Slashdot Log In
Schneier On Scareware Vendor Lawsuits
Posted by
CmdrTaco
on Thu Oct 02, 2008 08:25 AM
from the now-what-about-the-car-warranty-robot-who-calls-every-day dept.
from the now-what-about-the-car-warranty-robot-who-calls-every-day dept.
Bruce Schneier's blog says "This is good: Microsoft Corp. and the state of Washington this week filed lawsuits against a slew of 'scareware' purveyors, scam artists who use fake security alerts to frighten consumers into paying for worthless computer security software. "
Related Stories
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
You are trying to file a lawsuit. Cancel or Allow? (Score:2, Informative)
Microsoft is as big a culprit of this as anyone.
Re: (Score:3)
I'm actually not sure what you're trying to say... Your comment vaguely appeals to \. sentiment, but what exactly are you getting at? MS spreads FUD is somewhat off-topic...
Are you suggesting that MS scares users with security alerts into purchasing their software, which is legendary for being secure?
Re: (Score:3, Insightful)
Microsoft is sueing themselves? (Score:5, Funny)
Sounds a lot like an average Windows advertisement.
Unnecessary blog reference (Score:5, Insightful)
Why does this even reference Bruce Schneier's blog? There's no added value from there. Why not just reference the original article?
Re:Unnecessary blog reference (Score:5, Insightful)
Look at the name of the submitter.. this is blatant self promotion.
And, as is often the case, Schneier's blog doesn't add anything to the article either.
Parent
Re:Unnecessary blog reference (Score:4, Funny)
Repeat after me: Ad revenue from hits/views.
Parent
Re:Unnecessary blog reference (Score:5, Insightful)
Bruce Schneier has a lot more credibility in the security field than the Washington Post, the State of Washington, and Microsoft all put together.
Parent
Re: (Score:3, Funny)
Bruce Schneier has a lot more credibility in the security field than the Washington Post, the State of Washington, and Microsoft all put together.
That doesn't mean much. My left arse cheek has a lot more credibility in the security field than the Washington Post, the State of Washington, and Microsoft all put together.
Re:Unnecessary blog reference (Score:5, Informative)
Actually, Brian Krebs at the WaPo has a lot of credibility, and has been writing very good well-researched columns on computer security for as long as I've been reading that paper. What's your left arse cheek done lately?
Parent
Re: (Score:2)
What an awesome quote on his book cover (Score:3, Funny)
Re:What an awesome quote on his book cover (Score:5, Funny)
Parent
Re: (Score:2)
Yeah, not to mention that the advent of mp3 players and decent portable speakers means anyone who drops $1.25 into a jukebox to listen to whatever shitty music it has in rotation is a tool.
Hmm... do I want to pay through my nose to listen to Journey, or should I just whip out my cell phone and crank some Black Flag? Gee, this is a toughie...
Re: (Score:2)
Why?
I heard this claim several times already, but never seen an explanation. As far as I can tell, he's a pretty smart guy and what he says seems to make sense.
So what's the problem with him?
Re: (Score:2)
It's like people who say "I love reggae. Bob Marley is awesome".
It is usually just them name-dropping, because he is the only security guy they know of. Not sure I'd call him the rock star of the industry though- Dan Kaminsky and Johnny Long have that covered.
That said, having read a lot of security literature, and all of Bruce's books, he is the best mind I can think of on high-level security theory- what works, what doesn't, and how to evaluate a solution.
Re: (Score:2)
So what's the problem with him?
There is none. "QuantumG" (I assume he thinks he is the indivisible entity of a gangster) is just angry that people don't shun the "obvious" names.
Scareware (Score:2, Funny)
Re: (Score:2)
If Schneier wants to stop scaring people he should consider trimming his beard.
Halloween's coming up.
A state government and Microsoft both doing something I approve of? What's this world coming to?
Re: (Score:3, Funny)
Hell. Now serving ice cubes.
Re: (Score:3, Funny)
I don't know, add glasses and a crowbar and he could star in a videogame. Seems to me like the kind of guy you want talking about computing.
Re: (Score:3, Funny)
Never!
I wouldn't trust a cryptographer without a beard.
Wasn't their a TV advert about this? (Score:3, Funny)
scam artists who use fake security alerts to frighten consumers into paying for worthless computer security software
It was an Apple thing I think warning about some company who was pushing some "extra secure" version of its operating system which in fact gave you less performance and kept nagging at you the whole time. Yup I thought so [youtube.com].
Oh wait this is some OTHER companies who use security as a scare threat via nagging messages to get you to buy software.
Re: (Score:2)
Oh wait this is some OTHER companies who use security as a scare threat via nagging messages to get you to buy software.
You mean M$ "scares" users with UAC to buy Vista? You got some problem with your logic.
Last time I was checking [google.com] that trick didn't fly.
If this are lawsuits we're talking, somebody should charge M$ with false advertisement: many end-users were made to think that thanks to UAC Vista is more secure than XP.
FAKE security warnings, for Windows? (Score:4, Insightful)
I'm truly impressed that people can come up with security warnings about Windows that are not true... after all, is there anything as insecure as Windows?
The only thing I think they may have a case with is of course the fake software, as in software that does not do what is advertised. And I'm not even thinking of Windows itself this time.
Re:FAKE security warnings, for Windows? (Score:5, Interesting)
If you run a linux os with a modern web browser, and you visit a site with the scareware it is mildly amusing to see that your registry is screwed up and the site looks like internet explorer in colour scheme but you can download an exe to fix.
Its happened twice to me, and i find them amusing.
Im quite sure this is how windows zombies get signed up, but my penguin knows better.
Parent
Re: (Score:2)
Re:FAKE security warnings, for Windows? (Score:5, Funny)
...after all, is there anything as insecure as Windows?
