Interview with an Adware Author


M: Yes. I should probably first speak about how adware works. Most adware targets Internet Explorer (IE) users because obviously they’re the biggest share of the market. In addition, they tend to be the less-savvy chunk of the market. If you’re using IE, then either you don’t care or you don’t know about all the vulnerabilities that IE has.

IE has a mechanism called a Browser Helper Object (BHO) which is basically a gob of executable code that gets informed of web requests as they’re going. It runs in the actual browser process, which means it can do anything the browser can do– which means basically anything. We would have a Browser Helper Object that actually served the ads, and then we made it so that you had to kill all the instances of the browser to be able to delete the thing. That’s a little bit of persistence right there…[/i]

Very interesting interview.

[b]S: In your professional opinion, how can people avoid adware?

M: Um, run UNIX.[/b]

so he means, you can’t avoid adware if you’re using windows 88)

[b]S: How private is people’s information today?

M: Not at all.

S: Do you think that in our society we delude ourselves into thinking we have more privacy than we really do?

M: Oh, absolutely. If you think about it, when I use a credit card, the security model is the same as that of handing you my wallet and saying, “Take out whatever money you think you want, and then give it back.”[/b]

His position was different to those that write nasty (virus, trojan, malware, etc…) programs. He worked for a legitimate company that could be, and was, held legally accountable. So, in his position… it’s his opinion that he could have got away with it. But, it just takes one user (victim) to notice… game over. Also, he doesn’t really know how much the company he worked for actually trusted him. Given what they were doing… probably not a lot. They could have easily been monitoring him very carefully for this very reason.

UNIX: I guess as it stands now, with the majority still using MSIE as he described… then for the majority that is probably a true statement. However, it is equally true, that the very same majority he cites would probably never even consider using UNIX/Linux for exactly the same reason they’re still using MSIE.

Adware is Advertising Software. Unless you’re saying that just because some chap at Boeing makes statements about security, then the whole of the aircraft manufacturing industry should be considered a security issue?

But, whatever… you’re the professional & it’s your argument, not mine. :slight_smile:

“S: You wrote adware. You bastard.”


“M: People can have things as good as they are willing to work for. If you want to have a system that’s clean of nasty software, you can do that. If you want to have personal privacy, it’s possible– very hard, but possible. And I think it’s worth it.”

