Saturday, January 21, 2006

Security suite is in fact a spy

Web secury analysts from infoworld discoverd that a security suite called ZoneAlarm is in fact a disguised spy. The program was found to call home with information collected from the client computer, without consent from the computer user. According to INFORWORLD:
ZoneAlarm Security Suite has been phoning home, even when told not to. Last fall, InfoWorld Senior Contributing Editor James Borck discovered ZA 6.0 was surreptitiously sending encrypted data back to four different servers, despite disabling all of the suite’s communications options. Zone Labs denied the flaw for nearly two months, then eventually chalked it up to a “bug” in the software -- even though instructions to contact the servers were set out in the program’s XML code.

