This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

ZoneAlarm 6.0 "phones home" (?)

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://ww6.infoworld.com/products/print_fr…cringley_1.html
January 13, 2006
"…It seems that ZoneAlarm Security Suite has been phoning home, even when told not to. Last fall, InfoWorld Senior Contributing Editor James Borck discovered ZA 6.0 was surreptitiously sending encrypted data back to four different servers, despite disabling all of the suite’s communications options. Zone Labs denied the flaw for nearly two months, then eventually chalked it up to a “bug” in the software – even though instructions to contact the servers were set out in the program’s XML code. A company spokesmodel says a fix for the flaw will be coming soon and worried users can get around the bug by modifying their Host file settings. However, there’s no truth to the rumor that the NSA used ZoneAlarm to spy on U.S. citizens…"

Is your firewall spying on you?
- http://www.theinquirer.net/?article=29157
22 January 2006
"…Zone Alarm 6.0 was sneakily sending off data to four different servers. Cringely says that Zone Labs (acquired by Checkpoint in March of 2004) at first denied the activity for a couple of months before deciding the software had a "bug" even though, as he points out, "the instructions to contact the servers were set out in the program’s XML code." The company says it will fix the "bug" soon. In the meantime you can work around it by adding:

# Block access to ZoneLabs Server
127.0.0.1 zonelabs.com

to your Windows host file…"

:ph34r:
FYI…

- http://www.theinquirer.net/?article=29254
25 January 2006
"…The company sent us a statement outlining what it says is the truth of the matter…"For any users who are concerned about this communication between the user’s PC and the Zone Labs servers, it is important to note that Zone Labs does not infringe upon the privacy of our customers. We don’t save personal information. We don’t do many other things that legitimate software companies do to enhance their marketing efforts, like use persistent Web cookies. This conservative approach is intentional because we take privacy extremely seriously. "After being contacted by James Borck of Infoworld, we maintained an ongoing dialogue with him to discover the source of his issue. Initially, we were unable to reproduce it in our labs, until he submitted his log files. At that point, we were able to identify the bug and provided Mr. Borck with a temporary workaround. We never refuted his contention that an issue existed, although it did take some time to replicate it. "The actual communication in dispute is a simple encrypted GET request that is checking to see if the user’s security software is current. We will continue to work with Mr. Borck and anyone else who might have any concerns about this issue."

:oops: