Home > Security News > Antispyware legislation gets tepid reviews
Security News:
EMAIL THIS

Antispyware legislation gets tepid reviews

By Bill Brenner, Senior News Writer
11 Jul 2007 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

The problem here is that the federal government doesn't know how to find people and then track their behavior.
Jeffrey Jarzabek,
IT director, Matocha Associates

Congress is debating three bills that would protect citizens from spyware, but some IT professionals doubt whether the legislation can successfully address the problem.

The measures are generally designed to criminalize software that takes control of computers to collect personal data or display ads without the PC user's consent. The legislation would also bolster the ability of prosecutors to go after spyware pushers. The three bills are the Internet Spyware Prevention Act of 2007 (I-SPY Act) and Securely Protect Yourself Against Cyber Trespass Act (SPY ACT), both of which passed the House this past spring; and the Counter Spy Act of 2007, introduced last month in the Senate.

Jeffrey Jarzabek, IT director for Matocha Associates, an Oakbrook Terrace, Ill., firm specializing in architecture, engineering, general contracting and construction management, has doubts that any of these bills would be helpful. He said the latest efforts remind him of the CAN-SPAM Act, which has been largely panned as a failure.

"Laws only work when they can be enforced," he said in an email exchange. "The problem here is that the federal government doesn't know how to find people and then track their behavior. Just like the CAN-SPAM Act, if you cannot find the culprits, what can you do?"

Antispyware:
House passes antispyware bill: The antispyware bill passed by the U.S. House in January is opposed by software makers who say the provisions would penalize those who distribute legitimate software and Web sites.

IT pros give new antispyware guidelines a mixed review: The Anti-Spyware Coalition's "best practices" documents will aid the spyware fight, IT pros say. But some wanted a better threat-rating system and more of the corporate IT viewpoint.

Arkansas Sen. Mark Pryor, who introduced the Counter Spy Act in the Senate, said in a statement that spyware is a "serious infringement upon basic levels of privacy and security" and that there are very few, if any, legitimate reasons to launch it. He said his bill would prohibit the covert embedding of spyware on a user's computer without first obtaining their consent. The bill also requires the Federal Trade Commission to enforce the law as if a violation was an unfair or deceptive practice. The agency would have authority to bring a civil action against the perpetrators and criminal penalties could be imposed.

"My bill protects consumers' right to privacy and their confidence in using the Internet," Pryor said. "The industry has failed in self-regulating. It's time to step in and enact serious consequences against those who use this invasive and deceptive practice."

Bob Wilcox, vice president of corporate information security at Brookfield, Wis.-based Fiserv, is also doubtful that legislation would help crack down on spyware.

"My overall reaction is, who are we going to prosecute?" he said in an email exchange. "While it is a noble notion, the criminals are difficult to identify and without that ability, the thought that [the SPY ACT] will slow down malware, spyware, botnets or ID theft is a bit of a stretch. I don't see it being instrumental in the reduction of such activities."

Despite this skepticism, some see value in legislation if it's used to fight malware in addition to getting organizations to set sound corporate user policies and put in place tougher IT security tools.

"The use of regulations to deter malware is a piece in the overall pie," said Jeff Bardin, an IT professional working for a New England-based financial services firm. "Regulations alone can't remove malware, nor do I believe that it will ever be removed. [But] regulations in combination with technical controls at every potential layer of the Internet" can make a difference.

Bardin said regulations should be used to hold telecom providers more accountable for security, "forcing them to deliver clean pipes three miles out instead of my having to pay for dirty pipes as well as tools to clean the utility at my front door."



Tags: Information Security Laws, Investigations and EthicsMalware, Viruses, Trojans and SpywareVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Information Security Laws, Investigations and Ethics
Melissa Hathaway urges more cooperation, government attention to cybersecurity
Cybersecurity czar candidate questions clout of new position
DHS fills National Cybersecurity Center post
FTC shutters rogue ISP for hosting malicious content, botnets
Experts optimistic of Obama cybersecurity plan
WH cybersecurity plan needs private sector guidance
Obama announces creation of cybersecurity coordinator position
Cybersecurity Act of 2009: Power grab, or necessary step?
Face-off: Who should be in charge of cybersecurity?
Feds should get private sector advice on cybersecurity

Malware, Viruses, Trojans and Spyware
Malware in Google attacks uses spaghetti code
Preparing for future security threats, evolving malware
Facebook attacks prompt investments in social networking security
Another PDF attack targets Adobe zero-day vulnerability
Security report finds rise in banking Trojans, adware, fewer viruses
How to prevent rogue antivirus programs in the enterprise
How to stop keylogging malware with more than basic antivirus software, firewalls
Conficker-infected machines now number 7 million, Shadowserver finds
FBI estimates rogue antivirus losses exceeding $150 million
Security researchers continue hunt for Conficker authors

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
CALEA  (SearchSecurity.com)
cyberstalking  (SearchSecurity.com)
FERPA  (SearchSecurity.com)
HSPD-7  (SearchSecurity.com)
I-SPY Act  (SearchSecurity.com)
Information Awareness Office  (SearchSecurity.com)
intelligence community  (SearchSecurity.com)
lawful interception  (SearchSecurity.com)
lifestyle polygraph  (SearchSecurity.com)
vulnerability disclosure  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts