Linux Zoom client proactively reading everything written to X11 clipboard
Posted by encyclopedism 2 hours ago
Comments
Comment by rmellow 43 minutes ago
A few years back, there was something about gaining root on MacOS via Zoom due to shady execution on their end.
They've lost my trust since then, and I'll only run it sandboxed: https://gist.github.com/cielavenir/02f322e322a2a3555dbf2b38f...
I always ask (1) why does an app require installation and (2) why would it require root?
There are valid answers for both, but realistically, all a videoconferencing app should need (apart from audio and video and maybe screen sharing) is to store a config file.
There's no legitimate use for it accessing privileged or private paths.
Comment by mzajc 6 minutes ago
> I noticed it because I make heavy use of a "one-shot paste" tool which fulfills a single paste request and then terminates. Handy for filling in lots of fields of a web form – queue up pastes of several different things, then go to each form field in turn and just hit paste, bam bam bam.
This sounds very useful. Is the tool available anywhere? xclip -loops doesn't seem to do the trick, or maybe it just doesn't work that way on Wayland.
Comment by ocd 34 minutes ago
Comment by jmclnx 40 minutes ago
As people running Linux should know, you cannot trust proprietary applications.
Comment by st_goliath 25 minutes ago
It goes roughly like this: when you select a text in a window, the X client tells the X server "I have the selection now", when you paste in another window, the client behind the other window asks "who has the selection?" and requests the selection contents from the other client, the data is then forwarded through the server. The client that claimed ownership has to properly handle some associated requests/events for the whole thing to work.
The key point is, there is no central "clipboard" style repository like on Windows, the client that does the "copy" is responsible for the data, the client that wants to "paste" has to talk to it. If I try to copy/paste and quit the source program before the paste, the data is gone. That's why modern desktop environments usually come with a dedicated daemon that immediately reacts to selection ownership changes, grabs the data for itself and then claims the selection ownership to emulate the Windows style behavior.
If we play devils advocate, I suppose the Zoom client tries to do just that, not trusting whatever desktop environment you are running. I don't use this software, so I'm going out on a limb here, but I'd guess that the "Zoom Desktop Client" is just another Electron dumpster fire and it's actually Chromium or whatever underneath that does this?
Comment by rvz 2 hours ago
Comment by jrm4 2 hours ago
Just use Firefox, or Chromium if you must.
Comment by Joel_Mckay 52 minutes ago
Comment by jonathantf2 16 minutes ago
Comment by netllama 6 minutes ago
Comment by bix6 5 minutes ago