This is topic Allegation - ZoneAlarm has inbuilt spyware in forum Film-Yak at Film-Tech Forum ARCHIVE.
To visit this topic, use this URL:
https://ft-forum.com/ft/cgi-bin/ubb/ultimatebb.cgi?ubb=get_topic;f=8;t=005121
Posted by Leo Enticknap (Member # 534) on 05-29-2007, 02:52 PM:
quote: National Inquirer
Is your firewall spying on you?
Zone Alarm gets rumbled
By Paul Hales in Jerusalem: Sunday 22 January 2006, 12:39
IT’S OBVIOUS, REALLY, that the best way of penetrating users' PCs to see what they get up to online would be to become a Firewall maker.
Like, when I wanted a Firewall and was too tight to pay for one, I turned to Checkpoint’s little freebie Zone Alarm. It sits there between you and the Internet and lets you know when someone’s trying to sneak in through your backdoor or when a program you’re running tries to connect to the Web for no apparent reason. When you’re as techie as me – not very – you just have to trust it.
Of course, Checkpoint’s an Israeli company and as a foreign journalist working in Israel you know the hyperactive security services here would like to keep tabs on you. And you know that they do. It has been confirmed to me by a security sources here that mobile phone conversations I have had have been listened to – and in circumstances which I won’t reveal, the contents of a call I have been involved in have actually been relayed back to me.
It’s part of the game – like the airport interrogation, or the surreptitious copying of your notepad while you’re off having a body search. You know what goes on but you have a job to do and just get on with it – hoping that what you get up to in the legitimate pursuit of your business won’t upset anyone to the extent that they’ll come break your door down and cart you off somewhere.
Now, the handsomely-named Mr Cringely has revealed that a colleague of his at Infoworld noticed that Zone Alarm 6.0 was sneakily sending off data to four different servers. Cringely says that Zone Labs (acquired by Checkpoint in March of 2004) at first denied the activity for a couple of months before deciding the software had a "bug" even though, as he points out, "the instructions to contact the servers were set out in the program’s XML code."
The company says it will fix the "bug" soon. In the meantime you can work around it by adding:
# Block access to ZoneLabs Server
127.0.0.1 zonelabs.com
to your Windows host file.
The "bug" seems to be present in the retail version of Zone Alarm, so there’s no telling what the freebie gets up to. We called Checkpoint here in Israel to find out, but were referred to a US spokeszoner. Trouble is they’ll all be in bed there on this sunny Sunday morning.
...which, of course, begs the question as to what spyware is present in every other firewall product on the market, not least the one built into Windows. I use the firewall in Iolo System Mechanic Pro myself, and because it's a paid-for product would hope that at least they aren't selling my browsing data for commercial purposes. But without being a programming expert (which I'm not), there's no way of telling, I guess.
Posted by Frank Dubrois (Member # 3042) on 05-29-2007, 03:03 PM:
If you pay for it, and it doesn't disclose that it's sending information, I believe you might have a lawsuit.
Posted by Mike Blakesley (Member # 26) on 05-29-2007, 06:34 PM:
I would bet that anything the software is doing is covered by the "EULA" (End-user license agreement) that you have to accept either by clicking on a button when you install it, or (in some cases) you accept it simply by opening the package.
Posted by Joel N. Weber II (Member # 3530) on 05-29-2007, 08:39 PM:
Even if you are a programming expert, the complexity of modern computer systems makes them pretty much impossible to audit perfectly and completely.
Ken Thompson's paper Reflections on Trusting Trust explains how just looking at the C source code for a system isn't good enough to audit it. And the work behind that paper was done when computers were much simpler and less capable than they are today.
Posted by David Stambaugh (Member # 1102) on 05-29-2007, 08:56 PM:
As far as Windows firewall, there are legions of Microsoft haters who spend their every waking hour scrutinizing everything that Windows does, trying to find things like, say, the MS firewall "phoning home". It's not hard to prove something like that. Has anyone alleged that is happening? Not that I'm aware of. People would love to prove it though. It would be major news.
Posted by Leo Enticknap (Member # 534) on 05-30-2007, 10:26 AM:
I'd have thought it should be possible to establish that by connecting a PC to another PC which simulates the actions of an Internet server without actually being connected to the net, but which in reality logs all the connections the PC being examined tries to make. If one program repeatedly tries to 'phone home', that would show up in the log, I'd guess.
Posted by Joel N. Weber II (Member # 3530) on 05-30-2007, 10:51 AM:
If something blatantly tries to phone home, that ought to show up in a log, yes.
However, there are more or less legitimate reasons for software to phone home, such as to collect security updates. That might provide a channel over which small amounts of additional information could be smuggled.
If the computer you're doing your logging on is running software written by the same party as the evil software running on the computer being monitored, the computer doing the monitoring might be filtering the bad stuff out so that you don't see it. And there's always a chance that widely used software has security bugs that have been discovered by someone who is exploiting them in a subtle fashion that hasn't been noticed.
Posted by Peter Berrett (Member # 672) on 05-31-2007, 03:55 AM:
How is this for an idea?
If one put on TWO or even THREE firewalls at the one time they might block each others home phoning?
cheers Peter
Posted by Frank Angel (Member # 248) on 05-31-2007, 06:49 AM:
quote: Peter Berrett
If one put on TWO or even THREE firewalls at the one time they might block each others home phoning?
You pretty much will shut yourself down. Sometimes even one agressive firewall can be set so that everything slows down to a crawl. It becomes a self defeating exercise.
Powered by Infopop Corporation
UBB.classicTM
6.3.1.2