Why is the Zoom app listening on my microphone when not in a meeting?
community.zoom.com
community.zoom.com
With how good the browser APIs have become, there is little reason to run native apps, which nowadays are often just an outdated browser with a packaged web app anyways (Electron). Google Meet, Microsoft Teams, and even Zoom have demonstrated that web is good enough if they want it.
If you try to force me to install a native app, that's a strong signal that the app is going to do something against my interest. Given how aggressively Zoom has pushed the app, it was very clear to me that this thing is never going to hit my main machine (I think I have a VM somewhere that I used for a job interview that needed the more advanced features).
I’m afraid Zoom will upload my whole document folder to the internet “just in case you need to share them during the call, so we don’t consume bandwidth”…
So when running zoom in the browser, it could still keep the mic open and listen, until closing the browser tab. That would be equivalent to closing the native app.
I can see a small advantage when running in the browser, but it also comes with additional privacy risks. For example, if I want the browser to remember my settings for file and mic/camera access, I can't run it in a private tab, meaning that tracking via cookies and other techniques becomes a lot easier.
Another issue is that the network communication of a native app can be fenced in by e.g. Little Snitch, whereas fencing in an app running in Chrome is quite challenging. I'd have to apply any firewall rules to Chrome as a whole, instead of the web app.
Perhaps there even exists a firewall as a Chrome extension that would allow that kind of thing; but then we quickly approach the terrain where Chrome becomes something like a VM where just everything runs in, just slower compared to native executables.
There are plenty. I like both worlds. Telegram for example is a good example of an unneeded desktop app that lives fine in the browser ( web.telegram.org ), multiple versions, regular updates, platform independent. On the other side there is signal, which forces to use a very shitty desktop app (or maybe I have not found a better yet). It just sucks.
On linux I have no issues installing "native" apps whatsoever. My editor (emacs), cad software, music player (!) - sure spotify works, but I like my network transparent MPD way more. I could go a lot farhther.
Iam curious about (cloud-)gaming since I actually was very suprised how good it can work.
Edit: Why is this downvoted? What am I doing wrong?
Cloud gaming is one of the technologies I'm quite unsure about, it could become the de-facto standard in the coming decade, or it could remain a niche, all depending on consumer preferences and network infrastructure.
Usability is often the enemy of the security. Signal is full E2EE, including metadata. It compromises security in many ways when using a browser sharing the keys which were originally meant for single receiver and sender. (e.g malicious browser extensions could access the data).
Signal has chosen to implement only their own desktop app. And as their server side is kinda closed and not self-hostable, it is unlikely that we see other clients for a while.
My assumption is that you've got an E2EE link between the Signal app on the phone and the desktop app (with the messages decrypted on your phone in the middle). Why can't you do exactly the same thing with a web app?
I just gave an example - execution environment is accessible by browser extensions. All the code and runtime data is visible for them with certain permissions.
Browser extensions can additionally modify code on the fly. On desktops it is really difficult since you need to inject code into memory.
You are doing something wrong if you run your app as superuser or grant too much permissions by default.
You can also ptrace the process and completely control its execution.
It is true, that often you get PTRACE_MODE_ATTACH_FSCREDS with same UID/GId, but the most production systems have disabled ptrace or there are extra AppArmor rules to prevent its use. In most of the cases it is recommended to be disabled.
For example latest Ubuntu allows only ptracing child processes on the same userspace (https://wiki.ubuntu.com/Security/Features#ptrace)
You can also set your apps in such a way that they can’t be ptraced, for example ssh-agent is doing this with PR_SET_DUMPABLE attribute.
Even that protection doesn't seem to make it safe to run untrusted programs under the same UID, though? If nothing else, there's always the classic "modify user's rc files to put my malicious program first in $PATH." Similarly you could modify them to increase the core file size rlimit, then send SIGSEGV to the process later and collect the core file.
You could try to set it similarly than Ubuntu is doing. See Yama kernel module [1], and set mode 1 (restricted).
> Even that protection doesn't seem to make it safe to run untrusted programs under the same UID, though? If nothing else, there's always the classic "modify user's rc files to put my malicious program first in $PATH." Similarly you could modify them to increase the core file size rlimit, then send SIGSEGV to the process later and collect the core file.
AppArmor[2] is useful for this, you could define profile for the untrusted app, and it cannot access any other file than you allow.
[1]: https://www.kernel.org/doc/html/latest/admin-guide/LSM/Yama....
[2]: https://www.kernel.org/doc/html/latest/admin-guide/LSM/appar...
You should. Linux provides pretty much zero protection for your data. Any app you install can spy on the data of any other app you're using, and all your personal files.
Other OSes are slowly introducing some limitations and protections here, but Linux is really not doing much at all.
If you run X (except on Qubes!) any program can see everything every other X program is doing -- all keystrokes, all mouse clicks, all pixels.
> X program is doing -- all keystrokes, all mouse clicks, all pixels.
Parent was mentioning Wayland specifically to remove this threat.
It just doesn't work in practice.
In theory, the X11 Security Extension would seem to provide a middle ground. On the plus side, I don't notice any performance impact when running Firefox as an untrusted client. However, most programs aren't coded correctly to coexist with it. For example, Firefox crashes regularly when running as such (via SIGSEGV no less, which is its own yikes). Not only that but many programs that are themselves trusted (i.e. normal/default X11 clients) will misbehave if they are simply near an untrusted client: LibreOffice Calc, for example, will lock up hard if the untrusted clipboard is in use.
There's the X11 security extension, which offers the concept of "untrusted" clients, but many programs won't work with it. For example, Firefox segfaults regularly if run as an untrusted client.
I think I tried it at one point and didn't dislike it. I multiboot linux and windows and from day one it felt very comfortable to have a sticky telegram tab in my eternal browser session on both OS that behave the same.
That's a really sorry state of affairs. We should be able to trust our OS to work only towards our best interests. To me a web app represents a complete lack of user control over the content & metadata created by the user; my expectation for a desktop app is the opposite.
The signal I take that an app is going to do something shitty is the level to which the vendor asks/suggests/begs me to install the app. If they don't push it (other and advertising it for sale), I'm more likely to trust it. If they push it ("download our app for a better experience"), it's obviously on their side more than mine.
So yeah, not really that subtle, I agree.
I'm signed into reddit on the webapp, I click a link on the front page, it renders the page, then overlays a popup saying "this page is only available in the app"
and despite having the app, clicking "open in app" takes me to the apple store, so really I can only reliably use reddit if I start my reddit "session" in the app
I won't install the app and the mobile experience is broken.
Which is a shame since I've used it for 14 years.
Apollo for iOS: https://apps.apple.com/us/app/apollo-for-reddit/id979274575
Boost, for Android: https://play.google.com/store/apps/details?id=com.rubenmayay...
Hopefully on desktops old.reddit sticks around forever. https://redditenhancementsuite.com/ is essential.
If I wanted a Fisher Price styled social media thing full of user avatars and giant gifs, I'd use Facebook.
[0] - https://f-droid.org/en/packages/org.quantumbadger.redreader/
I won't install the Facebook app, because I can almost watch the battery drain; even when it's in the background.
It's easy for me to prevent any app from listening. I use an external monitor that doesn't have a microphone, and I connect via the DisplayPort, so there's no audio.
The only time I use anything with a mic, it's for Zoom, and I explicitly turn on my AirPods.
You may want to visit your control panel/system preferences/whatever to see how things are configured and perhaps explicitly disable/mute the laptop mic.
The Chinese app called "genie" used with devices like cheap Merkury cameras, sold at places like Walmart for impossibly low prices and that livestream thru "Tuya" (which likely provides the inputs to China-based deep learning models) also does this on all Apple Silicon platforms. Yes, the "Terms" for that app would seem to allow for it, just like other Chinese apps: https://www.npr.org/2021/01/05/953515627/facial-recognition-... Such streams help China develop models that interpret emotions and behaviorally profile all types of people, not just Uyghurs: https://www.bbc.com/news/technology-57101248 They can also be used like https://www.aei.org/articles/chinas-olympics-app-is-pure-spy...
