[32706] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Altova XMLSpy "phones home" user data

daemon@ATHENA.MIT.EDU (Alexander Falk)
Fri Dec 5 14:27:46 2003

Date: 5 Dec 2003 09:48:47 -0000
Message-ID: <20031205094847.18688.qmail@sf-www2-symnsj.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: Alexander Falk <al@altova.com>
To: bugtraq@securityfocus.com

In-Reply-To: <86ekvlkvmn.fsf@home.nest.cx>

>>>>>> "Bruno" == Bruno Lustosa <bruno@lustosa.net> writes:
>
>    Bruno> ... whenever someone will launch XMLSpy, the
>    Bruno> program will try to connect to Altova's servers, send some
>    Bruno> user info through a POST to a web server, and wait for a
>    Bruno> response. 

That is correct, this is a process described in our EULA in Section 1(k) Software Activation and Section 1(l) LiveUpdate. Please see our EULA for details, which is available on our website under this URL: http://www.altova.com/order_license4.html

>    Bruno> What bothers me is that
>    Bruno> it's sending user information that was _not_ entered into the
>    Bruno> program. It sends user name used to register the program, and
>    Bruno> it also sends an email address that I'm almost sure was not
>    Bruno> entered into the program.  

This is incorrect insofar as the information transmitted is data that has been entered by the user into the Registration dialog (Help menu / Registration). This does include the e-mail address, provided that the user has entered this into the Registration dialog when requesting an evaluation key-code from our license server.

Regarding the collection of e-mail addresses from users of our software, who are requesting an evaluation key-code, please see our strict privacy policy, which is available at this URL: http://www.altova.com/privacy.html

Altova takes privacy and security very seriously, and we believe we have properly disclosed any legitimate anti-piracy measures in our product in the EULA.

Sincerely,

Alexander Falk
President & CEO
Altova, Inc.


home help back first fref pref prev next nref lref last post