Share


Share

Share it !



share/bookmark
Showing posts with label Watching. Show all posts
Showing posts with label Watching. Show all posts

Anti-Spyware Coalition - Watching the Henhouse


In 2003 the Consortium of Anti-Spyware Technology vendors (COAST) was formed to "collaborate on projects to increase awareness of issues involving spyware." Their goals included helping consumers understand what had been installed on their systems, enabling them to remove what they didn't want and pressuring the advertising software industry to change their business practices.

However, things began to unravel when several founding members (Lavasoft, Computer Associates, Webroot and Aluria) pulled out of the consortium, reportedly because of the group's inability to create a set of standards and code of ethics. Some of those departing members also indicated that COAST had begun to certify -- for a fee -- certain publishers that were known by many anti-spyware firms as purveyors of spyware. Yes, my friends, allegedly the fox was watching the henhouse!

So COAST basically disintegrated and many say that was a good thing! The good news is this: in early 2005 the Center for Democracy and Technology (CDT) convened a meeting with industry anti-spyware leaders to discuss issues facing the anti-spyware industry, and the Anti-Spyware Coalition (ASC) was then formed. The new group includes the original COAST founders as well as consumer groups, academia and just about every big name in computing, including all the top anti-virus players.

Spyware has previously been defined as a computer program that, surreptitiously, gathers information without the knowledge of the user and may port that data back to another entity or as software that asserts control over a computer without the user's knowledge.

One of the first tasks that ASC did was to create a formal definition of spyware and other potentially unwanted technologies. Their description is this: Technologies deployed without appropriate user consent and/or implemented in ways that impair user control over the following: (1) material changes that affect their user experience, privacy or system security; (2) use of their system resources, including the programs that are installed on their computers; and/or (3) collection, use and distribution of their personal or other sensitive information.

Another task of ASC was to create a set of common industry guidelines for publishers who allege that their software has been improperly flagged as spyware. This is an important step because, well frankly, sometimes anti-spyware vendors make mistakes and it can be quite costly for a publisher to be flagged as a bad guy! The guidelines are just that -- guidelines -- ASC does not independently resolve the disputes but has framed recommended best practices for anti-spyware software publishers. Bravo!

ASC also has published a glossary of terms commonly used in discussions about spyware and a list of anti-spyware Safety Tips to provide basic guidelines for consumers to protect themselves and their computers. They recommend that users keep their security patches up to date, download programs only from websites they trust, read the fine print in license agreements, not be tricked into clicking anything on a popup window, beware of free software and use tools to detect and delete spyware.

In an effort to fight spyware, three U.S. Senators have introduced a bill that would attempt to combat this plague by making it a crime to offer this type of spying computer program. The bill (S.2145) is entitled "Software Principles Yielding Better Levels of Consumer Knowledge Act," or the "SPY BLOCK Act." Cute name!

If passed it will outlaw software that, without explicit user permission, installs itself or other programs, reconfigures settings (or redirects the user), captures personal information or keeps track of visited websites. And, this is the best part: the software must disclose in clear language each aspect of what the program will do to your computer and with your information and must obtain your consent to do so.

In addition, the software must be easily uninstallable through the "add and remove programs" feature (in Windows OS) or other standard methods. Spyware programs are so notoriously difficult to remove from infected systems they are often referred to as parasitic. It appears the proposed legislation is lingering in committee. So, we'll have to wait to see what happens to publishers of "unwanted technology" if SPY BLOCK ever becomes law.

According to a recent study by the Pew Internet & American Life Project, nine out of ten Internet users say they have adjusted their online behavior out of fear of falling victim to software intrusions and about 59 million American adults, say they have had spyware or adware on their home computer. Additionally the project reports that 68% of home Internet users or about 93 million American adults have experienced at least one computer problem in the past year that was consistent with problems caused by spyware or viruses.

