Sun, Dec 14, 2003 News Editorials 487819304 visits
 Photo News
 More Business Focus
 More IELTS
 Johnny Neihu
  • Back Issue

  •   << >>   Full List

  • TaipeiTimes
  •   Subscribe
  •   Advertise
  •   Employment
  •   FAQ
  •   About Us
  •   Contact Us
  •   Copyright
  • Search Most Read Story Most Viewed Photo

    Hidden extras in free software can prove costly

    Programs with hidden -- but legitimate -- spyware are on the increase, raising concerns about commercial espionage

    By Mary Branscombe
    THE GUARDIAN , LONDON
    Sunday, Dec 14, 2003, Page 12

    The deluge of viruses this year means that nearly everyone knows that emails with unsolicited offers of interesting pictures or system updates need to be treated with suspicion. But what about that handy utility you want to run on your office PC -- or that file sharing software you'd rather run from work because it's faster than downloading on your modem at home?

    There's a huge range of software -- from useful to dubious -- that you can download free, but some programs come with hidden extras.

    Instead asking users to pay if they like the program, some developers include extra software that tracks the Web sites you visit as a form of free market research. And some spyware tracks considerably more than that. And while spyware has been around for a couple of years, the past six months have seen it spreading.

    If you find your system slowing down or your Web browser opening to the wrong search engine, you might have an unwanted visitor, but because these programs aren't viruses, standard anti-virus software usually does little to protect you.

    For one thing, there are legal issues with detecting and blocking ad-sponsored software that users have agreed to install (even if they didn't bother to read the license agreement).

    For another, there are a lot of programs to track, and many people see it as a trivial problem for home users rather than a serious issue for business.

    But even if the spyware infesting business desktops is only ad tracking code, that can still be a huge burden on a company's network resources.

    One company that started using Websense to monitors its network found spyware was generating half a million outgoing messages from its desktop in three days.

    The company email addresses used to send those messages are likely to end up in spam databases as well, which means more traffic and time wasted.

    Having home page in your Web browser changed can affect your productivity as well as being an inconvenience.

    Tracking and removing spyware from every desktop is going to affect the productivity of your information-technology team as well.

    And can't just assume that spyware is benign, even if it is legitimate commercial software. Keystroke loggers are useful for parents wanting to keep track of what their children do online, but the same software running in your finance department is a major security issue.

    Gabe Newell, of Valve Soft-ware, believes that keystroke recording software helped hackers steal source code for the Half Life 2 game recently -- a theft that has meant postponing the release of the game for at least six months.

    If customers' information is stolen from your computers, they are going to lose confidence in your business. To add insult to injury, you could find yourself liable under data protection regulations, too.

    Commercial may not be common and many incidents can be traced to insiders, but Pete Simpson, manager of Clearswift's ThreatLab, thinks we're going to see more gene hackers.

    It is probably organized crime with some big money behind it and the motive is financial gain.

    "Clearswift recorded a major rise in spam email selling spy-ware following Microsoft's decision to close MSN's public chat rooms, which could suggest that the hackers had been distributing their code in chat and are looking for new victims to replace their lost audience," Simpson said.

    Few are protecting themselves against spyware, and most of the tools for detecting and removing it are designed for home users -- and have to be run on every desktop individually.

    Anti-virus are starting to take an interest and there may soon be adware and surveillance spyware available.

    But rather than tackling spy-ware as a separate security prob-lem, you should look at the implications for your security policy more generally, such as who is entitled to install which software on their PC.

    While spyware is downloaded through Web sites, more arrives in email, so blocking or quarantining incoming executable files will protect you.

    It is hard to block most spyware at the firewall because it sends messages back using email and HTTP, traffic you will want to allow through.

    Websense offering a free trial of its monitoring software to see if spyware is clogging up your network.

    This checks the destination of all outgoing email, blocks messages to known monitoring sites based on a list updated daily and lets you choose which users are allowed to send email, and to what addresses.

    Whatever you choose, to stop hackers spying on you, you may need to start monitoring your own systems much more closely.

  • Advertising