Emo kids?
Parent
Re: (Score:2)
WARNING! Your computer may have spyware. Click here for our FREE REGISTRY SCAN!
Re:FAKE security warnings, for Windows? (Score:4, Insightful)
Were those attack vectors directed at Linux or at packages running on Linux?
Apache != Linux
MySQL != Linux
etc
Parent
Re: (Score:2)
In that case you should say the same about Windows. Most of the attacks (particularly drive-by attacks related to surfing) are targeted at IE, an application. Oh bad example, according to MS it's an integral part of the OS. Never mind.
Then there are attacks directed at Outlook, ISS, and so on. Very few are directed at the Windows core. Same will account for Linux: unless the attack is done locally (most are over a network), it is always an application that is the first line of defense.
Re: (Score:2)
Yes I know, big strides have been made by Microsoft to improve it. The whole design of Windows unfortunately has never been with security in mind, this in contrast to Unix and it's clones and derivatives which is designed to be part of a network and multi-user.
Microsoft has a lot to do to really make it secure, and when seven years of development for a minor upgrade (XP to Vista) can't fix it, nothing short of starting from scratch can.
Win XP/Vista is a huge improvement over 98 and ME, however the number
colors (Score:4, Interesting)
Is that too obvious?
Re:colors (Score:5, Insightful)
Too obvious for your normal user, yes. Your average geek isn't going to get fooled by these things anyways (heck with the way NoScript and my popup blockers are set I don't see them at all anyways). But to the guy who fumbles with the power button and whose eyes glaze over when you speak of "cut and paste", changing the window colors and then having the foresight to pickup on a different color showing up being bad, is way beyond their capabilities.
Parent
Re: (Score:3, Insightful)
One of my insights doing a stint behind a helldesk was that some otherwise competent, intelligent people will disengage their thought process when sitting behind a keyboard. Sometimes I felt like psychiatrist - or at least what I suspect many of them do:
1. Listen to problem.
2. Restate problem as a question.
3. Confirm answer given by customer is correct.
4. Assure customer that while correct answer WAS somewhat obvious, we get it all the time and a lot of folks don't figure it out on their own. Add reas
Re: (Score:2)
True Story:
After reformatting, one of the first things I do is go to AVG's website and download some virus protection. I google, and, thanks to a shitty mouse or my stupidity, accidentally click on another legitimate website. Adware, crapware, and more all taint the once pure machine via IE. All because AVG returned a couple of sites that are no where near legitimate.
No warning would have helped in that case.
Oh, it gets worse. (Score:2, Insightful)
but surely somebody could just change the desktop colors...
It's worse than that, because it's even more obvious.
This is where the end-user epic fail really is:
Security Alert - Windows Internet Explorer
Or
Security Alert - Mozilla Firefox
End users have so trained themselves to not actually read dialogs that they simply can't tell something they've seen before from something they have not.
It doesn't take a genius to sit at a computer for hours, and hours, and hours on end, every day, at work and at home, to recognize that your "Security Alert - Windows Internet Explorer" causes the cursor to turn into a pointing finger, just like a hyperli
Re: (Score:2, Insightful)
I'm saying that if you're too ignorant to understand that you're asking for it because you feel it's not worth your time to learn anything from your hands-on experience, then it's your own damn fault that you put yourself in that situation. I never said there was anything right or just about crime.
Re: (Score:2)
I've occasionally seen actual dialog boxes pop up with these warnings back when I used Windows and IE, so it isn't just graphics that look like boxes.
Re: (Score:2)
Courts determining what's required for security? (Score:5, Insightful)
The law referenced "makes it illegal to misrepresent the extent to which software is required for computer security or privacy." This is such a fishy thing that I'm not really sure if I want courts to determine what exactly is required and therefore whether it is being misrepresented.
Now, maybe there's a case for fraud if the program doesn't do what it purports to do in its advertising, but that doesn't seem to be what's at stake here.
There also might be a case for fraud if, perhaps, the advertising pop-ups are being confused for actual Windows messages. But I suppose in the "real world" advertisements mimic other things to be creative, but are still fairly obviously ads.
Just not sure I like the sound of a law that requires a judge or jury to determine what's required for computer security.
--
Hey code monkey... learn electronics! Powerful microcontroller kits for the digital generation. [nerdkits.com]
Re:Courts determining what's required for security (Score:4, Interesting)
Parent
good point (Score:2)
It kinda looks like this law is written almost exactly with WGA and other nasties in mind.
all anti-virus companies (Score:3, Insightful)
"the law makes it illegal to misrepresent the extent to which software is required for computer security or privacy,and it provides actual damages or statutory damages of $100,000 per violation, whichever is greater."
lol, so all the anti-virus software companies(Norton, NOD32,VET etc) and anyone selling 'personal firewall software' is pretty much screwed.
Re: (Score:2)
While a lot of AV makers will try to convince you that you'll be screwed without the $100 security suite, they tend to sell what they say they are selling and don't have fake positives in the product in an effort to try to convince you to buy them.
And anyone that ran Windows XP RTM/SP1 knows that a firewall of some sort was required (hardware or non-Microsoft software) due to all the exploits. You could be own
More Government Regulation (Score:3, Funny)
Re: (Score:2)
You're right!
But, I can tell from your message that you have a high level of contamination in your home drinking water. It's already affecting your speech. I'm from the Federated Department of Drinking Water Security. (Flashes badge that is a perfect knock-off) You have nothing to fear though, for a nominal fee, I can provide you with a water security solution that will keep your faucet from broadcasting it's location to the evil germs and heavy metals that are lurking just outside.
It's about time (Score:2, Interesting)
Scaring consumers = basis of modern advertising (Score:3, Interesting)
Re: (Score:2)