7 ms·
Linux Zoom client proactively reading everything written to X11 clipboard
- rvz 4d agoThat's bad news. Don't use Zoom.
- jrm4 4d agoThat's wildly impractical advice for many. Just use Firefox, or Chromium if you must.
- Joel_Mckay 4d agoSpinning up a conference host for a small office is fairly trivial =3 https://jitsi.org/downloads/ https://jitsi.org/downloads/
- jonathantf2 4d agoGreat, til I have a job interview and they use Zoom
- netllama 4d agoSrsly, all those neck beards who over simplify the problem with a flippant "don't use zoom", as if everyone has the luxury to skip every job interview and employer meeting that absolutely requires Zoom. I wish I could live in their world where every problem is solved by simply avoiding that problem.
- GuestFAUniverse 4d agoUse a dedicated, otherwise empty account for job interviews. Linux is multi-process, _multi-user_ since forever. No need to leave a password manager, online banking, andwhatnot accessible in the background during an interview. And yeah: stop. using. X11. For God's sake!
- hagbard_c 4d agoJust use a browser instead of some silly client, problem mostly solved. Use X11 or Wayland or whatever else you want, for God's sake. I don't remember any god ever claiming salvation lies in abandoning the most functional display server on the market so I'll just keep on using X11. If and when Wayland or some other alternative ever becomes as useful as X11 I might hop over but for now Wayland is a solution in search of a problem as far as I'm concerned.
- Joel_Mckay 4d agoIt takes experience to learn why people call it the "bleeding edge". GPU acceleration is often broken in a lot of distros, and it is unkind to new users that have a panic attack dropping into a CLI shell. LightDM at least works 99% of the time, being Cross-desktop one can select a Wayland session just fine (great when it is working), or fall back to a software compositor Cinnamon Desktop when things bork after an update. =3
- Joel_Mckay 4d ago>And yeah: stop. using. X11. Fine words, until the GPU driver goes sideways in Wayland. And... I like running multi-seat headless sessions on my local LAN hosts for several reasons. =3
- wolvoleo 4d agoWayland doesn't work stable in kde on my OS yet so I have no choice but to use X11. However software just shouldn't be trash. No need to blame the display layer for this.
- dosisking 4d ago> And yeah: stop. using. X11. For God's sake! Why should I stop using software that is superior to the alternatives?
- abenga 4d agoIt isn't though. For example, the very article we are discussing.
- wolvoleo 4d agoZoom isn't just a technical problem. It's literally malware. The list of issues they've knowingly caused and sometimes even refused to fix is endless. They have made it clear they absolutely don't care about security in any way and they've built their entire business around that. As I work in cyber security there's no way I'll install that shit on my personal PC. Yes I could spin up a VM but I don't want to. I could probably use it over the web but that's it. So I'd refuse and that company's reply should inform me whether I'd want to work there in the first place. If they insist their security practices will be so lax that I will be just spending my time cleaning up everyone else's mess. In fact any employer using zoom in the first place is a huge red flag. I currently work for a huge multinational and they have the zoom client blocked through antimalware. Anyone wishing to use it with customers or suppliers must use the web version only.
- DANmode 4d ago> I'd refuse and that company's reply should inform me whether I'd want to work there in the first place This. Develop sufficient leverage to be able to show basic respect the right way to do things - and yourself.
- bentcorner 4d agoThis is a habit tech people fall into. "Amazon deleted my book" -> well just strip the DRM off it. "My ISP monitors me" -> well just use a VPN instead. "Ads make it hard to use the internet" -> well just use an ad blocker. Ironically if more tech people just rawdogged the internet I think we would have more progress.
- Joel_Mckay 4d agoUnfortunately, experience teaches people one can't affect political policy with gadgets, or deny human nature. =3 https://harmful.cat-v.org/people/basic-laws-of-human-stupidity/ https://harmful.cat-v.org/people/basic-laws-of-human-stupidi...
- saltcured 4d agoMy partial solution is to have the Android Zoom client on an idle tablet. Even though it is my office VOIP phone too, I power it off when I don't have meetings scheduled. If someone tries to demand screen sharing, I ask one of my coworkers to drive, since they've joined from their laptop already. I only launch the Linux Zoom client when I absolutely know I'm going to need to host a meeting and demonstrate software running on my end. I feel equally disgusted about Zoom and the corporate EDR agent. I basically feel like the most likely source of compromise of my laptop is these proprietary tools forced on me from above. The thing that worries me is SSO for work. I wish there was a completely different identity for all the work-related apps and for my payroll/benefits portal. I.e. if they want to endanger my login that manages my work product, fine, but I don't appreciate them endangering my login that manages my own compensation, tax deductions and retirement transfers, and health insurance...
