Zoom zero-day discovery
blog.malwarebytes.com
blog.malwarebytes.com
Entirely aside from their many past security holes which have been handled poorly , they have straight up lied about end to end crypto and what exact crypto it's using. That's before we get into the ownership of the company, its management and the location of most of the developers.
For sensitive data, only Cisco and Microsoft are allowed.
How does the West have anything to do with this? Moreover, the West is the birthplace of the "move fast and break things" ideology.
Just change the /j/ in the url to /wc/, and insert /join after the meeting id.
https://devforum.zoom.us/t/launch-zoom-client-from-browser-w...
This feels like a straight up PR piece.
Especially since they've faced serious accusations earlier on.
Also I find it funny that the heading "Not patched yet" is solved by the headline "Security done right".
Lets say if you are working with a company that deals with say healthcare information a 0-day certainly doesn't make things safer and since it is not patched yet this is definitely not done right.
Depends on your perspective. a 0-day is a very good thing if you are an advesary trying to get in. so maybe to the alphabet soup of groups CCP, FBI, NSA, etc, woohoo!!!
Thus it is NOT a "zero day" but a "critical vulnerability".
Sod the clickbait-y titles!
> A zero-day (also known as 0-day) is a computer-software vulnerability unknown to those who should be interested in its mitigation (including the vendor of the target software). Until the vulnerability is mitigated, hackers can exploit it to adversely affect programs, data, additional computers or a network.
Seems like someone knows how to exploit this, and zoom / the general public don't know how to mitigate or perform it. That seems to fit this definition, no?
And it shouldn't be the responsibility of the poster necessarily to quote it -- because there's no verifiability there.
Although there's no verifiability there, I would assume that most people on here comment in good faith.
Zoom zero-day discovery makes calls safer, hackers $200,000 richer
While we’re talking feature requests, I think each submission should offer an optional second weblink, reserved specifically for the “original” or “source” URL.
It bothers me when the link is changed after lots of comments reference the previous one.
- DEVCORE targeting Microsoft Exchange in the Server category (The DEVCORE team combined an authentication bypass and a local privilege escalation to complete take over the Exchange server.)
- The researcher who goes by OV targeting Microsoft Teams in the Enterprise Communications category (OV combined a pair of bugs to demonstrate code execution on Microsoft Teams.)
It would be kind of funny if Slack had one too...
[1] https://www.zerodayinitiative.com/blog/2021/4/2/pwn2own-2021...
This is about the implementation in the SerenityOS but it's my favourite explanation so far: https://awesomekling.github.io/pledge-and-unveil-in-Serenity...
Things like Windows Defender and Snap and the recent macOS hardening efforts are patchwork solutions to try and cope with the modern world, but they'll never really be enough because these systems can't be fundamentally re-thought; they have to keep doing everything everybody already expects them to do. Only brand new OSes really get the chance to do things right, and only the mobile ones really had the opportunity to gain wide adoption.
For example, phishing sites would be radically less effective if passwords are not a thing, and everyone logged in using hardware keys (e.g. Yubikeys) which cryptographically prevent phishing.
Of which there have been plenty.
As a Linux-based programmer who hasn't quite delved into the UNIX internals world, knowing that I have to write my own BPF filter or do some crazy stuff with file descriptors (in the case of capsicum) is enough to scare me. But on OpenBSD, I added `pledge` and `unveil` calls to all my silly Python chat bots in 15 mintes
But then I have lost all trust in Zoom due to the history involved with it. And I also don't thing Zoom will regain the trust, because due to the way they lost trust again and again and also acted in-honest it's pretty hard for them to convey that they changed (instead of just pretending they did).
It isn't if you're on a laptop from 2021. But that vast majority of people aren't. Companies don't provision new computers to their employees every time a new computer comes out. At the companies I've worked for, the minimum refresh time is 3-5 years, depending on tax laws, and financial ability.
It's also not a big deal if the computer is only used for Zoom. Most people, whether office drones or developers, run many programs at once.
That "ram is cheap and plentiful" is also seriously not true for Mac laptops, which both caps how much one can expand them and also charges unreasonable rates for the additions they do allow
Oh man, I'd love to live in the wonderland where you posted this comment from.
