I caught Sophos Mac Home having sent out 150MB of data. Is this program intended to send out any type of information? If so, what is being sent out?
I've removed the software for now.
This thread was automatically locked due to age.
damienthorne wrote:
I've had browsers open in the background, but nothing running - just static pages...and I walk away for 8 hours with SophosWebIntelligence at around 50k/50k... Can you explain why then when I come back to my computer several hours later, over a gig of data has not only been shown as processed incoming but OUTGOING as well via the process?
I can't explain it, although I can assure you that we aren't sending out any data that didn't originate from a web browser (or something that acts like one - curl, wget, and telnet all end up going through our daemon). Let me know how you get on with WireShark, I'm curious about the results. Be sure to watch for all TCP traffic that is destined for something not on the loopback address 127.0.0.1.
---
Bob Cook (bob.cook@sophos.com) Director, Software Development
damienthorne wrote:
I've had browsers open in the background, but nothing running - just static pages...and I walk away for 8 hours with SophosWebIntelligence at around 50k/50k... Can you explain why then when I come back to my computer several hours later, over a gig of data has not only been shown as processed incoming but OUTGOING as well via the process?
I can't explain it, although I can assure you that we aren't sending out any data that didn't originate from a web browser (or something that acts like one - curl, wget, and telnet all end up going through our daemon). Let me know how you get on with WireShark, I'm curious about the results. Be sure to watch for all TCP traffic that is destined for something not on the loopback address 127.0.0.1.
---
Bob Cook (bob.cook@sophos.com) Director, Software Development