<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" version="2.0">
  <channel>
    <title>StopBadware Blog</title>
    <link>http://blog.stopbadware.org</link>
    
    <language>en-us</language>
    <ttl>40</ttl>
    <description>Regaining Control of Our Computers</description>
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/StopbadwareBlog" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="stopbadwareblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
      <title>A successful web chat</title>
      <description>&lt;p&gt;
	We&amp;#39;d like to express a heartfelt thanks to Adobe&amp;#39;s Brad Arkin, Mozilla&amp;#39;s Johnathan Nightingale, and the many people who observed and contributed to yesterday&amp;#39;s web chat. The topic, applications&amp;#39; role in protecting users from badware, proved interesting and engaging. You can read the transcript of the chat &lt;a href="http://www.stopbadware.org/events/apps-web-chat"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;
	We hope to do more of these web chats in the future. What topics would you like to see covered?&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=3MwL8U6cfm4:zh-Y1F4csug:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=3MwL8U6cfm4:zh-Y1F4csug:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/StopbadwareBlog/~4/3MwL8U6cfm4" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 27 Aug 2010 15:45:00 -0400</pubDate>
      <guid isPermaLink="false">urn:uuid:46ca2b54-c819-4975-866c-84f927be9c38</guid>
      <comments>http://blog.stopbadware.org/2010/08/27/a-successful-web-chat#comments</comments>
      <category>events</category>
      <category>stopbadware</category>
      <link>http://blog.stopbadware.org/2010/08/27/a-successful-web-chat</link>
    </item>
    <item>
      <title>Web chat: Applications' role in protecting users from badware</title>
      <description>&lt;p&gt;
	Badware often installs itself by taking advantage of bugs or exploits in software on the user&amp;#39;s computer. While some of these exploits are in the operating system or default web browser, badware increasingly is targeting other applications and browser plug-ins.&lt;br /&gt;
	&lt;br /&gt;
	What role can and should these applications&amp;mdash;and their developers&amp;mdash;play in protecting users from badware? Join Brad Arkin, Adobe&amp;#39;s director of privacy and security, and Johnathan Nightingale, Mozilla&amp;#39;s head of Firefox development, for a free moderated web chat next Thursday.&lt;br /&gt;
	&lt;br /&gt;
	&lt;strong&gt;Title:&lt;/strong&gt; Applications&amp;#39; role in protecting users from badware&lt;br /&gt;
	&lt;strong&gt;Date/time:&lt;/strong&gt; Thursday, August 26, 1-2 pm EDT&lt;br /&gt;
	&lt;strong&gt;URL:&lt;/strong&gt; &lt;a href="http://www.stopbadware.org/events/apps-web-chat" style="color: rgb(128, 0, 0); text-decoration: underline; font-weight: normal;"&gt;http://www.stopbadware.org/events/apps-web-chat&lt;/a&gt;&lt;br /&gt;
	&lt;strong&gt;Cost:&lt;/strong&gt; Free! No preregistration required.&lt;br /&gt;
	&lt;br /&gt;
	We hope you&amp;#39;ll join us on the 26th for what promises to be an informative and interesting discussion!&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=gTHEone3S34:YHG-x7WLesc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=gTHEone3S34:YHG-x7WLesc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/StopbadwareBlog/~4/gTHEone3S34" height="1" width="1"/&gt;</description>
      <pubDate>Thu, 19 Aug 2010 11:48:00 -0400</pubDate>
      <guid isPermaLink="false">urn:uuid:070509b7-6e86-437f-b6cf-be0442127e9e</guid>
      <comments>http://blog.stopbadware.org/2010/08/19/web-chat-applications-role-in-protecting-users-from-badware#comments</comments>
      <category>mozilla</category>
      <category>adobe</category>
      <category>events</category>
      <category>stopbadware</category>
      <link>http://blog.stopbadware.org/2010/08/19/web-chat-applications-role-in-protecting-users-from-badware</link>
    </item>
    <item>
      <title>The continuing evolution of StopBadware</title>
      <description>&lt;p&gt;
	As StopBadware and the environment in which we operate evolve, we continually evaluate where to focus our resources and attention. Over the next couple of months, we&amp;#39;ll be making a few changes that reflect our current priorities. Hiring a &amp;quot;&lt;a href="http://blog.stopbadware.org/2010/08/11/now-hiring-a-professional-raconteur"&gt;raconteur&lt;/a&gt;,&amp;quot; or communication specialist, is one such change. This will allow us to work more closely with the community, our industry partners, and our other constituents to ensure that effective techniques for protecting users from badware reach the greatest possible audience.&lt;/p&gt;
&lt;p&gt;
	Another change is that we&amp;#39;ll reduce&amp;mdash;for now&amp;mdash;our emphasis on technical research and &amp;quot;deep-dive&amp;quot; analysis of badware sites. In place of a dedicated research function, we&amp;#39;ll create a new, broader role that includes a bit of data sifting, along with hands-on systems work, testing, documentation, and more. (Job posting coming soon.)&lt;/p&gt;
&lt;p&gt;
	Finally, we&amp;#39;ll be introducing more events, like our &lt;a href="http://blog.stopbadware.org/2010/08/12/save-the-date-upcoming-webcast"&gt;upcoming web chat&lt;/a&gt;, that bring people together to discuss and share ideas about how best to protect users from badware.&lt;/p&gt;
&lt;p&gt;
	With these changes, along with our continued work assisting webmasters and our data providers, we believe that StopBadware will be in a great position to expand our impact and make the Internet safer for all of us.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=_gX_bupm93c:cTM3M118dsY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=_gX_bupm93c:cTM3M118dsY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/StopbadwareBlog/~4/_gX_bupm93c" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 13 Aug 2010 08:17:00 -0400</pubDate>
      <guid isPermaLink="false">urn:uuid:2a98aeeb-82a8-46e3-9da6-cf5cf3d217b5</guid>
      <comments>http://blog.stopbadware.org/2010/08/13/the-continuing-evolution-of-stopbadware#comments</comments>
      <category>stopbadware</category>
      <link>http://blog.stopbadware.org/2010/08/13/the-continuing-evolution-of-stopbadware</link>
    </item>
    <item>
      <title>Save the date: Upcoming web chat</title>
      <description>&lt;p&gt;
	Save the date! On Thursday, August 26, from 1-2 pm EDT, StopBadware will host a web chat on the topic &amp;quot;The role of third-party applications in protecting users from badware.&amp;quot; The featured &amp;quot;speakers&amp;quot; will be Brad Arkin, director of privacy and security at Adobe, and Johnathan Nightingale, head of Firefox development at Mozilla.&lt;/p&gt;
&lt;p&gt;
	More information will follow soon. Meanwhile, if your company is interested in sponsoring this event, please let us know!&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=MAIq9rMfACA:yGSZuP_XhTs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=MAIq9rMfACA:yGSZuP_XhTs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/StopbadwareBlog/~4/MAIq9rMfACA" height="1" width="1"/&gt;</description>
      <pubDate>Thu, 12 Aug 2010 16:18:00 -0400</pubDate>
      <guid isPermaLink="false">urn:uuid:70106c01-3902-4a63-bece-5cf83173cbe8</guid>
      <comments>http://blog.stopbadware.org/2010/08/12/save-the-date-upcoming-webcast#comments</comments>
      <category>events</category>
      <category>stopbadware</category>
      <link>http://blog.stopbadware.org/2010/08/12/save-the-date-upcoming-webcast</link>
    </item>
    <item>
      <title>Now hiring a professional raconteur!</title>
      <description>&lt;p&gt;
	StopBadware is hiring! If you know someone looking for a full-time communications job here in Harvard Square, be sure to refer him/her to the &lt;a href="https://docs.google.com/document/pub?id=1PwpNQ2TxfntcYbkF7BNlKHrUsAYg0eWcxxlRLWen2jU"&gt;job description&lt;/a&gt;.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=SacbfTYWSTU:7JW_6a4R39Q:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=SacbfTYWSTU:7JW_6a4R39Q:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/StopbadwareBlog/~4/SacbfTYWSTU" height="1" width="1"/&gt;</description>
      <pubDate>Wed, 11 Aug 2010 11:10:00 -0400</pubDate>
      <guid isPermaLink="false">urn:uuid:f835bc26-331c-4808-94ba-1241f6b9bb9f</guid>
      <comments>http://blog.stopbadware.org/2010/08/11/now-hiring-a-professional-raconteur#comments</comments>
      <category>stopbadware</category>
      <category>jobs</category>
      <link>http://blog.stopbadware.org/2010/08/11/now-hiring-a-professional-raconteur</link>
    </item>
    <item>
      <title>Americans want security, don't know how to get it</title>
      <description>&lt;p&gt;
	A &lt;a href="http://staysafeonline.mediaroom.com/index.php?s=43&amp;amp;item=62"&gt;study released today&lt;/a&gt; by the &lt;a href="http://www.staysafeonline.org"&gt;National Cyber Security Alliance (NCSA)&lt;/a&gt; and the &lt;a href="http://www.antiphishing.org"&gt;Anti-Phishing Working Group (APWG)&lt;/a&gt; indicates that most Americans are genuinely concerned about online safety and security. Furthermore, according to the study, they recognize their responsibility to contribute to the Internet&amp;#39;s overall security and are willing to take steps in that direction.&lt;/p&gt;
&lt;p&gt;
	The biggest obstacle, perhaps unsurprisingly, is the lack of clear, concise instructions on what users should do to protect themselves. This is an area in which we, as an industry, have to improve. When you combine the complexity and diversity of available technologies with a lack of consistency around messaging, terminology, and visual symbols, it&amp;#39;s no wonder that consumers are feeling confused.&lt;/p&gt;
&lt;p&gt;
	The upcoming National Cybersecurity Awareness Campaign, which the NCSA and APWG are spearheading, should be a step in the right direction. It promises a unified messaging campaign to increase awareness nationwide, and perhaps even internationally. Of course, if this survey is any indication, this will be a challenge, as the issue isn&amp;#39;t so much awareness of the problem, but rather awareness of the &lt;em&gt;solution&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;
	Over the coming months, StopBadware will be working with industry partners to help them do &lt;em&gt;their&lt;/em&gt; part to protect consumers from badware. Part of this, undoubtedly, will be consumer education. Just as we (and, by extension, our partners like Google and Firefox) now offer webmasters &lt;a href="http://www.stopbadware.org/home/security"&gt;specific tips&lt;/a&gt; on finding, removing, and preventing badware on their websites, we need to work together to present clear guidance for users on how to protect their computers, their handheld devices, and their online information.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=zrpIozEsvWA:dhyGRWrohwA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=zrpIozEsvWA:dhyGRWrohwA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/StopbadwareBlog/~4/zrpIozEsvWA" height="1" width="1"/&gt;</description>
      <pubDate>Tue, 10 Aug 2010 09:39:00 -0400</pubDate>
      <guid isPermaLink="false">urn:uuid:7111d9ce-3197-486c-a65c-bf2448753805</guid>
      <comments>http://blog.stopbadware.org/2010/08/10/americans-want-security-dont-know-how-to-get-it#comments</comments>
      <category>surveys</category>
      <category>stopbadware</category>
      <category>apwg</category>
      <category>ncsa</category>
      <category>consumers</category>
      <link>http://blog.stopbadware.org/2010/08/10/americans-want-security-dont-know-how-to-get-it</link>
    </item>
    <item>
      <title>Hijacked subdomains still serving malware</title>
      <description>&lt;p&gt;
	Last month the &lt;a href="http://blog.unmaskparasites.com/2010/06/17/malware-on-hijacked-subdomains-part-2/"&gt;Unmask Parasites blog&lt;/a&gt; wrote about attacks using hijacked sudomains of legitimate websites to serve badware. &amp;nbsp;At the time of that articles publication the attacks had been going on for a month already. &amp;nbsp;We are still seeing a lot of infected websites pointing back to solk.seamscreative.info (on port 8080) and other sites like it.&lt;/p&gt;
&lt;p&gt;
	The standard attack used in Driveby Downloads required the injection of iframes into normally benign sites however the landing or intermediary sites those iframes pointed to weren&amp;#39;t normally registered to benign users. &amp;nbsp;This represents an interesting evolution of tactics by creating another layer of innocent victim into the network of infections. &amp;nbsp;The attack has been fairly successful if in the last two months the infected subdomains haven&amp;#39;t been taken down yet. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;
