ftc

ftc

Senate hears testimony on spyware

A U.S. Senate hearing was scheduled today to hear testimony on the issue of spyware, with the conversation focused primarily around the "Counter Spy Act of 2007":http://www.govtrack.us/congress/billtext.xpd?bill=s110-1625, proposed last year by Arkansas Senator Mark Pryor.

The bill provides some very specific definitions of prohibited behavior and grants explicit power to the Federal Trade Commission (FTC) to enforce compliance. It also increases the penalties available to the FTC.

Last year, there was "some":http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1263... "discussion":http://www.infoworld.com/article/07/06/28/Policy-experts-split-on-spywar... of this legislation and similar laws that passed the House. StopBadware.org even weighed in with "some":http://blogs.stopbadware.org/articles/2007/05/24/kudos-to-congress-house... "thoughts":http://blogs.stopbadware.org/articles/2007/06/08/more-spyware-regulation... of its own.

Taking a current look at the Counter Spy Act raises a few questions in my mind:

1. Does the FTC need explicit legislation granting it additional authority? As of last year, the "FTC said no":http://www.cio.com.au/index.php/id;1239574182;pp;1;fp;4;fpid;1935:

bq. Tracy Shapiro, an attorney for the FTC's Advertising Practices Division, said the federal watchdog would like to see legislation that increases civil penalties against cyber-criminals, but it feels that the new bills could eventually get in its way in bringing accused spyware companies to trial. Section V of the Federal Trade Commission Act remains broad enough to provide for continued prosecution of the most significant offenders, including spyware providers, she said.

2. StopBadware.org has changed its "badware guidelines":http://blogs.stopbadware.org/home/guidelines multiple times in just two and a half years, due to ongoing changes in technology and badware practices, as well as an ongoing desire to make sure that we're "getting it right." If legislation defines spyware specifically, what happens when a new piece of spyware falls outside that definition?

3. The Counter Spy Act appears to explicitly allow (or at least protect from FTC action under this law) unauthorized installation of software on a user's computer, so long as that software doesn't engage specifically in spying or certain advertising behavior. If the government is going to have enforcement authority, shouldn't it have more discretion?

4. Is stealing social security or account numbers as they're typed and sending them to a third party covered by this legislation? If so, I can't figure out how. One provision protects against wholesale keylogging (i.e., capturing every keystroke) and another protects against stealing private information "from the hard drive or other storage medium." Unless I'm missing it, I don't see anything about selective capturing of information via keylogging. This helps illustrated point #2.

In general, my opinion is that legislation that grants authority and resources to the government to fight spyware is helpful, but doing it right is really difficult. The FTC has already established some expertise and made use of existing legislation to go after spyware distributors. Maybe a simpler solution, then, would be to provide more funding and perhaps greater penalties without seeking to define a constantly-moving target.

_Note: This post has been edited to correct a factual error in the name of the legislation to which Tracy Shapiro of the FTC referred._

FTC forces pornographic ad pusher to clean up

Posted on December 7, 2007 - 14:55 by egeorge

The FTC this week reached a settlement with the owners of AdultFriendFinder.com over misuse of pornographic pop-up ads. The ads covered users' full screens and showed pornographic content to users of search engines, including many who had never requested an explicit site. According to the FTC's statement, some of the ads were distributed through badware.

As part of the settlement, the company behind AdultFriendFinder.com has committed to require consent before showing ads or sexual content. The company must also weed out any of its affiliates who don't do the same, making it harder for them to pass the buck if there is future abuse.

The FTC's statement says the practice of displaying explicit ads without consent is a violation of the FTC Act, but does not specify whether the core violation is of consent to being shown ads, consent to being shown sexually explicit imagery, or both.

StopBadware hosts Spyware Roundtable in DC

Posted on October 30, 2007 - 18:20 by egeorge

Yesterday, StopBadware hosted a Spyware Roundtable conversation in Washington, DC, gathering leaders in spyware research and policy to discuss emerging trends and potential remedies to badware threats.

With Federal Trade Commissioner Jon Leibowitz in attendance, much of the conversation centered on ways policy and legislation could better help the FTC keep spyware purveyors at bay. The FTC favors legislative solutions that would enable it to fine spyware purveyors.

The Roundtable was chaired by StopBadware co-director John Palfrey, Center for Democracy & Technology deputy director Ari Schwartz, and Ron Teixeira of the National Cyber Security Alliance in celebration of October as National Cyber Security Awareness Month.

You can read more about the Roundtable discussion at PC World and at CNet News.