- Related Stories
-
Security firms on police spyware, in their own words
July 17, 2007 -
Security from A to Z: Spyware
November 27, 2006 -
Keylogger spying at work on the rise, survey says
May 16, 2006 -
BBC stories used as bait for IE exploit
March 30, 2006 -
Verbatim: Search firms surveyed on privacy
February 3, 2006 -
Google, Sun, others band to fight spyware, adware
January 24, 2006 -
New spyware claim against Sony BMG
December 21, 2005 -
Windows anti-spyware to come free of charge
February 15, 2005 -
CA slaps spyware label on Kazaa
November 26, 2004 -
House approves spyware legislation
October 5, 2004 -
Spyware cures may cause more harm than good
February 4, 2004 -
U.S. keeps PC surveillance under wraps
August 24, 2001 -
"Spyware" piggybacks on Napster rivals
May 14, 2001
In the case decided earlier this month by the 9th U.S. Circuit Court of Appeals, federal agents used spyware with a keystroke logger--call it fedware--to record the typing of a suspected Ecstasy manufacturer who used encryption to thwart the police.
A CNET News.com survey of 13 leading antispyware vendors found that not one company acknowledged cooperating unofficially with government agencies. Some, however, indicated that they would not alert customers to the presence of fedware if they were ordered by a court to remain quiet.

Most of the companies surveyed, which covered the range from tiny firms to Symantec and IBM, said they never had received such a court order. The full list of companies surveyed: AVG/Grisoft, Computer Associates, Check Point, eEye, IBM, Kaspersky Lab, McAfee, Microsoft, Sana Security, Sophos, Symantec, Trend Micro and Websense. Only McAfee and Microsoft flatly declined to answer that question. (Click here for the verbatim responses to the survey.)
Because only two known criminal prosecutions in the United States involve police use of key loggers, important legal rules remain unsettled. But key logger makers say that police and investigative agencies are frequent customers, in part because recording keystrokes can bypass the increasingly common use of encryption to scramble communications and hard drives. Microsoft's Windows Vista and Apple's OS X include built-in encryption.
Some companies that responded to the survey were vehemently pro-privacy. "Our customers are paying us for a service, to protect them from all forms of malicious code," said Marc Maiffret, eEye Digital Security's co-founder and chief technology officer. "It is not up to us to do law enforcement's job for them so we do not, and will not, make any exceptions for law enforcement malware or other tools." eEye sells Blink Personal for $25, which includes antivirus and antispyware features.
Others were more conciliatory. Check Point, which makes the popular ZoneAlarm utility, said it would offer federal police the "same courtesy" that it extends to legitimate third-party vendors that request to be whitelisted. A Check Point representative said, though, that the company had "never been" in that situation.
This isn't exactly a new question. After the last high-profile case in which federal agents turned to a key logger, some security companies allegedly volunteered to ignore fedware. The Associated Press reported in 2001 that "McAfee Corp. contacted the FBI... to ensure its software wouldn't inadvertently detect the bureau's snooping software." McAfee subsequently said the report was inaccurate.
Security firms on police spyware
Later that year, the FBI confirmed that it was creating spy software called "Magic Lantern" that would allow agents to inject keystroke loggers remotely through a virus without having physical access to the computer. (In both the recent Ecstasy case and the earlier key logging case involving an alleged mobster, federal agents obtained court orders authorizing them to break into buildings to install key loggers.)
Government agencies and backdoors in technology products have a long and frequently clandestine relationship. One 1995 expose by the Baltimore Sun described how the National Security Agency persuaded a Swiss firm, Crypto, to build backdoors into its encryption devices. In his 1982 book, The Puzzle Palace, author James Bamford described how the NSA's predecessor in 1945 coerced Western Union, RCA and ITT Communications to turn over telegraph traffic to the feds.
More recently, after the BBC reported last year on supposed talks between the British government and Microsoft, the software maker pledged not to build backdoors into Windows Vista's encryption functions.
See more CNET content tagged:
Check Point Software Technologies Ltd., eEye Digital Security, keylogger, survey, agent






- Build a better mousetrap...
- by Impreza WRX July 19, 2007 7:10 AM PDT
- ...and they will build a better mouse.<br /><br />To circumvent the whole silent keylogger thing all you need is a bootable Linux CD that you pop into the drive when you want to do that kind of stuff. This bypasses the main operating system and the spyware keylogger. Plus, by using a CD-R or DVD-R, you can not get your bootable Linux infected, someone would have to physically burn an infected copy and swap the real one for it.<br /><br />Back to the drawing board!
- Like this Reply to this comment
-
-
- As long as they don't do something to your BIOS.
- by ralfthedog July 19, 2007 9:41 AM PDT
- You still have to use heavy encryption. You also have to worry about them doing something to your computer after it boots. <br /><br />They would have to reinfect your computer each time it booted, however booting from non writable media does not protect you from a worm sent by internet running from ram.<br /><br />The fact that it is a Linux CD helps quite a bit. Run as few services as you can. The more stripped down your operating system is, the safer it is.
- Like this View all 2 replies
Processing -
(53 Comments)