CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image PopUps: AOL Quietly Combats Pop-Up Spam Messages image
SPAM
AOL Quietly Combats Pop-Up Spam Messages
By Anick Jesdanun,
AP Internet Writer

NEW YORK (AP)—Even more annoying than junk e-mail are all the spam messages that pop up through a little-used feature in Windows. As part of its spam-fighting efforts, America Online has been turning off that feature for its customers without telling them.

AOL spokesman Andrew Weinstein said the feedback has been all positive, and he knows of no complaints to AOL call centers about side effects on other applications that may need that feature.

Nonetheless, AOL's action worries some security experts who were told about it by The Associated Press.

They are trying to do the right thing ... but you sort of feel dirty after you hear it, said Bruce Schneier, chief technology officer for Counterpane Internet Security Inc. It's a very dangerous precedent in having companies go into your computer and turn things on and off.

From there, he added, it's easy to turn off competitors' services.

Pop-up spam differs from pop-up ads in that no Web browser or Web site visit is required. Instead, these ads take advantage of a messaging function built into many Windows operating systems.

The function, generally enabled automatically when computers are shipped, was designed for computer network technicians to, for instance, warn people on their systems of a planned shutdown. Some applications also notify users of such actions as a network printer finishing a task.

About a year ago, spammers figured out that they, too, could exploit it, making ads automatically appear on users' screens at any time.

AOL#151;along with other Internet service providers and makers of security firewall products#151;responded by closing many of the Internet ports used, but closing all could disrupt other applications.

AOL then developed a tool that users could run to turn off the feature entirely, but few bothered, even though complaints about such messages kept growing, Weinstein said.

So two weeks ago, AOL began turning the feature off on customers' behalf, using a self-updating mechanism in AOL's software. But the setting changed is on Windows, not AOL's software. Users are not notified of the change, though they may manually turn the feature back on, and AOL won't change it again.

Weinstein said the company has changed settings for 15 million users already and will continue doing so over the next few weeks.

Almost none of the users will ever need this functionality, he said. Even in the office environment, it is rarely used.

Furthermore, he said, AOL won't change settings unless the user has administrative privileges on that computer#151;something employees generally don't have on their work machines.

Weinstein notes that besides blocking pop-up spam, it closes a Windows vulnerability that Microsoft Corp. deems critical and disclosed last week.

Microsoft officials said they were reviewing the AOL changes and had no immediate comment.

Lawrence Baldwin, president of the security Web site myNetWatchman.com, said that while AOL should be lauded for taking responsibility for ensuring computer security, I certainly wouldn't want my ISP (Internet service provider) messing with my system.

For software to change computer settings on its own isn't unprecedented. Software from other vendors, for instance, can automatically make itself the main application for playing music files or surfing the Web. Any warnings are often hard to find.

Russ Cooper, a security expert with TruSecure Corp., said anyone who needs the Windows messaging function that AOL disabled ought to be smart enough to know how to reactivate it.

I hope more and more providers do this type of proactive security, he said, and that we don't condemn them for things we wish everybody would do for themselves.

Copyright 2003 Associated Press. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.

eWeek
Posted on Thursday, 30 October 2003 @ 04:05:00 UTC by phoenix22 (871 reads)
[ Trackback ]
image

"PopUps: AOL Quietly Combats Pop-Up Spam Messages" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Microsoft
· Microsoft
· HotScripts
· Linux Manuals
· W3 Consortium
· Spam Cop
· America Online
· America Online
· More about SPAM
· News by phoenix22


Most read story about SPAM:
Messenger Pop-up Spam makes us sick

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer