Hacker News new | past | comments | ask | show | jobs | submit login
Abusing Zoom's Zero Touch Provisioning for Remote Attacks on Desk Phones (syss.com)
20 points by skilled 10 months ago | hide | past | favorite | 1 comment

Remember when Zoom was silently installing hidden web servers on Macs?[1] This vulnerability allowed any website to forcibly join a user to a Zoom call, with their video camera activated, without the user's permission.

Zoom has had such an amazingly flippant attitude towards security the entire history of the company. It's not that they aren't investing enough in security or that they have buggy software... they are just so damn brazen and actively create their own exploits. How else can you say it?

[1] https://www.theverge.com/2019/7/10/20689644/apple-zoom-web-s...

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
