AV-Comparatives - Data transmission in Internet security products

Discussion in 'other anti-virus software' started by Petrovic, Apr 29, 2014.

  1. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
    That's.... not good.
    Based on the above reply from ESET it looks like this report didn't necessarily gets its information directly from the vendors, so info like SSL, hashing and signed files probably would need to come directly from inquiries to the vendors. I think this report stirred up too much speculation since I assumed that all of the vendors responded, at least partially, when that now appears to not be the case.
     
  2. SweX

    SweX Registered Member

    Joined:
    Apr 21, 2007
    Posts:
    6,429
    @mrtwolman

    Many thanks for the answer and explaning it all. :thumb:
     
  3. Macstorm

    Macstorm Registered Member

    Joined:
    Mar 7, 2005
    Posts:
    2,642
    Location:
    Sneffels volcano
  4. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    So it seems that most AV software in the US collects basically everything. :eek:
     
  5. FreddyFreeloader

    FreddyFreeloader Registered Member

    Joined:
    Jul 23, 2013
    Posts:
    527
    Location:
    Tejas
    This report got me to thinking about trying Forticlient again. I remember it was a bit heavy a couple of years ago. After running Roboscan, and Immunet the past two years, I'm surprised that Forticlient feels just as light now as those two do.
     
  6. chillstream

    chillstream Registered Member

    Joined:
    Aug 2, 2013
    Posts:
    49
    Location:
    Croatia
    So the main conclusion is: do not trust anything made (based) in USA. Obviously, customer privacy is not especially valued in the States.
     
  7. ance

    ance formerly: fmon

    Joined:
    May 5, 2013
    Posts:
    1,359
    Avast transmit local IP addresses too ... :eek:
     
  8. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
    That's what I have been saying for quite some time. Plus the overseas products are usually better anyway.
     
  9. RejZoR

    RejZoR Lurker

    Joined:
    May 31, 2004
    Posts:
    6,426
    So? Without your IP address being transmitted, you wouldn't be able to use Google, this forum, avast! itself being able to even update itself in the most basic way. Without IP you can't communicate with the internet "world". Refusing to share IP is like expecting a postal package being delivered to your house without an exact home address. It's just not possible.
     
  10. whitestar_999

    whitestar_999 Registered Member

    Joined:
    Apr 1, 2010
    Posts:
    162
    i think you somehow missed the 'local' part.'local ip address' is different from actual/wan ip address & is not required for any critical or even important task.though for a single system behind a router i wouldn't call it a personal info but in case of multi-system setup behind a router it certainly qualifies as a personal information.
     
  11. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
    Yes, exactly. Your public IP is visible to everyone but the local one has to be specifically queried and uploaded for someone to collect it and it necessary for pretty much nothing other than to more specifically identify you.
     
  12. blasev2nd

    blasev2nd Registered Member

    Joined:
    Mar 27, 2014
    Posts:
    47
    fortinet is my second option again :D

    my first is still panda, but I would like for some explanation from them ;)
     
  13. act8192

    act8192 Registered Member

    Joined:
    Nov 9, 2006
    Posts:
    1,789
    I may have misunderstood your answer. But IMO local IP is needed. Local, LAN, behind the router, IP is part of the transit path and is necessary for the router to deliver stuff to the correct computer.
     
  14. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
    Your router needs to know your local IP for that. The recipient of your connection does not.

    -http://www.auditmypc.com/internal-ip-address.asp
    This explains it somewhat, though I think they exaggerate a bit as you have to have Java installed (I do not) to get your local IP, plus I have found that Kaspersky firewall will block them from getting it as well.

    That said, it is an extremely deliberate act for them to collect it, and there is no valid reason for them to do so.
     
    Last edited: May 2, 2014
  15. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Hmmm , never really thought about this subject.

    And I´m not that paranoid when it comes to privacy, but still I´m glad I´m not using any of these products. :)
     
  16. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    ESET !

    I wouldn't go juming up & down about ESET's reply. Check the PDF again, because they refuse to answer this CRUCIAL question.

    Are special updates delivered to users with specific IDs?
     
  17. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
    They didn't answer ANY question. Hence the following:
    "First of all, we want to set the record straight: we did not answer any question in the AV-Comparatives questionnaire."
     
  18. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    @ xxJackxx

    Well spotted ! I wonder how many vendors would answer that "specific" question ?
     
  19. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
    Well, nobody answered it yes. Originally the lack of an answer was interpreted as avoiding the question, with an assumed answer of yes. However, since ESET's posting we have reason to doubt the level of vendor response at all. I suspect that Symantec responded as every question was answered and extra details were given on a couple of them with footnotes included. Anyone else's level of participation is left to speculation.
     
  20. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,220
    Location:
    USA
    By local IP address do we the typical 192.168.x.x or 10.x.x.x? These IP ranges are assigned by every home router using default DHCP/NAT and are meaningless in terms of identifying the users behind the router. The IP address which actually serves to identify the user is the one assigned by the ISP to the broadband modem and that IP is always "internet facing". Am I missing something?
     
  21. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,898
    Location:
    localhost
    Exactly :thumb: . Another million user aside me will have my same IP... so what? Lol
     
  22. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
    Combining local IP with public IP can identify individual computer in multi system networks. Router can "hide" individual computers on network, but not if local IP is transmitted to 3rd party.
     
  23. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
    Exactly. This is about being able to identify you behind a router. Combine this with any "cloud based detection" and they know which machine behind a router visited what website and what files you have on your machine. If they combine this with retrieving your logon username if gives them a very detailed view of what you are doing. Information that can be requested by any authorities. Regardless of whether or not you have anything to hide, the capability is disturbing, and the fact that they are collecting this data is even more so.
     
  24. oliverjia

    oliverjia Registered Member

    Joined:
    Jul 21, 2005
    Posts:
    1,926
    I just saw this thread and was shocked.
    So what do you do, practically?
    Can we just quit using AV software?
    Guess not, but what else can we do?
     
  25. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,898
    Location:
    localhost
    And, again, so what? They identify the machine not me. There nothing personal in a local IP and often this IP will anyway change. On top before been able to spoof it you need more than just the two IPs
     
    Last edited: May 3, 2014
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.