My laptop from 2019 also had 32g and was less than 2000 usd.
Obviously most people don't need that and I'm sympathetic to anyone having to run teams on some shitty IT-provided low cost laptop loaded with 7 different management spyware suites, but 16g-32g is not baller in a limo outrageous.
On 16GB I was constantly running out of memory at work. It’s not just 1GB it’s 1GB times all the other crap you need running.
what's so bad about team's security that its almost on your ban list?
Well I did say I assume I'm not being trolled so I'm not sure what you're referring to. As a teams user I asked a good faith question to try and flesh out her reasons for considering banning Teams.
But to give you a reason why someone might assume a troll
- random internet stranger
- Microsoft mentioned, some people just don't like them as a company
- no actual reason given, just a comment with zero supporting evidence.
How many more reasons would you like?
These things shouldn’t end with a bounty for the researcher and a patch by the vendor. It should end with a root cause analysis and a plan to fix that type of vulnerability across the entire app, or better yet, the whole industry via a research paper.
Is $200k enough to motivate a company like Zoom to do an RCA after something like this? Maybe? I personally doubt it but don’t have any real reasoning for it one way or another.
I'm unsure (and open to discussion) on which classes of bugs make that possible. My initial thought is that finding a stack overflow bug (to randomly choose a bug class) results in "don't goof up memory", which is technically correct, but not actually useful in finding others of that class.
In this hypothetical, maybe the result would some combination of accessing programming language choice, programming practice, and testing tooling? Can't say those are a silver bullet though.
The web-app has fewer capabilities (no gallery view, last I used it), but works great.
Also, Meet is fully-featured and runs entirely in-browser.
Look, I prefer webapps when possible and keep mobile apps to a very minimum on my mobile (and preferably from F-Droid, at that). But I also understand that you can only do so much in a release and if your engineering team expertise, backlog, users, sales, EVERYTHING, is centered around native apps. Then damn it, you're going to make your native app look stellar because otherwise your competitors will get a leg up over you.
I deleted the FB app from my phone years ago (with difficulty because Samsung makes it undeletable by non-hackers) because the app gives FB far too much info about me.
My son's school uses Google Meet for online classes. 2 instructors + 36 students per section. All participants have their videos switched on. Even when the bandwidth fluctuates, we haven't noticed issues. In particular, Meet degrades well: audio continues to be high quality, with video becoming grainy or getting suspended. But, that is pretty rare. And, slide shows are never a problem.
You don't have to find many zero days. Just have enough. Huge backend of tools and network of contributors surely helps, but if 0-day is gone in Zoom, and say you don't have their explicit cooperation (which you totally can have) and you only have one, then it may not be such a worry if it is commonly used with other software that you can own.
Besides that, there are tiers of 0-days, some of which you would not touch unless the target is exceptionally valuable and you did some homework with oh-just-a-common-malware to learn about their system and response.
There is no system that is secure. There may be systems that are obscure. But if they would be targeted they can be owned with easy because they are not popular and security is really really hard.
This is not just crazy talk anymore, it's reality. It's enough to watch CVEs, think what you could do if you exploit them silently and what that allows you to do in the future. Watch them not only for abstractions on top, but for whole tons of firmware running both on your machine and machines that you trust. Oh and certificates... It's just too easy. Way too easy.
Their browser app does not have feature parity; recently I had to participate in a conference and the browser version fucked up my camera's aspect ratio, a problem that doesn't exist in their full client. A burner laptop was required, and was wiped immediately after.
Avoid Zoom whenever possible. Don't ask others to use it.
I really appreciate the article author mentioning this. It gives hope to all beginners and shows that "overnight success" is a result of months and years of learning and research
"We also know that the method works on the Windows and Mac version of the Zoom software, but does not affect the browser version."
Edit: Not an electron app.
Zoom is a C++ / Qt app
(I'll also point out that even if you have a Win32ChatWidget in the library, that doesn't many anyone is going to use it. Zoom simply did a bad job implementing chat, which is why it's so bad. The UI toolkit library is neither the problem nor the solution. Caring about making chat good is the solution.)
