Stories
Slash Boxes
Comments

News for nerds, stuff that matters

First Worm with a EULA?

Posted by michael on Fri Oct 25, 2002 01:03 PM
from the first-born-child-at-risk dept.
ErikRed1488 writes "There is a new virtual postcard from Friend Greetings, owned by Permissioned Media that prompts you to install their software to view the card. You are then presented with a EULA granting them permission to e-mail all the Contacts in your Outlook Address Book. Those people are presented with an e-mail from you telling them they have a greeting card to pick up. So, this thing spreads like a worm, but includes a EULA that 95% of users won't take the time to read. Symantec isn't detecting this as a virus, but does have information about it on their site. In addition to the worm-like way it spreads, it also installs spyware designed to deliver ads to your computer. You also give them permission to install further software any time they want. In my opinion this is completely nasty, but it's all clearly in the EULA that you must agree to before it installs the software."
This discussion has been archived. No new comments can be posted.
First Worm with a EULA? | Log In/Create an Account | Top | 800 comments (Spill at 50!) | Index Only | Search Discussion
Display Options Threshold:
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1) | 2
  • First Born by wilburdg (Score:2) Friday October 25 2002, @01:13PM
  • Admit it (Score:5, Insightful)

    by anthony_dipierro (543308) on Friday October 25 2002, @01:14PM (#4531612) Journal
    How many of you have read the Slashdot EULA [osdn.com]?
    • /. eula by Khopesh (Score:2) Friday October 25 2002, @01:30PM
    • Re:Admit it by Anonymous Coward (Score:1) Friday October 25 2002, @01:41PM
    • Re:Admit it by Ether Trogg (Score:2) Friday October 25 2002, @01:51PM
    • Re:Admit it by arban (Score:1) Friday October 25 2002, @04:19PM
    • 1 reply beneath your current threshold.
  • of course it's not a worm (Score:3, Interesting)

    by tps12 (105590) on Friday October 25 2002, @01:14PM (#4531613) Homepage Journal
    Now what reasonable person would expect this to be called a worm? The sysadmins are of course up in arms about any piece of software that threatens their delicate Windows networks. While I'm aware that most of the Slashdot audience consists of MS-certified admins fresh out of college, their lips adorned with sharp objects, I plead with readers to approach this with some sort of objectivity. Is any program that offers the ability to distribute itself to others now to be deemed a worm? That's hardly fair.

    In fact, given that the GPL'd software that's touted so often on this site is propogated through a similar device, villainizing this program borders on hypocricy. I don't even understand why traditional "worms" are given that name. Someone sends you an unknown executable that happens to distribute itself to your contact list, and you run it without Googling first to find out what it is...who's to blame here? The program's function is well-known, so the informed user won't be surprised when he fires it up and it does exactly what it's supposed to do.

    Let's use some common sense here, please.
  • Write up I sent to the office (Score:5, Informative)

    by doublem (118724) on Friday October 25 2002, @01:14PM (#4531614) Homepage Journal
    I haven't found anything on Symantec's site on this, but I did find McAfee's page Here [mcafee.com]

    And the removal instructions [mcafee.com]

    Google has a newsgroup post on the sucker [google.com]

    And here are some sample infection URLS for those who wish to catch the sucker or download the files for analysis:

    Infect Me 1 [friendgreetings.com]

    Infect Me 2 [friendgreetings.com]

    A similar worm is described by Symantec here [symantec.com]

    It works in IE, but not Phoenix (Mozilla based browser)

    You have to download the installer and the MSI file, which takes a while.

    I went so far as to download the files, but didn't go past the first EULA to see the really bad one that's supposed to come during the second install, so I didn't see the text in a live install myself, just in the McAfee
    writeup.

    So I downloaded the Microsoft Installer SDK and decided to crack open the MSI install file. Accroding to Servant Salamander, the word "Outlook" was in "Friend Greetings.msi."