While those stats are discouraging, the report also indicated that 25% of Internet users say they have stopped downloading music or video files from peer-to-peer networks to avoid getting unwanted software programs on their computers. Perhaps there is some silver lining to the epidemic!

The report also indicated that there is a significant gap between people's perceptions and the reality of what is on their computers. An October 2004 study by AOL and the National Cyber Security Alliance reported that 53% of respondents said they had spyware or adware on their computers, but a scan revealed that 80% of them actually had such programs installed. Yikes!

That same study found an average of 93 spyware applications on users' computers. The thought of nearly a hundred spyware applications per computer just blows my mind. Experts conservatively estimate that for every 1,000 users in an organization, the costs of fixing spyware-related problems are $83,000 per year. Forrester Research released "AntiSpyware Adoption In 2005," which indicated that 39% of respondents, dubbed "technology decision makers," did not know the percentage of desktops infected with spyware in their organizations and 56% were unsure of what percentage of help desk calls were related to spyware issues. However, the Forrester report indicates that, on average, 7% of all help desk calls are made in response to spyware infections. Considering how much time it usually takes to resolve a serious spyware infection, that number is huge.

I have been infected a couple of times on my home computer -- ahem -- when someone other than me was using it. It takes days to "fix" the problem. In fact, I now just re-image my PC because it is easier than trying to find the culprit(s) and eliminate them. I simply keep a backup of my data on an ongoing basis so that I don't have to deal with the potential loss of it.

Meanwhile, the need to fight spyware will push anti-spyware revenues from $12 million in 2003 to an estimated $305 million in 2005. Hum ... with all that revenue to be had, how motivated could anti-spyware publishers be to find a cure?

Folks, this insidious problem is not going away any time soon. The best we can do is to alter our cyber-behavior and keep our anti-spyware and anti-virus software up to date. Remember, my little chickens, it may not be Big Brother watching you, but somebody probably is -- let's hope it isn't a fox! Safe surfing.




Donna Johnson Edwards is the Director of Consulting for Tenax, Inc. Established in the U.S. in 2002, Tenax provides IT compliance certifications, training and targeted consulting services. For further information on IT Compliance [http://www.tenaxcorporation.com] and Software Asset Management [http://www.tenaxcorporation.com] please visit the Tenax Corporation website.




Are Predators Waiting , Watching, and Engaging on Your Child's Social Networking Sites?


MySpace and other social networking sites offer thriving communities where young people engage in countless hours of banal chatter and photo sharing. Not coincidentally, these social networking sites also have become hangouts for child predators, child pornographers, and other cybercriminals.

To stay one step ahead of authorities, these cybercriminals use tricks to conceal their identities online. One of the most common is lying about their ages, claiming to be younger than they are. And to hide their IP addresses and locations, predators and other cybercriminals often piggyback on Wi-Fi connections or use proxy servers. They use decentralized peer-to-peer networks to prevent material from being tracked to a specific server. They also use encryption to allow them to keep online chats private from those policing the Web. When law enforcement, ISPs, and others take down the websites of these pedophiles, predators, and cybercriminals, it's not long before they're back up, hosted by a different service.

Skillful with their cell phones, instant messaging accounts, and with access to personal computers at home and school, young people are easy targets for sexual predators. Too many of them are ready and willing to share personal information online without a thought to how it might be misused by others. The National Center for Missing and Exploited Children reports that one in five kids online has been solicited or enticed. Reports of child pornography on the center's CyberTipline have increased six of the last seven years.

Business and technology professionals may think of online child safety as a family issue, but it's a workplace issue, too. Social networks aren't just a teen phenomenon. A recent survey by Web filtering company, Websense, found that 8% of respondents visit social networking sites while at work. Companies can use Web filters to limit access to the sites, though Websense says its customers don't seem overly concerned. Whiling away company time on social networks is a productivity issue; luring children for sex is a criminal one.

There's little evidence that sexual predators are trolling from workplace personal computers, but it's been known to happen. In 2003, a Cincinnati-area police chief admitted to soliciting sex from someone he thought was a 15-year-old, using his work computer. And a deputy press secretary at the Department of Homeland Security, arrested in March for attempting to seduce a child, had his workplace computer seized as part of the investigation and gave the number to his government-issued cell phone to a police office posing as a 14-year-old girl.

Child porn stored on company computers and servers has been a bigger problem. Filtering and blocking can help keep the images off networks, though it's not failsafe. Keyword and URL-based filters have spotty coverage. Other software scans images for limbs and skin tones and blocks pictures it identifies as porn, but skin often takes up too little of the photographs, and innocuous material can be inadvertently blocked.

The Internet Crimes Against Children program last year investigated 2,329 cases of enticement and of predators traveling to meet minors, and 252,000 cases of child pornography. Yet those numbers provide just a glimpse of the activity, since many local police forces are too small to investigate child porn. "It's absolutely overwhelming," says Brad Russ, director of Internet Crimes Against Children's training and technical assistance program, which trains 1,000 officers each year. "The scope and the scale of the problem far exceeds our capacity." Intensifying the epidemic is that more than half the world has no laws dealing with child pornography.

Vigilante groups are fighting back. In January, NBC's Dateline featured a report about one such group, Perverted-Justice.org, which set up a sting that resulted in 51 men being busted in three nights. The group hasn't seen one acquittal from those it's helped bring to justice, and nearly all of its work is done with law enforcement. Yet some in law enforcement are wary of such efforts. "We certainly take any information that anyone has regarding an offender," says Randy Newcomb, an investigator with the New York State Police in Canandaigua, N.Y. However, vigilantes expose themselves to liability for entrapment or possession of child porn and might not properly maintain digital evidence, Newcomb says.

Putting filtering and monitoring software on kids' computers provides some protection. SearchHelp's Sentry line, for example, blocks Web sites based on keywords and creates a log of visited sites. It also lets parents and other guardians monitor a child's activity from other computers. Parents can be notified of violations via E-mail or cell phone. Sentry also monitors IM conversations, using expertise culled from law enforcement to flag phrases commonly used by predators. Any IT pro knows of the limitations of such tools. The filters don't work perfectly, and even if kids post and browse safely, social networking sites present a new set of problems. Profiles on the sites often link to other online information sources, providing the type of data a fixated predator might use to locate a child, such as a school name, says Michelle Collins, a unit director at the National Center for Missing and Exploited Children.

Investigator Newcomb recently spoke to an auditorium of elementary schoolers in western New York. He asked kids in the audience how many of them had more than 200 friends on their online buddy list--a bunch of hands shot up. Out of those, he asked how many have only friends on that list they can put a face to, and half of the hands remained raised. Finally, he asked if any of the kids had ever gone and met someone they'd got to know online, and a few hands were raised. "That's just totally frightening to me," Newcomb says. "The superintendent looked like his eyes were going to pop out of his head." It may take a village to raise a child, but in a world of online social networking, decentralized networks and servers, and increasingly tech-savvy child predators, it's going to take a united effort among government, industry, and families to keep them safe. To protect your child, you need an Internet security team of experts making sure that you, your family, and your business computer are always safe and secure.

The best protection you can have in today's rapidly changing world of cyber-attacks is to have expert support for all your Internet security needs that will provide technical support without any hassles and without charging you extra fees. It will become even more critical than it is today as time goes on. You need to find your own personal team of experts to rely on. If you ever have a security problem, you will want to have a trusted expert you can call for professional help, without any hassles and extra costs!

Remember: When you say "No!" to hackers and spyware, everyone wins! When you don't, we all lose.




Etienne A. Gibbs, Internet Safety Advocate, recommends to individuals and small business owners the protection (including free lifetime technical support and $25,000 identity theft insurance and recovery) package he uses. For more information, visit http://www.SayNotoHackersandSpyware.com/.




