I only watched their flash demo, but did not try to install the program. So, I am guessing, but I suspect that all of this only works as shown if the PC in question is not password protected (i.e. set to "auto-login", or whatever you call it under Windoze...).
I would expect that if the computer requires password protection, you would have to first make a connection to your PC through the gotomypc.com portal, then over a secure connection transfer your password to your machine. In that respect, at least on principle it is not any less secure than an SSH connection. So, unless you suspect gotomypc.com to have a backdoor in their software, they would never get to know the domain password of your LAN.
Furthermore, to install the gotomypc.com software presumably will require administrator privileges, so no user could install it without their sysops knowing.
Finally, as I said, I have not tried it yet, but I would certainly expect our firewall to intercept the gotomypc.com communications by default.
My main concern is therefore not so much corporate networks, where the sysadmins presumably know what they are doing, but gotomypc.com being used by home users, possibly new to the internet and its dangers, who then due to lack of understanding open their PCs wide to the outside world...
But that's me only guessing... |