Group: AOL 9.0 Uses Malware Tactics

By Ed Oswald | Published August 29, 2006, 3:10 PM

AOL is being accused of using malware-like tactics to install software unbeknownst to users when they install AOL 9.0, the company's latest version of its online service software. The charge was made by StopBadware.org, a coalition between Berkman Center for Internet and Society at Harvard Law School and the Oxford Internet Institute of Oxford University.

"AOL plainly does not belong in the same category as the all-too-prevalent, garden variety badware providers. But the free version of AOL 9.0 that we tested, in our view, does not live up to the company's rich legacy," Berkman Center executive director John Palfrey said.

StopBadware.org found eight separate instances where AOL 9.0 used questionable methods to either install software or make changes to a user's computer. Among them is additional software installed without permission including the AOL Toolbar to Internet Explorer, forced actions during installation, the addition of buttons and favorites to IE, and the failure to uninstall software completely.

In its response to the StopBadware charges, AOL explained that its failure to uninstall completely was a known flaw in the uninstaller in which two executable files remain, even after the computer is restarted. The company was taking steps to address it, including issuing a patch to remedy the problem, it said.

It should be noted that AOL 9.0 has been available since 2003, with the latest update coming in November 2004.

AOL was also taking steps to address other issues brought up by the report, it told the non-profit group. Palfrey said the group was very impressed by AOL's quick response and its commitment to address problems that StopBadware found objectionable.

"What we are calling on AOL to do today is to honor that trust by telling users exactly what they're putting on their computers, give users an easy way to opt out of having so many programs installed and running after download, and ensure that users can uninstall all the applications they don't want on their computers," he said.

Comments

AOL is dead in the water!

---------------------------------------------
Quite the contrary. They're doing quite nicely.

Score: 0

|

AOL is dead in the water!

Score: 0

|

Yeah I have noticed this ever since 9.0 came out however long ago that was. talk about annoying, you have to go to add/remove and get rid of it all. Why is the sol screen savor installed by default? Do they think people are stupid and won't be able to do a custom install? Let's just assume all our users are dumb, which seems to be true. We can't offer anything that is as confusing as a custom install.

Also I love the fact that after you tell it to create a new account, you can't back out of it. You have to ctrl alt del and end task to get rid of aol and retry.

These are just the many reasons why aol is going downhill fast. They suck, what more can you say. Also the free version of aol doesn't have chat rooms anymore, want to tell me the point of aol now then? making internet buddies was the only reason I ever used it and well, it is completely useless now.

Score: 0

|

No surprise to me. Had to have a friend rebuild my system a year or so ago. Told me then it was because of all the stuff AOL had installed.

Score: 0

|

...

Who would've thought that AOL would
do something like ~this~ ?

...

The Computer Rodent

...

Score: 0

|

It would seem you love to spam your rodent droppings via signature around here.

It would also seem I'd rather troll than be of any use tonight. ;)

Score: 0

|

"The uninstall flaw relates to the November 2004 upgrade"

Since BetaNews has experienced a bug disallowing replies and edits (funny how that is not news!!!) I am replying here...

So the uninstall flaw is from November 2004! And they are responding swiftly now, almost 23 months later instead of, I retract my comment. They are indeed responding VERY quickly to a KNOWN bug!!

Pardon me as I saddle my very trustworthy snail "Lightning" and ride off in swift pursuit of a solution!

...23 months, 35+ months...who cares!? After EITHER delay, the point has been MISSED!

Score: 0

|

Replies work just fine. Go "fix your sh-it" as we say around here. :)

Score: 0

|

Uninstall flaws are not news. Most uninstall routines are not rigorously tested because the company is either going to be arrogant enough to believe you'd never want to uninstall their product, or apathetic enough to not care what state your computer is left in when you DO.

This is why I like to use NSIS in my prjects, the uninstaller is generated, for the most part, automatically with minimal scripting. Less room for error.

Score: 0

|

Well, there's SOMETHING wrong. If I click on Post Reply, I get the following error message:

Error 404: Not Found
The requested URL /article//1156876704?do=reply&reply_to=396291 was not found.

Not the DOUBLE slash after the 'article' folder.

I had to manually edit that slash out so I can reply.

However, I then reloaded the page and now the Post works fine. So I'm a little baffled as to what happened and why.

Is it possible that there was some javascript being used and an incorrect version was in my cache? I'm using Firefox on Mac OS X

Score: 0

|

Nope i'm using IE7 on XP and am getting the same screwy error as you - sometimes it works tho.....weird.

Score: 0

|

I tested this in IE, Opera, and Firefox. (I didn't test K-meleon or Mozilla since if it's broke in firefox...)

Get the error frequently in all browsers. Closing the tab / window / etc and going back tot he topic via the main page fixes it quite often for me, but sometimes it takes several attempts.

Waiting works well also. If you get it, wait 10 minutes. If your comment was *really* that important....try again. ;)

Score: 0

|

Let me go v e r y s l o w l y this time for those not quite so swooft here.

First, there HAS been an intermittent site problem regarding replying and editing. If you are ignorant of it - well, you are ignorant and obviously your sh!t is working, as you represent it exceptionally well.

Secondly, my point was and still is, whether it is ~2 years or ~3 years, taking that long to respond to a problem that has been known for that long (as some have pointed out - ONLY since Nov 2004!!!) is TOO freaking long!

Score: 0

|

Or just edit the URL to delete one of the slashes

Score: 0

|

D'oh!

To tell the truth, I never even glanced at the URL. Feeling a bit lazy today...

Heh (Hey fewt!)

Score: 0

|

AOL CAN SUCK MY LEFT NUT.

Score: -1

|

I for one am going on the record to say I LOVE USING AOL 9.0. It's fast, secure, and full of amazing features. So what if it doesn't uninstall everything and leaves your computer slow as a** - that's what formats are for. You guys are just a bunch of whiners that can't handle how amazing the AOL experience truly is.

. .
. .
. .
. .
. .
. .
. .
. .
. .
Note - I'm just playin' AOL is the biggest POS ever created. If you use this software i'm going to run over your dog.

Score: 0

|

So you are very plain; okay.

I realize you meant playin'.

Score: 0

|

LOL slow day?

I fixed it of course ;)

Score: 0

|

Thus making his comment completely irrelevant, you insensitive jerk!

;P

How'd you like it if I made all of your comments irrelevant?

...oh, wait...

*grins*

Score: 0

|

Is this actually something recently posted?

I am confused how this couldn't have been reported till 2 years later.

Score: 0

|

"AOL explained that its failure to uninstall completely was a KNOWN FLAW in the uninstaller in which two executable files remain, even after the computer is restarted. The company was taking steps to address it...

"It should be noted that AOL 9.0 has been available SINCE 2003, with the latest update coming in November 2004."

"...Palfrey said the group was very impressed by AOL's QUICK RESPONSE and its commitment to address problems..."

If the version has been out since 2003, and the flaws have been known, and they are being so quick to respond to them...how does one respond in a slow manner?

Score: 0

|

The uninstall flaw relates to the November 2004 upgrade

Score: 0

|

I'm shocked! Shocked to find "badware" in AOL! ("Here are your winnings, sir.") Sorry, kbsoftware. I couldn't resist the "Casablanca" paraphrase.

Jeesh, I cannot believe this is being reported only now. I've been hand-cleaning registries after AOL uninstallations for years. That someone of note has only just noticed is the truly shocking news here.

So let's see. AOL is busted for not canceling users' accounts. AOL is [finally] "busted" for malware. AOL is busted for releasing users' search data, enabling one individual to actually be identified. No wonder AOL is going bust! And, it's no wonder they're now having to give their junk away.

Score: 0

|

AOL puts bad things on your computer........ This is news?

Score: 0

|

This is rediculous. I just read the report and i am just glad that i don't use AOL software. I hope AOL fixes these problems becuase that is just dishonest.

Score: 0

|

I'm shocked, I'm surprised, I can't believe it
Note the sarcasm :)

AOL sucks worst then a $5 hooker.

But at least if you have enough of the AOL cd's you can build a lamp with them
http://www.teamhackaday....um/viewtopic.php?t=1551

So at least they were useful for something lol

Score: 0

|

I agree 100%. The success AOL had once upon a time just went to their heads!