Pretty sure China has hacked all of the telecom companies to know which IPs (Tuya streams) would go with which Experian® profiles (https://www.fbi.gov/news/stories/chinese-hackers-charged-in-...) too, though such a hack probably involves somethingStupid™ like keyboard firmware injected into customer service terminals at multi-provider offshore customer/provisioning centers. (Those account number to DHCP lease servers/loggers are probably the least protected part of the consumer networks...BigTech has erybody thinking it's about surveillance capitalism, when it's really about surveillance period.) Apple's iCloud Private Relay service doesn't help much here either, as "Tuya" can associate the Apple-device running the app with the IOT devices that are streaming through the "Tuya" platform, providing a pretty good estimation of the identity of the user of the app on the Apple-device (which, of course, can be passed along in realtime to other apps in the "Tuya" family, even as Private Relay is rotating the IP addresses, so long as the "genie" like app is running in the background enough to phone home with an IP update packet).
(Originally posted to someone's duplicate of this thread.)
Nothing subtle about that. Some of the subreddits are completely blocked on mobile web, telling you to get the app.
Unfortunately, Android supports this by only letting verified apps respond to URLs by default and making it really hard for users to allowing unofficial apps to do it.
Yes, It's sad that browsers offer better security than our OS. I also like to point out that browsers pioneered tabs because the GUI toolkit and DE developers failed to do a good job at opening multiple documents well.
Another case pointing to failure with our OSes is the fad of running in containers. This is an extra layer doing what the OS should be offering.
The problem is our OS security models are a relic from the 1970's.
FWIW Linux containers are OS-level with cgroups.
Windows and macOS had tabbed interfaces long before browsers made them cute. This is also an irrelevant distraction from the conversation about trust levels.
> This is an extra layer doing what the OS should be offering.
As pointed out by a sibling, this is an OS provided tool. I run macOS and I find containerisation an annoying distraction from doing my front-end dev work. I see why you might want it for back-end work and I feel your frustration at being forced to use a VM to support a Linux feature in an OS that doesn't share the same feature (or provide a directly comparable alternative). That would be nice.
I don't think it's relevant to the web vs OS trust level conversation either. Containers might support better OS-level sandboxing, but they're still open to the web and to siphoning off user-generated data to the cloud.
The core thing we should collectively work towards is a mind-set (and tools) that better supports users owning their own data more often, and vendors making tools to support that data, rather than monetising it independently of the users they provide tools to. This was the norm through 'til Hotmail and Yahoomail took off; it swung exponentially away from user-benefit when Gmail took off.
I assume that for enterprise customers it's enabled by default though because they realize that making paying customers fail to have their meetings is not a winning strategy.
Edit: Not saying I wouldn't use it myself, though.
This type of thing is why I only run software from the Debian repos or that I build myself. On machines I own, anyway.
I personally still think the UI of web apps are generally terrible, and though they may not be listening to the microphone, spend 10 minutes using uMatrix and it's pretty clear they're spying on you and sending information all over the place.
From [Direct sharing in Zoom Rooms](https://support.zoom.us/hc/en-us/articles/214629303-Direct-s...):
> Direct sharing with proximity detection uses the microphone on your laptop to detect the Zoom Room controller.
With WebEx you can turn this off in the preferences. I'd assume Zoom has a similar config setting.
I haven't contacted Lutron yet which is bad of me, and I really should do that, but I don't think they would care since the amount of people who can identify that there's a problem with their devices is small.
I think it's a pretty cool hack.
It's awful in that using the auditory domain is too much an intrusion into the human space. There is enough noise pollution. Interference patterns around the room may generate harmonics at audible frequencies. Young kids can hear high frequencies we forgot we ever could. I can still hear CRT flybacks. Sometimes I thought I heard something electronic in conference rooms but convinced myself it was nothing.
Someone else was complaining about it affecting their cochlear implant. That is horrifying.
It is not so farfetched that it has an adverse affect on health either. America is losing diplomats left and right to some mysterious ultrasonic weapon, or at least that is one of the leading theories.
It is awful that my CPU has to be constantly running a FFT to read this signal. I think Apple has an ASIC which does the Siri voice recognition.
It's awful that it triggers the orange light to be constantly on so you end up ignoring it. What if Zoom is simultaneously using the microphone stream for nefarious purposes.
This is what Bluetooth was made for. This is a worse idea than Wifi over lighting. Even the 9-digit Zoom dial codes are better.
Definitely.
>It is awful that my CPU has to be constantly running a FFT to read this signal. I think Apple has an ASIC which does the Siri voice recognition.
Isn't it the zoom box that has to be doing the detection? The pc is just sending the signal, which wouldn't take much processing.