- tcfhgj 4d agoso? avoid it where you can
- Insimwytim 4d agoSpin up your own instance and ask them to join!
- PorciiVorbesc 4d agoGreat idea, if you want to stay unemployed. How many corpo HR/recruiter types you met that will gladly bypass company policy and switch to the tools demanded by the candidate?
- hdgvhicv 4d agoAs an engineer I’d be impressed and would put you up to the top of the pile Sadly I don’t run the company, and as a hiring manager that’s a great way to reduce my shortlist. We can’t have people like myself who ignore corporate policies.
- bix6 4d agoAh yes Jitsi! I have been invited to meet on Jitsi 0 times.
- ShinyLeftPad 3d agohttps://meet.jit.si/humanphilosophersdisplaceround https://meet.jit.si/humanphilosophersdisplaceround first time for everything
- kelnos 4d agoPerhaps things have gotten better over time, but I did this 4 or 5 years ago and it was anything but trivial. I got it working, but it was a huge pain to set up.
- Joel_Mckay 4d agoThe docker image build recipes should be easy to find these days. Usually it is just local networking appliance rules that cause issues for some users. Likely a great learning experience for the uninitiated. Have a great day =3
- somat 4d agoIf we are doing a survey of self hosted video conferencing services I would like to propose galene. Very easy to set up, I run it on obsd(an unsupported platform) and it just works. https://galene.org/ https://galene.org/
- Joel_Mckay 4d agoVery nice option, as getting WebRTC built on pi/aarch64 with v4l camera hardware codec support was a slog through mud a few years back. =3
- rvz 4d agoOr just use Google Meet on all browsers, which is more practical to use than Zoom. Zero software to install.
- uncle_kostya 4d agoIt's what we use at work and I'm sure it passed a security audit. How ironic.
- samus 4d agoThat's very telling about the quality of the security audit.
- deleted 4d ago[deleted]
- rmellow 4d agoNot the first time Zoom abuses privilege. A few years back, there was something about gaining root on MacOS via Zoom due to shady execution on their end. They've lost my trust since then, and I'll only run it sandboxed: https://gist.github.com/cielavenir/02f322e322a2a3555dbf2b38f2fedd59 https://gist.github.com/cielavenir/02f322e322a2a3555dbf2b38f... I always ask (1) why does an app require installation and (2) why would it require root? There are valid answers for both, but realistically, all a videoconferencing app should need (apart from audio and video and maybe screen sharing) is to store a config file. There's no legitimate use for it accessing privileged or private paths.
- syntaxing 3d agoWow thanks for the link. I have zoom on my personal laptop which isnt ideal. I always wanted to run it sandboxed
- mcintyre1994 4d agoOut of interest why do you still use the app and not just use it in the browser? I feel much more secure having it in the browser sandbox and everything I care about works in the browser.
- rmellow 4d ago99% of the time I use the browser. However, the video quality in the browser is worse, so depending on the use case I might have to use the app (via sandbox). It's been years since I've had to though.
- 3eb7988a1663 4d agoNot parent, but the web player used to be a down-graded experience from the native app. If you need Zoom for a professional setting, those functions could be important. Do not know if this is still true, but at one point, the web player would only let you see one speaker at a time, while the app would show multiple people at once.
- DANmode 4d ago
- jmclnx 4d agoPar for the course when running a proprietary application. If doing that on Linux, can you imagine what it and others do under Windows ? As people running Linux should know, you cannot trust proprietary applications.
- nomel 4d agoI would rather have a nice popup on first attempt "this application is monitoring your clipboard, allow?", ideally with that process completely suspended while that prompt is up. This should be behind a toggle driven by intent, rather than something allowed by default. Default stance on trust should be "don't". Open source has nothing to do with it, when a typo while installing with a package manager means you might accidentally install something else (a common attack vector).
- ocd 4d agoI miss ordinary conference calling being the norm. I like having a desktop IP phone.
- lxgr 4d agoIt’s a real shame that essentially all modern communication other than email runs over proprietary protocols.
- hdgvhicv 4d agoWe use a lot of sip with all manner of endpoints
- lxgr 4d agoSure, in a way SIP is bigger than ever with NGNs, and there’s SIP use beyond that too, but actual interoperable SIP (as in, I can dial sip:name@example.com) is effectively not a thing anymore.
- hdgvhicv 4d agoI don’t deal with corporate telephony but our sip accounts on the broadcast side have all manner of endpoints, including software and hardware from many different manufacturers. We land them on a pair of paired oracle sbcs which somehow (I’m not close to the details on this part) shares account detail and sessions between the two geographically resilient locations. You just need the dns, account and password.
- lxgr 4d agoI do believe that vendor-interoperable SIP exists today, but I also know that I can't call >99.9..9% of the people in the world via SIP, and 100% of the ones I practically do call. This is a very different story from e.g. email – even though most people I communicate with use either Gmail or some hosted Outlook service, I don't have to on my side (with some limitations around deliverability etc. lately).
- st_goliath 4d agoThere is no such thing as an "X11 clipboard" that something can be written to. As the poster goes on to allude, X11 has a concept of a "selection" (a primary and a secondary one). It goes roughly like this: when you select a text in a window, the X client tells the X server "I have the selection now", when you paste in another window, the client behind the other window asks "who has the selection?" and requests the selection contents from the other client, the data is then forwarded through the server. The client that claimed ownership has to properly handle some associated requests/events for the whole thing to work. The key point is, there is no central "clipboard" style repository like on Windows, the client that does the "copy" is responsible for the data, the client that wants to "paste" has to talk to it. If I try to copy/paste and quit the source program before the paste, the data is gone. That's why modern desktop environments usually come with a dedicated daemon that immediately reacts to selection ownership changes, grabs the data for itself and then claims the selection ownership to emulate the Windows style behavior. If we play devils advocate, it's possible the Zoom client tries to do just that, not trusting whatever desktop environment. I don't use this software, so I'm going out on a limb here, but I'd guess that the "Zoom Desktop Client" is just another browser in disguise? It might be actually Chromium or whatever underneath that does this?
- deleted 4d ago[deleted]
- porridgeraisin 4d agoIt's not chromium. But what's happening here is that even if you don't click paste, zoom is actively listening to clipboard events and consuming pastes. Tbh, if they aren't harvesting clipbakrds data which is a weird thing to do and is unlikely, this doesn't really mean much. Anyways any X client can read. I suspect it's something like: a bug report that said that I copied the link but when I opened zoom and pasted it it didn't it work. I.e, they probably closed the source application and thus the selection owner is gone, and the selection is gone too. This fixes that. I would test that maybe. See if paste after source app close works. Then again, if you use a ownership changing clipboard manager this shudnt be a problem.
- deleted 4d ago[deleted]
- mzajc 4d agoUnrelated to Zoom, but > I noticed it because I make heavy use of a "one-shot paste" tool which fulfills a single paste request and then terminates. Handy for filling in lots of fields of a web form – queue up pastes of several different things, then go to each form field in turn and just hit paste, bam bam bam. This sounds very useful. Is the tool available anywhere? xclip -loops doesn't seem to do the trick, or maybe it just doesn't work that way on Wayland.
- Lex-2008 4d agoTurns out, Wayland has wl-copy: https://man.archlinux.org/man/wl-copy.1 https://man.archlinux.org/man/wl-copy.1 (i was also interested :)
- Akronymus 4d agoI have a few scripts that interact with wl-copy. Like one that just cats all the files in a directory and pipes it into wl-copy so I can paste it somewhere else. Something like that would've been immensly useful when I was still on windows, but that would've been too much a bother to set up.
- fsflover 4d agoQubes OS saved me, once again. On it, Zoom only has the access to an empty VM and no access to the clipboard.
- sterlind 4d agoWhat's it like using Qubes? How much friction? I wish I could use some Nix-flavored variant of the sandboxing.
- nekusar 4d agoI dumped it after realizing Xen does its damndest in preventing you from hiding VM attributes from Guest OSes. Proxmox uses KVM, and is easy to configure a VM to make the guest think it's on bare metal. In the proprietary software space, a LOT of things run badly or refuse to run, or license stupidity with a guest OS. So for me, spoofing bare metal is an essential part of running ilk like Windows and proprietary apps. And also, school remote testing garbage.
- fc417fc802 4d agoDoesn't that preclude paravirtualization drivers? Seems like a major tradeoff for daily driver desktop stuff.
- nekusar 3d agoXen prevents modifying ACPI data. It also passes obvious "Xen emulated drive", and similar for all hardware interfaces. Passes CPUID. Can't stop any of this with Qubes/Xen. But is trivial with Proxmox/KVM. Honestly, I wish there was a Qubes/KVM variant. It would fix every complaint, and enable running potentially malicious software (MS windows) and lie to it regarding hardware interfaces.
- fsflover 4d agoRelated Issue with discussion: https://github.com/QubesOS/qubes-issues/issues/1142 https://github.com/QubesOS/qubes-issues/issues/1142
- amelius 4d agoI'm not surprised by news like this anymore. When will Linux distributions properly sandbox our applications? Our phones have had a better permission system for years.
- Gander5739 4d agoAndroid allows apps to read from the clipboard at will, though it does show a toast. GrapheneOS, I believe, asks for permission first.
- wilkystyle 4d agoThankfully iOS rolled out a permissions prompt for this. Pretty illuminating just how often other apps read the clipboard, e.g. Google Maps reading my clipboard every time I tapped on the text field to search for a destination.
- drnick1 4d agoLinux generally presumes that you run trusted software, not some proprietary program that is approximately malware. If you want a "sandbox" run that program as a separate unprivileged user or use bubblewrap.
- amelius 4d ago> Linux generally presumes that you run trusted software, not some proprietary program that is approximately malware. But this statement basically says: "Linux has no good permission controls for running software". The assumption is flawed. Trusting software is not a true/false thing. Yes, you can use sandboxing tools, but how many people use them properly? How many usability bugs do they still have?
- samus 4d agoUnix systems were initially designed to be multi-user systems (as in multiple meatbags accessing a mainframe across terminals), in an era before it was common to indiscriminately download and run applications from the internet. Files required explicit opt-in to become executable. There were always attempts at mischief, but it was deemed sufficient to separate user account from each other and denying direct access to the hardware so an account compromise wouldn't escalate to the rest of the system. Because of this heritage Android uses user accounts instead of namespaces a.k.a. containers (a much newer and less mature concept) to isolate apps from each other.
- wslh 4d ago[dead]
- nullc 4d agoReason 1492835 to use Qubes OS. Also reason 35892384242892 to not use proprietary software, especially proprietary software with network access.
- jeffbee 4d agoFeeling good about using Zoom, when necessary, in a tab in ChromeOS. Zoom is "Not allowed to see your clipboard" in Chrome preferences.
- Arbortheus 4d agoJust run these things in your browser. Despite the dark design patterns that try to trick you into installing their desktop client, the web-based versions are fine.
- theokrueger 3d agonot if you have to host meetings! the web versions are feature incomplete and don't support something as simple as screensharing with your camera overlayed in a corner (essential for recorded meetings). the zoom linux client consistiently locks up my entire computer whenever i copy from the chat. ridiculous.
- bamboozled 4d agoWhy I always shutdown the zoom process as soon as meetings end.
- ryandrake 4d agoThe "clipboard" as it is implemented in many (most?) operating systems today, only exists because it's a legacy idea that hasn't died. If it were freshly invented today, it would never get past even the most lenient privacy review. Think about the pitch for the feature: "So, we're going to make this in the OS, where the user can highlight anything in any application, invoke a command, and then that thing (which could be a sensitive password, private personal information, or the codes to a nuclear weapon) will instantly become available for all applications on the system to read and do anything with. Uhh... NO THANKS! Ideally, if an application wants to read from the clipboard, it should explicitly ask the user for permission, or the user should have to specify the exact app he's copy/pasting to. This reduces the clipboard's ease of use, but at least makes it NOT a truck sized privacy hole.
- superkuh 4d agoNo. You're assuming that you don't have control of your own computer. Think about the pitch for removing the feature, "So, we're going to make this in the OS, where visually disabled users cannot highlight anything in any application, can't move text between applications, cannot get the window title, cannot get the window tree, cannot have applications automate or know where other applications are, and basically they won't be able to use their computers. But everyting will be super private. Even the human using the computer won't be able to read it." This is what modern linux desktop computer is on waylands thanks to this toxic privacy meme. It literally just doesn't work for me. Privacy needs the kind you're talking about simply don't exist on desktop computers where the human actually controls everything (as opposed to smartphone model where the user controls very little and applications are hostile and opaque). If you want to break accessibility and functioning of smartphones, fine, go for it. But leave desktop computers alone.
- ryandrake 4d agoUnfortunately, we are living in a world where we need to treat every third party application that we run (and in some cases, even the operating system itself) as a hostile attacker. Gone are the days when you could download a software, run it, and trust that the developer isn't transmitting everything on your system back to their servers. Developers have poisoned the well and repeatedly demonstrated that they will run roughshod over the user's system, send telemetry back about everything the user is doing, enroll them in A/B experiments they didn't ask for, and take advantage of every resource, every peripheral and device, and every bit of personal information they can get their hands on. Unless you are 100% running open source software that you have personally vetted, or that you trust that the package manager / maintainer has sufficiently vetted, you can't copy a password into the clipboard with any kind of confidence that other apps aren't sneaking a peek.
- butterNaN 4d agohttps://jitsi.org/ https://jitsi.org/
- rascul 4d agoJitsi is an excellent free and open source alternative.
- sverhagen 4d agoAnd that is useless if you have meetings with people that "have standardized" on Zoom, and that hold some sort of leverage over you, like clients/customers.
- DANmode 4d agoCan’t see enjoying my time on this Earth putting up with that sort of burnout.
- rascul 4d agoI'm pleasantly surprised at how often someone will use jitsi when the alternative is not communicating with me in such a fashion.
- doublerabbit 4d agoI found Clients / Customers don't care, I just send them a meetings link and they find themselves shocked in that it just works. If they moan say it's Zoom but the corporate version. Self-hosting my own Jitsi and it's faultless and the way to go.
- ShinyLeftPad 3d agoJust send a meeting link and it works in any browser.
- teravor 4d agowith Wayland it's generally not any safer. if you use Wayland's security context to prohibit privileged protocols such as arbitrary clipboard access then an application will either not be able to grab clipboard content until you focus on it or the attempt will be noticeable as it spawns a short lived window in an attempt to grab focus.
- jszymborski 3d agoApps generally need not get clipboard contents unless focused on right? Like this should be the default in my view and kinda disappointed it isn't for Wayland.
- vancekai 4d ago[dead]
- bandrami 4d agoThat's "rude" but allowed; that capability is one of the reasons Wayland was developed (though their solution removed some capabilities people wanted with the result that the compositors now replicate the original flaw).
- Throwthrowbob 4d agoI remember a friend installing Zoom on a Linux computer through their software manager. Later, they removed it and found that when they visited the page in the software manager for Zoom, it automatically tried to install Zoom without interaction from them (ie, my friend did not click Install, but viewed the page and a password prompt for installing the package appeared). I'm not sure if this was behaviour that happened with the software manager on other packages, but was a concern for us.
- jlzhengkun 4d ago[flagged]
- SubiculumCode 4d agoUniversity of California has licensed zoom accounts with privacy agreements. I install it in Linux. Now I will check if I can replicate this behavior. I am not sure if it is a violation of their agreement or not if they do, but I don't like it.
- jlzhengkun 4d ago[flagged]
- chris_wot 4d agoIsn’t this one of the reasons Wayland is often recommended? Forgive me if I’m getting confused on this point.
- shevy-java 4d agoThat's so sad. These companies try to ruin Linux by spying on the user here.
- samus 4d agoIt's not about Linux.
- bytesandbits 4d agoZoom is malware, has always been.
- Lucasoato 4d agoI wish most Linux distributions had something like a standardized permission manager in which you enable the single policies apps are running with, similarly to what happens in Android (that has some Linux stuff under the hood). How hard would it be to have something like this? And I can’t even imagine the difficulty of gathering together the whole community around this standard...
- samus 4d agoQuite hard because on Linux there is no concept of "apps". There is a (very flimsy) separation between processes, but the strongest actual security boundaries are between kernel and user space as well as between users. Namespaces are explicitly not acknowledged as such, which limits the security guarantees that containers can provide. Snaps and Flatpak are steps towards that goal, but there are many issues surrounding these technologies, and many apps require sweeping permissions to work well since they were not initially designed to be limited in that way.
- kd913 4d agoSnaps are a lot lot better in this regard especially in the perspective of connections. You can define connections to home, camera, network etc... I have not seen the same in flatpak.
- vyskocilm 3d agoSure flatpak have a static permission system too, even it is not recommended and xdg portals are the way of integrating with a host. https://flathub.org/en/apps/com.github.tchx84.Flatseal https://flathub.org/en/apps/com.github.tchx84.Flatseal
- phendrenad2 3d agoI don't get why a big company like Zoom, with presumably lots of users who are on Linux, only gives us a .rpm/.deb instead of a Snap/Flatpak. Seems like doing the minimum.
- synapse_ilands 4d ago[flagged]