* Federal and state governments move to keep spam and spyware in check
endif; ?>When the CAN-SPAM Act of 2003 was signed into law, many critics complained that it wouldn’t do much good. The law left enough loopholes and leeway that even known spammers were pleased at the legislation. Indeed, they said the law legitimized their “mass-marketing” businesses.
Nevertheless, it’s important for the federal government, as well as state governments, to have such laws on the books. Without at least some type of law in place, we have little recourse to prosecute and punish someone for actions that the majority of us find objectionable.
In a highly publicized case, Howard Carmack, the man known as the Buffalo Spammer, was recently sentenced to three-and-a-half to seven years in prison for his misdeeds. Carmack was not prosecuted under the CAN-SPAM law, however. No, he was convicted under New York laws relating to identity theft and falsifying business records. Carmack’s mistake was in using the stolen identities of New York residents, under which he distributed millions of spam e-mail messages. As reported by IDG News Service (link below), the charges of falsifying business records stem from Carmack’s changing of e-mail header information to create forged sender addresses for the spam messages.
This case demonstrates the need for multiple types of laws that can be applied in this quick-changing era of computers and the Internet. Given the length of time that it takes to draft, review, debate and approve legislation, laws that are originally designed to address one type of problem – such as spam, spyware or privacy – may no longer fill the need once the laws are enacted. What’s more, the Internet world is moving so quickly that it’s impossible to anticipate how people will misuse technology tomorrow or the next day.
And speaking of misusing technology, the next subject to be put before federal legislators is likely to be spyware. The Center for Democracy and Technology is attempting to raise the profile of the problem before U.S. Congress. CDT Associate Director Ari Schwartz testified before the House Committee on Energy and Commerce Subcommittee on Commerce, Trade and Consumer Protection in late April. The text of his presentation can be found online.
Schwartz points out that there is no precise definition for “spyware.” Just like one man’s “spam” is another man’s “marketing message,” the term “spyware” has been applied to many types of applications with different types of functionality, both good and bad. According to Schwartz, however, these various applications we call spyware have one thing in common: a lack of transparency and an absence of respect for users’ ability to control their own computers and Internet connections.
In an effort to gain input from industry sources on what to do about the spyware problem, CDT has convened the Consumer Software Working Group. Companies and organizations such as AOL, the Consortium of Anti-Spyware Technology Vendors, Google, Microsoft, WhenU and Yahoo, among others, have joined the working group. (You can too, by submitting a request for membership to ari@cdt.org.) As described by CDT, the Consumer Software Working Group “is a diverse community of public interest groups, software companies, ISPs, hardware manufacturers, and others that are seeking consensus responses to the concerns raised by practices that harm consumers.”
Among the achievements of the working group is a set of examples of what “spyware” is and how it behaves. This is a crucial step in leading up to legislation that would ban the practice of spyware. After all, you must be able to positively identify something in order to declare it illegal. Perhaps the best way to identify spyware is to classify it by its behavior and outcome.
While anti-spyware legislation may still be months or even years away, there are current laws that can help prosecutors go after offenders today. Just as spammer Carmack was convicted for identity theft and fraud rather than for the distribution of spam, people or companies subjecting your computer to spyware could possibly be prosecuted under the Electronic Communications and Privacy Act (ECPA) or the Computer Fraud and Abuse Act (CFAA). While these two laws don’t specifically target the exploits of spyware, they could possibly cover the acts of surreptitiously intercepting communications from your computer, or of co-opting control of your computer – two common practices of known spyware.
Laws providing relief from spyware aren’t expected any time soon. Your best bet today to avoid the scourge of spyware is to get educated on how it is transmitted and to implement tools and practices that will safeguard you and your PC. For a good primer on the types of spyware, read CDT’s report “Ghosts in Our Machines: Background and Policy Proposals on the ‘Spyware’ Problem.”
Linda Musthaler is vice president of Currid & Company. You can write to her at mailto:Linda.Musthaler@currid.com




