Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't see anything wrongs here, you investigate the script and it just an installer. Did you even look at nvidia-installer? Why no one talks on that crap? So much hate on Zoom... I hate that too, I was at meeting yesterday and my interentet got disconnected and couldn't get back but even after reconnecting there was an audio issue.


What's wrong here is that Zoom hacked together an installer against all normal structure that Apple recommends. And that installed includes a very stupidly designed component that will try to run whatever you ask it with admin privileges.

This is yet another indication that nobody at Zoom has a single clue on how to build a secure and stable application. Another example of that mindset released today: https://www.theverge.com/2020/3/31/21201956/zoom-leak-user-i... They are proving to completely not understand how to design security/privacy features. Frankly, their technology team sounds like total amateurs that hack things together.


“Total amateurs hacking things together” somehow managed to ship something functionally better than products from mature shops like MSFT that mean serious business. The irony there.


It has long been the legendary case that Microsoft takes three major versions to get a usable product, then encrusts it with ornamental features until it has trouble breathing around version 7 or 8.


It's more like they gained better ease of use by bending platform rules, to the detriment of security.


I highly doubt Zoom’s video conferencing solution was solidly working while MS Teams crumbled under load two weeks ago is due to magic in Zoom’s macOS installer.


Wasn't talking about infrastructure, was talking about the ease of use that led to large market share. Zoom broke lots of platform rules to perform that trick.


Market Cap of 38bn USD, based on a single product that entered a settled and crowded market.

Public, profitable, founder was Head Engineer for Cisco WebEx. Runs global videoconferencing under massive new load during Covid-19, on their own servers.

HN comment: "total amateurs".

Love this place.


Better start getting used to it if you haven’t already.


> Did you even look at nvidia-installer?

You're free to analyse it and publish your findings. That's not making zoom any better.


Did you look at the tweet? The installer lets anyone run any script as root. That seems fairly bad.


It lets anyone with an admin account run any scripts as root. No privilege escalation here, it's basically a gatekeeper bypass.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: