that said, I checked, and it removes everything zoom installs that isn't in a user directory, plus (there is an extra script that does this):
remove_folder "/opt/zoom"
remove_folder "$HOME/.zoom/logs"
remove_folder "$HOME/.cache/zoom"
Which is stupid since it's removing this from root, who probably never ran zoom.Note it removes logs from .zoom, but not the directory itself. Which is good, since there might be user data in there (chat logs, and recordings).
Unlike Macs, there is no hidden webserver.
There is also (yes, it's commented out):
#logged_in_users=$(who -q | head -n 1)
#sorted_users=$(echo "$logged_in_users"|tr " " "\n"|sort|uniq|tr "\n" " ")
#for user in $sorted_users;do
# echo "removing $(grep -w ^$user /etc/passwd | cut -d ":" -f6)""/.zoom..."
# remove_folder "$(grep -w ^$user /etc/passwd | cut -d ":" -f6)""/.zoom"
# echo "removing $(grep -w ^$user /etc/passwd | cut -d ":" -f6)""/.config/zoomus.conf..."
# remove_file "$(grep -w ^$user /etc/passwd | cut -d ":" -f6)""/.config/zoomus.conf"Kudos to Apple for nuking this malware.
Strong work Apple.
They're blocked in my little snitch anyway so no problem.
From there you can manage the updates manually from the command line with the `softwareupdate` command. e.g. `softwareupdate --list --include-config-data` will show available updates, `softwareupdate -ia --include-config-data` will install them, etc.
It's no different than a virus scanner auto-updating its signatures.
Another application I've been running for years won't start-up anymore and is logging:
> Thu 11 Jul 2019 23:12:59 AEST Waiting for web server to come up
It may be coincidental, but would be good to know what Apple changed.
I figured.. this has probably evolved already to an acceptable situation.
So the calendar invite came in, I started up zoom to see what it would do. There's an update available, where zoom says they're abandoning the local web server.
Upgraded, should be good for tomorrow.
Came here, noticed the "softwareupdate -i MRTConfigData_10_14-1.45 --include-config-data" command and ran it. Checked last update -- back in June, to 1.42 ...
Updated that, ready to go.
Business continues, maybe I'll delete zoom another day, but not just yet.
Many users are unable to enable Video feature even after applying recent patch released by Zoom. Also zoom has become security joke/conversation topic while starting a con calls!
How many such apps am I running that I don't know about? And how many of them are exposing my system to malicious web sites, or to curious people in my office on the same subnet? I wish I knew.
I think I'd be happy with a popup once-per-tab asking me for permission for a web page to talk to a local web server... Might even be okay if it's scary (Are you a developer?)
Edit: Apparently there is:
I currently have a separate limited user account just for meetings, and that’s where I install various meeting apps. So in my case is there any way to know if Zoom or WebEx would install stuff on all accounts?
If we can’t trust an app that is the cornerstone of a 25 billion dollar business (Zoom’s market cap) not to install malware, then I don’t know.
I want the trust through the App Store.
PS. I love Zoom, and find it to be the best conference solution out there.
Zoom’s initial response to this incident was shameful. They basically said “that’s how are app works. F U”
I am moving away from Zoom.
Any suggestions? Preferably open source
Afk rn so i might be misremembering the name of the setting.
Apple gathers various anonymous metrics, yes, but I don't think they collect information on arbitrary web servers running on Macs.
What do you think the anonymous metrics are if the process list and open sockets are excluded?
i tried etrecheck on a lark. at the time i found it unremarkable. oh, i have this leftover dingle here, thanks etrecheck, i'll just remove it then. but otherwise i wasn't screaming etrecheck from on high.
now i am!!
The latest version of EtreCheckPro 6.0.2 has more features that might appeal to very tech-savvy users. It has a storage analysis feature to help find how your disk is being used since Apple’s own tools are notoriously bad at this. It also has a graphical view of the analytics data that macOS automatically collects. You won’t find this analytics display in any other tool.
the free version is perfectly adequate. it's simply an information gathering and reporting tool. anyone could write this tool themselves -- the mechanics of it are beyond simple. but like all sysadmin tasks, gathering the requirements is the hard part.
I think this scares me just as much. #singlePointOfFailure #rootKit
Event: GPU Reset RCS Ring is: - busy - in the ring <-- Appears hung
I suspect the automated GPU reset didn't quite work, as nothing wasn't redrawing properly.