	Considering our own methods of alerting the public to infections it is easy to see why. &amp;nbsp;The subdomains aren&amp;#39;t something the owners will be on the look out for and the DNS registrar likely has no idea that attacks are occurring on their customer base. &amp;nbsp;According to the blog post at Unmask Parasites the most affected DNS registrar seems to be GoDaddy. &amp;nbsp;I don&amp;#39;t know if this means there is some flaw in their DNS management panel or if legit customers have had their credentials stolen. &amp;nbsp;Either way this trend warrants more investigation.&lt;/p&gt;
&lt;p&gt;
	UPDATE 7/28: The GoDaddy abuse team has been notified.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=uV4x0WoMk5k:R5bAxFvazLk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=uV4x0WoMk5k:R5bAxFvazLk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/StopbadwareBlog/~4/uV4x0WoMk5k" height="1" width="1"/&gt;</description>
      <pubDate>Mon, 26 Jul 2010 16:43:00 -0400</pubDate>
      <guid isPermaLink="false">urn:uuid:3bf54d07-f0c2-44c2-adfc-612085926e27</guid>
      <comments>http://blog.stopbadware.org/2010/07/26/hijacked-subdomains-still-serving-malware#comments</comments>
      <category>trends</category>
      <category>godaddy</category>
      <category>subdomains</category>
      <category>infections</category>
      <link>http://blog.stopbadware.org/2010/07/26/hijacked-subdomains-still-serving-malware</link>
    </item>
    <item>
      <title>NSFOCUS, our newest data provider</title>
      <description>&lt;p&gt;
	We are pleased to welcome Chinese security firm &lt;a href="http://www.nsfocus.com/en"&gt;NSFOCUS&lt;/a&gt; as a new data provider! NSFOCUS joins Google and Sunbelt Software in feeding our &lt;a href="http://stopbadware.org/home/clearinghouse"&gt;Badware Website Clearinghouse&lt;/a&gt; with updated information about URLs they have discovered to be bad. Like all of our data providers, NSFOCUS will participate in our &lt;a href="http://stopbadware.org/home/faq#review_process"&gt;independent review process&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;
	We are particularly excited to work with NSFOCUS because their team&amp;#39;s extensive knowledge will give us insight into the often opaque world of Chinese networks and hosting providers.&lt;/p&gt;
&lt;p&gt;
	NSFOCUS&amp;#39;s press release about the data provider arrangement can be found &lt;a href="http://www.nsfocus.com/en/news/201007/687.html"&gt;here&lt;/a&gt;.&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=jTwNulNoLR0:OUpR468jho0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=jTwNulNoLR0:OUpR468jho0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/StopbadwareBlog/~4/jTwNulNoLR0" height="1" width="1"/&gt;</description>
      <pubDate>Fri, 23 Jul 2010 15:35:00 -0400</pubDate>
      <guid isPermaLink="false">urn:uuid:3ccaa10c-181d-4576-b698-8e7ee19e0e18</guid>
      <comments>http://blog.stopbadware.org/2010/07/23/nsfocus-our-newest-data-provider#comments</comments>
      <category>china</category>
      <category>nsfocus</category>
      <category>stopbadware</category>
      <link>http://blog.stopbadware.org/2010/07/23/nsfocus-our-newest-data-provider</link>
    </item>
    <item>
      <title>StopBadware welcomes new developer</title>
      <description>&lt;p&gt;
	StopBadware is pleased to welcome Matthew Shanley, our new lead developer! As we mentioned previously, our current lead developer, Brandon, will be heading off soon to tortue himself for three years as a law student.&lt;/p&gt;
&lt;p&gt;
	Matt joins us from Constant Contact, where he worked on their web development team. He holds a Master&amp;rsquo;s of Fine Arts in Interrelated Media from Massachusetts College of Art and Design, a Bachelor&amp;rsquo;s of Science in Electronic Media, Art, and Communication from Rensselaer Polytechnic Institute, and also attended Cornell University. He&amp;#39;s also an all-around cool guy, and we&amp;#39;re glad to have him on the team!&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=yqr2UnG31Jc:hOLuVF7SyA8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=yqr2UnG31Jc:hOLuVF7SyA8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/StopbadwareBlog/~4/yqr2UnG31Jc" height="1" width="1"/&gt;</description>
      <pubDate>Wed, 14 Jul 2010 16:18:00 -0400</pubDate>
