On TechRepublic: Badly configured laptop ruins man's life
BNET Business Network:
BNET
TechRepublic
ZDNet

By Declan McCullagh
Posted on ZDNet News: May 4, 2005 11:42:00 AM

Ben Edelman may be spyware's most dangerous enemy.

The 25-year-old researcher has spent years analyzing how spyware and adware programs work and disclosing his findings publicly. That often results in red faces and, occasionally, lawsuit threats from companies like WhenU and Claria, formerly known as Gator.

When testing spyware and adware, Edelman isn't about to sacrifice his own Windows XP computer. So he uses the VMware utility to create a virtual Windows box.

"I infect the hell out of it," he says. "It destroys the infected machine."

A law student at Harvard University, Edelman also is completing a doctoral degree in economics. CNET News.com caught up with him after he spoke at a conference in San Francisco sponsored by News.com's sister site, Download.com.

Q: What got you interested in spyware in the first place?

Edelman: I took a call from the plaintiffs in the Washington Post case against Gator. They thought what Gator was doing was absolutely destructive to the availability of free content on the Web. After all, if advertisers could buy ads from Gator to reach the Washington Post's audience, who would buy ads from the Washington Post?

I happened to think they were right. But the case settled out of court on the eve of trial so we didn't find out for sure whether Gator's business was legit.

How much time have you spent since then on spyware-related topics?

Edelman: It's scary. It's what gets me out of bed in the morning right now, more so than classes, more so than my dissertation research. I probably spend 30 hours a week. It's been nonstop for the past 15 months. Before that, it was quite a bit less intense.

What was the most interesting thing you've discovered?

Edelman: There's just a huge amount of money changing hands here. The biggest, richest American companies are buying advertising through spyware. The biggest, richest venture capital firms are investing in those who make this kind of unwanted software. That's names like American Express, Sprint PCS, Disney, Expedia, Guy Kawasaki's firm.

It's absolutely fascinating to watch Symantec and McAfee struggle with this...Virus writers don't fight back.
You're using the word spyware. But you also mean the advertising-based networks with pop-up ads, right?

Edelman: Absolutely right. My claim is that each of the so-called adware networks has obtained installations and is still obtaining installations in ways that offer such poor notice and obtain such limited consent--sometimes none at all--that users can't fairly be said to have consented. If they didn't consent, and their activities are being monitored or transmitted, then that's spying.

Have you ever been threatened by spyware makers or adware makers?

Edelman: Yes. Some vendors have challenged the permissibility of my methods, for example, Gator was awfully angry when I posted a Web service that let any Web site operator see how Gator was targeting their site with competitors' pop-ups. They sent a series of legal papers, complaints, threats to me and my then-bosses at Harvard's Berkman Center.

I seem to remember that you had written some controversial software that tested what one adware program was doing--I think it was WhenU.

Edelman: I can't comment about that.

Ask Jeeves seems to be an above-the-board company. What's your complaint with them?

Edelman: The core problem is Ask Jeeves' installation practices. Sometimes their software gets installed without any notice or consent at all through security hole exploits. When they do ask for permission, they don't always tell users everything they need to know to make an informed choice. For example, when installing a Web browser toolbar, they use euphemisms like "directly accessible from your Web browser" instead of the obvious and natural word "toolbar."

You don't have any objection to pop-up applications like WhenU or Claria as long as the user knows what they're getting?

Edelman: I have no comment on any matter pertaining to WhenU. As to Claria, their core business seems to me to be troubling because it's so parasitic. They can only show ads thanks to users requesting other sites which get no share of the revenues from those ads.

Suppose a site spends a million dollars on a Super Bowl ad or $3 on a Google pay-per-click ad. Claria's pop-up then siphons away the resulting users. This undermines the incentives for sites to promote themselves through legitimate advertising.

Ask Jeeves has a search engine that nobody really wants to go to. To get users to come, they push these toolbars.
What's the latest in terms of threats to anti-adware companies who label certain software "spyware"?

Edelman: The background here is that historically users have been tricked into getting all manner of unwanted software into their computers. Their computers become slow, unreliable. Companies step in to help by offering detection programs.

From the perspective of the spyware makers these detection programs are bandits: they take the spyware off the users' computer after the spyware makers have gone to such lengths to infect the computers in the first place. So the spyware companies have been attempting intimidation tactics to force the removers to omit removal of particular advertising software.

Name names. Who's been the most litigious?

Edelman: One of the few companies to file suit is Claria, which sued PC Pitstop in 2003 alleging unfair business practices when PC Pitstop told its users its view of Claria's software. And New.net took the novel approach of suing Lavasoft in federal court.

