ellen_messmer
Senior Editor, Network World

Feds declare war on spyware scams

News
Oct 18, 20045 mins

Last week’s federal complaint against an alleged spyware purveyor is only an opening salvo in what promises to be an all-out effort against spyware-related scams on the Web, according to regulators and industry experts.

Not only did the Federal Trade Commission (FTC) take its first-ever legal action to stop spyware by targeting two businesses said to be engaged in deceptive business practices, but lawmakers and security companies also have been joining the call to arms as complaints from businesses and consumers continue to grow. Among the recent developments:

• The U.S. House of Representatives this month passed a pair of bills intended to criminalize spyware, following a Senate spyware bill that passed earlier this year.

• California lawmakers enacted legislation that, beginning Jan. 1, bans software that steals personal information or sends viruses.

• The nonprofit Internet Education Foundation and Dell last week launched a campaign to help consumers fend off spyware. The foundation published on its Web site, www.getnetwise.org, video tutorials and tips for Internet users to keep spyware off computers and detect any spyware already installed. It directs visitors to dozens of free and commercial tools to easily remove spyware. The foundation’s members include America Online, Microsoft and AT&T.

Vendors are increasingly focusing on products to combat spyware, as was evident this week with announcements from Blue Coat Systems and Computer Associates. (see story).

The FTC filed its complaint against Seismic Entertainment Productions and SmartBot.Net, as well as the owner of both companies, Sanford Wallace, who earned the nickname “Spamford” in the 1990s for his junk e-mail operations through another company, Cyber Promotions. In the complaint the FTC asserts that Web sites operated by Wallace were loading spyware onto visitors’ computers without their consent by exploiting holes in Microsoft’s Internet Explorer.

The spyware changed the user’s home page, triggered pop-up ads and crashed computers, according to the FTC. After creating the problems, the spyware caused a CD-ROM tray on the computers to open, and then sent a warning that said, “You desperately need to rid your system of spyware pop-ups IMMEDIATELY!” The message included a recommendation to download purported anti-spyware products, called SpyWiper and SpyDeleter, promoted by the Web sites for about $30. (See Columnist Mark Gibbs’ take on the government’s action)

The case was expected to begin earlier this month in a New Hampshire U.S. district court. The most immediate action might entail a judge issuing an order that could temporarily shut down Wallace’s companies, observers say.

In addition to asking a federal court in New Hampshire to issue an order to prevent Wallace and his companies from disseminating spyware, the FTC wants to pursue unspecified monetary damages. (Seismic Entertainment is said to have its principal place of business in Rochester, N.H.)

“Consumers don’t deserve to be pestered and spied on by people who illegally hijack their computers,” says Lydia Parnes, acting director of the FTC’s Bureau of Consumer Protection. “This is our first spyware case, but it won’t be our last.”

The FTC’s case was spurred in part by a complaint filed against Seismic Entertainment and another company, MailWiper, by the Center for Democracy and Technology (CDT), a Washington advocacy group.

The spyware problem has risen to “epidemic proportions” in the last six months, says Mike Steffen, a policy analyst at CDT.

CDT, which issued a spyware report last November, asked Internet users to notify it about specific problems they experienced. The feedback about Seismic Entertainment and MailWiper’s software SpyWiper led CDT to file its complaint with the FTC. Steffen says it appears that Web banner ads at gaming and sports sites that might have appeared as innocuous public-service messages about heart disease were able to hijack the browser’s home-page setting, changing the Web site to one owned by Seismic Entertainment. This is sometimes called a “drive-by download.”

Steffen says the CDT was glad to see the FTC follow up on the complaint.

Wallace last week said the FTC’s case against him is unwarranted and he intends to fight it. “We feel our actions are fully legal,” he said, while adding that he’s open to changing some practices.

“There’s some political motivation here,” Wallace added. “They went after someone with a controversial, high-profile background, and they want to paint me as the poster boy in all this.”

He says Seismic is bankrupt.

Companies that make a living off Web ads – and that are eager to distance themselves from any connection to spyware – applauded the FTC’s enforcement actions.

“We’re happy to see the space cleaned up,” says Pete Celano, vice president of marketing at Weather Bug.com, which markets desktop software for weather information to consumers and businesses.

The Gaithersburg, Md,.company claims its Web site has no spyware in it and cites an audit from an outside firm, Aluria Software, as verification.

IT professionals who have added anti-spyware software to their users’ desktops are also skeptical that government action to either ban spyware or chase after those that create it will not do much good.

“It’s a lofty goal,” says Chris Hoff, chief information security officer at Western Corporate Federal Credit Union, which provides check imaging and back-office management services for about 1,000 credit unions. “Wiping out spyware is nice in theory, but as it has with spammers, new laws will probably be largely ineffectual.”