ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Anti-Spyware Coalition to define terms

Joris Evers ZDNet.co.uk

Published: 03 Jun 2005 13:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Anti-spyware software makers are taking another shot at creating a definition of spyware, this time with help from consumer organizations.

A new group, tentatively named the Anti-Spyware Coalition, plans to publish proposed guidelines later this summer that define spyware, best practices for desktop software development, and a common lexicon, people involved with the group told ZDNet UK's sister site CNET News.com.

Debate has gone on for years over spyware and adware, with manufacturers defending some of these applications as legitimate marketing tools. The terms are slippery, frequently used to apply both to the information-thieving software and the often-annoying advertising tools bundled with free software programs.

For ZDNet UK's glossary of spyware terms and to find the latest spyware removal tools, see our Spyware special report.

Both spyware and adware can impact PC performance. They are often surreptitiously installed on computers to gather information about people that is used for advertising or provided to other interested parties. The market for tools to remove the unwanted software is booming.

If the new coalition succeeds, its work could clear up confusion over spyware and adware. Also, the group's work could help software makers and legitimate advertisers improve their products.

While specific examples of legitimate and illegitimate behavior aren't hard to pinpoint, identifying clear categories has proved difficult. "The key benefit is getting a handle on the nature of the problem, (getting) industrywide acceptance on what is accepted and what is not," Fewer said.

In an example of why standard definitions are needed, Computer Associates International earlier this year temporarily removed the Gator adware program from the spyware detected by its PestPatrol program. It has since been put back on CA's list of spyware, and the company has changed the way it deals with appeals from spyware makers.

Drafts of the coalition's guidelines are finished and should be published by the end of the summer, when they will be open to public comments, said Ari Schwartz, an associate director at the Center for Democracy and Technology.

The Anti-Spyware Coalition counts software makers, online businesses and security providers among its members. Watchdog groups are taking part too, but they have an associate role.

The Anti-Spyware Coalition is still in its formative stages, with all the parties involved meeting for the first time last week at the CDT offices, Schwartz said. There is commitment to form the coalition, but the group's name has not been formally announced yet, he said. The CDT, a Washington-based public advocacy group, is running the coalition.

Ultimately, according to Fewer, judging whether software is spyware comes down to three components: notice, consent and control. During installation of an application, it should be clear to the user what the tool does. The user should also have to give permission for installation and should be able to remove the application. In many cases, spyware and adware don't meet those basic rules, Fewer said.

The lack of a common approach to defining the unwanted programs has resulted in the anti-spyware tools that flag perceived threats in different ways. Sometimes one anti-spyware tool will identify an application as spyware or adware, while another won't.

"There is much confusion over what spyware is and what it is not. And it starts with the fact that there is no definition," said Tori Case, director of security management at CA.

"What one person calls spyware, another calls adware, another calls surveillance software and yet another says it is not anything. That has

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
143 out of 288 people found this useful


Full Talkback thread

1 comment

  1. The "test" for deciding the "nature" of a software... PRAVEEN DALAL

Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

QA (Quality Assurance) Auditor

The role involves: + auditing, both internally and externally, to ISO 13485 guidelines + heavy involvement in the management and running of Quality ...

Financial Services - Risk and Compliance

Specific Technical Experience The individual will need change programme and systems implementation experience in a selection of the following areas: ...

PHP Manchester-The definition of creativity! 30000

Skills: PHP, MySQL SQL Server. A PHP Developer is currently sought after to join a PHP Development team to continue to develop the web systems using ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation