news.volyx.in

Zoom has a signed binary that runs any unsigned script (twitter.com)

562 points by kccqzy · 2381 days ago · 214 comments on HN

Article summary

Zoom's macOS installer uses a signed binary called zoomAutenticationTool to run unsigned scripts, which can bypass code signing requirements. This tool prompts the user for administrator privileges. The installer's behavior has been described as unusual and potentially insecure. The issue was discovered by analyzing the installer's script.

Main themes

  • Zoom security
  • macOS installer
  • code signing
  • security bypass
  • developer practices
  • Apple ecosystem restrictions

What commenters say

  • Zoom's installer practices are insecure and bypass normal security measures.
  • The company's lack of attention to detail and poor QA are evident in the installer's code.
  • The use of a signed binary to run unsigned scripts is a deliberate attempt to circumvent security rules.
  • The issue is not unique to Zoom and other companies may be using similar tactics.
  • The problem lies not with Zoom, but with the restrictions imposed by Apple's locked-down ecosystem.
  • A walled garden approach can help protect non-technical users from insecure software.
  • Locking down systems can encourage bad behavior from developers who try to find ways to circumvent the rules.