|
|
To print: Select File and then Print from your browser's menu
-------------------------------------------------------------- This story was printed from ZDNet Australia. --------------------------------------------------------------
|
Security vendor survey: Will they side with the government? By Declan McCullagh and Anne Broache , CNET News.com July 18, 2007 URL: http://www.zdnet.com.au/insight/security/soa/Security-vendor-survey-Will-they-side-with-the-government-/0,139023764,339280166,00.htm
Security software vendors may soon side with US government authorities and intentionally fail to report "certain spyware" to customers if ordered by a court to remain quiet, according to a survey of leading firms. In a case decided earlier this month by the 9th US Circuit Court of Appeals, federal agents used spyware with a keystroke logger to record the typing of a suspect who used encryption to scramble his communications. But would that government spyware used in that investigation actually be detected by security software? Or would security companies intentionally fail to report it? To answer that question, ZDNet Australia's sister site CNET News.com conducted a survey. We asked three questions of 13 security companies, ranging from tiny ones to corporations like Microsoft and IBM. When there is no answer listed for a specific question, the company chose not to answer it. In some cases we followed up with additional questions. The survey was conducted over the past week. AVG/Grisoft Q: Has Grisoft/AVG ever had any discussions with any government agency about not detecting spyware or keystroke loggers installed by a police or intelligence agency? Is it Grisoft/AVG's policy to alert the user to the presence of any spyware or keystroke logger, even if it is installed by a police or intelligence agency? Do these policies vary depending on the country (the US vs others, for instance)? We understand that you have to comply with applicable laws and regulations. But do any laws and regulations currently require security companies to ignore spyware/malware/key loggers placed on computers by governmental agencies? Have you ever received such a court order signed by a judge requiring you to cooperate with law enforcement authorities in terms of not detecting government-installed spyware or delivering government spyware to your users? Check Point Has Check Point ever had any discussions with any government agency about not detecting spyware or keystroke loggers installed by a police or intelligence agency? Is it Check Point's policy to alert the user to the presence of any spyware or keystroke logger, even if it is installed by a police or intelligence agency? In a follow-up conversation, we asked Check Point under what circumstances they would afford that "courtesy". Have you ever received such a court order signed by a judge requiring you to cooperate with law enforcement authorities in terms of not detecting government-installed spyware or delivering government spyware to your users?
Computer Associates Have you ever had any discussions with any government agency, not counting conversations related to a lawful court order signed by a judge, about not detecting spyware or keystroke loggers installed by a police or intelligence agency? Is it your policy to alert the user to the presence of any spyware or keystroke logger, even if it is installed by a police or intelligence agency in the absence of a lawful court order signed by a judge? Have you ever received such a court order signed by a judge requiring you to cooperate with law enforcement authorities in terms of not detecting government-installed spyware or delivering government spyware to your users? eEye Has eEye ever had any discussions with any government agency about not detecting spyware or keystroke loggers installed by a police or intelligence agency? Is it eEye's policy to alert the user to the presence of any spyware or keystroke logger, even if it is installed by a police or intelligence agency? As soon as a company, like we have seen with McAfee, starts making exceptions to their protection products, they can no longer guarantee a sound and safe product for their customers. We will not play that game. Have you ever received such a court order signed by a judge requiring you to cooperate with law enforcement authorities in terms of not detecting government-installed spyware or delivering government spyware to your users? IBM Have you ever had any discussions with any government agency, not counting conversations related to a lawful court order signed by a judge, about not detecting spyware or keystroke loggers installed by a police or intelligence agency? Is it your policy to alert the user to the presence of any spyware or keystroke logger, even if it is installed by a police or intelligence agency in the absence of a lawful court order signed by a judge? Have you ever received such a court order signed by a judge requiring you to cooperate with law enforcement authorities in terms of not detecting government-installed spyware or delivering government spyware to your users? Kaspersky Lab Have you ever had any discussions with any government agency, not counting conversations related to a lawful court order signed by a judge, about not detecting spyware or keystroke loggers installed by a police or intelligence agency? Is it your policy to alert the user to the presence of any spyware or keystroke logger, even if it is installed by a police or intelligence agency in the absence of a lawful court order signed by a judge? Have you ever received such a court order signed by a judge requiring you to cooperate with law enforcement authorities in terms of not detecting government-installed spyware or delivering government spyware to your users? McAfee Have you ever had any discussions with any government agency, not counting conversations related to a lawful court order signed by a judge, about not detecting spyware or keystroke loggers installed by a police or intelligence agency? Is it your policy to alert the user to the presence of any spyware or keystroke logger, even if it is installed by a police or intelligence agency in the absence of a lawful court order signed by a judge? Have you ever received such a court order signed by a judge requiring you to cooperate with law enforcement authorities in terms of not detecting government-installed spyware or delivering government spyware to your users? Microsoft Has Microsoft ever had any discussions with any government agency about not detecting spyware or keystroke loggers installed by a police or intelligence agency? Is it Microsoft's policy to alert the user to the presence of any spyware or keystroke logger, even if it is installed by a police or intelligence agency? Is Microsoft able to answer more directly whether its spyware/key logger detection tools are ever turned off per the government/law enforcement's request, or whether it has ever had discussions with government agencies about not detecting spyware/key loggers they install? We were hoping to push our luck and see if you would give a yes-or-no answer to these two narrower questions: Has Microsoft ever had any discussions with any government agency, not counting conversations related to a lawful court order signed by a judge, about not detecting spyware or keystroke loggers installed by a police or intelligence agency? Is it Microsoft's policy to alert the user to the presence of any spyware or keystroke logger, even if it is installed by a police or intelligence agency in the absence of a lawful court order signed by a judge? Have you ever received such a court order signed by a judge requiring you to cooperate with law enforcement authorities in terms of not detecting government-installed spyware or delivering government spyware to your users? Sana Security Has Sana ever had any discussions with any government agency about not detecting spyware or keystroke loggers installed by a police or intelligence agency? Is it Sana's policy to alert the user to the presence of any spyware or keystroke logger, even if it is installed by a police or intelligence agency? Have you ever received such a court order signed by a judge requiring you to cooperate with law enforcement authorities in terms of not detecting government-installed spyware or delivering government spyware to your users? Sophos Has Sophos ever had any discussions with any government agency about not detecting spyware or keystroke loggers installed by a police or intelligence agency? Is it Sophos policy to alert the user to the presence of any spyware or keystroke logger, even if it is installed by a police or intelligence agency? (Editor's note: During a follow-up conversation, Sophos added that it would still stand by that statement today if approached by law enforcement or intelligence agencies and asked to change its policies.) Have you ever received such a court order signed by a judge requiring you to cooperate with law enforcement authorities in terms of not detecting government-installed spyware or delivering government spyware to your users? Symantec Have you ever had any discussions with any government agency, not counting conversations related to a lawful court order signed by a judge, about not detecting spyware or keystroke loggers installed by a police or intelligence agency? Is it your policy to alert the user to the presence of any spyware or keystroke logger, even if it is installed by a police or intelligence agency in the absence of a lawful court order signed by a judge? Have you ever received such a court order signed by a judge requiring you to cooperate with law enforcement authorities in terms of not detecting government-installed spyware or delivering government spyware to your users? Trend Micro Have you ever had any discussions with any government agency, not counting conversations related to a lawful court order signed by a judge, about not detecting spyware or keystroke loggers installed by a police or intelligence agency? Is it your policy to alert the user to the presence of any spyware or keystroke logger, even if it is installed by a police or intelligence agency in the absence of a lawful court order signed by a judge? However, we can comment on your specific question: "Is it your policy to alert the user to the presence of any spyware or keystroke logger, even if it is installed by a police or intelligence agency in the absence of a lawful court order signed by a judge?" Our answer is "yes". Have you ever received such a court order signed by a judge requiring you to cooperate with law enforcement authorities in terms of not detecting government-installed spyware or delivering government spyware to your users? Websense Has Websense ever had any discussions with any government agency about not detecting spyware or keystroke loggers installed by a police or intelligence agency? Is it Websnese policy to alert the user to the presence of any spyware or keystroke logger, even if it is installed by a police or intelligence agency? Have you ever received such a court order signed by a judge requiring you to cooperate with law enforcement authorities in terms of not detecting government-installed spyware or delivering government spyware to your users?
Copyright © 2009 CBS Interactive, a CBS Company. All Rights Reserved. |