      <guid isPermaLink="false">urn:uuid:39e4d19a-6122-4764-a68f-a31d0ca4756b</guid>
      <comments>http://blog.stopbadware.org/2010/07/14/stopbadware-welcomes-new-developer#comments</comments>
      <category>stopbadware</category>
      <link>http://blog.stopbadware.org/2010/07/14/stopbadware-welcomes-new-developer</link>
    </item>
    <item>
      <title>Establishing expectations for AV vendors</title>
      <description>&lt;p&gt;
	At StopBadware, we&amp;#39;re currently revising our guidelines for badware applications. The goal of these guidelines is to distinguish between applications that are badware (defined as &amp;quot;software that fundamentally disregards a user&amp;#39;s choice about how his or her computer or network connection is used&amp;quot;) and those that aren&amp;#39;t. One major reason for distinguishing badware from non-badware applications is to help people make informed choices before installing software that may compromise their privacy or security. &lt;/p&gt;
&lt;p&gt;
	It is in this context that we ask a question that has been troubling us: &lt;strong&gt;if a &amp;quot;legitimate&amp;quot; anti-virus or security product has to send data about your computer use (e.g., your web search or browsing history) back to the vendor&amp;#39;s servers to protect you as promised, how clearly should that data usage be disclosed?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;
	Historically, we have thought of surreptitious collection of this type of data as a badware behavior. But what if the data isn&amp;#39;t really being collected or used in any nefarious way, and the transmission of the data is necessary to make the product work as intended?&lt;/p&gt;
&lt;p&gt;
	Consider a product like McAfee SiteAdvisor, a free browser plug-in that informs you of the safety of websites as you visit them or while browsing through search results. SiteAdvisor has to query a McAfee server with the URL (or the hash of the URL) of every site you visit or find during a search.&amp;nbsp; This means that, if McAfee wanted to (or if a rogue employee gained access), a profile of your browsing history could be compiled and tied back to your IP address. Yet this is never disclosed in any visible way prior to or during installation. In fact, it&amp;#39;s not even in the Privacy Policy. (It could be considered covered by a vague provision in the EULA about the collection of personal information from your computer necessary to the function of McAfee&amp;#39;s security products.)&lt;/p&gt;
&lt;p&gt;
	This is not unique to SiteAdvisor. Many AV products now query a centralized database about URLs and/or executables to ensure users are protected. In our experience, most of these products fail to disclose this potential threat to a user&amp;#39;s privacy in any meaningful way.&lt;/p&gt;
&lt;p&gt;
	So, back to the question. Is this a badware behavior, one that in this case is being perpetuated by several well-respected software companies? Or is it reasonable to expect that users either know or wouldn&amp;#39;t care that their security comes at the price of a company having access to some private data? Is it dependent on the trustworthiness of the vendor or the stated use of the data once it&amp;#39;s been received? What should we expect as a &lt;em&gt;minimum&lt;/em&gt; bar from AV vendors whose products behave in this way?&lt;/p&gt;
&lt;p&gt;
	Please let us know your thoughts in the comments!&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=e1UwuBawb0U:iyyMcLJgAQ4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/StopbadwareBlog?a=e1UwuBawb0U:iyyMcLJgAQ4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/StopbadwareBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/StopbadwareBlog/~4/e1UwuBawb0U" height="1" width="1"/&gt;</description>
      <pubDate>Wed, 07 Jul 2010 11:02:00 -0400</pubDate>
      <guid isPermaLink="false">urn:uuid:e00ec90e-c5f5-4412-90da-17c812320c1a</guid>
      <comments>http://blog.stopbadware.org/2010/07/07/establishing-expectations-for-av-vendors#comments</comments>
      <category>guidelines</category>
      <category>policy</category>
      <category>antivirus</category>
      <link>http://blog.stopbadware.org/2010/07/07/establishing-expectations-for-av-vendors</link>
    </item>
  </channel>
</rss>