Score: 0

|

Hmm... I have actually had a damn nice suck from a $5 wh***!

I think AOL sucks worse than a 50¢ wh***!!

Score: 0

|

AOL sucks and has sucked since the mid 90's. If you still use it, you should be ashamed.

Score: 0

|

AOL sucks and has sucked since the mid 90's. If you still use it, you should be ashamed.
-----------------------------------------------
Please tell us why? I bet you can't put up one cogent argument. Saying anything sucks doesen't say anything intelligent much less worthwhile. Proud AOL subscriber here.

Score: 0

|

I think we should use "crapware" to refer to software which doesn't actually have malicious intent but throws a bunch of crap on your system either carelessly or thoughtlessly. Although AOL should be slapped silly, this isn't a criminal act. Save "malware" for the criminals who are trying to steal your identity.

Score: 0

|

Spiked: They didn't use "malware" the name of the coalition is "stopBadware.org" and I think we can all agree that AOL is BAD, and not just because of the flaws mentioned in the article.

The only thing I have found worse than a machine installed with AOL, is one that has AOL and RealPlayer installed. They should just include the format command in the install package to save people time.

Also, I agree, responding to a known issue from November 2004 now is NOT a quick response. What this does show is that legit companies (did I just call AOL legit? Sorry.) will react to the negative publicity that is generated from this stuff. Unfortunately there are a LOT more fly by night operations who couldn't give a crap, and thus are installing this s**t on people's machines in the first place.

Score: 0

|

Can Linux do BitLocker better than Windows 7?

Betanews kicks off a new series with a look at how the Linux operating system's FDE stacks up against BitLocker, the Windows feature that today commands a $120 premium.

Firefox 3.5: The need for speed

This has been the big payoff week for Mozilla's developers, who worked overtime to squeeze out the last drop of performance from their new JavaScript engine.

'GeoHot' gets a shower, cleans up nice, reveals new iPhone 3G S jailbreak

Either puberty has been very kind to the author of the new 'Purple Ra1n' jailbreak tool, or George Hotz may also have some adequate Photoshop skills.

What's Next: Obama gives 'Einstein' the go-ahead, while China gives 'Green Dam' a thumbs-down

Plus: If you put up a Web site and name it after you and you're a federal judge, you might not want a bunch of weird nudity hanging around on it.

Why would Windows 7 customers spend $120 more for BitLocker?

For pre-orders from now until July 11, Microsoft is offering the Windows 7 Professional SKU for a very steep discount. So why invest in Ultimate?

Geeks vs. journalists: A tale of two worldviews

Recovery with Angela Gunn Why geeks think most mainstream journalism is flaky, and why the mainstream thinks geeks are trying to kill them. (They're both right.)

Fire in downtown Seattle data center knocks out businesses, online services

Small fire has global impact with payment centers, city services down.

Hybrid satellite cell phones aren't far off

The first satellite in Terrestar's hybrid cellular/satellite phone network has been launched.

SMS could be a critical iPhone vulnerability, says white-hat hacker

Mac hacker Charlie Miller knows how to get into your iPhone.

Will Oracle's Java-based Fusion middleware 'fuse' with Java?

Now that Oracle has acquired Sun Microsystems, Java developers and supporters are wondering when Oracle will formally welcome Java into the family.

All together now: iPhone and Palm Pre, likely to both grace O2's UK portfolio

European wireless network operator O2 has reportedly reached a deal to exclusively carry the Palm Pre in the UK. O2,...

Vista's dead: Microsoft kills an OS and no one cares

Carmi Levy: Wide Angle Zoom Can you kill an operating system? Microsoft is about to find out.

Kantaris Media Player 0.5.7

July 3 - 5:34 PM ET

Wine 1.1.25

July 3 - 5:30 PM ET

ChrisTV Online! Free 4.00

July 3 - 5:22 PM ET

glu 1.0.19 RC1

July 3 - 5:11 PM ET

Website-Watcher 5.1.0 Beta 10

July 3 - 1:20 PM ET