I had a quick read on what they do and it makes perfect sense.
1
1
Do you have a link to the document that makes perfect sense?
1
From this community.sophos.com/kb/en-u… I derive it's about lookups of domains against some blacklist. Given that these domains are themselves queried over DNS, there's little point to encrypt the blacklist lookups. Basic obfuscation against keyword matching could make sense.
1
2
This was the result I saw, which says it can contain URLs and file submissions, which does not make perfect sense unless there was some context I'm missing... community.sophos.com/kb/en-u…
1
Hmm I think that's not good.
3
5
Sending full URLs plaintext over the public internet? 😬I know Avast used to do it with a chrome extension, but we told them they need to stop that or they're out of the webstore... I think they agreed to start sending them over https.
1
3
Should have used ROT26 as higher number means better encryption

Nov 26, 2019 · 8:16 PM UTC