10 comments

  • rmellow2 hours ago
    Not the first time Zoom abuses privilege.<p>A few years back, there was something about gaining root on MacOS via Zoom due to shady execution on their end.<p>They&#x27;ve lost my trust since then, and I&#x27;ll only run it sandboxed: <a href="https:&#x2F;&#x2F;gist.github.com&#x2F;cielavenir&#x2F;02f322e322a2a3555dbf2b38f2fedd59" rel="nofollow">https:&#x2F;&#x2F;gist.github.com&#x2F;cielavenir&#x2F;02f322e322a2a3555dbf2b38f...</a><p>I always ask (1) why does an app require installation and (2) why would it require root?<p>There are valid answers for both, but realistically, all a videoconferencing app should need (apart from audio and video and <i>maybe</i> screen sharing) is to store a config file.<p>There&#x27;s no legitimate use for it accessing privileged or private paths.
    • mcintyre19941 hour ago
      Out of interest why do you still use the app and not just use it in the browser? I feel much more secure having it in the browser sandbox and everything I care about works in the browser.
      • rmellow1 hour ago
        99% of the time I use the browser.<p>However, the video quality in the browser is worse, so depending on the use case I might have to use the app (via sandbox).<p>It&#x27;s been years since I&#x27;ve had to though.
    • wolvoleo45 minutes ago
      Yes Apple even blocked their app because they refused to fix it. Eventually they did and unfortunately they were allowed again.<p>It wasn&#x27;t really root as much as an open backdoor on a TCP port as far as I recall.
  • mzajc1 hour ago
    Unrelated to Zoom, but<p>&gt; I noticed it because I make heavy use of a &quot;one-shot paste&quot; tool which fulfills a single paste request and then terminates. Handy for filling in lots of fields of a web form – queue up pastes of several different things, then go to each form field in turn and just hit paste, bam bam bam.<p>This sounds very useful. Is the tool available anywhere? xclip -loops doesn&#x27;t seem to do the trick, or maybe it just doesn&#x27;t work that way on Wayland.
    • Lex-200841 minutes ago
      Turns out, Wayland has wl-copy:<p><a href="https:&#x2F;&#x2F;man.archlinux.org&#x2F;man&#x2F;wl-copy.1" rel="nofollow">https:&#x2F;&#x2F;man.archlinux.org&#x2F;man&#x2F;wl-copy.1</a><p>(i was also interested :)
  • jmclnx2 hours ago
    Par for the course when running a proprietary application. If doing that on Linux, can you imagine what it and others do under Windows ?<p>As people running Linux should know, you cannot trust proprietary applications.
    • nomel57 minutes ago
      I would rather have a nice popup on first attempt &quot;this application is monitoring your clipboard, allow?&quot;, ideally with that process completely suspended while that prompt is up.<p>This should be behind a toggle driven by intent, rather than something allowed by default. Default stance on trust should be &quot;don&#x27;t&quot;. Open source has nothing to do with it, when a typo while installing with a package manager means you might accidentally install something else (a common attack vector).
  • amelius1 hour ago
    I&#x27;m not surprised by news like this anymore. When will Linux distributions properly sandbox our applications?<p>Hell, our phones have had a better permission system for years.
  • ocd1 hour ago
    I miss ordinary conference calling being the norm. I like having a desktop IP phone.
  • fsflover1 hour ago
    Qubes OS saved me, once again. On it, Zoom only has the access to an empty VM and no access to the clipboard.
    • wolvoleo44 minutes ago
      Just not using that piece of trash that is zoom would work very well too in this case
    • sterlind1 hour ago
      What&#x27;s it like using Qubes? How much friction? I wish I could use some Nix-flavored variant of the sandboxing.
      • nekusar39 minutes ago
        I dumped it after realizing Xen does its damndest in preventing you from hiding VM attributes from Guest OSes.<p>Proxmox uses KVM, and is easy to configure a VM to make the guest think it&#x27;s on bare metal.<p>In the proprietary software space, a LOT of things run badly or refuse to run, or license stupidity with a guest OS. So for me, spoofing bare metal is an essential part of running ilk like Windows and proprietary apps. And also, school remote testing garbage.
        • fc417fc8028 minutes ago
          Doesn&#x27;t that preclude paravirtualization drivers? Seems like a major tradeoff for daily driver desktop stuff.
  • rvz3 hours ago
    That&#x27;s bad news. Don&#x27;t use Zoom.
    • jrm43 hours ago
      That&#x27;s wildly impractical advice for many.<p>Just use Firefox, or Chromium if you must.
      • Joel_Mckay2 hours ago
        Spinning up a conference host for a small office is fairly trivial =3<p><a href="https:&#x2F;&#x2F;jitsi.org&#x2F;downloads&#x2F;" rel="nofollow">https:&#x2F;&#x2F;jitsi.org&#x2F;downloads&#x2F;</a>
        • jonathantf21 hour ago
          Great, til I have a job interview and they use Zoom
          • Insimwytim50 minutes ago
            Spin up your own instance and ask them to join!
          • netllama1 hour ago
            Srsly, all those neck beards who over simplify the problem with a flippant &quot;don&#x27;t use zoom&quot;, as if everyone has the luxury to skip every job interview and employer meeting that absolutely requires Zoom. I wish I could live in their world where every problem is solved by simply avoiding that problem.
            • wolvoleo36 minutes ago
              Zoom isn&#x27;t just a technical problem. It&#x27;s literally malware. The list of issues they&#x27;ve knowingly caused and sometimes even refused to fix is endless. They have made it clear they absolutely don&#x27;t care about security in any way and they&#x27;ve built their entire business around that.<p>As I work in cyber security there&#x27;s no way I&#x27;ll install that shit on my personal PC. Yes I could spin up a VM but I don&#x27;t want to. I could probably use it over the web but that&#x27;s it.<p>So I&#x27;d refuse and that company&#x27;s reply should inform me whether I&#x27;d want to work there in the first place. If they insist their security practices will be so lax that I will be just spending my time cleaning up everyone else&#x27;s mess. In fact any employer using zoom in the first place is a huge red flag.<p>I currently work for a huge multinational and they have the zoom client blocked through antimalware. Anyone wishing to use it with customers or suppliers must use the web version only.
            • bentcorner33 minutes ago
              This is a habit tech people fall into. &quot;Amazon deleted my book&quot; -&gt; well just strip the DRM off it. &quot;My ISP monitors me&quot; -&gt; well just use a VPN instead. &quot;Ads make it hard to use the internet&quot; -&gt; well just use an ad blocker.<p>Ironically if more tech people just rawdogged the internet I think we would have more progress.
              • Joel_Mckay26 minutes ago
                Unfortunately, experience teaches people one can&#x27;t affect political policy with gadgets, or deny human nature. =3<p><a href="https:&#x2F;&#x2F;harmful.cat-v.org&#x2F;people&#x2F;basic-laws-of-human-stupidity&#x2F;" rel="nofollow">https:&#x2F;&#x2F;harmful.cat-v.org&#x2F;people&#x2F;basic-laws-of-human-stupidi...</a>
            • GuestFAUniverse1 hour ago
              Use a dedicated, otherwise empty account for job interviews.<p>Linux is multi-process, _multi-user_ since forever.<p>No need to leave a password manager, online banking, andwhatnot accessible in the background during an interview.<p>And yeah: stop. using. X11. For God&#x27;s sake!
              • wolvoleo43 minutes ago
                Wayland doesn&#x27;t work stable in kde on my OS yet so I have no choice but to use X11.<p>However software just shouldn&#x27;t be trash. No need to blame the display layer for this.
              • hagbard_c1 hour ago
                Just use a browser instead of some silly client, problem mostly solved. Use X11 or Wayland or whatever else you want, for God&#x27;s sake. I don&#x27;t remember any god ever claiming salvation lies in abandoning the most functional display server on the market so I&#x27;ll just keep on using X11. If and when Wayland or some other alternative ever becomes as useful as X11 I might hop over but for now Wayland is a solution in search of a problem as far as I&#x27;m concerned.
                • Joel_Mckay45 minutes ago
                  It takes experience to learn why people call it the &quot;bleeding edge&quot;. GPU acceleration is often broken in a lot of distros, and it is unkind to new users that have a panic attack dropping into a CLI shell.<p>LightDM at least works 99% of the time, being Cross-desktop one can select a Wayland session just fine (great when it is working), or fall back to a software compositor Cinnamon Desktop when things bork after an update. =3
              • Joel_Mckay55 minutes ago
                &gt;And yeah: stop. using. X11.<p>Fine words, until the GPU driver goes sideways in Wayland. And... I like running multi-seat headless sessions on my local LAN hosts for several reasons. =3
            • saltcured20 minutes ago
              My partial solution is to have the Android Zoom client on an idle tablet. Even though it is my office VOIP phone too, I power it off when I don&#x27;t have meetings scheduled.<p>If someone tries to demand screen sharing, I ask one of my coworkers to drive, since they&#x27;ve joined from their laptop already.<p>I only launch the Linux Zoom client when I absolutely know I&#x27;m going to need to host a meeting and demonstrate software running on my end. I feel equally disgusted about Zoom and the corporate EDR agent. I basically feel like the most likely source of compromise of my laptop is these proprietary tools forced on me from above.<p>The thing that worries me is SSO for work. I wish there was a completely different identity for all the work-related apps and for my payroll&#x2F;benefits portal. I.e. if they want to endanger my login that manages my work product, fine, but I don&#x27;t appreciate them endangering my login that manages my own compensation, tax deductions and retirement transfers, and health insurance...
        • bix61 hour ago
          Ah yes Jitsi! I have been invited to meet on Jitsi 0 times.
  • wslh11 minutes ago
    [dead]
  • st_goliath1 hour ago
    There is no such thing as an &quot;X11 clipboard&quot; that something can be written to. As the poster goes on to allude, X11 has a concept of a &quot;selection&quot; (a primary and a secondary one).<p>It goes roughly like this: when you select a text in a window, the X client tells the X server &quot;I have the selection now&quot;, when you paste in another window, the client behind the other window asks &quot;who has the selection?&quot; and requests the selection contents from the other client, the data is then forwarded through the server. The client that claimed ownership has to properly handle some associated requests&#x2F;events for the whole thing to work.<p>The key point is, there is no central &quot;clipboard&quot; style repository like on Windows, the client that does the &quot;copy&quot; is responsible for the data, the client that wants to &quot;paste&quot; has to talk to it. If I try to copy&#x2F;paste and quit the source program before the paste, the data is gone. That&#x27;s why modern desktop environments usually come with a dedicated daemon that immediately reacts to selection ownership changes, grabs the data for itself and then claims the selection ownership to emulate the Windows style behavior.<p>If we play devils advocate, it&#x27;s possible the Zoom client tries to do just that, not trusting whatever desktop environment. I don&#x27;t use this software, so I&#x27;m going out on a limb here, but I&#x27;d guess that the &quot;Zoom Desktop Client&quot; is just another browser in disguise? It might be actually Chromium or whatever underneath that does this?