Coalition Posts Spyware Risk Guidelines

By Nate Mook | Published October 27, 2005, 1:27 PM

The Anti-Spyware Coalition published new guidelines on Thursday designed to help consumers assess whether or not a software product is considered spyware. The group also revised an earlier draft of definitions that differentiate between acceptable and invasive advertising.

With 43 percent of Internet users reporting they have been infected with spyware, tools to detect and remove the malicious applications have become a prerequisite for PC users. But much confusion still exists on what constitutes spyware and adware, which has led to improper classification and even lawsuits.

The Anti-Spyware Coalition, headed by the Center for Democracy & Technology with support from industry giants AOL, Earthlink, Microsoft, and Yahoo is attempting to set the record straight with a series of guidelines. Along with educating consumers, anti-spyware software vendors could avoid legal attacks from ad companies who claim their software is unfairly targeted.

In the new "Risk Model" guidelines, the coalition ranks various practices common in spyware and adware with risk levels. Installing a program without a user's permission, intercepting instant messaging and e-mail, and displaying ads while hiding the source program are all considered "high risk."

Medium risk practices include changing a user's homepage set in their Web browser, while collecting data on consumers by using cookies is of low risk. Rankings are also assigned to consent, with manual downloading receiving high marks while complicated EULAs rated low.

"It is important to note that with proper notice, consent, and control some of these same technologies can provide important benefits," the guidelines acknowledge. "Tracking can be used for personalization, advertisement display can subsidize the cost of a product or service, monitoring tools can help parents keep their children safe online, and remote control features can allow support professionals to remotely diagnose problems."

In addition to these guidelines, the Anti-Spyware Coalition updated an earlier list of definitions, which received over 400 public comments following its publication in July. Little changed, however, in the final revision.

The group defined "potential threats" -- a term that includes spyware, adware, cookies and hijackers -- as programs that: impair users' control over their systems, including privacy and security; impair the use of system resources, including what programs are installed on their computers; or collect, use and distribute personal or otherwise sensitive information.

Public comments will be accepted on the draft Risk Model guidelines until November 27, the coalition said.

Comments

View comments by with a score of at least

Spyware is a program that tracks what you do. Period. Adware is a program that displays ads outside of the target program.

Opera's way of displaying ads (it not longer does through :P) is preferable to Kazaa's way, for example.

Anything that installs into Firefox or IE without me requesting it is spyware. Anything that fits into another program, without me requesting it, is spyware. All the above should be illegal, not semilegal.

Score: 0

|

Well let me just say that i do agree with rijp has stated.

It is well documented that adware is spyware when these companies want to see where you got so they can blast you with ads on those website you go to if they are not there.

In fact this is the reason i stay with Lavasoft product only because they created that committee and they are the ones that saw it being taken over by the marketing and ad agencies and being told to accept certain ads because they were members to that committee. When Lavasoft left that committee it made all those companies on their list of and that was several years ago.

I have looked at the McAfee and Symantec versions of antispyware program and they leave so many holes that it is as useless as something on a bull.

I being an earthlink user have issues with them as they are operating like AOL in there need to display ads on their sites. Of course they support the use of Symantec products and I have seent the factor of ads increase on them so much that I am glad I never use their products.

Everyone understands the idea of advertising but the concept of allowing even cookies to Betanews is no different in this respect becasue they too are monitoring you to display ads.

Thank God for Firefox and Adblock and RIP extensions Spybot and Ad-aware and blocking many of the marketing and ad agency in my firewall it takes longer but then they don't get on the machine nor are they allowed to contact their website. I am looking onto the Host file to stop them even further.

This has nothing to do with politics but money. When a company wants to advertise the advertising company now forces them to exclude them from any antispyware programs or they have to pay a much higher price for their service.

I have been doing my best to teach my relatives , friends and my fellow computers friends of nearly 30 years on this.

Score: 0

|

ha, i don't need any coalitions to tell me what spyware is. Why tell me what it is, so that they can push on me the stuff they deem not to be a threat? With all the spyware/adware venders trying to act legit these days, this smells of wolf in sheeps clothing. I define spyware, with my own "coalition" of cells called a brain. It's not perfect but i trust it's motives more then that of big corps.

Score: 0

|

The point is... to create a formal definition of it so that anti-spyware companies won't have to guess at what should be deemed spyware or not. It should also act as a sort of mild-policing of the makers of spyware to let them know they are in the red zone.

Up until now (well actually still now), it's just been one side saying, "You guys are spyware!" and the other side saying, "No we're not!" "Yes you are!" "No we're not!" etc...

Now there will be a formal definition to use as a reference.

Score: 0

|

SPYWARE is a invasion of PRIVATE PROPERTY

ITS MY COMPUTER NOT YOURS TO PLACE ANYTHING ON IT PERIOD

STAY OUT

Score: 0

|

ANY SPYWARE IS BAD no matter what it is.

It Infects Clean Computers, does harm,and is not right to put any infections or spy traces in anyone's computer its like total private property. You didn't buy my computer I DID.

Score: 0

|

I don't care what definition they deem spyware, spyware is ANY program that infringes on a users ability to function. There is no "acceptable" limit to this type of activity. If a program STARTS harmless and BECOMES a nuisance, its spyware. Period. The word "spyware" may have become an all inclusive term to blanket cover programs that do other things, but maybe the term should be coined "nuisanceware". Either way, investigating software in add-remove programs is very revealing. People have items that they didn't put there, nor do they want it.

AOL could be deemed spyware/nuisance if you have multiple versions, and the removal program only removes "known" versions, and previous versions persist, THAT's spyware.

If you have programs that get installed ALONG with a acceptable or wanted program, then THAT program should be termed SPYWARE. Programs that facilitate other programs infiltration is spyware.

If you commit a crime, and you do it with someone, that someone is guilty by association of you are found guilty. Same with software, guilty by reason of affiliation. That's spyware!

What I don't want is a bunch of programs on my machine that fill it up, and I didn't SPECIFICALLY put it there, it shouldn't be "ignored" simply because some damn committee doesn't think its harmful. Its harmful, if I say its harmful, I don't give a damn. If AOL won't remove from my system, after the deletion routine is finished, and AOL continues to infiltrate and infringe or interfere with proper operation of my system, that's SPYWARE! Even if it wasn't to begin with, it is now, and should be removed.

OK, that's a drastic measure, but the old addage, if it walks like a duck, looks like a duck and acts like a duck, it MUST be a duck!!!!! It can't be anything else.

If companies make programs that APPEAR to retain spyware like activity or programs simulate spyware activity, then maybe there is a problem there.

This is a prime example of not including the people this ruling will affect. The people. We use it, we should be able to vote on the outcome, but no, instead they leave it some committee. If a few months from now, I have sypware I can't remove and my anti-spyware is updated to ignore it, I am going to be pissed, and there will be hell to pay.

Score: 0

|

Well said

Score: 0

|

PDC 2009: What have we learned this week?

There was the freebie that no one will forget, the heebie-jeebies courtesy of Scott Guthrie, and a teensy bit clearer picture of how this cloud thingie should work.

Live report: Will Google Chrome OS change Linux?

The mysteries of just what Chrome OS is, and how much of an operating system it truly is, may be resolved today.

PDC 2009: Microsoft cares about Web browser performance

The effort to give users of the world's dominant Web browser the impression of quality, is a personal one for the man who leads that battle.

Nokia re-affirms its commitment to Symbian, sort of

Maemo won't necessarily be replacing Symbian in the Nokia N-Series, but that's definitely a place where it will be found.

E-book readers will be in short supply this holiday season

E-readers are hot this year, and a lot of compelling new products have been released, but are there enough electrophoretic displays to go around?

Sony looks to finally open a single storefront for downloads

Sony has had many different download portals for movies, music, e-books, and games, and now it's looking to make a single shop for all of it.

Tuning out the tablet: Time to give the endless speculation a rest

Wide Angle Zoom: Wishing and hoping and thinking and praying....won't put an iTablet on the market.

Five improvements for IT managers in 2010

If businesses are to improve their efficiency for next year, they need to stop and reassess the basic tenets of their job.

AOL's spinoff from Time Warner to shed 2,500 jobs

As AOL moves toward become an independent company again, it will cut nearly a third of its workforce.

Gartner: SMS-based money transfer will be bigger than mobile browsing, search

Gartner issues its predictions for the 10 things our phones will be doing in 2012.

Don't forget to upgrade to Firefox 3.6 beta 3 today

Mozilla has released the latest beta its Firefox 3.6 browser software, just over one week after beta 2.