Outsmarting Google isn't easy. So on the issue of user privacy, Google's competitors are trying a different tactic: knowing less.
Microsoft (nasdaq: MSFT - news - people ) announced Monday that it's introducing new measures on its Live Search application that would erase identifying data from search logs 18 months after it's recorded and will allow users to surf sites with Microsoft-provided ads without having their behavior tracked.
Yahoo! (nasdaq: YHOO - news - people ) plans to make all search data anonymous after 13 months, according to a spokesman, and InterActiveCorp's (nasdaq: IACI - news - people ) Ask.com announced last week that it will be launching AskEraser, a search option that erases all history of Ask searches. Microsoft and Ask.com issued a joint statement over the weekend calling on members of the search industry to meet and discuss ways they can work together to define privacy principles and protect user information.
The wave of privacy announcements comes a month after Google (nasdaq: GOOG - news - people ) was lambasted in a report from Privacy International, which placed the search engine at the very bottom of its rankings for protection of private user information and labeled the company "hostile to privacy."
Google's plans to acquire the ad-serving company DoubleClick--which would combine an unprecedented volume of information about Web users' surfing behavior with Google's search data--have also drawn protests from a wide range of privacy groups in the U.S. and the European Union. E.U. government investigators and the Federal Trade Commission are both examining the consequences of a Google-DoubleClick deal, and the acquisition will be reviewed by Congress in the coming months.
All this spotlighting of privacy offers Google's competitors a chance to shorten Google's lead in the search industry, says Ben Edelman, an assistant professor at Harvard Business School. "Competing search engines struggle to figure out what they can offer users that Google can't," he says. "With Google's limited efforts to protect privacy, that's a clear area where other search engines can flex their muscles."
Peter Cullen, Microsoft's chief privacy strategist, says that Google's troubles were just one factor in the timing of their new privacy campaign. "We surveyed the landscape over the past couple of months relating to privacy search and ads, including the debate regarding Google and the E.U.," he says. "We decided it was time for us to provide a much more comprehensive package."
Ask.com would have the most to gain from competition with Google: In June, Ask had 5% of U.S. search market share, compared with Google's 49.5%, according to comScore Media Metrix. Yahoo! accounted for 25.1% of all searches, and Microsoft had 13.2%.
Despite criticisms over its privacy policies, Google is one of the few search engines that has yet to leak user data. In August 2006, AOL released the search records of 650,000 of its users--the data from a total of 20 million searches-- to the U.S. Department of Justice. And in January 2007, Microsoft, Yahoo!, and AOL offered up millions of search queries as part of an ACLU lawsuit seeking to overturn a federal pornography law. Google, by contrast, fought the subpoena on grounds of trade secrecy and avoided revealing user data.
But Google's increasing array of services creates an unprecedented collection of intertwined personal information, says Ben Edelman. Those applications now include online payment, video, mapping, e-mail, social networking, search and soon, DoubleClick's behavior-tracking advertising data. "They've built more and more services with increasingly fundamental privacy consequences," Edelman says. "The more attention these issues get, the more users will look at them and start to think it's a bit scary."
In response to Monday's announcement from Microsoft, Google's global privacy counsel Peter Fleischer offered a statement pointing out Google's decision in June to make user data anonymous after 18 months. "We hoped it would stimulate debate across the industry, and we're delighted that is has," he writes. "Debate and discussion are good for users. That's why we've made improvements to our policies over the last few months. We'll continue to do so in the future, and [we] look forward to working with other companies, regulators and others."
Ari Schwartz, a spokesman for the Center for Democracy and Technology, agreed that competition on privacy matters will likely benefit users. "The proof will be when the products actually roll out," says Schwartz, "But I think this has the potential to teach the industry that they're limited by consumer expectations about how their data will be collected. We haven't seen this kind of attention to privacy in a long time."
Wednesday, 25 July 2007
Out-Gagging Google
Labels: by Andy Greenberg
The Top Countries For Cybercrime
Cybercrime, like every digital industry, is outsourcing. Though the U.S. still produces more malware, spam and viruses than any country in the world, illicit IT jobs are increasingly scattered across an anarchic and international Internet, where labor is cheap, legitimate IT jobs are scarce and scammers are insulated from the laws that protect their victims by thousands of miles. As Thomas Friedman might say, the criminal underworld is flat.
According to a Symantec (nasdaq: SYMC - news - people ) report at the end of 2006, Beijing is now home to the world's largest collection of malware-infected computers, nearly 5% of the world's total. Research by the security company Sophos in April showed that China has overtaken the U.S. in hosting Web pages that secretly install malicious programs on computers to steal private information or send spam e-mails. And another report from Sophos earlier that month showed that Europe produces more spam than any other continent; one Polish Internet service provider alone produces fully 5% of the world's spam.
Cybercrime this geographically diverse isn't just hard to stop; it's hard to track. Common tactics like phishing and spam are usually achieved with "botnets," herds of PCs hijacked with malware unbeknownst to their owners. Botnet attacks can usually be traced only to the zombie computers, not to their original source. That means the majority of studies mapping botnet attacks point to every place in the world that has vulnerable PCs, with no real sense of where the attacks begin.
In Pictures: The Cybercriminals' Map Of The World
Researchers at Sophos Labs say they have a solution: They can roughly identify the host country of malicious software by tracing the default language of the computer on which it was programmed. According to their analysis of the default language linked with about 19,000 samples at the end of last year, Americans and other non-British English speakers still produce the most malware, more than a third of the world’s total. Close behind is China, producing 30%, followed by Brazil, with 14.2%. Russia places fourth with 4.1% of the world’s malware.
Bill Pennington of White Hat Security attributes these developing countries' bad behavior to an overabundance of technologically trained young people with low-paying jobs. "If you’re in Russia or China and you have a computer science degree," he says, "You can either go work for nothing or you can make money using your skills for nefarious purposes."
Cybercrime isn't merely spreading to certain foreign countries, it's becoming cosmopolitan, says James Lewis, director of the Technology and Public Policy Program at the Center for Strategic and International Studies. As crime syndicates in Europe and Asia move into online scams, Lewis says that a single cybercrime operation can now be distributed among many different groups in several countries. One may create a "botnet" while another rents those computers to send credit scam e-mails and a third party transfers funds using the fraudulently obtained banking information. Sometimes each operation is on a different continent.
"The big problem here is political. It’s sovereignty," Lewis says. "The FBI cannot go enforce American law without the consent of the country where cybercrime is being carried out. So even if U.S. laws were perfect, it wouldn’t be enough to protect you." He describes a "Bonnie and Clyde" situation, where police stop at the edge of their jurisdiction rather than pursue criminals to their hideouts.
The growth areas of the malware industry aren't easily predicted. India, for instance, is one of the world’s most technologically booming developing countries, but ranks surprisingly low on Sophos' list. The U.K. and India together contribute only 1.3% of the world's malware--both use British English as a default language, so their samples couldn't be separated--and Sophos researchers say the majority of that criminal activity comes from the U.K. Eugene Kaspersky, Russian security guru and head of Kaspersky Labs, can only explain India’s lack of cybercrime as a "cultural difference."
Nandkumar Saravade, director of cyber security for India's National Association of Software and Service Companies, says that India has so far avoided a cybercrime epidemic thanks to the success of its legitimate IT industry. "Today, it is a fact that any person in India with marketable computer skills has a few job offers in hand," he says.
But Saravade and Kaspersky both warn that security professionals should expect the subcontinent’s malware contribution to grow in coming years. When it does, India likely won't be ready to contain the problem: The country's last major cybercrime law was created in 2000, long before botnets became an issue.
India isn't alone in being unprepared: Kaspersky says that the growing industry of malware professionals around the world hasn't been fully recognized by international legal bodies or the software industry, which continues to build vulnerable programs.
"We in the security industry need to attract the attention of government authorities, educate users and encourage changes in basic operating systems," he says. "Alone, we don’t have a chance."
Labels: by Andy Greenberg