john_dix
Editor in Chief

D.C. spyware discussion

Opinion
Apr 11, 20052 mins

The need for legislation that would define spyware and criminalize its distribution heated up last month when Claria asked Computer Associates to disable the ability of Pest Control to detect Gator, which Claria claims is not spyware. CA consented while it reviewed the request, but later that week reinstated the detection.

Agreeing on exactly what constitutes spyware is one of the chief problems Congress and others have had in figuring out a cohesive strategy for fighting back.

Last month the Federal Trade Commission (FTC) released a report summarizing a workshop on spyware it hosted 12 months ago. Participants in the workshop included a range of experts, from Justice Department computer crime specialists to representatives from Dell, Microsoft, AOL, Google, McAfee and Symantec. Their conclusion, as summarized in an FTC staff report: Spyware is a “serious and growing problem,” but it is very hard to define.

For example, everyone in the workshop seemed to agree that software that sneaks onto a PC is spyware, but fewer agreed about programs that come bundled with purchased products, the ones you never know about unless you read the End-User License Agreements.

The FTC said the definition problem is most challenging when it comes to adware. Some panelists classified adware as spyware if the user isn’t given adequate notice about its installation, while others argued that adware isn’t spyware if it doesn’t monitor computer use.

Interestingly, the FTC and Department of Justice participants weren’t the ones calling for new spyware legislation. Current laws give them enough ammunition to go after spyware sources. Their efforts, the report says, have “not been stymied by a lack of federal legislation but rather by the inherent difficulties in investigating and prosecuting spyware cases.”

If nothing else, though, the spyware laws being kicked around by Congress – Spy Act, I-Spy Act and Spy Block Act – help focus attention on the problem. Vendors such as Trend Micro, for example, advocate that legislation is good because, if nothing else, it will help better define spyware and lead to the development of standards, something along the lines of what happened in the fight against viruses. New laws or not, it is critical to have all hands on deck.

One conclusion of the FTC report that most everyone seems to agree on: “The incidence of spyware can be decreased if the private sector and the government act separately and in concert.”