Every 5th Call At Dell Is Spyware-Related
prostoalex writes "Financial Express quotes a Dell executive saying that spyware is installed on roughly 90% computers out there. Right now 20% of all Dell phone support calls are spyware-related. University of Washington research this March published a moderate estimate of 5.1% PCs running spyware."
Techs should feel lucky there's yet another thing out there creating a job market for them, whether they're still based in the USA, or shipped off to another country. You know, I thought Dell had the worst Dell tech support for sure, but I had to call Dlink last week to clarify on something, and I got into an argument from India about what was written on the configuration page of a cheap office router. It's up in the air -- The Dell tech couldn't read, and the Dlink tech said what I was reading was not possible. Hrm.
slashdot: where everyone yells sarcastic metaphors to themselves to understand the issue
The antivirus companies claim that removing spyware will get them sued, becuase they'll be committing libel by lumping it in with viruses. In reality, they just want to create a separate product, which is just a virus scanner with a different set of signatures, and charge each user a second time.
I wonder if this policy is still in effect ("Dell To Techs: Don't Help Customers Remove Spyware").
By the way, I love the "Your browser has blocked a popup" image over the article text. Really helps in the journalistic integrity department.
See this forum discussion on BroadbandReports. On my office Dell Dimension 8250, its support program (support.exe) phones home. I consider this a spyware.
Ant(Dude) @ Quality Foraged Links (AQFL.net) & The Ant Farm (antfarm.ma.cx / antfarm.home.dhs.org).
I have been using DOS then Windows since 1984 and have never had spyware or a virus either. In fact I don't even run checkers constantly, just every few weeks to double check. (And for the record I have been doing Linux since late 1991 and not had anything there either).
If you are prepared to put the time and effort into it, it is all pretty easy. You don't blindly run or view stuff from other sources, you don't steal software (if you don't have the originals then you have no idea what you are actually getting), you pay attention to the dialog boxes that various programs display etc. Heck I even read the contents of those dialog boxes with legal agreements in them before clicking Ok or Cancel. Most people just don't do that, and as a result their computers end up with more "helpful" software than they otherwise anticipated.
To say that Linux by design is invulnerable is nonsense. It doesn't take too much to infect an individual user (remember they aren't reading those dialog boxes either). And notice how on many Linuxen, when you try to run an admin tool on your ordinary user desktop, prompt for your (sudo) or the root password and which then leaves a key icon in your panel. That is one thing that can be abused to go from ordinary user to root. In many cases a piece of malware could probably just prompt and the average user would type in the necessary password.
Quite frankly I don't know the answer. Signing stuff doesn't work. User education is futile - why should someone have to know about the internals of their computer, operating system, access and authorisation models? It probably comes down the programmers and user interface. Every time the software has to ask a question, it is being stupid. We need to continually work on the software meeting the user's goals without needing to be babysat, and especially without them having to make these decisions all the time.
I work at my school (Cornell Univ.) in the Information Technologies department taking calls and basically doing technical support for folks who don't know anything about computers. Our ratio of spyware questions to any other questions is definitely at LEAST 4:1. It gets real old, real fast. Thing is, we're not allowed to give advice on what spyware removal tools to use, which makes it that much harder. The problem never gets fixed, and we just get more and more repeat calls.
I find it ironic that half of the stuff that Dell ships on their prebuilt computers makes computers run ust as slow as a lot of spyware. I know that when clients of mine buy a new Dell computer, they're disappointed at how slow it runs. Reformatting the HD always makes the computer run 10 times+ faster.
There's someone who does an organized scan of my ISP's IP space every morning at 8:42 and 9:42 EDT. When I have two DHCP IPs, both get hit with an average of eight bots each trying ports 5554, 1023, 9898 and 445. The IPs it comes from are usually Korean or Japanese. When I listen at the ports, they try various exploits on bots which do listen on those ports to download their own bot software.
I suspect that "8:42 Zombie Charlie" scans a lot more than my ISP's space. So it looks like someone is running a very organized and *punctual* effort to harvest a whole lot of botted machines for unknown purposes. Joy. (Actually, it's kind of fun. I wrote a sound effects program from my firewall, and I drink my coffee listening to the chorus of sounds as the ports are checked. Too bad I can't arrange to be checked a little earlier in the morning.)
One line blog. I hear that they're called Twitters now.
I've been looking into ways to remove the profit incentive from the spyware guys. These morally challenged cruds monitor your web browsing habits and then sell that info. What if that info was full of bad entries? Like increasing the junk to valid signal ratio?
What I envision is a screen saver that we load on all the machines we can get our hands on. This screen saver then contacts these spyware sites and uploads random info. The aggressiveness could be controlled by the user, allowing it not to flood any Internet connection. The screen saver could have spyware lists, just like anti-virus software that could be updated. Imagine having millions of pcs uploading junk to coolwebsearch. How long would you say these guys would stay in business? Would those that are buying this info continue to do so even if it full of garbage?
Obviously this would be OSS, but we could license it in such a way as to allow folks like Dell to preload this and set it as default.
So folks, what do you think? Is this the way to kill these guys or is the recent criminalization enough to stem the tide?
Quit playing Monopoly with Bill.
Linux - of the people, by the people, and for the people.