NTA Monitor

Latest News

Finance industry faces serious IT security issues

23rd June 2008 The finance industry needs to keep its eye on the small change as well as the bigger picture of its security vulnerabilities Read More

Retail sector faces serious IT security issues

23rd June 2008 The retail sector needs to set out its stall and ring the changes in its security vulnerabilities if it is to avoid the potential for hackers to gain unauthorised system access and disrupt service availability Read More

IT managers have more security headaches to deal with

11th May 2008 NTA Monitor's 2008 Annual Security Report has revealed that the average number of vulnerabilities found per test have increased to 21 compared with 19 in 2007 Read More

Solutions not excuses for patch management warns NTA Monitor

23rd April 2008 Patch management is a vital security requirement for any organsation Read More
Date: 30th October 2005
Risk: Informational

The legal battle against adware and spyware programs has taken a new turn with a pair of putative class action complaints against Direct Revenue and 180Solutions, two companies facing allegations of installing online tracking software through security holes and making it virtually impossible for computer users to remove the unwanted programs.

Now that a judge has issued a preliminary order to allow one of the cases to proceed to trial, anti-spyware advocates say they believe the tide has shifted dramatically in favour of exasperated computer users.

In the Direct Revenue LLC suit, in which the actions alleged range from installing ad-serving software without user consent to privacy invasion and computer tampering, District Court judge Robert Gettleman ruled that the case can proceed on four of the five counts.

The order was a major blow to Direct Revenue's request to have the case thrown out. It also may open the floodgates to similar suits against other adware vendors.

Two weeks later, the Collins Law Firm, which filed the Direct Revenue suit, copied and pasted the point-by-point complaint in a new case against 180Solutions Inc., again seeking class action status for the complaint.

A spokesperson for the Collins Law Firm declined to speculate on new targets for such suits, saying it was difficult to track down the more notorious spyware companies, but he refused to rule out the possibility of new class action complaints.

"We received a nice ruling to allow that [Direct Revenue] case to go forward and we're pursuing those," the spokesperson said in an interview. "We're asking the court to allow millions of consumers to come together to join the complaint ... We want the court to hear the case on behalf of millions of consumers."

Some critics argue that class action suits only benefit lawyers and aren't necessarily the best way to fight against spyware, but, according to two prominent anti-spyware advocates, any move that forces adware vendors to clean up their installation and ad-serving practices eventually benefits consumers and businesses struggling to cope with the spyware scourge.

"I think it's too soon to say whether we'll see a flood of these kinds of suits. Clearly some folks would love to portray this litigation as a bad thing. But the fact is, there aren't that many companies that fall into the magic window herebased in the United States, with big powerful funding and easy-to-find headquarters, while also installing their software without consent (or paying others to do so)," said Ben Edelman, a researcher studying spyware and a Ph.D. candidate at Harvard University.

"It's probably still too soon to say what will happen for future class actions in this genre. Will the plaintiffs prevail? The initial Direct Revenue ruling means the plaintiffs will at least have a chance to put on more of their case. But that doesn't mean they'll win for sure," Edelman said.

Still, Edelman said he sees value in holding adware vendors accountable, and said it was no surprise that 180Solutions and Direct Revenue were the first to be sued.

"Non-consensual installations of 180Solutions through security exploits were reported as long ago as August 2004, 13-14 months ago," he said, pointing out that video evidence of non-consensual software installations almost always include 180Solutions and Direct Revenue.

Both companies have gone to great lengths to drop rogue affiliate distributors and soften their public images. But Edelman said he believes the evidence in support of the lawsuits is overwhelming.

"As these vendors report tens of millions of dollars of annual revenues, it's natural to want to hold them accountable for their actions. After all, they're earning this money from showing ads to users who were never asked to agree, and who never did agree," he said.

Eric L. Howes, an anti-spyware activist who serves as a consultant to Sunbelt Software, said he believes the class action complaints have the potential to snowball.

"What this law firm is effectively doing is showing how attorneys can pursue these cases. It's still very early on in these two cases but I'm sure there are other attorneys paying close attention to how they proceed. There are other plaintiff attorneys who are scouting around for other targets as well."

References