(Mis)Uses of Technology

(Mis)Uses of Technology

by Mike Masnick




ZoneLabs Won't Fix Hole In Free Firewall

from the if-it's-free,-you-should-suffer-through dept

ZoneLabs provides the most popular "free" firewall product out there. It seems to be the standard product that people recommend, but now that a security vulnerability has been found, ZoneLabs only response is that people should upgrade to the paid-for version. They won't fix the free version, because it would be too much trouble, and they don't think the security hole is that big (basically begging hackers to exploit the hole). I can understand not adding new features to a free version, but leaving open a known exploit for a security product doesn't seem too smart. It wouldn't make me that comfortable using either version. If I were a competing company like Kerio (which also offers a similar free-for-home-use personal firewall), I'd be out there promoting how my solution was more secure than the market leader's.

9 Comments | Leave a Comment..

 
 

Reader Comments

(Flattened / Threaded)

    Jul 2nd, 2003 @ 8:54am
  • No Subject Given

    by CHIA GARCIA

    Zone Alarm used to be a freeware product. Then they started messing with lite and full editions. I stopped using their products then. When I upgraded my zone alarm to find that half of the features in the free version were disabled. I was pissed! Why should I bother with a company that pulls this kind of crap???

    (reply to this comment) (link to this comment)

    • Aug 18th, 2003 @ 8:42pm
    • Re: zonealarm freeware features disabled

      by kenzo

      I worked there when this decision was made by sales/marketing. It was a conscious marketing ploy to try and trick/force people to have to buy the full version after they thought they were doing an update to the free version...

      (reply to this comment) (link to this comment)

    • Feb 4th, 2004 @ 5:26pm
    • ZZZoneLabs

      by Ivan Barnes

      What is free ? Ever tried 3.7 version

      (reply to this comment) (link to this comment)

    Jul 2nd, 2003 @ 9:30am
  • Is there some evidence that Kerio is not vulnerabl

    Quote from the ExtremeTech article: "... since the vulnerability was tied to Windows, the vulnerability would also affect other firewall manufacturers and not just ZoneAlarm."

    I searched Kerio's website for some mention of the ShellExecute vulnerabilty and they make no reference to it. Similarly a few simple Google searches yeilded no results.

    I'm not sure if this problem warrants everybody picking on only ZoneAlarm just yet.

    (reply to this comment) (link to this comment)

    • Jul 2nd, 2003 @ 2:17pm
    • Re: Is there some evidence that Kerio is not vulne

      by bob

      eeerm, if it WASNT just zonealarm and was a windows problem

      1: why would the 'pro' paid for version of zonealarm not have the problem
      2: why would they be telling people to upgrade to the paid for version

      (reply to this comment) (link to this comment)

      • Jul 3rd, 2003 @ 5:47am
      • Re: Is there some evidence that Kerio is not vulne

        by Vigil

        Whether it is a Zonealarm specific bug is neither here nor there. The fact remains that they are using the threat of this bug to virtually blackmail people. Either pay them money or be vulnerable. Or use someone else's product.

        (reply to this comment) (link to this comment)

        • Jul 3rd, 2003 @ 12:04pm
        • Re: Is there some evidence that Kerio is not vulne

          by gravy

          OR......you can go get emule plus and go to www.sharereactor.com and look under the software category for a ed2k link to the full pro version.

          you get what Zone Labs says you should to fix it and you don't have to pay for it. HA!

          (reply to this comment) (link to this comment)

    Jul 2nd, 2003 @ 3:49pm
  • No Subject Given

    by CraweN

    Read the Article on ExtremeTech. It is a problem in windows as stated previously and of course if it takes to many resources(money) to fix versus how hard it is getting the hack to work, i fell he's right. why fix it! Would be a great advertisement fixing it though.

    (reply to this comment) (link to this comment)

Add Your Comment

Have a Techdirt Account? Sign in now.
Get Techdirt’s Daily Email
Plain Text HTML
Save me a cookie
  • Plain Text: A CRLF will be replaced by break <br> tag, all other allowable HTML is intact
  • HTML: No formatting of any kind is done without explicitly being written in
  • Allowed HTML Tags: <b> <i> <p> <a> <em> <br> <strong> <blockquote> <hr> <tt>
Close
Have a Techdirt Account? Sign in now.
Get Techdirt’s Daily Email
Plain Text HTML Save me a cookie

Search Techdirt
And now, a word from our Sponsors..



Subscribe to Techdirt's Daily Email Newsletter

Techdirt's Daily Email Newsletter

Related Stories
Close
E-mail It