ICTNUT Posted November 14, 2005 Posted November 14, 2005 As reported here, N2H2 (a weak but widely sold into schools web URL filter) has been collecting information about the school children's web surfing habits. Not only that they have sold the information to marketeers and website owners for $15,000 per year. This amounts to N2H2 being simply Spyware and people are being urged to rid the schools of the software. We were already in the process of removing it but this just compunds it.
Guest Posted November 14, 2005 Posted November 14, 2005 OMG! That is just plain wrong. That is a huge invasion of privacy and abuse of trust. Shocking.
Ric_ Posted November 14, 2005 Posted November 14, 2005 @ICTNUT: I'd check the Ts & Cs in your license - see if you can get some money back off the Rat B@*%$#+s!
ICTNUT Posted November 14, 2005 Author Posted November 14, 2005 @Ric_: It was supplied to us by our county, I have spoken to them this morning and they say they had no idea. They had also just purchased a county wide upgrade to the new SmartFilter/Bess software which is in essence N2H2 re-badged. I am looking into alternatives now but it just sickens me that a compnay would abuse it's position in this way
Geoff Posted November 14, 2005 Posted November 14, 2005 I always thought they were a bit dodgy. They way Smartfilter intergrates with Squid is probably a GPL violation and large chunks of their 'blacklists' are just a vertibam copy of the ones avalible (for considerably cheaper) from http://www.urlblacklist.com Consider Squid + Dansguardian as a replacement. You can use the blacklists from urlblacklist.com too for a small fee. At least with open source you know no one is spying on you. Dos_box, any comment? seeing as we have smartfilter here up in lancs?
ICTNUT Posted November 14, 2005 Author Posted November 14, 2005 @Geoff: I am putting together a smoothwall + dansguardian + clamAV solution. As yet there has been no word from anyone at either N2H2 or Secure Computing <-- New owners !
russdev Posted November 14, 2005 Posted November 14, 2005 hi guys have look at date of article this is from 2000/2001 "according to The Wall Street Journal (1/26/01), N2" Russ
Geoff Posted November 14, 2005 Posted November 14, 2005 Is that relevant? They've put profit before ethics and demonstrated they cannot be trusted.
E1uSiV3 Posted November 14, 2005 Posted November 14, 2005 I agree with Geoff, but out of interest take a read... http://www.commercialalert.org/issues-article.php?article_id=585&subcategory_id=37&category=2
ICTNUT Posted November 14, 2005 Author Posted November 14, 2005 @E1uSiV3: We have used this product since 99/00 and as far as I can remeber NOT had any upgrades for it other than the block list updates that come down via the web. So as far as I am concerned the information is STILL being pumped out, regardless if they are still harvesting or not, and I have no way of stopping it other than removing it from the servers.
Geoff Posted November 14, 2005 Posted November 14, 2005 You can confirm its still happening by doing a traffic dump on the network interface. Something like Ethereal is quite revealing..
ICTNUT Posted November 14, 2005 Author Posted November 14, 2005 Thanks Geoff, I'll take a look at lunch time and see If i can see anything.
E1uSiV3 Posted November 14, 2005 Posted November 14, 2005 We dont "run" N2H2 here but the BGfL do and our volera boxes bounce through it.
beeswax Posted November 15, 2005 Posted November 15, 2005 unless I've misread the article, they've only stopped selling information in the USA. no mention of world wide. beeswax
peterhodgson Posted November 16, 2005 Posted November 16, 2005 This is complete and utter nonsense! The facts are that more than 5 years ago, N2H2 had a proxy server based web filtering soluiton, whereby every acceptable (allowed) page was served to the PC by the N2H2 server. N2H2 decided to offer a service in the US, whereby the customer paid nothing at all for the solution, N2H2 provided the hardware, software, support and upgrades, in return for the ability to post banner ads on the pages served, and an ability to sell AGREGATE data on surfing habits of schoolchildren. This data did not refer or relate to individual children, or even individual schools but was based on compounded statewide data. N2H2 made one such sale of data, but by that time the internet had moved on, the solution was made available as software, the pages were not served by a proxy server, there was no banner advertising and any data collected was by the customer themselves. N2H2 was purchased by Secure Computing Inc. in 2003, and the award winning database amalgamated with Secure's SmartFilter solution. To-day that solution is employed in more schools and major corporates worldwide than any other.
peterhodgson Posted November 16, 2005 Posted November 16, 2005 This is complete and utter nonsense! The facts are that more than 5 years ago, N2H2 had a proxy server based web filtering soluiton, whereby every acceptable (allowed) page was served to the PC by the N2H2 server. N2H2 decided to offer a service in the US, whereby the customer paid nothing at all for the solution, N2H2 provided the hardware, software, support and upgrades, in return for the ability to post banner ads on the pages served, and an ability to sell AGREGATE data on surfing habits of schoolchildren. This data did not refer or relate to individual children, or even individual schools but was based on compounded statewide data. N2H2 made one such sale of data, but by that time the internet had moved on, the solution was made available as software, the pages were not served by a proxy server, there was no banner advertising and any data collected was by the customer themselves. N2H2 was purchased by Secure Computing Inc. in 2003, and the award winning database amalgamated with Secure's SmartFilter solution. To-day that solution is employed in more schools and major corporates worldwide than any other.
