Tuesday | 14 October, 2008
CIO
Spyware may be next Australian government target
Stephen Bell (Computerworld) 01 October, 2004 08:32:51

Australia's federal government may look at adware and spyware as a follow-up to its legislative actions against spam. On the other hand, some caution should be attached to "promises" in the run-up to an election -- the event currently dominating all Australian news.

Paul Ducklin of security company Sophos approached IT minister Helen Coonan after her address to a media seminar and flagged the spyware problem. An official accompanying her quickly said, yes, the government was aware of the issue, and would start to look at it when (and if) re-elected. This was likely to be done by the same team that evolved the antispam legislation, he said.

Ducklin reckons this will be an even more intractable problem than legislating against spam, because it involves judging the degree of a user's informed consent. Adware is usually delivered as adjunct to a useful product that the user will download and enthusiastically install -- without too close a look at the agreement to which they are being asked to confirm with a mouse-click.

Such agreements often contain wording allowing "updates" to the program to be loaded automatically onto the user's machine when it is connected to the Internet, and allowing other programs that the vendor thinks might appeal to the user to be similarly loaded.

So the luckless customer is trapped into acquiring software of "an increasing degree of shonkiness" until their system is compromised, Ducklin says.

Adware and spyware agreements have been known to include clauses permitting use of the computer as a relay for outward e-mail and allowing onsale of details enabling other vendors to access the machine without explicit authority from the original user, Ducklin says.

The trouble is, the vendor will always be able to point to the click-signed agreement and argue that the user consented to everything that has been done.

"It's a question of a legal commodity, usually called 'adware', which shades into those illegal things called 'spyware', and it's very difficult to draw the line," says Ducklin.

Senator Coonan used her set speech to announce the coalition government's IT policy. This concentrates on affirmation of a number of existing policies for support of the industry -- the words "keep" and "continue" figure largely in the policy document. The most prominent new undertaking is a study into the factors preventing teleworking.

While capable telework technology is there, there are still significant people, relationship and attitude problems to be overcome, Coonan says. "A study by Sweeney Research found that half of Australian management wouldn't trust their workers to work away from the office and 75 percent of co-workers think that colleagues who work out of the office may not be doing work at all." The taskforce will look at the causes of these attitudes and ways of overcoming them, Coonan says.

She promised continued funding for broadband, maintaining the AU$107.8 million (US$75.2 million) Higher-Bandwidth Incentive Scheme (Hibis), which subsidizes rural broadband development so users pay a similar price to that paid by urban customers. However, further broadband announcements are reserved for the communications policy.

Delegates to the seminar remarked afterwards that talk of "broadband" in Australia, as in New Zealand, is misleading. "What they usually mean is 256k bps (bits per second) down and 128k bps up, or 512k bps down and 256k bps up if you're lucky," said one.

More about Sophos, Onsale
Market Place
 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
  • +

    CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00

    Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00

    Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05

    Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    Cutting Through the Spin of Recent Vulnerability Disclosures 13 October, 2008 10:53:00

    The FUD surrounding the ClickJacking and TCP/IP vulnerabilities has the world seemingly frozen in fear. But once you cut through the spin, the vulnerabilities aren't all that they were made out to be.
    There are a few highly publicised vulnerabilities at the moment which haven't completely been disclosed and which, it is claimed, could threaten the whole Internet as-we-know-it. Only, when the vulnerabilities are finally disclosed, it seems that the whole incident has been somewhat Chicken Little.
  • +

    PCI app security: Who's guarding the data bank? 13 October, 2008 11:09:00

    Compliance strategies for PCI's new application security requirements
    While Willy Sutton never really said it, the truth is that people rob banks because that is where the money is. Today's criminals don't walk into banks with loaded guns and get-away drivers. Rather they connect from a remote location using a browser and are armed with hacking tools and spyware.
  • +

    Data-center security tools to not overlook 10 October, 2008 11:37:00

    With the rise of security suites, it's time to consider some emerging security tools and rethink others
    Protecting a corporate data center is like trying to keep an elephant safe from a swarm of flies. Despite your best efforts, bites happen. As the staples of security -- such as firewalls, antivirus software, spam and spyware filters -- come together in suites of products that allow for sophisticated management, there are other security tools either emerging or worth a rethink.
  • +

    IBM, Secret Service, others study identity/cybercrime issues 09 October, 2008 10:09:00

    Center for Applied Identity Management Research organization teams experts in criminal justice, financial crime, biometrics, cybercrime and cyberdefense, data protection, homeland security and national defense.
    IBM, LexisNexis and the Secret Service are among a group of corporations, government agencies and academic institutions that has formed to study and help solve identity management challenges around cybercrime, terrorism and narcotics trafficking.
  • +

    Strange account management at Amazon 09 October, 2008 09:51:00

    A careless login led to the discovery of some strange ccount management practices at one of the Internet's largest retailers.
    Via the RISKS mailing list comes an interesting tale of poor online account management at a major online retailer. According to Graham Bennett, accounts with Amazon display an odd behaviour that doesn't seem to have attracted much attention in the past.
CIO Webcast Innovation #8 - What are the biggest roadblocks to IT's involvement in innovation at your company?
Watch the latest latest edition of CIO Innovation which is now available for download.
Watch the webcast
Sign up to the CIO Innovation update email


CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper

The IP Storage payoff: Turning your investment into efficient, affordable results

Recent advances in IP-based storage technologies leverage existing technology and staff to easily and cost-effectively build and maintain sophisticated storage networks. Discover the solutions to your data storage challenges with IP storage.