>It's awful that it triggers the orange light to be constantly on so you end up ignoring it.
I think someone commented that's for the purpose of detecting if someone is muted and notifying them. Still, there should definitely be a choice to disable this behavior. I wouldn't be able to ignore it.
>What if Zoom is simultaneously using the microphone stream for nefarious purposes.
There's a lot of nefarious things they could potentially do even without using the mic, considering it's software already running on your pc that already has an encrypted connection to their servers.
>This is what Bluetooth was made for.
Good point, that would have been better.
If the PC were just sending the signal it wouldn't need the microphone to be on. And it would stop working when people turn off their speakers like a lot of people do in a busy meeting room.
By the way there seem to be other ways to do it too. Not sure if it's Bluetooth but MS Teams warned me in the past that I was in a room with a Surface display (the huge first generation one). It doesn't keep the microphone active though.. I never investigated how it figured that.
Because this “hack”:
* Works on devices without Bluetooth (or that have it disabled)
* doesn’t require anyone installing privileged software or drivers
* gives a very good “in the same room” indicator
* doesn’t require any custom/expensive hardware components
From the description it sounds like it's just a handoff feature, as in you go into a conference room with whatever their conference room product is.
Once you get in handoff range they only need to exchange sufficient information to get the AV equipment to start a connection to the appropriate zoom/webex/whatever channel, and presumably the reverse of getting the original zoom client to close.
I'm assuming there is some work to reduce the likelihood of unintentionally triggering it, and some basic authentication, but this is not a lot of data, and ultrasound is more than sufficient to do it very "instantaneously".
I mean, if I ever switch off Bluetooth it's exactly for the reason that I don't want my device to be detected/tracked. Zoom going around this by using ultrasound is kind of mean, since I can't prevent zoom from using audio if I want to be able to make calls.
That was my interpretation of the feature described earlier in the thread
> But this means that at least some kind of access token must be transmitted over ultrasound. ...
Yup, I agree I'd love to know more about what is involved. I like to think there's a degree of authentication involved, but this is also Zoom. The company that installed a persistent service in order to circumvent a security feature in safari, that also allowed unauthenticated RCE.
> I mean, if I ever switch off Bluetooth it's exactly for the reason that I don't want my device to be detected/tracked.
I had assumed Android and PC had adopted the randomized MACs apple uses to prevent such tracking?
> Zoom going around this by using ultrasound is kind of mean, since I can't prevent zoom from using audio if I want to be able to make calls.
If we assume for now that it is properly authenticated, and has safe tokens to break tracking, identification, etc, then this behaviour seems reasonable. It would require you to open zoom in a room with the requisite enterprise-y teleconference equipment.
But of course that is quite a load bearing "if", and it already appears that they're trying to maintain the channel when they aren't active.
True, and this is why I rarely switch it off, except in situations where I don't want to be visible to devices that I previously connected to. Same for wifi.
I just find it quite over the top to work around user-controlled communication channels like bluetooth that the user might have chosen to disable, by using a medium (sound) that the user cannot switch off and still use the app.
As I noted earlier it works without bluetooth available, but more importantly I suspect, if it were bluetooth everyone would have to peer their devices with every conference room. If it were wifi you'd need to know the network name of the conference room's AV system.
While both options would work, having a single "switch to AV system" button is clearly the best user experience, so you try to make that possible. Given both the app and the AV system have the ability to create and record sound, that's the obvious choice.
But again, I'm not making any statement on the security of the actual implementation from Zoom :D
Where this reasonable solution is actually implemented securely is another question, and Zoom’s track record isn’t exactly fantastic.
Zoom deciding to use the mic while not in use is clearly a terrible bit of behavior :)
If so someone should make a jammer.
When it works, it means someone can walk into an appropriately equipped meeting room, and the software on their machine detects that. The audio, video, and screen sharing all route through the meeting room, rather than the laptop. Virtually zero involvement for the user.
I recall that if you were not signed in to an account on their Org, it would only show up with you as that you were a guest in the room, and you could not do much/anything without someone from that org authorising you.
I dont know if the token is long lived, i would hope its rotated frequently.
i also suspect that because it's above audible range, your average video compression might strip it out.
Plenty of people use conference rooms for non video chat reasons, and many of those reason have confidentiality rules.
I know for example there are strict rules around what is required to protect client/lawyer confidentiality, and most of the protection goes out the window if you record, or allow some one else to record them. Would zoom listening in on that count? I have no idea
The only class of apps that have any business using a microphone while not in active use are “assistants”, and those have no business doing anything other than listening for their initiator phrase (except haven’t they all been caught sending arbitrary recordings to their parent company?)
Hmm... but, then again, there was that thing where Amazon Alexa was recording people without their knowledge... hmm.
Every place I have worked in the past there have been zero pathway for IT/Developers to notify a lawyer about anything or ask a question.
https://thenextweb.com/news/zooms-scary-webcam-flaw-also-aff...
And then the people in charge of the money would do the math on "this earns us 1 billion dollars and the fine has a 10% chance of happening and would be 100 million... so do it anyways, it's worth the tradeoff". This happens over and over.
No need to use quotes here, that was literally my question :D
> In all US states and probably a lot of countries, recording is illegal without the consent of at least one party to the conversation. In the US, in some states, all parties must consent to recording.
Literally every company that got caught having their assistants record conversations turned around and said the victims were informed and consented through the terms of use agreement.
Their lawyers didn't stop them from claiming to provide end-to-end encryption, a blatant misrepresentation that resulted in receiving a consent order from the FTC [1] and settling a class-action suit for $85M [2], so I don't think it's safe to assume that they would prevent the company from doing obviously unacceptable things.
[1]: https://www.ftc.gov/system/files/documents/cases/1923167zoom...
[2]: https://arstechnica.com/tech-policy/2021/08/zoom-to-pay-85m-...
Meeting start -> probe for hardware -> make decision where to host
This situation may exist because it’s inevitable but it still sucks.
I can close it and know it is closed.
As others have said, Jitsi is a for many meetings a good FOSS alternative. And if that does not work, use Zoom in the browser.
A desktop operating system that comes with a proper security and permission model (i.e. not a standard Linux system). Right now, QubesOS seems like the only candidate here.
I can't believe Android and iOS are now >=15 years old and Linux is still struggling with this.
The primary cause of this problem is the conventional desktop OS which has no meaningful security model.
IOS and Android have the correct approach to mitigate this, strong sandboxing and mandatory access control.
GNU/Linux phones bring these problems to mobile, which considering how much of our lives are on these devices, is an absolute disaster.
The only way to meaningfully secure a GNU/Linux desktop is to run multiple instances of it through a type-1 hypervisor.
For a mobile device, a user prioritizing privacy, security and FOSS would be much better served by GrapheneOS.
It's a pick your poison type of situation I think. I personally run FOSS where I can, and compartmentalize the environment where I can't but I still want the benefits.
But for personal use- totally makes sense
The number of Android phones in existence is evidence of how important it is to have affordable tech.
Google's algorithm knows you opened your browser. They almost certainly know what page you opened and how long you have been on it [on chromium, everything typed in URL bar is sent to them]. They probably know that you asked the above question.
If it is a cheap android phone (or even if not, if it uses Rockchip chips, if it is a Xiaomi and likely if it is a Oppo) then at least one Chinese corporation, with ties to a very sophisticated gov apparatus knows it as well.
Considering how many permissions they allow each app to receive (esp. on older versions, which are the majority of users) other apps likely know it as well.
I have a Samsung, and there are lots of clues that they know everything I type and a lot of what I say as well.
Probably other actors as well, since a porous pail will leak...
Also, look at other things that are made invisible to the people, and when made visible, people react negatively. Treatment of animals in the various industries, treatment of workers in countries where labour is cheap, issues with waste and its environmental effects.
So all you are doing is making the rest of the community look bad, by essentially doing zealot preaching: you’re telling the people who don’t have a choice that they’re stupid for not doing exactly what you do.
If you are a student at a university using zoom then there's no other realistic way to participate and learn today. I also can't imagine many employers makng an exception for a single employee.
I’m also going to get that while bullshit (I trust signal’s crypto a hell of a lot more than more or less any other company) I would bet they don’t have some arbitrary set of certificates or whatever for doctors to be able to use them
Similarly, if I attend a virtual meeting elsewhere those people choose what software to host it with.
So feel free to "preach" to companies instead of people.
We need defence in depth, and a physical switch would be one of the best protection mechanism.
Just like developers learnt the hard way that user input should not be trusted, users need to realise that software should not be trusted either.