The InfoSec community seems to be quite happy giving away their hard work, while the large security vendors make mountains of cash on snake oil solutions to enterprises. For context, Zoom certainly paid many multiples of $200k during any given month for firewall licensing.
Still, 200k seems _low_ for a bug that should imperil the reputation of a many-billion dollar company. And a few years ago it seems like that would have been $1000 and a firm handshake...
Critical Zoom vulnerability triggers remote code execution without user input
https://www.zdnet.com/article/critical-zoom-vulnerability-tr...
"The attack must also originate from an accepted external contact or be a part of the target's same organizational account," Zoom added.
"As a best practice, Zoom recommends that all users only accept contact requests from individuals they know and trust."
It's our own damn fault for becoming over-reliant on CI to find all the bugs.
You'd need to understand who/what are your threats to understand if you're "safe" or not.
But the short answer is probably not. Unless you are running Qubes or something, if someone can exploit an RCE then they can probably own your system.
For two researchers, that sounds like a lot. $100k each in less than a week for this bug sounds just rightly priced.
"zero-day discovery makes calls safer" "Understandably, Zoom has not yet had the time to issue a patch for the vulnerability" "This event, and the procedures and protocols that surround it, demonstrate very nicely how white-hat hackers work"
Imagine if that was your run of the mill well-hated big corp
"Yet another security vulnerability leaves millions at risk" "XYZ Corp shows its incompetence once again exposing users' private data to hackers" etc etc
No specific point here. I am just amused!
For me it one of the more enjoyable online meeting options and it leaves Teams, Skype, webex and what have you, far behind.
See: Privacy concerns, lying about encryption, connections to china, bad security.
Possibly "people on HN hate zoom, and then use it anyways because it's forced."
Microsoft seems to be the one banging the "zoom is insecure" drum hardest and teams had, like, 4 zero days and paid < 30K for them IIRC.
Mistakes were made with security early in their product. It’s clear that has turned a lot of potential users against them.
I’m curious why companies like Facebook get more acceptance over terrible security, but other companies are never forgiven
This is not my experience at all. Early in the lockdown when Zoom became the darling, I was forced to install their app. Pre-pandemic, Zoom was already panned on this site for crap they were doing, so I pushed back hard against using Zoom before ultimately relenting. Running zoom with a simple 3 person call would bog down my 2017 MBP with fans running full tilt. I've since upgraded hardware and zoom is not allowed to be installed on this computer.
>I’m curious why companies like Facebook get more acceptance
Is there anyone on this site that agrees with that comment? I certainly don't. There are multiple billions of FB users, so I'm quite sure the readers of HN is just a mere rounding error level of numbers.
IE11 (ew), old Edge (ew), Chromium Edge and Chrome are fully supported. Newest Safari has limited support, and only Firefox and older Safari versions are the only ones explicitly not supported.
The ding is that, because it was a "public contest", the existence of the vulnerability is known. And that's probably a higher risk scenario in the abstract I guess. But I think it's clear to all that Pwn2Own and similar activities are a net benefit to global software security nonetheless.
Responsibe disclosure processes are just as much about closing the vectors that we can't prove are under active exploit.
And these help patch not just the specific hole but the general approach of the exploit chain may expose a whole area the development team had not previously considered.
Just to be clear, I think programs like this are great and they do improve safety, but only because they result in patches. This news shouldn't make users feel safe until there is a patch.
I don't know what the general perception of Zoom is. Our opinions of it never really come up at work. The discussion I see of it online largely focuses upon the security issues so that is going to be negative. There is one thing I am grateful for though: it seems as though the masses settled on a product with decent cross-platform support for once. You rarely see that unless the product is intended for a niche market (e.g. science, engineering, software development). Heck, they even package it for Arch.
*citizens not yet evacuated from radiation zone
Google Meet, Slack calls, literally everything else works perfectly. With screenshare. On Wayland. I just call in to Zooms now.
Clearly your experience differs, not sure why.
Of the proprietary video meeting apps, they all have problems, but Zoom sucks less than Teams, Webex, or Skype and is a lot easier for non-technical folks to use.
Zoom is one of my, and several of my coder friends', top-five well-hated big corps.
This far into the pandemic, I take personal pride that I hadn't installed what for a while was essentially reported as Chinese spyware on my machines. :)