On last.fm: Taylor Swift photos and free music!
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 29 of 54:
Next »
« Previous
Windows and Spyware
I used to be a generic computer technician. But like all of my friends in this industry, the last two years have forced me to become a spyware-removal specialist. I'd estimate that a third to a half of my billable hours are spent searching for an removing spyware from customers' computers; and the spyware information pages on my site are now the most popular pages on the site, by far.

What always occurs to me as I clean the slime out of someone's computer is how nearly all of this garbage could easily be prevented save for inherent "features" in Windows that invite malware into the system.

You assert that spyware doesn't exploit specific vulnerabilities in Windows. I assert that spyware exploits the general lack of security that permeates Windows and its included components, especially IE.

Windows was designed to make computing accessible to idiots; and because of that, a great many extensibility "features" were built into the system. These "features" are little short of a red carpet rolled out for hackers, crackers, script kiddies, and now, spyware publishers.

For example, Browser Helper Objects, ActiveX components, and other "customizations" allow those with the required skills to splice their applications directly into Windows (since IE is really just an extension of the file manager, when you get right down to it).

Properly setting the security settings in "Internet Options" will prevent some spyware from installing (or will at least prompt the user first), but it's not all that hard for spyware programmers to include code to change these settings, since in Windows, everyone is an administrator by default.

Another Windows vulnerability that is frequently exploited is the way the Windows deals with the issue of shared dll's, the Registry, and other essential system files. A more secure alternative would be to make the system directories and the bulk of the Registry off-limits to third-party programs. Require applications to come with their own application-specific libraries, in their own directories, rather than allowing them to modify or add to the system directories.

Another glaring fault in Windows is that everyone is an administrator by default. Because of this unhappy tradition, many applications won't even run in a limited user profile. Compare this to Linux. Even a neophyte Linux user knows that the first thing you do after installing Linux is to establish a non-root user account for yourself. You never log in as root unless you need to, and you never, ever log onto the Internet as root unless you have a very, very good reason for doing so. Accordingly, Linux apps are written to run well in what Windows would call "limited" profiles, once they are installed by root.

To some extent, NT/2K/XP users can duplicate this environment by assigning themselves limited accounts for day-to-day use (something I always encourage my customers to try, at least); but it's an imperfect solution. Many apps break when they're run in a limited profile. Most of these can be fixed by isolating the offending file(s) and modifying permissions, making Registry changes, etc.; but this is way beyond what most users know how to do.

How much better it would be if apps were designed from the start to be installable only by an administrator, but to work properly in a limited profile.

You mention that spyware-removal apps only work on Windows machines. Frankly, I'm not aware of any commercial spyware written for any other platform, and it's not only because of the ubiquity of Windows. It's also because it would be a lot harder to write spyware that would install on more secure platforms.
Posted by: RichardM_z   Posted on: 06/04/04 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Spyware is even worse than spam in my view  mreilly19 | 06/01/04
Wow! Thanks for the info!  G.A.L. | 06/01/04
Re: Spyware is even worse than spam in my view  crm_z | 06/01/04
Enemy of the good  Anton Philidor | 06/01/04
Re: Enemy of the good  crm_z | 06/01/04
Comments on prevention  Anton Philidor | 06/02/04
Re: Comments on prevention  crm_z | 06/02/04
You're right, I should ask for the $60.  Anton Philidor | 06/03/04
Will definitely check out TDS-3  mreilly19 | 06/01/04
Try Deep Freeze  David1951 | 06/04/04
Deep Freeze  mryan@... | 06/07/04
Deep Freeze Thawspace  David1951 | 06/07/04
From an admin's perspective...  toadlife | 06/01/04
Re: From an admin's perspective...  crm_z | 06/01/04
Re: From an admin's perspective...  toadlife | 06/01/04
Re: From an admin's perspective...  crm_z | 06/01/04
I just learned last night ...  mwagner@... | 06/07/04
Spyware = Virus  slamspam | 06/01/04
Our hero: Webroot Spy Sweeper  Anton Philidor | 06/01/04
Cut your risk - Dump IE & Outlook  TMM_z | 06/01/04
Firefox 0.8, Yahoo Paymail, and XTerminator  tbbrickster_z | 06/04/04
Spyware following spam into the enterprise  billh@... | 06/01/04
Re: Spyware following spam into the enterprise  crm_z | 06/01/04
Spyware is JUST as evil as a virus...  Wolfie2K3 | 06/01/04
Re: Spyware is JUST as evil as a virus...  crm_z | 06/01/04
Cwshredder and Hijack This  icrovop@... | 06/03/04
Sources of spyware/adware  p_korman | 06/02/04
The Answer to Kazaa  toadlife | 06/03/04
Windows and Spyware  RichardM_z | 06/04/04
Microsoft needs to be sued over this one.  lavallie | 06/04/04
Avoid Spy Sweeper, hoc sugit!!!  tbbrickster_z | 06/04/04
Re: Avoid Spy Sweeper, hoc sugit!!!  crm_z | 06/04/04
Re: Avoid Spy Sweeper, hoc sugit!!!  tbbrickster_z | 06/04/04
Ahhh spyware.....  JoeMama_z | 06/04/04
It's everywhere even here  dougbeer | 06/04/04
spyware is like Al-Qaeda  I know everything | 06/04/04
I hear you  mreilly19 | 06/04/04
Add My Hear!! Hear!!  tbbrickster_z | 06/04/04
Spyware can be removed with every restart  David1951 | 06/04/04
Your talking about CleanSlate  I know everything | 06/04/04
Deep Freeze  David1951 | 06/07/04
Centurion Guard  Hanover Phist | 06/15/04
Google the King of Spyware  anthonycea | 06/06/04
Google Toolbar  mgcarley-zdnet | 06/07/04
Spyware from ZDNet  jcbick | 06/07/04
Context of safety  mgcarley-zdnet | 06/07/04
Cookies, etc  jcbick | 06/08/04
If it's in the EULA it isn't spyware  Sam Hobbs | 06/07/04
Biometrics Method  LeeKP | 06/09/04
Don't forget non-DOS partitions  CruelMcC | 06/14/04
Trojan Horse = Spyware/Adware SUE THEM!  John Rosengarten | 06/17/04
Sue  jbochner | 11/10/04
Is it just me or is spyware making you feel like youre home's been invaded?  virtual_insanity6969 | 03/18/05
Has anyone tried barracuda anti spam ware and anti spyware products  rakshitupl@... | 11/14/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline