Ex-NSA hacker drops zero-day for Zoom
techcrunch.com
techcrunch.com
Spooky23, a former guest of a Holiday Inn also used by elite NSA Hackers, discovered that if you walk into a remote worker's home while they are engaged and distracted by a Zoom meeting, you can physically pick up the laptop and throw it out the window. In most cases, this will result in a denial of service.
Zoom has not made a fix available at this time. Users can work around this threat by securing any nearby windows.
But before you install, you have to give Microsoft a copy of your DNA that it can sell on to marketing companies. Microsoft needs this "telemetry" to improve its software, otherwise everything will break.
The machine must already be compromised for this vulnerability to be useful, but doesn't necessarily mean it isn't a problem. A good security model uses layers to reduce the impact of successful attacks. This vulnerability potentially enables an attacker to escalate their privileges, bypassing some of those layers and compromising the machine further.
This article probably overstates the problem (maybe don't use "doom" in the headline next time, even though it rhymes) and there are plenty of examples of worse vulnerabilities, but that doesn't excuse this one.
https://amonitoring.ru/article/steamclient-0day
Valve tried to downplay this too. Privilege escalation is an attack vector that's easy to downplay
Presumably if you have possession of the computer and are able to exploit this bug, you could do any number of other things anyway...
Zoom might have issues but if I were to list them, this wouldn't be high on / make the list. Obviously they should fix it, but of all the things, not sure this one is front page worthy.
I suspect there was a nasty mis-translation. The article should have said "local network", but it was strip down to "local" and gets mis-interpreted as "local computer".
https://twitter.com/hackerfantastic/status/12451333712626196...
There's no malice there (on the posters' side). If Zoom does better people won't have cause for shining a flashlight on their data privacy policies or security holes. We will see if Zoom grows up fast, since the momentum towards them is already so large I don't see it changing prior to the Fall when schools might risk re-evaluating their tools.
You can access Zoom meetings through a pure web interface without installing anything. The experience is somewhat reduced.
1) The lack of e2e encryption despite trying to market themselves as having secure video chat.
2) https://news.ycombinator.com/item?id=22749805 (comment in this thread - they literally phish you)
3) https://twitter.com/c1truz_/status/1244737672930824193 abusing the traditional installation process on OSX
EDIT: OK (2) may be a real system prompt - https://twitter.com/DigitalResist0r/status/12452813782932807...? I didn't see anyone else in the twitter thread claim that it was using a real system dialog, so I'd still say it was poor practice of them to have such a shady looking system dialog.
Personally, the fact that I filled out what turns out to not be a system dialog with my password (https://twitter.com/raganwald/status/1244994636982222848) makes me feel violated.
I'm genuinely quite angry about this. I never enter passwords into 3rd party apps - I've had arguments with companies who embed oAuth flows into their app about this.
Thanks for clearing that up, though I must say they (Zoom) bring this upon themselves by having such a poorly worded dialog.
"Maybe try to read the blog post" can be easily replaced with a less patronizing and just as informative "It's in this blog post".
You have good points to make, they don't need the vitriol to be taken.
I was clearly also making a meta-comment about Twitter misinformation, so the patronizing part was inevitable.
Oh, if you're already hacked in enough to run code on MacOS, you can grab the camera with Zoom. Or, you know, use any of many methods to do that I'm sure. The problem, and the reason for HIPS / AV / security solutions is to stop running "hacker code". If I'm running arbitrary code on your Mac, I don't need Zoom to grab a password.
Now, the bad installer methods used on MacOS - yes, those should not happen and ought to be fixed. I think it's the big problem, no one gets paid for a secure system, but one that people can use. Security just causes issues sadly, and making it possible for the most incapable computer user is why everyone loves Zoom for "just working". That sadly incentivizes them to try and work around security roadblocks, which is bad.
None of this is contrived; and all of it is serious when you're the parent of a school age child.
Regarding the hatred for Zoom... I'm sure a lot of people feel the same as me. I'm tired of having to install and trust yet another native app just to perform a task I've been able to easily do with countless other solutions for well over a decade. I understand why Zoom in particular has found recent success, but it's still annoying.
Zoom's recent surge in popularity also probably draws a lot of attention from cynics and skeptics.
Every zoom post I've read here has at least one highly-upvoted comment about "hey everyone lay off zoom". Why? Why should we give a company that millions are now using for the first time a break? Why should we ignore issues with software that tons of people are now using and potentially opening themselves up to danger?
I use zoom, I used to before the pandemic and I've used it with friends since multiple times. I'm not some anti-zoom, burn it all down type. That said I think issues with it warrant a discussion and there is a reason these things are upvoted: because millions of people are now using it and are unaware of the risk they are taking.
From what I can gather. You can send a message in zoom with a link like "\\host.example.com\calc.exe". Zoom will highlight it as a clickable link.
Assuming you can get the user to click it:
1) It will fetch the remote executable and run.
2) It transparently transmits windows authentication of the user to the remote server, expecting a network share that may require authentication.
Hangouts: \\servername.tld\share doesn't parse as a UNC, instead becomes clickable and brings up a browser to "servername.tld"
Skype for business: Does exactly what Zoom does, turns the entire thing into a clickable link
MS Teams: Doesn't parse as clickable at all
That's all I have in front of me at the moment...
And runs it when you click on it?
Testing in zoom, it launches the OS prompt to confirm .exe launch. Tested in Windows 10.
There is a good chance it will run file.exe if they cut the end of the string naively. :D
Skype for business threw an error: "Sorry, we couldn't open the link".
Outside of paranoid nerds who refuse to use an admin account day-to-day (I’ve only heard about this kind of people online, yet to meet one in meat space), who uses their Mac like that? (Genuine question.)
It does show that whoever manages security at Zoom should go back to school though. Operating system security features are not an obstacle but a tool. Trying to work around them reminds me of the age of IE6 toolbars and "system optimisers" who won't let you uninstall them.
TechCrunch got this wrong. "Local" means local privilege escalation, as opposed to "remote" code execution. They do not require physical access.
That being said, local privilege escalation on a single user computer where that user is an admin (most Macs), isn't a massive problem in my mind. It would allow malware, once run by the user, to bypass security prompts usually required to elevate access.
(WebEx is as bad if not worse.)
This is an odd way of describing a year in which Zoom's stock has doubled in price.
Basically people don't like thinking even one step ahead. What's the consequence of millions of people exposing their private information (PDF bank statements, DOB, scans of their ID docs, etc) via something like Zoom? Massive identity theft and scamming. E.g. people are going to be asked to send money to relatives, and they'll do it. Loans will be taken out using your PII.
If you think identity theft is bad now, consider the problem when you can't go to the DMV, your bank, etc.
Countries with good digital ID programs (like Germany) and vastly more prepared for this problem.
I feel like that's really easy to say if you're not an enterprise/big tech employee who has to use the product to maintain their employment during the quarantine.
Are there any privacy solutions out there for those of us who are required to use Zoom anyway?
By default I would recommend a dedicated laptop for Zoom. Don't use it for anything else. Also shut the laptop down completely when it's not in use.
This means there won't be anything to snoop on, and the hardware will be turned off when you aren't using it.
If you don't need to give it admin credentials (and can just give it anyone's non-special password instead) and it installs to /Applications without an admin's permission, then there's a huge problem. If you do need to give it admin credentials, this still needs to be fixed (urgently, as I'm sure there's tons of one-off developer/designer macs that aren't monitored by IT and have the Zoom client on them), but that would mean the security model on OS X wasn't entirely broken by a badly written video conferencing installer.
These companies presumably all pivot on going public and making a crapton of money: couldn't they anticipate the need to respect the users longer term as opposed to selling them like commodity to investors and advertisers?
The worst types are the ones that advertise how good and amazing they are, and when the "tide goes out they are found swimming naked" as Buffett might say.
When I was in the Seattle startup scene, I came to the conclusion that the Silicon Valley bubble had become overrun with charlatans, grifters, and amoral people only interested in making a quick buck. Pretty much any rando who grew tired of being a used car salesman could max his Visa card putting together a flashy office and a piece of craptastic demoware as a lure to hook investor money.
I think it's just a natural progression. Sleaseballs follow the money.
When flipping houses became popular, the worst kind of people starting flipping houses to make a quick buck. When day trading became popular, the worst kind of people starting day trading to make a quick buck. When software started becoming big business, the worst kind of people started pretending to be "startups" to make a quick buck.
For a more historical perspective, see also: Railroads, mining, logging, banking, shipping, etc...
> need to respect the users longer term as opposed to selling them like commodity to investors and advertisers?
This is the opposite of the truth? There is no /market/ need to respect users, the intention is to sell them to advertisers/etc. Your comment is just conflating your personal (And hn's) moral views of privacy with how markets actually work in the real world.
