•  
  •  
 

Computer Law Review and Technology Journal

Authors

Abstract

"Spyware" has become a major problem for computer users over the past few years. In response, quite a few states have enacted statutes intended to control the problem. But most of the existing legislation has taken the wrong approach to the problem of defining spyware. Generally speaking, most legislative definitions of spyware either have been too technology-specific to adapt to future developments, or have swept too broadly. Additionally, many legislative definitions of spyware have focused too little on protecting consumers. This article argues that any effective regulatory definition must have three characteristics: 1) it must protect the user's control over his or her computer; 2) it must be technologically neutral; and 3) it must not be over-inclusive. The article then proposes a regulatory definition that has these three characteristics.

A couple weeks after one of my colleagues, J, got her new laptop in 2004, a certain infamous celebrity video was leaked onto the Internet and created quite a buzz. J's husband, wishing to download the video but unwilling to do so using his work computer, borrowed J's laptop and went searching for a website from which he could download the file. He never did find the video he was after, but while he was looking, a large number of programs somehow made their way onto the laptop without his knowledge. Dozens of these programs launched themselves each time the computer booted and slowed the computer down to the point that it was virtually useless. J had to wipe the drive and start fresh, as it would have been impossible to undo all of the changes made by those malicious programs. Most of these programs were designed to monitor J's web browsing habits and send pop-up ads to her machine. In other words, J's laptop had been infested with "spyware."

Share

COinS