Are Predators Waiting , Watching, and Engaging on Your Child's Social Networking Sites?


MySpace and other social networking sites offer thriving communities where young people engage in countless hours of banal chatter and photo sharing. Not coincidentally, these social networking sites also have become hangouts for child predators, child pornographers, and other cybercriminals.

To stay one step ahead of authorities, these cybercriminals use tricks to conceal their identities online. One of the most common is lying about their ages, claiming to be younger than they are. And to hide their IP addresses and locations, predators and other cybercriminals often piggyback on Wi-Fi connections or use proxy servers. They use decentralized peer-to-peer networks to prevent material from being tracked to a specific server. They also use encryption to allow them to keep online chats private from those policing the Web. When law enforcement, ISPs, and others take down the websites of these pedophiles, predators, and cybercriminals, it's not long before they're back up, hosted by a different service.

Skillful with their cell phones, instant messaging accounts, and with access to personal computers at home and school, young people are easy targets for sexual predators. Too many of them are ready and willing to share personal information online without a thought to how it might be misused by others. The National Center for Missing and Exploited Children reports that one in five kids online has been solicited or enticed. Reports of child pornography on the center's CyberTipline have increased six of the last seven years.

Business and technology professionals may think of online child safety as a family issue, but it's a workplace issue, too. Social networks aren't just a teen phenomenon. A recent survey by Web filtering company, Websense, found that 8% of respondents visit social networking sites while at work. Companies can use Web filters to limit access to the sites, though Websense says its customers don't seem overly concerned. Whiling away company time on social networks is a productivity issue; luring children for sex is a criminal one.

There's little evidence that sexual predators are trolling from workplace personal computers, but it's been known to happen. In 2003, a Cincinnati-area police chief admitted to soliciting sex from someone he thought was a 15-year-old, using his work computer. And a deputy press secretary at the Department of Homeland Security, arrested in March for attempting to seduce a child, had his workplace computer seized as part of the investigation and gave the number to his government-issued cell phone to a police office posing as a 14-year-old girl.

Child porn stored on company computers and servers has been a bigger problem. Filtering and blocking can help keep the images off networks, though it's not failsafe. Keyword and URL-based filters have spotty coverage. Other software scans images for limbs and skin tones and blocks pictures it identifies as porn, but skin often takes up too little of the photographs, and innocuous material can be inadvertently blocked.

The Internet Crimes Against Children program last year investigated 2,329 cases of enticement and of predators traveling to meet minors, and 252,000 cases of child pornography. Yet those numbers provide just a glimpse of the activity, since many local police forces are too small to investigate child porn. "It's absolutely overwhelming," says Brad Russ, director of Internet Crimes Against Children's training and technical assistance program, which trains 1,000 officers each year. "The scope and the scale of the problem far exceeds our capacity." Intensifying the epidemic is that more than half the world has no laws dealing with child pornography.

Vigilante groups are fighting back. In January, NBC's Dateline featured a report about one such group, Perverted-Justice.org, which set up a sting that resulted in 51 men being busted in three nights. The group hasn't seen one acquittal from those it's helped bring to justice, and nearly all of its work is done with law enforcement. Yet some in law enforcement are wary of such efforts. "We certainly take any information that anyone has regarding an offender," says Randy Newcomb, an investigator with the New York State Police in Canandaigua, N.Y. However, vigilantes expose themselves to liability for entrapment or possession of child porn and might not properly maintain digital evidence, Newcomb says.

Putting filtering and monitoring software on kids' computers provides some protection. SearchHelp's Sentry line, for example, blocks Web sites based on keywords and creates a log of visited sites. It also lets parents and other guardians monitor a child's activity from other computers. Parents can be notified of violations via E-mail or cell phone. Sentry also monitors IM conversations, using expertise culled from law enforcement to flag phrases commonly used by predators. Any IT pro knows of the limitations of such tools. The filters don't work perfectly, and even if kids post and browse safely, social networking sites present a new set of problems. Profiles on the sites often link to other online information sources, providing the type of data a fixated predator might use to locate a child, such as a school name, says Michelle Collins, a unit director at the National Center for Missing and Exploited Children.

