Slashdot Mirror


Spyware or Researchware?

prostoalex writes "When the story of Firefox Web site visitors being predominantly male was published, many questioned the methodology used to acquire such research data. This MSNBC article talks about another research company, ComScore Networks, using a free antivirus utility to lure the Web users into downloading a small utility to their hard drives. The catch? The software watches not only sites visited, but even locations of the mouse clicks. ComScore swears the final data does not contain any personal information, but, as the article states, anti-spyware utility manufacturers are still thinking whether to include it on their list."

3 of 244 comments (clear)

  1. Choice by mfh · · Score: 5, Interesting

    The beef I have with spyware is that it's never given me a choice; it installs without me knowing and lurks like a drooling Rutterkin in the corner -- waiting for me to spill my drink or drop The One Ring. But this research program is optional, right?

    I have no problem with optional programs that record data to be used in a study. My wife also participates in allgery studies. So?

    --
    The dangers of knowledge trigger emotional distress in human beings.
  2. If you give choice, there's no research by nigham · · Score: 5, Interesting

    Unfortunately, if they give the users a choice to turn it off, you can't qualify the statistics obtained from users who allow information to be logged as good - e.g. who's to say whether guys may be more inclined to turn it off than girls - or conversely, women feel more threatened about privacy... in either case your stats will be skewed.

    In any case most users (myself, certainly) would turn it off - I am supremely uncomfortable with some random company knowing anything about what I do on my computer.

    --
    I don't want to read /. I want to go home and re-think my life.
  3. Re:Depends... by Dead+Kitty · · Score: 5, Interesting

    A new question is exactly which parties does the software need to be upfront with? The Marketscore software has just recently changed it's tatics, it's no long just an issue with the End User anymore. They now are actively hiding themselves from end servers. The implications?

    Banks with online banking services have long banned authentication attempts coming from customers using known Marketscore proxies for obvious security reasons. This is due the violation of the terms & conditions presented when setting up an online banking account. The traditional Marketscore setup had client traffic sent to their proxies which was then forwarded to the intended site. This made it easy for us to track customers with "compromised" machines (Marketscore would never admit to compromising anything).

    Lately (last 1 or 2 weeks), we noticed in our server logs that connection attempts from Marketscore proxies suddenly dropped to nothing (from 100's to 0). After some investigation, we learned that the new Marketscore spyware now installs its proxy locally on the user's machine. It accumulates data in a local cache which is then sent back to Marketscore for their anaylsis. Because of this, we can no longer filter compromised machines running Marketscore shitware. Of course there's the other garbage like secretly installing their own root cert on the victim's machine, harder detection by anti-spyware programs, etc.

    Yes, maybe the user knows the benefits (and the world of hurt) they can expect from using this software...but what about the banks (or other businesses) who are actively trying to protect its customers? We're still trying to figure out how to deal with this on our side while individually informing the affected customers.