Group pitches anti-spyware guidelines

By Alorie Gilbert, CNET News.com
Friday, October 28, 2005 10:56 AM

The Anti-Spyware Coalition offered up standard guidelines on Thursday for detecting, rating and protecting against unwelcome programs that have plagued Internet users in recent years.

The group, composed of software companies and consumer advocates, also finalized its definition of spyware, veering little from

The coalition defines spyware and other potentially unwanted technologies as programs deployed without sufficient user consent or impair user control over any of the following: privacy, system security and user experience; use of their system resources; or collection, use and distribution of personal information.

Spyware and adware have become widely despised for sneaky distribution tactics, unauthorized data gathering, the eating-up of computer processing power and other annoyances. Although adware makers say there are legitimate uses for their programs, an entire anti-spyware market has been spawned to combat the stuff.

Yet attempts to define spyware and create guidelines are also controversial. Critics fear spyware makers will use the guidelines to avoid getting caught by blocking tools, but will find ways to continue bad behaviors.

The Anti-Spyware Coalition acknowledged the concern in one of the documents it published on Thursday. "This is a valid concern that ASC discussed in detail," the group said in a document summarizing public comments it had received. "However, it is ASC's contention that the current 'Definitions' has been written with the problem in mind and leaves plenty of room for individual anti-spyware software companies to decide what fits their criteria for detection."

In its proposed spyware detection guidelines, the group said anti-spyware companies should focus on how the programs in question behave and rate them on risk. Among the behaviors the group considers high-risk are programs that replicate themselves via mass e-mails, worms, viruses and those that install themselves without a user's permission or knowledge, via a security exploit, for example.

Other high-risk programs are those that intercept e-mail or instant messages without user consent, transmit personally identifiable data, or change security settings. Using tracking cookies to collect information or running programs automatically without explicit user consent are considered low risk, according the guidelines.

The Anti-Spyware Coalition is collecting public comment on the document until Nov. 27 and plans to release a final version next year. The group said it expects the guidelines to set the stage for "best practices" for the anti-spyware industry.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Cost and graphics concerns delay a VDI project

Tech Management

Virtual desktops are a serious paradigm shift and Scott Lowe is taking it in a slow and measured way. In this article, he provides an update on ongoing VDI efforts at Westminster College.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web