4-Port USB 3.0 Hub Power Switches https://www.amazon.com/gp/product/B00TPMEOYM
Windows/browser permissions don't have device level granularity AFAICT, so I can't allow access to only an external cam/mic, but I can disable the internal ones in the OS for full tinfoil hat compliance.
Most importantly off is actually off when a button cuts the power.
Although I wonder if the bios on this HP let's you disable it...
Good thing! Yields superior audio quality (because it means there is a powered pre-amp right next to the microphone's recording point) and allows to physically turn off microphones.
"You fixed it so that it doesn't switch the microphone on at all, not just stopping the light coming on, right?"
"Right?"
(Yay! Memes in text form!)
https://github.com/cormiertyshawn895/RecordingIndicatorUtili...
In Chromium/Chrome it does but limited to 9 people.
How many "mistakes" do they have to make before you reconsider? They lied to their users for years that their software was end to end encrypted. They sent user's data along with their keys through servers in China. They rolled out their own encryption system, lied about what algorithms they were using, and the encryption they were actually using had well known weaknesses. If they aren't outright malicious they've somehow managed to maintain a level of incompetence that's just as harmful.
I argue that they are definitely knowledgeable and capable of security. The nuance is they care about their own security, not the users'.
Case in point: Their MacOS installer abuses the pre-installation step to fake a System prompt to obtain root, very much like malware. Before you actually click install, it's already done [1].
In this case it was merely a shortcut to reduce the number of clicks to install, but it clearly betrays their disregard for user control & security.
[1] https://www.digitaltrends.com/computing/zoom-mac-one-click-i...
* SEO Bonus: I couldn't find this article on Google no matter what I queried for. But DuckDuckGo found it on my first attempt.
Guess abusing SEO to hide negative press is among their tactics as well.
I have previously reported bugs to Google, including one where they simply didn't put any auth on an API endpoint for a new feature, allowing access to any account's data. That is a massive oversight, but at Google scale we realise these things happen, and the more important consideration is how companies respond.
Zoom have a private bug bounty program, but I previously disclosed Zoom bugs publicly [1] as I didn't think their bug bounty program was worthwhile engaging with.
However, they overhauled it, and now of the dozens of private programs I am part of, Zoom's is one of the absolute best. The payouts are great, the team actively engages with the researchers, and seem to legitimately care about getting things right.
Are they perfect? Of course not. But I would feel safer on a Zoom call that call with many competitors who simply don't get as much scrutiny.
[1] https://www.tomanthony.co.uk/blog/zoom-security-exploit-crac...
Nothing about this company's attitude towards privacy has changed in years.
Chrome: https://chrome.google.com/webstore/detail/zoom-redirector/fm...
Firefox: https://addons.mozilla.org/en-US/firefox/addon/zoom-redirect...
Edge: https://microsoftedge.microsoft.com/addons/detail/dkhjempaia...
Opera: https://addons.opera.com/en/extensions/details/zoom-redirect...
Concerning this line: https://github.com/arkadiyt/zoom-redirector/blob/master/back... Why is it sometimes returning undefined? (or is that known)?
Cheers!
> const match = /^\/[js]\/(\d+)\/?$/.exec("something")
> undefined
[1] https://tc39.es/ecma262/multipage/ecmascript-language-statem... [2] https://tc39.es/ecma262/multipage/ecmascript-language-statem...
What fun! :-)
Edit: apparently as also mentioned https://news.ycombinator.com/item?id=30268412
Also match[1] will never be undefined: it’ll either throw an exception, or be a string. No, this is just a bug, a poorly written guard that fails to guard what it was supposed to, and I suppose an exception is just silently swallowed and treated equivalently to the intended early return. But the clause should be changed to just `if (!match) return;` or similar.
Sure thing. All browser extension source code is available to you anyhow, even if the author doesn't publish it.
> Why is it sometimes returning undefined?
Looks like a simple bug as some folks below have pointed out. It doesn't impact the functionality of the extension in any way here.
Apparently H.323 works too, but I haven't tried that either --- just noticed the "dial this IP to join via H323/SIP" at the bottom of the invites and did so.
Despite them doing the same thing.
I use teams a lot for work and Jitsi with the makerspace crowd and Jitsi is just so much better imo..
Everything else seems to work fine in both.
On Chromium, sometimes video/screenshare is not visible for me, only black screen.
Often there is no choice but use the app… sadly.
RIP a trustable keybase.
Massive GCHQ data grab!
1. On first opening the link, a browser confirmation window immediately asks me for permission to launch the app. I press "Cancel".
2. There is no option to join from my browser. But, there is a big blue button that says "Launch Meeting". I press it.
3. Again, the confirmation window from (1.) is raised. I press "Cancel".
4. Choosing to cancel a second time causes a visibility toggle for a small link on the bottom of the page (hidden beneath the giant blue button) that says, "Having issues with Zoom Client? Join from Your Browser".
Anti-patterns out the wazoo!
I can't see how it can be that hard to just close the mic device when you go off a call.
Another infamous example is proctoru. Literally a spyware, but delivering a spyware requires much less effort (both intellectually and financially) compared to designing a product that makes security-savy customers happy.
[0]: https://8x8.vc
I have a wrapper script that installs, starts the meeting then uninstalls because unfortunately people use it and sometimes I need to contact them.
The biggest problem for me is having multicolored noise covering most of the Zoom windows/controls when I'm sharing a window.
Also, it takes like ten seconds to share or stop sharing a window.
Exclusive mode is a bit like full-screen for GPUs. DirectX games can do things like override the output color management, gamma ramps, brightness, HDR mode, and even set the "white point" on some displays! Similarly, audio applications can take control of your audio devices in all sorts of ways if permitted.
While "full control" of a GPU is still useful, because we're not living in a utopia where all displays are 12-bit HDR all the time, audio has long ago passed the point where direct control delivers tangible benefits. Software mixing is more than capable of "keeping up" even with an absurd number of simultaneous streams at a quality level that vastly exceeds what the human ear can perceive.
I found that with Teams, it's more important to turn off direct control of the microphone than the speakers, but I do both just to be on the safe side...
The only pulse audio annoyance happening here is pulse audio itself assuming all my 3.5mm jack headphones have a microphone.
I regrettably had to install Zoom on my Mac because so many people use the service.
However the Mac makes it an easy process to block microphone and camera access. So when I don't have any Zoom meetings scheduled imminently, I just go to System Preferences -> Privacy Settings and kill off Zoom's access there. Only takes, what 5-10 seconds. I guess I could even script it via AppleScript (or potentially CLI), but have never had the time to investigate.
One of the best things about Apple MacOS and Apple iOS is the centralised privacy settings that make it easy to see what has access and easy to turn it off.
tell application "System Preferences"
set securityPane to pane id "com.apple.preference.security"
tell securityPane to reveal anchor "Privacy_Microphone"
activate
end tell % brew install zoom
When done, eradicate all traces with the zap option: % brew uninstall -z zoom
It's pretty wonderful, IMHO.open zoom, join a meeting, then pkill -9 zoom when done. Didn't trust having it around.
Docker images, by design, don't anything while not running. So you wouldn't even have to uninstall it. Just stopping it guarantees it does nothing.
ads targeted to users based on conversations within ear shot of an always listening device sounds like a big money maker to me
although I don't use zoom, something(s) is already doing this on my phone as I get targeted ads based on conversations I have, routinely ( typically within 45 mins) despite taking many precautions... some technology is already out there in production
EDIT: This formatting sucks, how does HN not have markdown fenced codeblocks? Anyway, here's less fail formatting:
``` <key>SMPrivilegedExecutables</key> <dict> <key>us.zoom.ZoomDaemon</key> <string>identifier "us.zoom.ZoomDaemon" and anchor apple generic and certificate leaf[subject.OU] = BJ4HAAB9B3 and certificate leaf[subject.CN] = "Developer ID Application: Zoom Video Communications, Inc. (BJ4HAAB9B3)"</string> <key>us.zoom.ZMSipLocationHelper</key> <string>identifier "us.zoom.ZMSipLocationHelper" and anchor apple generic and certificate leaf[subject.OU] = BJ4HAAB9B3 and certificate leaf[subject.CN] = "Developer ID Application: Zoom Video Communications, Inc. (BJ4HAAB9B3)"</string> </dict> </dict> </plist> ```
That's `~/Applications/zoom.us.app/Contents/Resources/Zoom-Info.plist`, last few lines of the file.
