Please explain the purpose of the following and under what circumstances they become active. In addition, do either of these phone home? If so, with what data?
-SophosScanD
-SophosSXLD
This thread was automatically locked due to age.
Please explain the purpose of the following and under what circumstances they become active. In addition, do either of these phone home? If so, with what data?
-SophosScanD
-SophosSXLD
---
Bob Cook (bob.cook@sophos.com) Director, Software Development
Thanks Bob. Several follow up questions re. privacy:
>>SophosScanD runs the scanning engine. It uses Live Protection when the feature is enabled in preferences, which means it may send encrypted information to SophosLabs for real-time AV checks. The transport is DNS. It does not do any other "phone home" type communications. Today it is only used for scanning downloads from the web, however it will start doing all scanning in the future as we rework the on-access and custom scanning code.
Does it now, or will it in the future, when it will be responsible for all scanning, keep track of what a user has downloaded, and associate that to a particular user---thus building up a potential profile? Is all data anonymized?
>>SophosSXLD performs SXL lookups for web reputation to learn the risk level of a given URL or IP address. It communicates with the SophosLabs servers via HTTP and/or DNS in order to provide this information (the database is far too big to download to each endpoint). It does not do any other "phone home" type communications.
Basically, same question as above, but for SophosSXLD. Does it keep a record of URLs or IPs visited, this allowing the creation of a personal profile?
And what does Sophos do with the data it collects from any given user?
Also, can you please explain what "transport is DNS" means in this context? I know you already said, elsewhere, that SophosConfigD uses that to connect with the mothership, but really don't understand what that is.
Thanks Bob. Several follow up questions re. privacy:
>>SophosScanD runs the scanning engine. It uses Live Protection when the feature is enabled in preferences, which means it may send encrypted information to SophosLabs for real-time AV checks. The transport is DNS. It does not do any other "phone home" type communications. Today it is only used for scanning downloads from the web, however it will start doing all scanning in the future as we rework the on-access and custom scanning code.
Does it now, or will it in the future, when it will be responsible for all scanning, keep track of what a user has downloaded, and associate that to a particular user---thus building up a potential profile? Is all data anonymized?
>>SophosSXLD performs SXL lookups for web reputation to learn the risk level of a given URL or IP address. It communicates with the SophosLabs servers via HTTP and/or DNS in order to provide this information (the database is far too big to download to each endpoint). It does not do any other "phone home" type communications.
Basically, same question as above, but for SophosSXLD. Does it keep a record of URLs or IPs visited, this allowing the creation of a personal profile?
And what does Sophos do with the data it collects from any given user?
Also, can you please explain what "transport is DNS" means in this context? I know you already said, elsewhere, that SophosConfigD uses that to connect with the mothership, but really don't understand what that is.
---
Bob Cook (bob.cook@sophos.com) Director, Software Development