news.volyx.in

How the Zoom macOS installer does its job without you clicking ‘install’ (twitter.com)

796 points by _Microft · 2382 days ago · 325 comments on HN

Article summary

The Zoom macOS installer uses preinstallation scripts and a bundled 7zip to install the app without user consent. If the user is not an admin, it uses a helper tool and the AuthorizationExecuteWithPrivileges API to gain root privileges. This behavior has been described as shady and potentially malicious. Zoom has since released an updated installer that removes the questionable techniques.

Main themes

  • security concerns
  • company culture
  • user convenience
  • macOS pkg format
  • privilege escalation
  • alternative software options

What commenters say

  • Enterprise customers do care about security, but may prioritize convenience and cost over security concerns.
  • The prevalence of security issues in popular software like Zoom and Uber suggests a company culture that accepts borderline behavior.
  • Some argue that users are willing to overlook security concerns if the software is useful and performant.
  • Others believe that security should be a top priority, even if it means sacrificing some convenience or cost savings.
  • The use of root privileges and password prompts by Zoom's installer is seen as a potential security risk.
  • Some commenters argue that the issue is not with Zoom's behavior, but with the macOS pkg format and the way it handles privilege escalation.
  • There is disagreement over whether users can easily replace Zoom with alternative software, with some citing the convenience and ubiquity of Zoom as a major obstacle.