Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG is contacting whatfix.com when I change firewall rules

I noticed that when using the GUI, and do some changes to rules or policies, that in bottom left corner of my browser there is "waiting for whatfix.com".

So it seems the XG is sending information to that website. Why is it doing this? What data is transferred? And how can I disable that?

Running Browser Inspections this is shown:

<script type="text/javascript" charset="utf-8" integrity="sha384-Ri1cUxmQGTk6k9rHS1TVx4oxxxxxxxxxxxxxxxxxxxxxp5yiG53soWAwGA4pxnnd" crossorigin="anonymous" src="">cdn.whatfix.com/.../script>

Even Javascript is downloaded! Why?



This thread was automatically locked due to age.
  • Totally true. The outcome is the same no matter how we state it. But I think the statement should be accurate. The XG is not contacting an external site. The HTTP you get from the XG includes a link to that site and your web browser reaches out, and that opens a potential exploit. True.

    All I'm saying is the description's accuracy matters, not just the point that there is a potential problem that the new SFOS introduced.

  • Given this info, Sophos should consider making the Assistant an item that can be easily disabled.... It is a cool feature but this does introduce some new attack vectors (some outside of anyone's control).

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Sophos Platinum Partner

    --------------------------------------

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • I'm thinking it might be that Sophos could have processes SC that monitor the contents of included code or destinations of links, etc, and sends a kill signal to XGS's if they detect a change that was not coordinated with Sophos. But that might be too iffy.

    So a switch in the XG to turn it off would allow folks to make their appropriate tradeoff of security and ease-of-use.

    We, of course, have the option to block outbound communications to whatfix.com, either through the XG, or endpoint, or other laptop firewall software. I've stopped it that way, but an actual switch would be nicer. And now that I think of it, I wonder if my fix has caused slight glitches in the rest of the interface... Hmmm...

  • what kind of action did you take against Sophos? Someone already having a case ID?

    I'd create one as soon as we're on the new version next week Adding existing case# to new cases speeds things up.

    Disabling that by adding block rules is not what I like.

    I also think this has been introduced for new Sophos admins. It is OK but there should be something on GUI to disable it because I see it  as a security issue.

  • Thanks for noting this here.

    Can confirm this.

    https://widget.usersnap.com
    https://cdn.whatfix.com

    Are contacted while working on the XG Web GUI. Also both services track your XG with a GUID.

  • Case ID: 04818805

    I was thinking about this feature also to be "in-line with industry best-practices" like mentioned in an announcement about a CLI change coming in SFOS 19?

  • final answer from Support to my question about a possibility to toggle this Sophos assistant thing on or off was:

    "there is a signature available in application filter for whatsfix and usersnap. You can block this from there making application filter policy or rule" "that this is the only secure, convenient and effective way to achieve it."

    If you want them to build this feature, more support cases would be needed, I guess.

  • As I said above, adding whatfix to a TLS/SSL block rule disables all access.
    After logout/log in to the Webadmin the Sophos Assistant sidebar does not show up anymore.

     
    SFVH (SFOS 20.0.0 GA-Build222) - Last (re)boot on November 6th  2023
    Asus H410i-plus - Pentium 6605 Gold - 250GB M.2 PCIe NVMe SSD - 8GB - 3 ports
    [If any of my posts are helpful to you please use the 'Verify Answer' link]