Edit - I don't mean to be a dick, but you can't just push your morals on the world and say thats how the world should work.
I could just as easily say that "users don't care whether we hash their passwords in our database so why waste the CPU cycles" and I would be right. The vast majority of users don't know anything about storing passwords securely, but
1. They absolutely care if their passwords get pilfered and used to access their accounts. 2. We still have an ethical responsibility to protect people from dangers that we know full well can cause them harm even if they don't understand what those dangers are.
Zoom used the Facebook SDK to provide a social login button. When they discovered that the SDK sends device data over to Facebook even when users are not utilizing the feature, they removed the SDK and reimplemented it using the native browser. Almost every app on your phone that has a Facebook login option has this same privacy leak. Facebook deserves more of the negative focus here for not explicitly stating to developers that they're bundling spyware on their apps.
Every negative coverage of Zoom that I can think of has shown that its flaws were the result of its focus on streamlined/dead-simple user experience rather than any kind of advertising or selling of user data. Meanwhile people suggest alternatives from Google and Microsoft. After Facebook, I can't think of two companies that have a worse track record on privacy than those two targeted advertising companies.
It reminds me of the Dropbox trick they used to get past the accessibility restrictions. The implementation is different, but it's essentially to get around all the limitations that Apple has been building into macos.
I feel like developers shouldn't have to fight the operating system.
> Because Wardle dropped detail of the vulnerabilities on his blog, Zoom
> has not yet provided a fix. In the meanwhile, Wardle said,
> “if you care about your security and privacy, perhaps stop using Zoom.”
This is not the time to release 0-days in telecommunications software, people need this software to save lives.If you work in InfoSec, or just idle in random hacker channels, please push back on this kind of behavior. It would be "irresponsible" at any other time, but in this era, it's literally life-threatening.
Wardle has done more to damage the reputation of the NSA than anyone else I'm aware of.
With Zoom there are compounding factors. Software, video conferencing, video conferencing software, and software businesses are all topics in HN's wheelhouse—as is anything security or privacy related. There have been security and privacy surprises (shall we say) with Zoom in the past, so people are naturally hunting for more. Also, readers are primed to pattern-match any new findings as part of the ongoing sequence. That's a strong multiplier. Familiarity reactions—cache effects, if you like—magnify how much attention a story attracts. There was a similar, though slower-motion, sequence of stories about Facebook last year.
It's not a YC company.
When there's a major ongoing story, such as the current crisis, floods of follow-up and copycat posts appear, since every website and media outlet wants in on the action. After the Snowden deluge of 2013, we learned to moderate these counter-cyclically, so that HN can surf the big waves without getting totally sogged with repetition. The test for a new submission on a MOT (Massive Ongoing Topic) is: does it contain SNI (Significant New Information) [2]? If no, we downweight the MOT. If yes, we try to have one thread about each SNI. I just made up those TLAs.
Zoom has become a MOT in its own right. You can tell that when objections like [3..9] start cropping up. The question is: is the OP a SNI?
[1] https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
[2] https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
[3] https://news.ycombinator.com/item?id=22749596
[4] https://news.ycombinator.com/item?id=22743303
[5] https://news.ycombinator.com/item?id=22748549
[6] https://news.ycombinator.com/item?id=22750059
[7] https://news.ycombinator.com/item?id=22750251
Even though it's free and open source there will be bugs and usability issues that need to be solved. If we pool our effort right we can make open source solution into "just works" solutions, reducing the need for companies like Zoom.
If you propose a new videoconf solution, and the first time a C-suite or major prospect joins the call the call buffers, or someone doesn't have the right drivers installed, or someone doesn't know how to click the link - you are absolutely getting hauled over the coals afterwards.
No one, at any company wants to get the "We're a technology company - why can't we organize a video call?" line.
Convenience is often neglected by people proposing a privacy-conscious, self-hosted FOSS alternative that merely requires you to install it from binary and configure your own Digital Ocean droplet, but it really does matter.
The fact that most users don't care is more reason why product developers HAVE to care. I could just as easily say "only paranoid security people care if we hash their passwords in our database so why waste the CPU cycles?" And I would be right, the vast majority of users don't know anything about storing passwords securely but they absolutely care whether their passwords get pilfered by an attacker and used to compromise their account.
It's free, it's open-source, and can be self-hosted.