Slashdot Mirror


The Pure Software Act of 2006

lurker412 writes "The MIT Technology Review features a proposal by Simson Garfinkel to provide honest labels on software in the same way that the Pure Food and Drug Act of 1906 forced manufacturers of foods and drugs to divulge the contents of their products. The proposal targets adware, spyware and other unsavory practices. It suggests that by requiring software manufacturers to include clear icons for each nasty behavior--rather than hide the disclosures in seldom read or understood click-through SLAs--end users will be better protected. Garfinkel specifically lists eight types of sneaky behavior, but the list is not meant to be exhaustive."

8 of 261 comments (clear)

  1. The sound of silence by pudding7 · · Score: 5, Funny

    Anyone see the name as "Simon and Garfunkle"?

    I'll go back to work now...

    1. Re:The sound of silence by Prince+Vegeta+SSJ4 · · Score: 5, Funny

      Hello Clippy, my old friend,

      I've come to talk with you again,

      Because a exploit softly creeping,

      Left its worms while I was sleeping,

      And the vision that was planted in my brain

      Still remains

      Within the sound of silence.

    2. Re:The sound of silence by brandond1976 · · Score: 5, Funny

      In that case I think I'll change my name to one of these:
      Hercules Rockefeller
      Rembrandt Q. Einstein
      Handsome B. Wonderful
      Max Power

      Which one would be best? Should I post an AskSlashdot?

  2. Erm... by r4bb1t · · Score: 5, Insightful

    How do they plan on labeling software solely distributed over the internet? I'd venture to say that 90% of the spyware that's out there comes through download-only software (DivX, peer to peer software, etc...).

  3. Finally by JoeShmoe950 · · Score: 5, Informative

    Spyware is a big problem which isn't Window's fault. Because windows is the biggest, it gets targetted by spyware. You can still right a program which uses 100% CPU Usage and makes everything really slow,etc. for another OS, no matter how secure. Unfortunetly, its targeted at windows. My friend thought that windows XP was horrible because it was running so slow. On a 2ghz, it would take 5 minutes to load IE. I showed him Ad-Aware from lavasoft. It detected 589 spyware objects, quite a few of them different. I found that a big problem with spyware, is not only the spying, yet the fact that it slows your system to a hault. If this works, and makes spyware go away, or atleast well known spyware label itself (such as gator), I will rejoice.

  4. Re:Can there be a label... by dspfreak · · Score: 5, Funny
    to denote buggy code?

    Yeah, it has red, blue, green, and yellow wavy squares in a 2x2 pattern with a black border.

    --
    "Tolerance is the virtue of the man without convictions." -- G. K. Chesterton
  5. article text by Anonymous Coward · · Score: 5, Informative

    The Pure Software Act of 2006
    100 years ago, Congress passed a law requiring honest labeling of food and drugs. Now the time has come to do the same for software.

    By Simson Garfinkel
    The Net Effect
    April 7, 2004

    Spyware is the scourge of desktop computing. Yes, computer worms and viruses cause billions of dollars in damage every year. But spyware--programs that either record your actions for later retrieval or that automatically report on your actions over the Internet--combines commerce and deception in ways that most of us find morally repugnant.

    Worms and viruses are obviously up to no good: these programs are written by miscreants and released into the wild for no purpose other than wreaking havoc. But most spyware is authored by law-abiding companies, which trick people into installing the programs onto their own computers. Some spyware is also sold for the explicit purpose of helping spouses to spy on their partners, parents to spy on their children, and employers to spy on their workers. Such programs cause computers to betray the trust of their users.

    Until now, the computer industry has focused on technical means to control the plague of spyware. Search-and-destroy programs such as Ad-Aware will scan your computer for known spyware, tracking cookies, and other items that might compromise your privacy. Once identified, the offending items can be quarantined or destroyed. Firewall programs like ZoneAlarm takes a different approach: they don't stop the spyware from collecting data, but they prevent the programs from transmitting your personal information out over the Internet.

    But there is another way to fight spyware--an approach that would work because the authors are legitimate organizations. Congress could pass legislation requiring that software distributed in the United States come with product labels that would reveal to consumers specific functions built into the programs. Such legislation would likely have the same kind of pro-consumer results as the Pure Food and Drug Act of 1906--the legislation that is responsible for today's labels on food and drugs.

    The Art of Deception

    Mandatory software labeling is a good idea because the fundamental problem with spyware is not the data collection itself, but the act of deception. Indeed, many of the things that spyware does are done also by non-spyware programs. Google's Toolbar for Internet Explorer, for example, reports back to Google which website you are looking at so that the toolbar can display the site's "page rank." But Google goes out of its way to disclose this feature--when you install the program, Google makes you decide whether you want to have your data sent back or not. "Please read this carefully," says the Toolbar's license agreement, "it's not the usual yada yada."

    Spyware, on the other hand, goes out of its way to hide its true purpose. One spyware program claims to automatically set your computer's clock from the atomic clock operated by the U.S. Naval Observatory. Another program displays weather reports customized for your area. Alas, both of these programs also display pop-up advertisements when you go to particular websites. (Some software vendors insist that programs that only display advertisements are not spyware, per se, but rather something called adware, because they display advertisements. Most users don't care about this distinction.)

    Some of these programs hide themselves by not displaying icons when they run and even removing themselves from the list of programs that are running on your computer. I've heard of programs that list themselves in the Microsoft Windows Add/Remove control panel--but when you go to remove them, they don't actually remove themselves, they just make themselves invisible. Sneaky.

    Yet despite this duplicity, most spyware and adware programs aren't breaking any U.S. law. That's because many of these programs disclose what they do and then get the user's explicit consent. They do this with something that's called a click-wr

  6. More evil bits .... by Frater+219 · · Score: 5, Interesting
    It ain't a joke. Honest software makers will indeed likely support it, since it allows them to make clear how their software differs from crapware. I'd go for a few more labels, though, intended to illustrate the intent of the software, so you get what you are paying for.
    • A portcullis. This software filters or alters the content of files or incoming Internet traffic. Web pages you see, for instance, might not represent the exact transmissions of the Web server or the intent of the author. Appropriate to anti-virus software, porn-filtering censorware, privacy software ... and adware that replaces ad banners with other ad banners.
    • A police badge. This software runs by default under elevated or superuser ("root" or "Administrator") privilege. (Simply requiring superuser privilege to install the software doesn't count. Creating a dummy user with most of the privileges of the superuser does, though.) Therefore a bug in this software, including a security vulnerability, can affect anything on your computer -- not just the files owned by the user actively using it.
    • A cable plugged into a wall socket. This software accepts incoming network connections in the default configuration. If you do not intend this software to accept traffic from the Internet, you will need to change the configuration or have a firewall.
    • A computer with an arrow through the monitor. This software is designed to be remotely disabled by the publisher under certain circumstances (such as breach of license or expiration of subscription). The fact that it is installed and working today does not imply that it will continue to work without future intervention.
    • A closed mouth with a finger making the "shush" gesture. This software's license forbids or encumbers the publication of reviews without the permission of the publisher. Reviews you may have read of this software may have been selected by the publisher to represent it in an unfairly positive light.
    • A pair of handcuffs. Documents or other files you produce using this software are encumbered by its license, patents, or other proprietary rights of the publisher. Appropriate for a word processor whose file format is patented, or a compiler whose license forbids you to use it to write software that competes with the publisher's other software.