Investigator Newcomb recently spoke to an auditorium of elementary schoolers in western New York. He asked kids in the audience how many of them had more than 200 friends on their online buddy list--a bunch of hands shot up. Out of those, he asked how many have only friends on that list they can put a face to, and half of the hands remained raised. Finally, he asked if any of the kids had ever gone and met someone they'd got to know online, and a few hands were raised. "That's just totally frightening to me," Newcomb says. "The superintendent looked like his eyes were going to pop out of his head." It may take a village to raise a child, but in a world of online social networking, decentralized networks and servers, and increasingly tech-savvy child predators, it's going to take a united effort among government, industry, and families to keep them safe. To protect your child, you need an Internet security team of experts making sure that you, your family, and your business computer are always safe and secure.

The best protection you can have in today's rapidly changing world of cyber-attacks is to have expert support for all your Internet security needs that will provide technical support without any hassles and without charging you extra fees. It will become even more critical than it is today as time goes on. You need to find your own personal team of experts to rely on. If you ever have a security problem, you will want to have a trusted expert you can call for professional help, without any hassles and extra costs!

Remember: When you say "No!" to hackers and spyware, everyone wins! When you don't, we all lose.




Etienne A. Gibbs, Internet Safety Advocate, recommends to individuals and small business owners the protection (including free lifetime technical support and $25,000 identity theft insurance and recovery) package he uses. For more information, visit http://www.SayNotoHackersandSpyware.com/.




Anti-Spyware Coalition - Watching the Henhouse


In 2003 the Consortium of Anti-Spyware Technology vendors (COAST) was formed to "collaborate on projects to increase awareness of issues involving spyware." Their goals included helping consumers understand what had been installed on their systems, enabling them to remove what they didn't want and pressuring the advertising software industry to change their business practices.

However, things began to unravel when several founding members (Lavasoft, Computer Associates, Webroot and Aluria) pulled out of the consortium, reportedly because of the group's inability to create a set of standards and code of ethics. Some of those departing members also indicated that COAST had begun to certify -- for a fee -- certain publishers that were known by many anti-spyware firms as purveyors of spyware. Yes, my friends, allegedly the fox was watching the henhouse!

So COAST basically disintegrated and many say that was a good thing! The good news is this: in early 2005 the Center for Democracy and Technology (CDT) convened a meeting with industry anti-spyware leaders to discuss issues facing the anti-spyware industry, and the Anti-Spyware Coalition (ASC) was then formed. The new group includes the original COAST founders as well as consumer groups, academia and just about every big name in computing, including all the top anti-virus players.

Spyware has previously been defined as a computer program that, surreptitiously, gathers information without the knowledge of the user and may port that data back to another entity or as software that asserts control over a computer without the user's knowledge.

One of the first tasks that ASC did was to create a formal definition of spyware and other potentially unwanted technologies. Their description is this: Technologies deployed without appropriate user consent and/or implemented in ways that impair user control over the following: (1) material changes that affect their user experience, privacy or system security; (2) use of their system resources, including the programs that are installed on their computers; and/or (3) collection, use and distribution of their personal or other sensitive information.

Another task of ASC was to create a set of common industry guidelines for publishers who allege that their software has been improperly flagged as spyware. This is an important step because, well frankly, sometimes anti-spyware vendors make mistakes and it can be quite costly for a publisher to be flagged as a bad guy! The guidelines are just that -- guidelines -- ASC does not independently resolve the disputes but has framed recommended best practices for anti-spyware software publishers. Bravo!

