Anti-spyware: Into the front lines

Q&A

In the past few months, Ari Schwartz and the Washington, D.C.-based Center for Democracy and Technology have leapt into the front ranks of the Net's spyware-fighters.
They're not programmers by trade. Instead, they are using their D.C. experience and clout to raise the issue of computer hijacking and intrusive advertising to the policy level, asking regulators to crack down on abuses. After a first report on the issue last November, Schwartz's group filed a first round of complaints with the Federal Trade Commission on Wednesday about so-called anti-spyware products that the group contends are abusing customers' trust.

The practices outlined in the CDT complaint read like a technophobe's nightmare, and even the most tech-savvy surfers will recognise serious dangers. Pop-up windows spring up, Javascript warning messages flash, the CD-ROM drive on computers even opens and shuts for no apparent reason -- all in order to frighten surfers into downloading and buying a specific product, the CDT alleges.

Schwartz has played the role of lead investigator for his organisation's complaint against Mail Wiper, a company that had previously used unsolicited mail to advertise spam-blocking software. He quickly became familiar with the maze of affiliates, advertising partners and other third parties that often make it difficult to determine who exactly is responsible for taking advantage of surfers' credulity.

"There are so many parties involved, that it's hard for any consumer to know who they're involved with, or to trust the whole system," Schwartz said.

Still, his group isn't yet pressing for new legislation or regulation against spyware companies or other computer hijackers. Existing law will probably be enough, if it is enforced, they say.

CNET News.com spoke with Schwartz about spyware, deceptive advertising, and his group's decision to complain to federal regulators about one anti-spyware company's hard-sell software distribution tactics.

Why is this case serious enough to take to the FTC?
This case is symptomatic of the larger problems of fraud and deception and unfair trade practices on the Internet. We feel as though it is really the first in what we hope will be a succession of cases that will highlight some of the things that are happening online, so that some of the people that think they can get away with things due to the anonymity of the situation will not be able to do so in the future.

Does the spyware issue raise new issues of privacy and the amount of confidence people can have in their computers? Or is this just next-generation spam?
I think it does raise some of the issues to a new level. Especially in cases where people are getting software installed on their computer without their knowledge, or their default settings changed without their knowledge. It's more than just spam when someone is able to constantly monitor your behaviour or send pop-ups to you without your consent. So it's more than an annoyance, it can be a privacy problem, and it can be a major security problem for the Internet.

How is this phenomenon evolving? We saw the first explosion of adware and spyware companies come with the boom in free file-swapping tools, but what have you seen in the last six months or year?
We've seen the fact that the category of spyware, as we documented in our November report, includes a lot of different things. It's hard to talk about it as a category by itself. Some of it has existed for a long time, and some of it is a range of new things. However, despite the fact that it is hard to define in that way, we have seen an upsurge in techniques to try and get consumers to download applications, to consent to make changes to their system without actually having informed consent.

Mail Wiper (the company named in your FTC complaint) is not the only antispyware company that uses affiliates to distribute or advertise their software. Some of these affiliates use techniques such as unsolicited email advertising. In your opinion, does the original company bear responsibility for the actions of its affiliates?
According to our understanding of FTC law, they do bear responsibility if they were a partner to the action. So if they knew what was going on, maybe even beyond, then yes, depending on the actual case.

Is current law structured well enough to handle these kinds of cases? Or does there need to be more regulation of what third parties can do to computers?
We believe that the most egregious cases, where software is placed on people's computers without their consent, where information is transferred back, or where people are deceived into downloading software, we believe current law does cover those cases. We think there needs to be more active enforcement -- that's why we're bringing these complaints -- but we think current law does cover most of the egregious cases we've seen.

There is legislation out there, where they want to try to focus the issue a little more, make sure that current law is covered. Some of them try to come up with standards for software generally. We'd like to see more enforcement of existing law before we go down that road. However, it is worth exploring. We certainly need more attention to the issue and how it's going to work.

We'd rather see the privacy cases dealt with through general privacy legislation rather than adding another piece for software, or spyware, to this large puzzle we have of privacy law.

What's your advice to consumers? A lot of people have no idea what's going on under the hood in their computers?
Well, it is difficult. I think there are more tools out there now than there were in the past. You have the large companies, the OEMs (original equipment manufacturers) and the ISPs, both offering anti-spyware tools that are trustworthy. The other thing is to read through the reviews before you download the software. It's likely that the ones that have gotten good reviews from reliable sources are the ones that are going to be best for you. I think that's true for all software.

There are cases where kids download something on their parents' computer, and their parents don't know what's there, and they try to remove something, and the kid keeps downloading it again. We do see a lot of cases like that. We are going to need better self-regulation and technologies to help parents, and systems administrators generally, to control their networks better.

Post your comment

In order to post a comment you need to be registered and logged in

Log in or create your ZDNet UK account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Membership FAQ

ZDNet UK Live

dava4444

that comment bot is a nutter, it just referred me to the moderator on my own blog. shocked look. please help thank you Dava I'm afriad to...

24 minutes ago by dava4444 on Welcome to the new ZDNet UK community!
dava4444

Hi Rupert! Don't think I could fill the above shoes... but if your ever looking for a consumer rights Tech blogger..tip me the wink lol peace Dava

2 hours ago by dava4444 on Fancy working for ZDNet UK?
dava4444

Hi Rupert My photo is gone from my profile and I just got told i was a spammer by the comment bot. the navigation is gone for my profile. :O on...

2 hours ago by dava4444 on Welcome to the new ZDNet UK community!
ator1940

With windows it is always more bloat, and a lot of that seems to be duplicated in various places. I've noticed that you will have freed space on...

8 hours ago by ator1940 on Can you believe it - 2765 kB will be freed?
BuzzMyStat

Buzz My Stat : New search for http://www.zdnet.co.uk Take a look: http://www.buzzmystat.com/site/zdnet.co.uk

Karen Friar

Hi Jamie, I'm sorry your comment got caught in the spam filter. We use an industry standard blacklist for this. I suspect that the comment may...

16 hours ago by Karen Friar on Spam? Filter Changed?
J.A. Watson

Pop - Neither have I. Ever, under any circumstances. I'm much more accustomed to Windows slowly, but inexorably, consuming more and more disk...

17 hours ago by J.A. Watson on Can you believe it - 2765 kB will be freed?
John Molloy

Apple are currently pushing to get tv content on the iPad by April 3rd. This could possibly be seen as a spoiler for that announcement I suppose....

1 day ago by John Molloy
Andrew Donoghue

Hey - presume you mean something that builds on Apple's existing TV device? Apple have already had a couple of runs at building Apple TV and it's...

1 day ago by Andrew Donoghue on Google's TV timing may reveal more to come
BVE2011

Google, Sony, Intel may build TV project www.zdnet.co.uk/news/emerging-tech/2010/03/18/google-sony-intel-may-build-tv-project-40088359/

ator1940

70,0000 to 90,0000 computers? A very small number considering some of these botnets are in the millions, and there are so many of them operating,...

2 days ago by ator1940 on Microsoft says it decimated Waledac botnet
ator1940

I agree Roger, and why can't they write secure code? What will happen when they find stolen code in windows? They have a track record of...

2 days ago by ator1940 on Microsoft lashing out at Linux, open source
ator1940

Do you think it will really take days?

2 days ago by ator1940 on Microsoft previews Internet Explorer 9 with HTML 5 support
neilfab

@evilmanic have you seen the new hp on zdnetuk

Xwindowsjunkie

Wonder how many days it will take before somebody codes an exploitive hack for IE9?

2 days ago by Xwindowsjunkie on Microsoft previews Internet Explorer 9 with HTML 5 support
roger andre

There are some really good people in Microsoft and I wonder, how embarassing it must be for them to see how the organisation behaves from it's...

2 days ago by roger andre on Microsoft lashing out at Linux, open source
J.A. Watson

On further inspection, it looks like some things are missing, is it possible that there was a time lag between whatever state the site was in that...

2 days ago by J.A. Watson on Welcome to the new ZDNet UK community!
Tezzer

Ok. Now I'm getting annoyed. Previously I could just click on just about any item or comment I saw and get a reply box. How do I manage that...

2 days ago by Tezzer on ZDNet UK: faster, smarter, still IT all the way
Andrew Donoghue

hey Roger. Think I have spotted a bug as when I click on my name it takes me to the same page as if I had clicked on "Edit Profile". i.e...

2 days ago by Andrew Donoghue on ZDNet UK - Now cleaner than an Archbishop's conscience
ajclarke

Great new look for ZDNET UK web-site http://bit.ly/9R5eAA to check it out @ZDNetUK #zdnet

Featured white papers

Achieving PCI Compliance for:Privileged Password Management & Remote Vendor Access

For multi-store outlets, including retail, banking, grocery, gas, hospitality, convenience stores and others, reducing (or avoiding) the cost of in-store system support and maintenance while maintaining compliance with PCI and other requirements has become a strategic challenge.

Download now

Web 2.0 Security Threats: How to Protect Your Enterprise Network

Speaker: Dr. Chenxi Wang, Principal Analyst, Security and Risk Management, Forrester Research, Inc. As Enterprises are increasingly connected to the Internet and as hard organizational boundaries are fast disappearing, security professionals are facing fresh challenges in Enterprise computing.

Download now

MindManager - Tutorial for New Users - Short

This tutorial is for new MindManager users and teaches you how to get started, by creating maps, reading maps and organizing your information.

Download now