Personally, the fact that I filled out what turns out to not be a system dialog with my password (https://twitter.com/raganwald/status/1244994636982222848) makes me feel violated.
I'm genuinely quite angry about this. I never enter passwords into 3rd party apps - I've had arguments with companies who embed oAuth flows into their app about this.
Thanks for clearing that up, though I must say they (Zoom) bring this upon themselves by having such a poorly worded dialog.
"Maybe try to read the blog post" can be easily replaced with a less patronizing and just as informative "It's in this blog post".
You have good points to make, they don't need the vitriol to be taken.
I was clearly also making a meta-comment about Twitter misinformation, so the patronizing part was inevitable.
Oh, if you're already hacked in enough to run code on MacOS, you can grab the camera with Zoom. Or, you know, use any of many methods to do that I'm sure. The problem, and the reason for HIPS / AV / security solutions is to stop running "hacker code". If I'm running arbitrary code on your Mac, I don't need Zoom to grab a password.
Now, the bad installer methods used on MacOS - yes, those should not happen and ought to be fixed. I think it's the big problem, no one gets paid for a secure system, but one that people can use. Security just causes issues sadly, and making it possible for the most incapable computer user is why everyone loves Zoom for "just working". That sadly incentivizes them to try and work around security roadblocks, which is bad.
Regarding the hatred for Zoom... I'm sure a lot of people feel the same as me. I'm tired of having to install and trust yet another native app just to perform a task I've been able to easily do with countless other solutions for well over a decade. I understand why Zoom in particular has found recent success, but it's still annoying.
Zoom's recent surge in popularity also probably draws a lot of attention from cynics and skeptics.
None of this is contrived; and all of it is serious when you're the parent of a school age child.
Every zoom post I've read here has at least one highly-upvoted comment about "hey everyone lay off zoom". Why? Why should we give a company that millions are now using for the first time a break? Why should we ignore issues with software that tons of people are now using and potentially opening themselves up to danger?
I use zoom, I used to before the pandemic and I've used it with friends since multiple times. I'm not some anti-zoom, burn it all down type. That said I think issues with it warrant a discussion and there is a reason these things are upvoted: because millions of people are now using it and are unaware of the risk they are taking.
There's no malice there (on the posters' side). If Zoom does better people won't have cause for shining a flashlight on their data privacy policies or security holes. We will see if Zoom grows up fast, since the momentum towards them is already so large I don't see it changing prior to the Fall when schools might risk re-evaluating their tools.
You can access Zoom meetings through a pure web interface without installing anything. The experience is somewhat reduced.
1) The lack of e2e encryption despite trying to market themselves as having secure video chat.
2) https://news.ycombinator.com/item?id=22749805 (comment in this thread - they literally phish you)
3) https://twitter.com/c1truz_/status/1244737672930824193 abusing the traditional installation process on OSX
EDIT: OK (2) may be a real system prompt - https://twitter.com/DigitalResist0r/status/12452813782932807...? I didn't see anyone else in the twitter thread claim that it was using a real system dialog, so I'd still say it was poor practice of them to have such a shady looking system dialog.