Geoff Posted November 16, 2005 Posted November 16, 2005 Ok, so according to you the original article is FUD. Fine, but can we have some evidence to back up your version of history? Also you haven't addressed the other points I've previously raised.
eduabncs Posted November 16, 2005 Posted November 16, 2005 I know Peter quite well as he is our main contact at Secure Computing (UK subsidary). He has never been less then honest with us, so I do trust what he says above is in fact correct.
peterhodgson Posted November 16, 2005 Posted November 16, 2005 Ok, so according to you the original article is FUD. Fine, but can we have some evidence to back up your version of history? Also you haven't addressed the other points I've previously raised. I'm sorry - I'm new to this and cannot find your other comments. What I can tell you is that I, either in the position of MD of N2H2 Limited or now as MD of Telocator Limited, have been the sole point of presence for distribution of N2H2 in Europe since 1999 and we have never ever sold customer data or given the solution away. Furthermore, since the takeover by Secure Computing, the N2H2 and SmartFilter databases have been merged and this solution is the most robust that money can buy, including as it does 70 categories, including daily updates and Real Time updates of phishing, spyware and malware sites. This all happens in the background with no administrative involvement required. There are cheaper solutions such as Dans gaurdian but in the schools arena in particular using such a list is a false economy - or as one of our customers put it - using a sieve in a rainstorm.
Geoff Posted November 16, 2005 Posted November 16, 2005 I'm sorry - I'm new to this and cannot find your other comments. I said They way Smartfilter intergrates with Squid is probably a GPL violation and Large chunks of their 'blacklists' are just a vertibam copy of the ones avalible (for considerably cheaper) from http://www.urlblacklist.com What I can tell you is that I, either in the position of MD of N2H2 Limited or now as MD of Telocator Limited, have been the sole point of presence for distribution of N2H2 in Europe since 1999 and we have never ever sold customer data or given the solution away. Fair enough. I shall poke and prod my copy of smartfilter just to be sure though. Furthermore, since the takeover by Secure Computing, the N2H2 and SmartFilter databases have been merged and this solution is the most robust that money can buy, including as it does 70 categories, including daily updates and Real Time updates of phishing, spyware and malware sites. This all happens in the background with no administrative involvement required. I think blacklisting/whitelisting a unworkable idea to start with. You're always playing catch up with the internet. I'm also paticularly uncomfortable with the idea of 'no administrative involvement required'. Surely your inviting lots of false positives/negatives into your listings taking such an approach. Its also been my experience that Smartfilter (at least here at Lancashire) regularly misses large amounts of Javascript and ActiveX based nasties. Dansguardian OTOH (especially when you hook it up with ClamAV) does a good job of catching everything Smartfilter misses. Which nicely leads me on to your next point. There are cheaper solutions such as Dans gaurdian but in the schools arena in particular using such a list is a false economy - or as one of our customers put it - using a sieve in a rainstorm. Cheaper and better in my book. Not only does it block based on blacklists/whitelists. It also does keyword based grey listing and content matching based on mime types/activex and a few other things. Throw in ClamAV as I've mentioned and hardly anything nasty gets through. Yes, the kids still get to places they shouldn't do but they will manage that regardless of what technological means we put in the way to stop them. Technology is not a replacement for supervision!
eejit Posted November 22, 2005 Posted November 22, 2005 Hey guys, I think it's about time that the name of this thread got changed There is certainly a 'grey area' at minimum, and possibly the company has been completely exonerated. So, the title is unfair on the company, as some users may just browse the headlines without reading the content and will be unaware of the debate within. Maybe one of these instead: N2H2 is unofficially spyware - on a massive scale N2H2 may not be spyware - on any scale N2H2 ROCKS!!! BTW it's nothing to do with me, as I'd never even heard of them or the product before.
Geoff Posted November 22, 2005 Posted November 22, 2005 The company representative's lack of reply to my questions speaks volumes.
eejit Posted November 22, 2005 Posted November 22, 2005 The company representative's lack of reply to my questions speaks volumes. I think that apart from the "GPL violation" claim, the rest of your points were that it just wasn't very good software. I don't think that that warrants the "officially spyware" thread title. Maybe it should be "N2H2 is officially crap", that would keep everyone happy
Geoff Posted November 22, 2005 Posted November 22, 2005 My main arguements were: 1. The way Smartfilter intergrates with Squid is probably a GPL violation but IANAL so I'm not sure. I've contacted the Squid project and the FSF for clarification though. 2. Large chunks of the blacklists are subsets of the ones avalible from http://www.urlblacklist.com. compare the prices! 3. The actual software isn't as flexible and competent as the leading opensource rival, dansguardian.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now