- Related Stories
-
Adware cannibals feast on each other
December 7, 2004 -
CA gives anti-spyware a consumer face
November 9, 2004 -
Study: Few corporations use anti-spyware tools
October 27, 2004 -
Spyware opponents win another battle
October 25, 2004 -
Net privacy and the myth of self-regulation
October 16, 2001
ComScore Networks' Marketscore application is installed on more than 1 million PCs in the United States, forming the backbone of a well-regarded research service used by Fortune 500 companies, universities and media outlets, including CNET News.com. Now the software is in the privacy spotlight, tied to warnings from some universities and computer security experts about secretive and invasive software, sometimes known as adware or spyware, that can take over a PC with little or no warning.
ComScore denies the charges and is preparing to go on the offensive with a lobby campaign aimed at legitimizing data collection products such as Marketscore. A ComScore proposal currently being shopped to security firms and Internet service providers would create a new "researchware" label for its software in order to explicitly distinguish it from badly behaved spyware products.
What's new:
ComScore's Marketscore application is in the privacy spotlight, tied to warnings from some universities and computer security experts about adware and spyware.
Bottom line:
The controversy over the widely used data collection tool could help define limits of legitimate software behavior.
"There's a small group of people in universities who've taken it upon themselves to take an issue with our software," said Dan Hess, senior vice president of industry analysis at ComScore. "We're trying to make them fully aware of the nature of our (products and services). It's a completely voluntary program."
What's in a name? Quite a bit, it turns out, if you happen to make your living tracking the private lives of millions of consumers over the Web.
Labels such as spyware and adware cut a wide swath, with many gray areas that can spark disagreements among software makers, consumers and security experts over legitimate and illegitimate practices. Now these basic categories are poised for an overhaul, as federal spyware legislation moves forward and companies like ComScore push for finer definitions from the security companies that are largely responsible for classifying specific products one way or the other.
Depending on how these changes are handled, consumers could face an even more bewildering labyrinth of warnings and terminology over little-understood products such as Marketscore and dozens of other products up for grabs on the Web.
Webroot Software, an Internet security company that counts Microsoft and EarthLink among its customers, said it plans to unveil a new category of potential threats in the next version of its security software, due out in the next few months.
"We're going to have an 'other' category, where we'll be able to identify things like Marketscore, describe what it does, and give users an option to remove it," said Richard Stiennon, vice president of threat research at Webroot. "It's ironic. When we do focus groups with consumers, they say they have too much information. So they're not going to be happy, but we're going to do it."
Webroot currently identifies Marketscore as a subcategory of
See more CNET content tagged:
ComScore, computer security expert, university, Webroot Software Inc., warning







Another one that really bugs me is software companies that do the same thing. No they are always installing what I would consider spyware, but they install button bar and all kinds of other crap when you install their programs and give you no way to either not install it or or remove it. Two pet peeves right now is Adobe Acrobat who installs button bars in Microsoft Word with no way of turning them off. The other one is Macromedia FlashPaper 2 which installs a button bar in to Microsoft word as well.
Other companies like Corel install little TSR programs that keep nagging you to register so that they can spam you with crap for the rest of your e-mail addresses life.
Their needs to be a consumer law that allows us to take back control of our property. Until companies start giving us high end computers and stuff in exchange for this type of crap they need to keep their paws off my property.
Robert
Is there any law and order or money can buy anything??
As far as secutiry goes, I would like to see a BIOS on computers that uses a 'natural flow' file to determine if the process desired to be executes it valid for the program. It would require the system administarting user to accent to any new installation and should note, in their native tongue, what the files or directories are used for, that the new program want to access.
Sincerely,
Gregory D. MELLOTT
Such intrusions should be treated exactly the same as trespassing.
Any software which installs in any less of a forthright manner, such as behind a long "terms of use" disclaimer, is using tactics which steal for me. It is my computer time, my internet connection and my resources which are being used without my consent. That's theft.
Spam, spyware, adware is all theft as far as I am concerned. Perhaps if these companies that use these tactics were prosecuted for theft there would be less of it happening.
Most spyware programs are willingly installed on a target PC because most users just aren't willing to sit down and spend thirty minutes reading the End User Licensing Agreements (usually done in fine print, with any references to data collections deeply buried under a mountain of legalese mumbo-jumbo).
These spyware programs are no more "RESEARCH" programs than government sanctioned wire-taps, or Echelon data collections.
Nice try, but your logic just doesn't doesn't make sense - whichever way you would like to spin it.
You say that it's being done with the users' consent, but I'll bet you just about anything that at least 1.4 million out of the 1.5 million users of these infected PCs have NO IDEA that their internet activity is being spied on.
This program perfectly fits the description of the worst kinds of spyware in every detail. There is no point in trying to claim it is somehow legitimate.
Gathering information on trends wrt to surfing habits is one thing. Collecting private information is something quite different.
The problem is that most computer users don't realize what they are agreeing to and have no clue what a proxy server is or how it can be used. That's where clear disclosure is necessary. I don't care how "top notch" a company is if they are redirecting users through their own server. That's as bad as or worse then MSFT's Passport.
What they claim is that people downloaded the program knowing what it does - mining data and sending it somewhere, and those people trusted them when agreeing to the instalation. this is not the same as something a user got infected with while trying to install something else for a different purpose.
I think it was about 4 years ago that I installed my first adware-supported "freeware". I liked the idea back then: the ads where not intrusive (they were only shown when I was using an app that didn't need even 10% of the screen, and disappeared with the app as soon as it lost focus). Then later I found that I have three or four different ad-serving programs on my system, that came with things like pkzip and other shareware. One of them was shared but more than one ad-supported app, and what annoyed me was not that they are trying to use my data, but that I have way too many of them installed and using resources. Why can't they use just one ad-serving engine? Then started all the public ranting about spyware spying on you, and it all added up:
I think the model of paying for a software license by being served targeted ads is a good idea. It is just not implemented correctly. It should be TRUSTWARE and not SPYWARE! There should be one ad-serving program on a user's system, and it should be the user's choice which ad-serving program it is. The user would choose an ad-serving service the user trusts for doing the ad-serving. Ad-supported software downloads would not have bundled spyware. Instead it would look in the system to see what ad-serving software exists, and would negotiate with this ad-server. If there is no compatible ad-server on the user's system, the ad-supported app would inform the user that a compatible ad-serving program should be installed and running before the app can be used.
For this to work there should be a standard open protocol for ad-servers to negotiate with ad-clients (ad-supported apps) and for them to serve ads to the client, and also to pay the vendor of the ad-client for displaying the ads in their app.
The point is that this way the user doesn't get unwanted software sneaked into her system. Instead she gets ads from a source she trusts, and this way perhaps she is willing to share much more info with this trusted source, which can result in much better targeted ads, which serve her better and earns more money for the advertisers.
Of course there are lots of security issues to be solved for this to work. On the other hand there is potential in this model beyond just serving ads. It's really about different software components in a single computer negotiating and transfering real value between them, so it's a sort of micro-payments system working inside a single PC, and when aggregated over many users on many PCs resulting in real money being transfered between the user's chosen ad-server vendors and the ad-client vendors.
- If the end user does not want to participate then any spying is just that.
- If the tracking must be done by imbedding code into the user's computer, it is a blatant intrusion, a trespass.
- It does slow down PC's and I have seen it interfere visibly with browser operations and ultimately corrupt drive data on a PC virus checked daily.
- It is also a violation of trust by those who do so without permission or clear ability to opt out.
Just call it for what it is. Rape Derived Data.
Until the big uproar occurred over the last couple of years, many major corporations used the services of the worst spammers, and the same corporations continue to push annoying pop-up ads that people complain about and try to block.
Until the activity in question is clearly illegal, or until a sufficient number of customers become aware of it and start complaining (to the point it would be bad PR for a company to be associated with it), companies will continue to use these services. Spam and pop-up ads are cheap and effective. So is spyware-derived research. Until there were sufficient complaints and laws targeting it, customers of spam services claimed there was nothing wrong with it. This doesn't make it desirable or something we should just accept as OK.
Awareness of spyware and adware is just lagging behind that of more in-your-face intrusions like spam and pop-up ads, mainly because it IS so invisible (which makes it all the more troubling).
In fact, this kind of spyware is far more potentially damaging than standard pop-up ads and spam, if less immediately annoying. We should not just "trust" some company to know all of our passwords, bank account logins, personal activities, everything we buy, everything we read, every site we visit, every personal email and chat message we send, etc. Any such software would need an extraordinary level of awareness and accepance on the part of the user, not just clicking past some fine print in an EULA, and any personally-identifying information should be stripped fully before the data ever leaves the computer. The user should also be able to see the data that will be transmitted before it is sent, and have the ability to prevent its transmission if it tells more than they want to.
Going through a proxy is a REALLY REALLY bad idea. At the least, there should be suitable warnings each time someone logs into the computer or goes onto the internet that this is occurring (if a proxy IS used, all web pages should be in a frame which clearly explains what is happening, what data is being collected and by whom, and giving the easy option to bypass it at any time, and similar warnings should display any time email, news, ftp, or other internet activity occurs).
Of the 1.5 million claimed users of this software, I bet at least 1.4 million would be surprised (and probably angered) to discover that their online activities were being monitored in any way.
There is nothing distinguishing this company from any other disreputable spyware company. No new category is needed here, except for "illegal".
First class research firms such as Nielsen adhere to strict ethical standards. I can't imagine Nielsen conducting a focus group or other type of research where they write down the social security number and credit card numbers of the participants involved. And I certainly think that Nielsen's research participants would know why, when and where they were being questioned or observed.
To say that MarketScore's type of research is ethical or OK because companies like AOL use it is a weak argument. To label their software as "Researchware" does not change the type of methods they employ.
I have an idea for a survey that the Federal Trade Commission might want to conduct with Comscore's "panelists". Since they know who the users are, it should be easy to pull a sample of MarketScore panelists.
Q1) Are you familiar with ComScore, MarketScore or JDCouncil.org ?
Q2) Is the MarketScore software program currently installed on your computer ?
Q3) Is the MarketScore software program currently running on your computer ?
Q4) Do you know that you agreed to have Comscore capture your personal information such as credit card numbers, bank passwords, social security numbers and other private information ?
Q5) Did you read the End User License Agreement prior to installing the MarketScore software?
Q6) Did you understand the End User License Agreement prior to installing the MarketScore software?
Q7) Do you know how to de-activate or uninstall the MarketScore software ?
Q8) Did you receive any renumeration or conisderation for installing the MarketScore software ?
Q9) Do you want your personal information such as credit card numbers, bank passwords, social security numbers, and internet purchases recorded and tracked by MarketScore?
Q10) Do you want the MarketScore software installed and running on your computer?
Q11) Would you like to recieve a short, easy to understand confirmation from MarketScore that would REQUIRE YOU TO CONFIRM that you would like to continue as a panelist?
Q12) If your personal information were to "leak out" as a result of your use of the MarketScore software and cause you personal harm such as identity or credit card theft do understand what liability MarketScore has to you?
I don't think that full disclosure equates to fine print. The mortgage loan industry used to bury it's disclosures in fine print. Now there are separate forms in large print and easy to understand language in loan documents. Government intervention was required to at least make an attempt to insure that people knew what they were getting into.
For now I applaud Webroot's and the universities mentioned stance on classifying this program as "Spyware". Until MarketScore can prove that it's panelists truely understand and agree to having this software installed and running on their computers, the panelists should have the option of this program being flagged as Spyware.
If you need information ask.
Intrusion without permission in the name of science is still intrusion. If I wanted to be part of a study group for these theives then I'd sign up.
I will say it again...the anti-spyware makers have a huge amount of power. They recommend what they think is good software and bad software. They have the power to remove "bad" software. This is all well and good if anti-spyware makers were all kind and benevolent, but they obviously want to make money too. The wheels can be greased. If the anti-spyware company has a large enough distribution, they can put out a software or definition update and kill another program in no time at all.
A good example is the tie between Alluria and WhenU. One could argue there is a little bit of a conflict of interest there:) In fact most of what I have seen is companies that do not want to be viewed as spyware have a tactic of teaming with a anti-spyware maker to get them on their side. This gets to the heart of my fears about this.
On the other hand I do think Privacy Protection Software is a good idea and that it is good for everyone if there are good rules. I think the P3P is a good example of how we can better inform consumers about privacy. This Privacy Protection Software may even be able to hit a web sites P3P policy and convey that in clear english for folks. Anyhow, I would like to see criteria like the following:
1) Objectivity - There needs to be a clear list of criteria by which software privacy will be measured. (the term spyware needs to go away because is not objective, it is just hype). Actual research needs to be done on the software and that research needs to be documented against the list of criteria. GIANT/Microsoft actually has a decent list of criteria, but maybe there needs to be an independent organization that sets the criteria?
2) Transparency - Both the consumer and the developer of the software applications need to have 100% disclosure of what the scoring criteria is for their application. This promotes having legitimate companies that are "in a gray area" to improve their practices and prevents anti-spyware makers from choosing how they want to apply their definitions to different vendors.
3) Fairness: ALL software must be treated and analyzed equally. i.e. the spyware companies cannot decide to include one piece of software and not another. All software has privacy concerns even if it is purchased by a consumer or used by an IT organization. For example, we use RAdmin here at work. By NO means is it spyware in the hyped sense of the word, but it could definitely be used to monitor what a person does on their computer and people have a right to know its capabilities.
Anyhow, just throwing out some thoughts. I think these are issues that are out there, but not too many consumers seem to be afraid of who we are giving power to. They hate spyware and any company that helps get rid of it is good in their books...Lets just not forget that the biggest reason anti-spyware companies are getting into this area is to make money and things can get out of hand if we let it.
Hopefully this will cause someone to think about this more..
- Big Brother by any other name....
- by December 29, 2004 6:36 PM PST
- It is no more acceptable by ANY company whether for marketing purposes or whatever. It is still an invasion of our privacy to install anything unknowingly on our compters. If the Goverment did it (who knows) we would not stand for it. It slows down our machines and causes bandwidth to be used. I believe it to be worse than spam, since spam does not invade our systems, just fills our email boxes. (Spam does suck though)
- Like this Reply to this comment
-
Showing 1 of 2 pages (31 Comments)