Mostly these threats don't lead to litigation. Either the spyware vendors give up or they succeed in their intimidation tactics without having to go to court. There have been at least half a dozen examples just in the past few months.

It's absolutely fascinating to watch Symantec and McAfee struggle with this. It's a very different problem from what they're used to. Virus writers don't fight back.

You've been on the attack against Ask Jeeves recently. Why?

Edelman: They're getting installations from kids' sites. I've been trying to figure out how these programs have such a large installed base: Who in their right mind would agree to have their computer become a vehicle for pop-up ads? It turns out that many of these programs target kids. They advertise their software at kids sites. They bundle it with videogames. They use advertisement images like smiley faces.

Ask Jeeves has a search engine that nobody really wants to go to. To get users to come, they push these toolbars. But if the toolbars are installed without proper notice and consent, then the entire business collapses. They have no legitimate business source of any substantial traffic to their web site.

Ask Jeeves just tries to get people to download their toolbar. Does that make it spyware or adware?

Edelman: It's not exactly spyware like the others. It doesn't show pop-up ads. As far as I know it doesn't track and transmit to its servers every Web site you visit. Yet it uses equally tricky installation tactics. (Editor's note: This week, CBS MarketWatch calculated that Ask Jeeves is valued at $1.8 billion and receives up to two-thirds of its search traffic from sources that also distribute adware.)

How much money have you made by consulting for anti-adware companies so far?

Edelman: I've made enough to pay for law school.

What next?

Edelman: I don't know. I might end up teaching. I can see myself practicing law, and potentially serving as some sort of a professional consultant.

  • Talkback
  • Most Recent of 212 Talkback(s)
Better Than Spying
Well, if they didn't ask my permission, it's not my problem. Ignorance is no excuse, just ask a police officer when he pulls you over for doing 35 in a school zone. They still owe me for they processo... (Read the rest)
Posted by: DRogue6 Posted on: 02/17/06 You are currently: Logged In | Log out
Looks to me like . . . James Dean_z   | 05/04/05
Could have been cured long ago Too Old For IT   | 05/04/05
Maybe ... maybe not... dalecosp   | 05/04/05
Black box is spyware MacGeek2121   | 05/04/05
Not to mention rsouza@...   | 05/05/05
MSAS is not spyware! Uncle Buck   | 05/12/05
spyware Hyperload Mah Jongg GeoWolford   | 05/13/05
Try this. Uncle Buck   | 05/13/05
Looks to me like broom   | 05/04/05
Public execution would stop... Anton Philidor   | 05/05/05
Public Executions!!! rsiron2000@...   | 05/06/05
when you kill one... linuxoverwindows   | 05/07/05
Message has been deleted. MIS Master   | 05/04/05
Yes, but this is a Windows ONLY problem Jeff Spicoli   | 05/04/05
they dont have time for you 4% Linux strokers MIS Master   | 05/04/05
Message has been deleted. Jeff Spicoli   | 05/04/05
yes, but but tomhood@...   | 05/04/05
You obviously know nothing because... Windroid_Deprogrammer   | 05/04/05
Hey ZDNet, please read... Windroid_Deprogrammer   | 05/04/05
False info helps no one. Tank252ca   | 05/04/05
Nope Jeff Spicoli   | 05/04/05
False info? dimonic   | 05/04/05
PIllory be d*mned, let's give 'em 39 lashes apiece... dalecosp   | 05/04/05
WOW DalyDose   | 05/04/05
You're missing it dude-aloo Jeff Spicoli   | 05/04/05
You are working for MS dimonic   | 05/04/05
I look at it this way Jeff Spicoli   | 05/04/05
Not everyone reads the news. The King's Servant   | 05/04/05
You so crazy mmck   | 05/06/05
Jeff you ARE an.... DragonBRockin   | 05/04/05
did I hit a nerve? Jeff Spicoli   | 05/04/05
Nope... DragonBRockin   | 05/04/05
Hey delete message police, over here^^^ Windroid_Deprogrammer   | 05/04/05
Nice try Jeff... DragonBRockin   | 05/04/05
Windroid_Deprogrammer = MepisLINUXuser Windroid_Deprogrammer   | 05/04/05
Jeff you're missing the point qtrback   | 05/04/05
%3 - %7 $$$$ develop stemcellphone   | 05/06/05
RE: You're missing it dude-aloo nightshade0143   | 05/05/05
They "deserve" to be toyed with??? alhefner   | 05/06/05
ok...time the hell out.... rob.astleford@...   | 05/04/05
What good would Linux a real Linux Virus do? klmmicro   | 05/05/05
Microsoft know their users. Anton Philidor   | 05/05/05
A lot of users foresake security for said same reason FilledOut   | 05/05/05
.. so waiting for the wailing Too Old For IT   | 05/04/05
...as are the rest of us... dalecosp   | 05/04/05
RE: .. so waiting for the wailing nightshade0143   | 05/05/05
It's not a Windows problem, it's a legislative one. digital@...   | 05/04/05
Not so fast... dalecosp   | 05/04/05
remember, focus on the desease qtrback   | 05/04/05
Solution or part of the problem?? TotalKayeos   | 05/04/05
RE: It's not a Windows problem, it's a legislative one. nightshade0143   | 05/05/05
Wake up!! bammike   | 05/04/05
Dear uniformed Mac-sucking tool, workgroup@...   | 05/04/05
You obviously don't read the Microsoft website Bennopia   | 05/08/05
Right, and just how may magical pixies fly out? workgroup@...   | 05/19/05
BlaBlaBla rsouza@...   | 05/05/05
RE: BlaBlaBla Linux User 147560   | 05/05/05
break and entry pesky_z   | 05/04/05
Don't use a Masterlock? You deserve to be robbed blind! Jeff Spicoli   | 05/04/05
sales pitch still isn't working MIS Master   | 05/04/05
that's because you enjoy being whipped.. Jeff Spicoli   | 05/04/05
Message has been deleted. MIS Master   | 05/04/05
Message has been deleted. Jeff Spicoli   | 05/04/05
Blame the victim osreinstall   | 05/04/05
Love my little Mac Bill4   | 05/04/05
That's a valid point woot!   | 05/04/05
And.. Jeff Spicoli   | 05/04/05
What are you talking about? jpfitz@...   | 05/04/05
Don't be embarassed LinuxHippie   | 05/04/05
so to recap... Cahill, US Marshall   | 05/04/05
Good Answer! brian.giordano   | 05/04/05
Yet, another Microcult member... Windroid_Deprogrammer   | 05/04/05
Really? Linux User 147560   | 05/05/05
If you move to a Mac the advertisers won! - until next time osreinstall   | 05/04/05
Did you shut the M$pyware off? Windroid_Deprogrammer   | 05/04/05
Go back to your other alias Mepis osreinstall   | 05/04/05
I like this screen name... Windroid_Deprogrammer   | 05/04/05
It is 100% client mode osreinstall   | 05/04/05
Its more like this... kdaulton   | 05/04/05
Nah Jeff Spicoli   | 05/04/05
Ok.. So.. In that case... Wolfie2K3   | 05/04/05
Times have changed dimonic   | 05/04/05
Bingo!! rob.astleford@...   | 05/04/05
You sound like me... Windroid_Deprogrammer   | 05/04/05
Oops, that's windohs, not windows, sorry (nt) Windroid_Deprogrammer   | 05/04/05
Thankyou for the compliment... Windroid_Deprogrammer   | 05/04/05
no one deserves to be robbed Youdontget Myrealname   | 05/05/05
Congress H2929 LaSenorita   | 05/04/05
Good thinkin qtrback   | 05/04/05
Spyware Removal Tools LaSenorita   | 05/04/05
add these to your list... dalecosp   | 05/04/05
Lets not forget... DragonBRockin   | 05/04/05
warning on Spyware Blaster Neil Parks   | 05/04/05
Good advice!!! DragonBRockin   | 05/04/05
Spyware Removal Tools yableep   | 05/04/05
Maybe, maybe not... BitTwiddler   | 05/04/05
Thanks for the tip qtrback   | 05/04/05
I like CounterSpy lildreamweaver   | 05/05/05
Spybot is good, but... BitTwiddler   | 05/04/05
I use both Spybot and Ad-Aware doctormoriarty   | 05/05/05
Don't blame us qtrback   | 05/04/05
Spyware removal advice Paul.Quirk   | 05/05/05
Free AdAware does work Anton Philidor   | 05/05/05
Knowing vs unknowing Dr_Zinj   | 05/04/05
The sweetness of vindication!!! Thuss80   | 05/04/05
Hang 'em all by the gonads bammike   | 05/04/05
That would severly limit the posters on Zdnet FilledOut   | 05/05/05
A Virus is merely a harmless annoyance dbrimlow   | 05/04/05
Harmless annoyance hrengifo   | 05/04/05
Applause qtrback   | 05/04/05
Here is an idea for you Linux User 147560   | 05/04/05
brimlow on;y 1/2 right; wrongthink re: virus... ricmeyer@...   | 05/04/05
LOL! dbrimlow   | 05/05/05
I Found A Great Antivirus Program lildreamweaver   | 05/06/05
virus vs spyware hesim   | 05/04/05
Spyware on Warez & Kazaa l.bancroft   | 05/04/05
New.Net not removed by SpyBot S&D by default just_wondering   | 05/04/05
Umm, if you read up, you will... Windroid_Deprogrammer   | 05/04/05
ignoe, not remove qtrback   | 05/04/05
WhenU revealed Melgibstone   | 05/04/05
'No comment' - why? what's he hiding? buran   | 05/04/05
Think about it.... jesup   | 05/04/05
WhenU's gone lawsuit happy doctormoriarty   | 05/05/05
Spy ware with so called free programs AZson   | 05/04/05
Spybot vs. Eudora meckles   | 05/04/05
Logic dictates... aaron91983   | 05/04/05
Spyware The Punisher   | 05/04/05
instant execution WarHippy   | 05/28/05
Charge for Spyware Allen_z   | 05/04/05
Have you been tricked into buying an Operating System johnpall@...   | 05/04/05
tricked into buying an Operating System doc_cotton   | 05/28/05
Tricked? WarHippy   | 05/28/05
Here is what the law should look like... Windroid_Deprogrammer   | 05/04/05
Whoa!!!! DragonBRockin   | 05/04/05
Ever Been Tricked Into An OS Upgrade By Microsuck? itanalyst   | 05/04/05
itanalyst DragonBRockin   | 05/04/05
Hey dude, the name is a joke and... Windroid_Deprogrammer   | 05/04/05
Its all good dude DragonBRockin   | 05/04/05
Also... DragonBRockin   | 05/04/05
Okee dokee then. (nt) Windroid_Deprogrammer   | 05/04/05
Typo correction -->than hackers (not then) oops Windroid_Deprogrammer   | 05/04/05
You don't have to be tricked... BitTwiddler   | 05/04/05
I love term 'drive-by install', makes me feel... Windroid_Deprogrammer   | 05/04/05
Don't expect legislative help the_doge   | 05/04/05
I think members of congress like... Windroid_Deprogrammer   | 05/04/05
tricked isn't the word for it fmbrowniii   | 05/04/05
I am sure you are not the first to... Windroid_Deprogrammer   | 05/04/05
that's buy, not by, sorry. (nt) Windroid_Deprogrammer   | 05/04/05
tricked stemcellphone   | 05/06/05
linux spyware 007lizard   | 05/04/05
Linux is safe from spyware matrixdomain   | 05/04/05
Ease of use=ease of infection doctormoriarty   | 05/05/05
Windows can easily be made safe mggordon   | 05/05/05
Windows can easily be made safe doc_cotton   | 05/28/05
Get Noticed WarHippy   | 05/28/05
Breaking and Entering Maximum Overdrive   | 05/04/05
IN DEFENSE OF ADWARE scott.sangster@...   | 05/04/05
Are you serious? ploco@...   | 05/04/05
It's because of the Linux User 147560   | 05/04/05
Well Said Altern_z   | 05/06/05
Analogy -- close but Wrong jjsch   | 05/04/05
RE: IN DEFENSE OF ADWARE? damox_z   | 05/04/05
Hear Hear! daver_z   | 05/05/05
Say What? Altern_z   | 05/06/05
there is no defence jb_bristol   | 05/21/05
Speking from Experience deanbu   | 05/04/05
SPYWARE goldbug@...   | 05/04/05
This is a Homeland Security Issue osreinstall   | 05/04/05
not quite aaron91983   | 05/04/05
Work with this a little osreinstall   | 05/04/05
Yeah, fire them b@$t@rd$, throw away the key! MepisLINUXuser   | 05/05/05
How about the Social Security Administration osreinstall   | 05/05/05
Reward courageous anti-spyware companies! sconnell@...   | 05/04/05
Better yet Zoraster   | 05/04/05
Linux is not that clean dgclay   | 05/04/05
Clean is not the issue (right now) mggordon   | 05/05/05
spyware mysongreg   | 05/04/05
Re Spies:CATCH 22 <---!!! mysongreg   | 05/04/05
Uh, what's your point? mejerry   | 05/04/05
Tricking Kid's into Spyware jjsch   | 05/04/05
time for ur wakeup call conan99   | 05/04/05
Tricking Kid's into Spyware jjsch   | 05/04/05
Adware/Spyware w2xaq   | 05/04/05
Love That Spyware! mejerry   | 05/04/05
Spying On The Spyware Makers dfarrich@...   | 05/04/05