Personally, the fact that I filled out what turns out to not be a system dialog with my password (https://twitter.com/raganwald/status/1244994636982222848) makes me feel violated.
Personally, the fact that I filled out what turns out to not be a system dialog with my password (https://twitter.com/raganwald/status/1244994636982222848) makes me feel violated.
I'm genuinely quite angry about this. I never enter passwords into 3rd party apps - I've had arguments with companies who embed oAuth flows into their app about this.
Thanks for clearing that up, though I must say they (Zoom) bring this upon themselves by having such a poorly worded dialog.
"Maybe try to read the blog post" can be easily replaced with a less patronizing and just as informative "It's in this blog post".
You have good points to make, they don't need the vitriol to be taken.
I was clearly also making a meta-comment about Twitter misinformation, so the patronizing part was inevitable.
Oh, if you're already hacked in enough to run code on MacOS, you can grab the camera with Zoom. Or, you know, use any of many methods to do that I'm sure. The problem, and the reason for HIPS / AV / security solutions is to stop running "hacker code". If I'm running arbitrary code on your Mac, I don't need Zoom to grab a password.
Now, the bad installer methods used on MacOS - yes, those should not happen and ought to be fixed. I think it's the big problem, no one gets paid for a secure system, but one that people can use. Security just causes issues sadly, and making it possible for the most incapable computer user is why everyone loves Zoom for "just working". That sadly incentivizes them to try and work around security roadblocks, which is bad.