Hearing of House Committee on Energy and Commerce - Combating Spyware: H.R. 29, the Spy Act

Date: Jan. 26, 2005
Location: Washington, DC
Issues: Energy


HEARING OF HOUSE COMMITTEE ON ENERGY AND COMMERCE - COMBATING SPYWARE: H.R. 29, THE SPY ACT

BREAK IN TRANSCRIPT

Ms. Schakowsky. Thank you, Mr. Chairman. I would like to first also welcome our new members and particularly thank the new Democratic members who made it possible for me to rise to this lofty position in the second row and close to the chairman. This is a big day for me. And I wanted you--to thank you, Chairman Barton, for holding this hearing on H.R. 29, the SPY ACT, a strong, pro-consumer, bipartisan piece of legislation, which addresses one of the newest and most troublesome consumer and privacy issue: spyware. And I would also like to thank Ranking Member Dingell, who is unable to be here today. And as the ranking Democrat on the Commerce Trade and Consumer Protection Subcommittee in the 108th Congress, I had the privilege of working closely with my Chairman, Chairman Stearns, along with Representative Towns and Bono on the first version of the SPY ACT.

As we learned last year, spyware, while not yet a household word, is a household phenomenon. The recent--a recent study by America Online found that 80 percent of families with broadband access had spyware on their computers. EarthLink, one of our witnesses here today, along with Web Route, an anti-spyware software provider, found that in 3 million scans of computers, there was an average of 26 instances of spyware on each and every computer. With those kinds of numbers, spyware will soon be a part of everyone's vocabulary.

However, because of the surreptitious nature of spyware, because of the furtive practices of the spyware purveyors, many people have no idea that their computers have been infected with the software. People notice that pop-up ads will not go away and they notice when their computers are much slower. And of course, they notice when their home pages have been hanged, but not by them. Consumers tend to blame viruses, their--on their old computer or their Internet service providers. But because spyware is bundled with software people do want to download, and because it is drive-by downloaded from unknowingly visiting the wrong website, people do not know that, in many cases, the real cause of their headaches is spyware.

As we pointed out last year, spyware is much more than merely annoying. Slow computers and pop-up ads are just symptoms of the real trouble spyware can cause. The software is so ``resourceful'' that it can snatch personal information from computer hard drives, track every website visited, and log every keystroke entered. Spyware is a serious threat to consumer privacy and potentially a powerful tool for identity theft, a serious crime that is on the rise. Although we do not want to stop legitimate uses of the software underlying spyware, like allowing easy access to online newspapers, we do want consumers to have control of their computers and personal information and to stop truly nefarious uses of the programs.

The SPY ACT finds the balance that helps protect consumers from truly bad acts and actors while preserving the pro-consumer functions of the software. It prohibits indefensible uses of the software, like keystroke logging, and it gives consumers the choice to opt in to the installation or activation of information-collection software on their computers, but only when consumers know exactly what information will be collected and how it will be used.

Furthermore, the SPY ACT gives the FTC the power it needs, on top of laws already in place, to pursue predatory uses of the software. The SPY ACT puts the control of computers and privacy back in consumers' hands, and I am glad that we are moving the bill forward once again.

And once again, I thank my colleagues for this pro-consumer, pro-privacy, and bipartisan piece of legislation, and I look forward to working with you again this year.

Thank you, Mr. Chairman.

BREAK IN TRANSCRIPT

Ms. Schakowsky. Thank you, Mr. Chairman, and thank you for your testimony. I say that to all of our witnesses.

I wanted to--and we have talked a lot about what spyware can do to individual computers and to individual consumers, but one thing we really haven't talked about is the potential damages that a spyware infection can do to businesses, to Congressional offices. And I wondered if any of the panelists would like to fill us in a bit on those threats.

Mr. Schmidt, go ahead.

Mr. Schmidt. Yeah, I would be happy to. As a matter of fact, I alluded to that during my verbal testimony. What we have seen is sort of--as I have mentioned, sort of the additional pieces of spyware, which include Trojans, which then give someone an access to remotely control your system to create a bot network out of a robot network, which basically then could be used against critical infrastructure as a distributed denial service attack, keystroke capture to grab passwords, which generally not only relate to what you may be doing in your work environment, but also, oftentimes, your online banking and everything. So these things become very, very insidious as far as their ability to affect more than just an individual. And that is why corporations and enterprises are working very hard to make sure that they can wipe out the spyware on there, because it does affect their ability to manufacture, to provide--you know, for example, we have seen the situations in the past where airline reservation systems have been down for computer problems that could have conceivably been affected by spyware as well.

So it is your--you are quite correct. It is more than just about privacy and personal protection.

Ms. Schakowsky. That terrible situation we had during a snowstorm where all of the baggage was tied up, has that been attached at all to spyware, do you know?

Mr. Schmidt. Not to my knowledge, no.

Ms. Schakowsky. Okay. Mr. Rubinstein, according to a September 2004 article by Consumer Reports, Microsoft has found that spyware is directly responsible for more than 1/3 of application software crashes that might be linked to as many as half of the crashes Microsoft customers experience. Let me just ask you some basic--what does Microsoft mean by a ``crash''? What does this do to a person's computer, to any files that they may have? And I am wondering if there is any way that you can estimate, in dollar amounts, how much damage this has caused for consumers or for businesses or for Microsoft.

Mr. Rubinstein. It is hard to put precise dollar amounts on the damage it has caused. I know that it is probably the leading reason for support calls, both to Microsoft and to the leading manufacturers, such as Dell, so that imposes, certainly, millions of dollars of cost on the providers of technology. In terms of crashes, spyware is often responsible for either slowing down the performance of a computer or simply not allowing the user to navigate to a selected site or even to use certain programs to stop pop-ups from interfering and so on. So it is certainly quite damaging, and I think the one point that I really want to call attention to is that the scenarios we have heard where I--the spyware tools are getting more sophisticated, but the scenarios we have heard where they were ineffective and where the consumer is forced to reformat a hard drive or replace a computer are just simply unacceptable, and I think that is why I think we need to bring together all of these different elements to combat the spyware.

Ms. Schakowsky. Finally, Mr. Schwartz has emphasized the need for baseline privacy legislation. I just wanted to ask the other three of you what your feeling was about the need to do just that. Mr. Baker?

Mr. Baker. Privacy legislation?

Ms. Schakowsky. Baseline privacy legislation.

Mr. Baker. Well, I think that--meaning this legislation, we have already taken a large step to protecting consumers' online privacy, because one of the insidious applications of spyware is, of course, transmitting personally identifiable information to another website without that user's knowledge. So this is--and so with or without stand-alone privacy legislation, this bill will--it takes a big step toward protecting consumers' online privacy.

Mr. Rubinstein. Microsoft is committed to strong consumer protection of privacy, and we would be--we would welcome the opportunity to talk about legislation.

Mr. Schmidt. Yes, I think one of the things that I have always found very helpful is you look at legislation after market forces now, and I think with the collaborative effort that we have been looking at from the private sector agreeing on some baselines, if you would, for privacy protection, I think that would be the first avenue that I would recommend. And then if that, indeed, failed within a relatively short period of time, then I would look more toward the legislation. But even in that vein, I think the dialog that your leadership and Mr. Towns and Ms. Bono have done as well basically give us that vehicle that--to have the dialog to make sure we do things in the proper manner.

Mr. Stearns. The gentlelady's time has expired. The full Chairman, Mr. Barton.

BREAK IN TRANSCRIPT


Source
arrow_upward