ASC also has published a glossary of terms commonly used in discussions about spyware and a list of anti-spyware Safety Tips to provide basic guidelines for consumers to protect themselves and their computers. They recommend that users keep their security patches up to date, download programs only from websites they trust, read the fine print in license agreements, not be tricked into clicking anything on a popup window, beware of free software and use tools to detect and delete spyware.

In an effort to fight spyware, three U.S. Senators have introduced a bill that would attempt to combat this plague by making it a crime to offer this type of spying computer program. The bill (S.2145) is entitled "Software Principles Yielding Better Levels of Consumer Knowledge Act," or the "SPY BLOCK Act." Cute name!

If passed it will outlaw software that, without explicit user permission, installs itself or other programs, reconfigures settings (or redirects the user), captures personal information or keeps track of visited websites. And, this is the best part: the software must disclose in clear language each aspect of what the program will do to your computer and with your information and must obtain your consent to do so.

In addition, the software must be easily uninstallable through the "add and remove programs" feature (in Windows OS) or other standard methods. Spyware programs are so notoriously difficult to remove from infected systems they are often referred to as parasitic. It appears the proposed legislation is lingering in committee. So, we'll have to wait to see what happens to publishers of "unwanted technology" if SPY BLOCK ever becomes law.

According to a recent study by the Pew Internet & American Life Project, nine out of ten Internet users say they have adjusted their online behavior out of fear of falling victim to software intrusions and about 59 million American adults, say they have had spyware or adware on their home computer. Additionally the project reports that 68% of home Internet users or about 93 million American adults have experienced at least one computer problem in the past year that was consistent with problems caused by spyware or viruses.

While those stats are discouraging, the report also indicated that 25% of Internet users say they have stopped downloading music or video files from peer-to-peer networks to avoid getting unwanted software programs on their computers. Perhaps there is some silver lining to the epidemic!

The report also indicated that there is a significant gap between people's perceptions and the reality of what is on their computers. An October 2004 study by AOL and the National Cyber Security Alliance reported that 53% of respondents said they had spyware or adware on their computers, but a scan revealed that 80% of them actually had such programs installed. Yikes!

That same study found an average of 93 spyware applications on users' computers. The thought of nearly a hundred spyware applications per computer just blows my mind. Experts conservatively estimate that for every 1,000 users in an organization, the costs of fixing spyware-related problems are $83,000 per year. Forrester Research released "AntiSpyware Adoption In 2005," which indicated that 39% of respondents, dubbed "technology decision makers," did not know the percentage of desktops infected with spyware in their organizations and 56% were unsure of what percentage of help desk calls were related to spyware issues. However, the Forrester report indicates that, on average, 7% of all help desk calls are made in response to spyware infections. Considering how much time it usually takes to resolve a serious spyware infection, that number is huge.

I have been infected a couple of times on my home computer -- ahem -- when someone other than me was using it. It takes days to "fix" the problem. In fact, I now just re-image my PC because it is easier than trying to find the culprit(s) and eliminate them. I simply keep a backup of my data on an ongoing basis so that I don't have to deal with the potential loss of it.

Meanwhile, the need to fight spyware will push anti-spyware revenues from $12 million in 2003 to an estimated $305 million in 2005. Hum ... with all that revenue to be had, how motivated could anti-spyware publishers be to find a cure?

Folks, this insidious problem is not going away any time soon. The best we can do is to alter our cyber-behavior and keep our anti-spyware and anti-virus software up to date. Remember, my little chickens, it may not be Big Brother watching you, but somebody probably is -- let's hope it isn't a fox! Safe surfing.




Donna Johnson Edwards is the Director of Consulting for Tenax, Inc. Established in the U.S. in 2002, Tenax provides IT compliance certifications, training and targeted consulting services. For further information on IT Compliance [http://www.tenaxcorporation.com] and Software Asset Management [http://www.tenaxcorporation.com] please visit the Tenax Corporation website.