Spyware bill reintroduced in Congress
It allow fines of up to $3M for spyware software makers
IDG News Service - Spyware legislation that would allow fines of up to $3 million for makers of software that steals personal information from a user's computer or hijacks its browser will get a second look after the U.S. Congress failed to pass the legislation in 2004.
Rep. Mary Bono (R-Calif.) reintroduced an antispyware bill yesterday that passed the House of Representatives last year but failed in the Senate. The Securely Protect Yourself Against Cyber Trespass Act, or SPY ACT, defines most functions performed by so-called spyware as unfair business practices subject to U.S. Federal Trade Commission fines.
Bono said in a statement that she expects the bill to sail through Congress this year. The measure passed the House in October on a 399-1 vote.
"The SPY ACT was introduced because we feel that consumers have the right to know and be protected when they are downloading software that has the ability to collect and transmit personal information," Bono said. "From its original introduction, the SPY ACT has evolved through a tremendously collaborative bipartisan effort to what we feel is strong and sound legislation. We ... are confident that this year we will see a spyware bill in the law books."
The SPY ACT would require a user's permission before software is downloaded onto a computer. It ran into objections from software vendors, who suggested that it could force them to notify users every time software scans their machines for updates. The SPY ACT also would prohibit unauthorized software from changing a browser's default home page, changing the security settings of a computer, logging keystrokes and delivering advertisements that the computer user can't close without turning the machine off or ending all sessions of the browser.
The bill Bono introduced is the same one passed by the House, except for a one-year extension in the bill's sunset clause, from December 2009 to December 2010. An earlier version of a Bono spyware bill, introduced in July 2003, sought to broadly prohibit spyware and defined it as "any computer program or software that can be used to transmit from a computer, or that has the capability of so transmitting, by means of the Internet and without any action on the part of the user of the computer to initiate such transmission, information regarding the user of the computer, regarding the use of the computer, or that is stored on the computer."
Some software vendors, including those that market antivirus update software, objected that the definition was overly broad and could make their services subject to fines.Some technology companies continued to call the amended version of the bill too broad, but authors of the amended version attempted to address concerns that the original bill outlawed a type of technology instead of outlawing bad activities.
Some consumer and privacy advocates supported the bill, however. The Center for Democracy and Technology, a civil liberties group, supports the bill's penalties, said Ari Schwartz, the center's associate director. "It would be a lot easier to get the message out in terms of deterrence," he said.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Gov't Legislation/Regulation White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Gov't Legislation/Regulation Webcasts