Even though I didn't install it with admin permissions, it's at least trying to slip that shady shit in under the radar. No idea if it succeeded or not, need to do some deep analysis to find out, but probably the simplest/surest fix is to nuke the entire filesystem and rebuild my macos installation from scratch. Done it before many a time, easy enough, just a laborious pain.
Never again, Zoom. Never again.
(Same goes for Teams, and basically anything that isn't browser-based, by the way. Assumption of human rights violations is now the default.)
I don't care if this is just a "harmless bug" or an accident. Too many attempts at shady shit have been glossed over in the name of forgiving an honest mistake. Not anymore. I'm done.
Code blocks are made by indenting by four spaces, like this:
<!-- last few lines of ~/Applications/zoom.us.app/Contents/Resources/Zoom-Info.plist -->
<key>SMPrivilegedExecutables</key>
<dict>
<key>us.zoom.ZoomDaemon</key>
<string>identifier "us.zoom.ZoomDaemon" and anchor apple generic and certificate leaf[subject.OU] = BJ4HAAB9B3 and certificate leaf[subject.CN] = "Developer ID Application: Zoom Video Communications, Inc. (BJ4HAAB9B3)"</string>
<key>us.zoom.ZMSipLocationHelper</key>
<string>identifier "us.zoom.ZMSipLocationHelper" and anchor apple generic and certificate leaf[subject.OU] = BJ4HAAB9B3 and certificate leaf[subject.CN] = "Developer ID Application: Zoom Video Communications, Inc. (BJ4HAAB9B3)"</string>
</dict>
</dict>
</plist>Of course four or more work as well, but they add extra indentation that you don't need.
The issue: While watching Zoom webinars on Mac, clicking on Audio Settings auto-activated the mic for testing audio levels. However, Zoom forgot to deactivate it upon leaving the settings. For the rest of the webinar, the input device stayed activated in the background (as evidenced by OverSight and Micro Snitch). I could not find a way to deactivate it.
This issue is similar to one that affected Shazam: "Shazam Keeps Your Mac’s Microphone Always On, Even When You Turn It Off" https://www.vice.com/en_us/article/8q8ee3/shazam-keeps-your-....
I can view full-HD video without the fan even making a sigh, but joining a Zoom meeting and turning off everything except incoming audio makes the fan scream.
What's going on? Is that app doing crypto-mining in the background?
Just FYI, Little Snitch resolves the DNS request (to IP) while the dialogue is onscreen (i.e. before you click `DENY` or `ALLOW`, a DNS query has already been sent).
All Little Snitch does is prevent the connection to the IP address, but your DNS host (e.g. ISP) knows what URL(s) you are requesting, even if/when you click `DENY`.
[0] https://www.privateinternetaccess.com/blog/google-chrome-lis...
What about phones and other devices that respond to voice commands that are also constantly listening?
There is no such thing as privacy. Only the trust that you have in companies to not abuse the data that is collected of you, or you go completely off grid
It makes me much more comfortable in the age of WFH. I never know when someone or something might be listening.
I have to use Zoom lately, and my solution is an old Android tablet that I don't use for anything else. I opened it up and physically disabled the built-in microphone. I use a headset for meetings, and simply disconnect it from the tablet when the meeting is over.
After all, anyone noticing (or caring) that mic on indicator is probably <1%, and I'm obviously talking about the general public, not HN community.
but that only works when the device (computer) actually requests mic data. e.g. if I just connect it to listen to music, press the button will not do anything. if I'm in a google meet meeting and I muted myself in google meet, press the button will also do nothing.
but if I'm in a zoom meeting (via browser, I don't allow their apps anywhere near me), even if I have myself muted in zoom, press the button will still have the announcement, which means even if I'm "muted" on zoom, zoom still keeps requesting my mic data.
>Resolved Issues
> Resolved an issue regarding the microphone light indicator being triggered when not in a meeting on macOS Monterrey
Conceptually, it's similar to Apple always listening for "Hey Siri".
But the huge difference between these two cases is that most people will probably trust Apple more than Zoom, which is understandable.
Uninstalling Zoom. Team discussion on dumping zoom for the whole company to come.
Surely people know better by now.
You can choose whether to trust the company or not, but I don't.
Haha, a problem with the light staying lit, not with the mic staying on. Riiiiiiggggght.