Stanford CIS

Web-Wide Cops

By Colin Rule on

John Dunn, on the PCWorld web site: "The Internet needs to be globally regulated if it is to have any chance of stopping scams such as security 'scareware', a researcher has suggested...

According to Mary Landesman of ScanSafe, the recent Federal Trade Commission (FTC) injunctions against two companies accused of distributing fake anti-virus programs is a step in the right direction but against a backdrop of widespread abuse.

Landesman was referring to the recent case against US outfits, Innovative Marketing and ByteHosting Internet Services, both of which were said to have peddled bogus anti-virus programs designed to tempt users into paying to clean their PCs of non-existent malware.

The problem is that piecemeal action is fighting against a rising tide of such scams, fuelled by the release of automated tools in 2007 that made it simple for criminals to set up such cons.

"Large numbers of users are trusting 'scareware' scams as fraudulent companies are using increasingly sophisticated techniques to lure users into downloading the software. Some of the scams we have seen are branded Anti-virus 360 and look extremely convincing," said Landesman.

Part of the problem dated from the de-regulation of Internet registration nearly a decade ago with the removal of the monopoly enjoyed by Network Solutions, she agreed. That had allowed a multitude of unregulated companies to decide who was and who wasn't allowed to set up shop, making official oversight almost impossible.

"Hosts and registrars need to be held accountable. [At the moment] security researchers report sites but get no response," she said..."

Why can't ICANN play this role?  Or some UN body?  I don't agree that ending Network Solutions' monopoly was the key decision here.  It was absolutely the right thing to do.  Who wants a central name registrar deciding who should and shouldn't be able to get a domain name?  The internet would not have achieved a tenth of what it has achieved if Network Solutions still controlled all domains.  But that said, I am sympathetic to the broader point -- we need better global coordination in fighting these scammers.

Published in: Blog