Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
I Spy With My Little Eye
Mark Rasch, 2004-09-13

Forget Congress' myopic efforts to outlaw spyware. What we really need is better enforcement of existing computer crime laws.

Comments Mode:
I Spy With My Little Eye 2004-09-14
Anonymous
I Spy With My Little Eye 2004-09-14
Anonymous
I-SPY... 2004-09-16
Dave
Please stop the advertising for spyware authors... 2004-09-19
Peter
>Current U.S. federal criminal law, 18 U.S.C. 1030, already makes it a crime to access (read that "use") a protected computer (read that "any computer") without authorization (or in excess of authorization)
Who is allowed to authorize such use of a computer? The person that paid for the computer? The person who administers the network? Or the minor who clicked OK? Federal courts haven't even agreed on what "accessing" a computer really means. Nor have they agreed on what "protected computer" means, either. It quickly becomes a jurisdiction lottery where the standard of justice depends upon which circuit you are to be tried in.

>It seems to me that this is a perfect vehicle for prosecuting existing spyware that transmits your personal information, assuming it truly does so by accessing your computer without your consent.
Yeah, you would think so. Except there is exactly zero method of determining if the user was legally of age to consent. Or if they did consent at all. Or if they were authorized by the owner of the computer to consent. Through those loopholes have driven all of the spyware/trojan authors. All one needs to do, to avoid a lenghty criminal stay in Club Fed is to put up some weasel words, called a EULA, and proclaim to the prosecution that the victim pressed an OK button, thus authorizing it to be there.

Here are a couple of scenarios that you didn't try to consider:
1 - My child clicks OK to install spyware/trojanware (like gator/claria), even though I told him not to install anything.
2 - At work, one of my employees clicks OK to installing spyware/trojanware even though it is against company policy to do so.
3 - The spyware/trojanware delivery mechanism (can) use one or more of the exploits allowing it to be installed without the user even knowing it is installing.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/266/28520#28520
I Spy With My Little Eye 2004-09-23
Mene Tekel







 

Privacy Statement
Copyright 2009, SecurityFocus