Why is Zoom even still popular? Remember when Apple had to push a security update to undo its insane HTTP daemon? I guess we’re all just okay trusting their janky-ass Windows adjacent UI and security model.
post
Affected users who are running X11 should audit their Zoom version, isolate conferencing workloads onto dedicated hardware or virtual machines, or move to a browser-based version of Zoom where sandboxing prevents unprompted clipboard access.
Anyone running a Linux system with Wayland should be OK.
Also Flatpak would be helpful in this case too, if there was a package for.
Anyone running a Linux system with Wayland should be OK.
And this is exactly why I put up with the functionality regressions of Wayland over X11 for the first few years.
I understood that all X11 apps running under Wayland are running inside the same environment, or is that wrong?
In other words, all X11 clipboards are shared.
I'm also not sure about clipboard isolation, since I'd have thought that copy/paste between Wayland and X11 would be expected.
The Wayland spec doesn't allow for clients to arbitrarily get clipboard data under typical conditions. Since most applications these days are running under Wayland, it should be that copying to the clipboard isn't exposed to X11 clients most of the time (only when copying from or pasting into XWayland).
Yeah this is why Zoom is constantly pushing you to download their fucking app, and exactly why I don't fucking do it.
Would the sandbox permissions in Flatpak be able to block this?
Stallman was right.
I'm going to have to go on some remote interviews sometime soon. I don't know if Zoom is the way those are usually done or if they use some other software that's more purpose-built for that. But whatever the case, I'll definitely have to figure out how to run whatever it is "in jail" somehow.
I would recommend running untrusted proprietary software as a webapp if possible, it will not be able to be as intrusive in that case compared to native app even with all the sandboxing (flatpak, snap, etc...). Or Virtual machine as the most secure option, but it may be overkill.
all 19 comments