    Then I decided, "To hell with it, it's in there as clear text anyway" and opened the install File with VIM. Here is the offending text:

    1. Consent to E-Mail Your Contacts. As part of the installation process,
    Permissioned Media will access your MicroSoft Outlook(r) Contacts list and
    send an e-mail to persons on your Contacts list inviting them to download
    FriendGreetings or related products. By downloading, installing,accessing
    or using the FriendGreetings, you authorize Permissioned Media to access
    your MicroSoft(r) Outlook(r) Contacts list and to send a personalized e-mail
    message to persons on your Contact list. IF YOU DO NOT WANT US TO ACCESS
    YOUR CONTACT LIST AND SEND AN E-MAIL MESSAGE TO PERSONS ON THAT LIST, DO
    NOT DOWNLOAD, INSTALL, ACCESS OR USE FRIENDGREETINGS.

    If anyone is interested, I'll e-mail out both EULAs. There's some rude stuff in there. (You agree to receive pop-up and pop-under ads and HTML e-mail for example)

    Below is the original e-mail from Cheryl, for the sake of reference and forwarding:

    --- Forwarded Message Follows-----
    FYI...

    It's not so much a virus as it is a potential worm. And it's an interesting one at that because it's a "permissive" worm. It banks on the fact that people install products without reading their EULAs. If you read the EULA they include, it specifically says that by accepting the EULA, you are giving them permission to send email to everyone in your MS Outlook Contact list!!!!! (I included the pics they sent us, but I'm not sure how many of you will actually see them).

    Pretty fascinating, actually. And smart. Because people don't read EULAs! (Er, for Dad: EULA is "End User License Agreement" - and I'm guessing you and Steve read them because you are lawyers... ;) )

    Ilene

    -----Original Message-----
    From: Kronos Norton AntiVirus
    Sent: Friday, October 25, 2002 10:51 AM
    To: All Kronos Employees
    Subject: Please read about a potential virus....
    Importance: High

    Potential virus as a Greeting Card ~ Please be aware of this
    potential threat via a web link.

    Friendgreetings

    iscovered on: October 24, 2002
    Last Updated on: October 24, 2002 03:20:23 PM PDT
    Symantec Security Response is aware of a widespread E-card which appears to have the characteristics of a worm. Security Response does not classify this as a malicious threat and as such will not detect any files associated with the E-card. The installation of software associated with the E-card requires the user's permission in order to perform it's mass-mailing capabilities. By cancelling the installation of the software, no worm-like activities will be performed. The recipient would recieve an email with the following characteristics:

    Subject: %recipient% you have an E-Card from %sender%.
    Message:
    Greetings!

    %sender% has sent you an E-Card -- a virtual postcard from FriendGreetings.com. You
    can pickup your E-Card at the FriendGreetings.com by clicking on the link below.

    http://www.friendgreetings.com/pickup/pickup.asp x? <extra contentremoved>

    Message:
    %recipient%
    I sent you a greeting card. Please pick it up.
    %sender%

    When the link is followed, the recipient is asked to download some software in order to view the E-card.

    The installer package will require the user to accept 2 End User License Agreements in order to complete the installation. The second EULA (see below) explicitly states that by accepting the agreement the end user is authorizing the software to send an email to all contacts in the Microsoft Outlook Contacts List. The email is formatted as displayed above.

    If this agreement is not accepted, the installation is not complete and the software will not send a link to the www.friendgreetings.com website via email.
  • Whoo hoo, another one for the scrap heap by ScannerBoy (Score:2) Friday October 25 2002, @01:15PM
  • GAHHHH by _ph1ux_ (Score:2) Friday October 25 2002, @01:15PM
    • Re:GAHHHH by _ph1ux_ (Score:2) Friday October 25 2002, @01:17PM
  • Getting even... by pkinetics (Score:1) Friday October 25 2002, @01:15PM
  • This is not exactly a "license" (Score:4, Insightful)

    by Dr. Awktagon (233360) on Friday October 25 2002, @01:15PM (#4531631) Homepage

    This just describes what the program does, and by placing it in the license, they hope that you don't read it. Kinda like saying something in 4pt-font fine print: ("note: Happy Fun Toy will explode into sharp shards, killing your child"). Shady practice, but not directly related to the real problems with EULAs ("you may not use this program unless...").

    Just nitpicking.. But it's true, you should always read your EULAs (prounounced EWWWWWWW-lahz).

  • Saves some people a lot of time (Score:3, Insightful)

    by msheppard (150231) on Friday October 25 2002, @01:16PM (#4531638) Homepage Journal
    This thing which automatically sends itself to everyone in your mailbox is saving a lot of people a lot of time. It's only slightly worse than the emails which end, "Send this to everyone you know." Most people believe the crap in them and forward to everyone they know.

    Never: EVER, have I recieved an email which read "Forward to everyone you know" that should actually have been forwarded to anyone.

    NEVER NEVER NEVER NEVER NEVER send to everyone you know! How many times must I say this? There is *NOTHING* that needs to be sent to everyoen you know.

    Execpt this excellent cookie recipie...

    M@
  • Almost Funny by slide-rule (Score:1) Friday October 25 2002, @01:16PM
    • 1 reply beneath your current threshold.
  • Oh no! by Anonymous Coward (Score:2) Friday October 25 2002, @01:17PM
    • 1 reply beneath your current threshold.
  • I just got a notice from our IT dept this morning by techstar25 (Score:2) Friday October 25 2002, @01:18PM
    • 1 reply beneath your current threshold.
  • Example of Future Problems for Linux and other OS by RazzleFrog (Score:2) Friday October 25 2002, @01:18PM
  • by Khopesh (112447) on Friday October 25 2002, @01:18PM (#4531659) Homepage
    i got an email a while ago (during the .com bubble) telling me that i got that email because somebody was romantically interested in me (i don't use dating services of any sort, online or not).

    basically, here's the scheme:
    a person likes another, but is too shy to ask him/her. this site allows a way to anonymously email that person. the message essentially says "guess who" ...literally.

    i was expected to guess the admirer by giving the site every email i could think of that might be the admirer. if there's a match, each party is informed. for all those non-hits, an email identical to the first was sent out; spam.

    i happen to use unique email addresses and handed this address to only four people, two of whom were female, so i knew it was one of them or a friend ... but the notable thing is that i started getting TONS of spam at that address (>20emails/day)

    this type of ponzi-style scheme with unforseen problems seems to be getting popular now; EULAs often take complete advantage: people blindly give permission to have third-party software downloaded and installed, to become the source of spamming and/or propogation, or to allow use of spyware.
  • Politics by e03179 (Score:2) Friday October 25 2002, @01:18PM
    • 1 reply beneath your current threshold.
  • Beautifully evil (Score:3, Funny)

    by gila_monster (544999) on Friday October 25 2002, @01:20PM (#4531672) Homepage
    ...and a good example of why geeks and lawyers shouldn't mate. :)

  • the company is in Panama by e40 (Score:2) Friday October 25 2002, @01:20PM
  • Company is in Panama. by compwizrd (Score:1) Friday October 25 2002, @01:21PM
  • Lovely by seanb (Score:2) Friday October 25 2002, @01:23PM
  • Illegal contract by xyloplax (Score:1) Friday October 25 2002, @01:23PM
  • Some things to keep in mind by CAIMLAS (Score:2) Friday October 25 2002, @01:23PM
  • The only worms here by Rupert (Score:2) Friday October 25 2002, @01:25PM
  • What does the EULA say? by Kikaid. (Score:1) Friday October 25 2002, @01:26PM
  • Unenforcable by bwt (Score:2) Friday October 25 2002, @01:26PM
  • Fraud by cperciva (Score:2) Friday October 25 2002, @01:27PM
    • Re:Fraud by whovian (Score:2) Friday October 25 2002, @01:53PM
  • EULAs on viruses = legit software? by gsfprez (Score:2) Friday October 25 2002, @01:27PM
  • Yay for evil! (Score:4, Insightful)

    by ChaosDiscord (4913) on Friday October 25 2002, @01:29PM (#4531780) Homepage Journal

    It's unfortunate that it has to be this way, but unless people get burned by EULAs they're not going to take EULA's seriously. Discovering that they've agreed to let this software spam their boss, coworkers, and business contacts will hopefully encourage people to seriously read EULAs in the future. I expect that when people start seriously reading EULAs, they'll discover they don't actually agree with many of the terms. (Or at least they'll discover that they can't make heads or tails over the thing.) A little backlash would be help restore balance to EULAs and make the work a more fair place.

  • self-inflicted DOS? by upper (Score:2) Friday October 25 2002, @01:29PM
  • Anyone have a kid? (Score:5, Interesting)

    by nick_davison (217681) on Friday October 25 2002, @01:29PM (#4531785)
    I Am Not A Sentient Being but...
    • Under US law, storing personally identifiable information about children is [largely] illegal.
    • The EULA, as far as I can tell, makes NO mention about this product not being allowed for under 13s.
    • With its infection (uh, I mean, transmission) mechanism, it makes no attempt to discover the age of the user before beginning to log their personal information.
    So, as soon as you discover your child has installed this program, sue them for failing to make any attempt to avoid violating their rights. Their EULA get out clauses don't work either as, being a child, they couldn't legally agree to the EULA anyway.

    Hopefully it'll spread better than they ever hoped. A class action lawsuit for every child in America would probably make a fairly clear point to anyone else trying this.

  • The EULA by Grip3n (Score:2) Friday October 25 2002, @01:29PM
  • Hack? by Dannon (Score:2) Friday October 25 2002, @01:30PM
  • Problem Solved. (Score:5, Funny)

    by Jade E. 2 (313290) <slashdotNO@SPAMperlstorm.net> on Friday October 25 2002, @01:30PM (#4531801) Homepage
    The worm has been completely stopped (at least for the moment) because their server is slashdotted to hell.

    Who knew reading /. could be a public service?

  • Not the first ridiculous EULA, but a goodie... by Kjella (Score:2) Friday October 25 2002, @01:33PM
  • Just slap a EULA on it, and it's okay. by lynx_user_abroad (Score:1) Friday October 25 2002, @01:33PM
  • Let them know by Derkec (Score:2) Friday October 25 2002, @01:34PM
  • Got one this morning by Over_and_Done (Score:1) Friday October 25 2002, @01:35PM
  • Not a worm. by RandomIO (Score:1) Friday October 25 2002, @01:35PM
  • Good! by 89cents (Score:1) Friday October 25 2002, @01:37PM
  • And who said RMS was paranoia? by internet-redstar (Score:1) Friday October 25 2002, @01:37PM
  • by nick_davison (217681) on Friday October 25 2002, @01:37PM (#4531875)
    Now worms are "legal", maybe it's time to go begging to Microsoft?

    "Hi, could you add the following term to your EULA?..."

    Third parties: You agree not to reverse engineer or exploit Microsoft Outlook in such a way as to create "worms" [define to your lawyers hearts' content] on penalty of $1trillion US, to be paid to [add deserving fund].

    Now they can make their worms as legal as they like and, by expecting others to live to their EULA, they have to abide by Microsoft's and file for bankruptcy.

    Never thought I'd like Microsoft having EULAs.

  • This was in the User Agreement by LittleLebowskiUrbanA (Score:1) Friday October 25 2002, @01:37PM
  • Preposterous by MilleniumUcita (Score:1) Friday October 25 2002, @01:40PM
  • by Powercntrl (458442) on Friday October 25 2002, @01:40PM (#4531902)
    Yes, I know about Adaware, but average Sally or Joe computer user does not. They think that the copy of Norton bundled with their Gateway or Dell will protect them from everything bad and that it's okay to click on "Yes" when prompted "Do you want to install and run X by Spyware Inc.?"

    This worm is no worse than the sites that have javascript to prompt you to install Cometcursor, Gator, Download accelerator, Bonzi Buddy and other spyware apps. I've already seen quite a few shockwave greeting card sites (with a Gator or other spyware install attempt) that ask you to "Send this card to a friend" and I've been sent links to these by my less computer-savvy friends. What's worse, you end up on more spam lists too...

    Sooner or later, EVERYONE online ends up being prompted to install some kind of spyware. The companies that produce antivirus software need to include features to actively scan and disable spyware (with a default setting enabling scanning for spyware/adware, but an option to disable it if for some reason you want to). I've personally become sick of explaining to people that NO, their Norton or McAfee isn't going to catch the program that's been giving them all these popups and that they need some free program they've never heard of before (AdAware) to get rid of them.

    While AdAware is great for power users, for the average population of PC users, automatic background protection like virus scanners provide for viruses is what is required. When a worm like this or a web page tries to install some new spyware, the user won't even be prompted - the antivirus software just says NO.
  • i've never wanted to DOS more by dextr0us (Score:1) Friday October 25 2002, @01:40PM
  • Many sneaky 'EULA's' (Score:3, Interesting)

    by YrWrstNtmr (564987) on Friday October 25 2002, @01:41PM (#4531910)
    ..not just in software.

    Enter to win a "Free Trip" at the mall, (and have your long distance service switched), for one example.

    I know it's hard, but you have to read (and attempt to understand) what they are actually asking you to do. But, I guess the result of that will be ever more obfuscated wording, so that no real human could get the true meaning of what it is doing.
    Legalese could expand a common, two line description into many, many pages. NO ONE would read and understand its true meaning.

    Store files on my computer? Oh, that must mean the graphics that come with the card.
    No, Virginia, they mean they will store whatever they feel like putting there.

    Send emails to my friends? COOL!
    No, send anything they want, any time they want. And possibly have their interface hacked by some OTHER fool next month.

    "Oh, we reserve the right to change this EULA at any time. The new one will be posted on our website." (Way back 7 levels deep, at the bottom of the page in a font no human can read).
    What might a new EULA do? Again, Virginia, anything they want.
  • Is this legal? by Spazholio (Score:2) Friday October 25 2002, @01:43PM
  • 95%? Incredible! (Score:3, Insightful)

    by waldoj (8229) <{waldo} {at} {jaquith.org}> on Friday October 25 2002, @01:43PM (#4531924) Homepage Journal
    Anybody that thinks that 5% of people read a EULA obviously gives a lot more credit to humanity than I do.

    -Waldo Jaquith
  • Cracks also has EULA's (Score:4, Funny)

    by rehabdoll (221029) on Friday October 25 2002, @01:44PM (#4531929) Homepage
    This is the EULA that pops up when you start a DAMN-keygen. Quite entertaining :)

    DAMN
    Electronic End-User Software License Agreement

    THIS PROGRAM IS PROTECTED BY COPYRIGHT LAW AND INTERNATIONAL TREATIES. BREAKING THE FOLLOWING AGREEMENT WILL RESULT IN SEVERE CIVIL AND CRIMINAL PENALTIES AND WILL BE PROSECUTED TO THE MAXIMUM EXTENT POSSIBLE UNDER LAW.

    THIS AGREEMENT IS A LEGAL DOCUMENT. READ IT CAREFULLY BEFORE USING THE SOFTWARE. IT PROVIDES A LICENSE TO USE THE SOFTWARE. BY CLICKING ON THE "YES" BUTTON AND USING THE SOFTWARE, YOU ARE CONFIRMING ACCEPTANCE OF THE SOFTWARE AND AGREEING TO BECOME BOUND BY THE TERMS OF THIS AGREEMENT. IF YOU DO NOT WISH TO DO SO, DO NOT RUN THE SOFTWARE AND PRESS "NO" BUTTON.

    1. Definitions
    "Software" means the programs supplied by DAMN herewith.

    2. License Restrictions
    You MAY NOT use this Software AT ALL. Using the Software will be prosecuted to the maximum extent possible under law. You also may not make or distribute copies of the Software, or electronically transfer the Software from one computer to another or over a network. You may not decompile, reverse engineer, disassemble, or otherwise reduce the Software to a human-perceivable form. You may not rent, lease or sublicense the Software. You may not modify the Software or create derivative works based upon the Software.

    3. Ownership
    This license gives you NO rights to use the Software. Although you own the media on which the Software is recorded, you do not become the owner of, and DAMN retains title to the Software. All rights including Federal and International Copyrights, are reserved by DAMN.

    4. Limitations of Damages
    DAMN SHALL NOT BE LIABLE FOR ANY INDIRECT, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES, EVEN IF DAMN HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES AND EVEN IF A REMEDY SET FORTH HEREIN IS FOUND TO HAVE FAILED OF ITS ESSENTIAL PURPOSE.
  • I suspect when these worms hatch by kvn299 (Score:2) Friday October 25 2002, @01:45PM
  • Funny points of their EULA (Score:3, Interesting)

    by SoCalChris (573049) on Friday October 25 2002, @01:46PM (#4531949) Homepage Journal
    From http://www.permissionedmedia.com/license.htm [permissionedmedia.com]:

    3. Updates/New Information. Permissioned Media reserves the right to add additional features or functions to the version of PerMedia you install, or to add new applications to PerMedia, at any time. As more fully disclosed in our Privacy Statement, PerMedia is designed to regularly communicate and provide information regarding your Internet use to Permissioned Media. Accordingly, Permissioned Media has the right and you hereby authorize it to update or automatically install a new version of PerMedia on your computer when a new version is released to the general public and/or when new features are available. Notwithstanding the foregoing, Permissioned Media and its business associates have no obligation to make available to you any subsequent versions of PerMedia. You may not distribute or copy PerMedia (r)other than for backup purposes).

    So you can't distribute their program in any way? Isn't that the whole point of the program? These guys really are a bunch of idiots!
  • Arrrrr..... by user311 (Score:1) Friday October 25 2002, @01:47PM
  • What are EULA's for? by A non moose cow (Score:2) Friday October 25 2002, @01:48PM
    • And one more thing... (Score:4, Funny)

      by A non moose cow (610391) <terralos@hotmail.com> on Friday October 25 2002, @02:08PM (#4532193) Journal
      I forgot to say...

      End users should have the leisure of clicking through software liscense agreements without reading them. These agreements were designed to protect the software companies from legal action by end users.

      If this intent is to remain intact, end users need to be able to click through EULAs with the mental summary of, "Yeah, Yeah, whatever, I promise not to abuse your software or sue you frivolously", instead of "I wonder if I just allowed a software company to use my computer and my data any way they see fit".
      [ Parent ]
  • Taking it one step further (Score:3, Funny)

    by kbielefe (606566) <d0s492i02@@@sneakemail...com> on Friday October 25 2002, @01:49PM (#4531971) Homepage
    This gives me an idea.

    I can create a virus and then sue anti-virus companies for distributing my virus "signature" in their software, which is obviously a derivative work.

    Another idea is to apply for a patent and then sue for patent infringement. Does anyone know if the buffer overflow technique has been patented yet?

    • 1 reply beneath your current threshold.
  • Not much different then the Microsoft EULA by caldaan (Score:2) Friday October 25 2002, @01:52PM
  • What? No /. effect? (Score:3, Insightful)

    by YrWrstNtmr (564987) on Friday October 25 2002, @01:53PM (#4532002)
    permissionedmedia.com is still up? Jeez, guys...let's get on the ball here. If any company's server needed to die, this is it.
  • Thank god for Trend Micro (Score:5, Informative)

    by unicorn (8060) on Friday October 25 2002, @01:54PM (#4532010)
    As of yesterday afternoon, Trend was classifying this as a virus, and will catch it.

    I knew there was a reason I migrated us from Symantec to Trend at the office here.
    • 1 reply beneath your current threshold.
  • EULA by aikido_kit (Score:1) Friday October 25 2002, @01:54PM
  • Sue them by flowerp (Score:1) Friday October 25 2002, @01:54PM
    • 1 reply beneath your current threshold.
  • I don't really care anymore. by /dev/trash (Score:1) Friday October 25 2002, @01:54PM
  • I've said it before. (Score:3, Interesting)

    by Restil (31903) on Friday October 25 2002, @01:55PM (#4532029) Homepage
    The only difference between this and a conventional worm is that it doesn't come with a payload package that will cause damage to the system, although spyware isn't much better. From what I can tell, this software serves no legitimate purpose. You have to install it to read the greeting card, which is sent by someone else installing the software. Does anyone ever actually send a legitimate "greeting card?" If not, there would be no reason to install this software. The only functional aspect of this application is to provide the user with advertisements, which even the most clueless user probably wouldn't install intentionally for only that purpose.

    Because the user has no legitimate reason to WANT to install this software, he/she has to be coerced into doing so with false pretenses. If this is legal to do, it would be no less legal to install a dangerous payload, so long as the EULA explains it and gives the user an option to cancel.

    Perhaps this would be a good time to try to challenge the validity of the EULA. Can't have it both ways. Either it's a binding contract and therefore if you agree to spam your contacts and have your harddrive formmated, you can't hold the author liable. Or EULA's will have to NOT be considered contracts and therefore this will apply to ALL EULA's. Or we can hope. :)

    -Restil
  • Reminds me of an awesome Dilbert by Dejohn (Score:2) Friday October 25 2002, @01:55PM
  • Makes you wonder... by BurKaZoiD (Score:1) Friday October 25 2002, @01:56PM
  • EULAs (Score:3, Insightful)

    by pizza_milkshake (580452) on Friday October 25 2002, @01:57PM (#4532061) Homepage
    yes, I think there's a valid argument for EULAs, however, I think there should be some kind of regulation. for instance...

    • important items in the EULA are often hidden or hard to find. EULAs should be ordered in chronological order of what will happen when the software is installed. also, items should be ordered in order of probability of happening, i.e. any actions the program is written to do (like spam your mailbox's email addies) would have to come before the 15 pages of lawyer-speak about how we can't sue the developer in the case that the software malfunctions (which, hopefully, it wasn't programmed to do) and your house burns down.
    • 90% of EULA content is the same. when software is released under the GPL or Apache or Artistic licenses, the user (assuming they've reviewed the license once before) has a reasonable idea of what they can or cannot do. common EULA sections, such as "you can't sue us, even if our program blows your machine up" (and the pages of related wording afterwards) can be summarized, or pointed to hyperlink-style. i.e. "this software is covered under the 'You Cannot Sue Us' clause, which could be a link to a standardized, common document that explains all the ugly details. the actual EULA could contain this statement, as well as any modifications the developers have made... that way, there's hopefully less to look at ("ah, they support the 'We Won't Ever Touch Any Non-Directly-Related Files on Your Computer', but they do take a snapshot of my entire filesystem and send it back to the mothership every night. *clicks 'NO'*
    i think there are alot of very reasonable ways to standardize and govern EULAs. of course, I'm just a programmer, so what do i know.
  • Want to complain? (Score:3, Informative)

    by AyeRoxor! (471669) on Friday October 25 2002, @01:58PM (#4532070) Homepage Journal
    Registrant:
    Permissioned Media Inc.
    Sun Towers, 1st Floor, Office #39
    Ave. Ricardo J. Alfaro
    Panama City, El Dorado Zona 6
    PA

    Registrar: Dotster (http://www.dotster.com)
    Domain Name: PERMISSIONEDMEDIA.COM
    Created on: 18-JUL-02
    Expires on: 18-JUL-07
    Last Updated on: 18-JUL-02

    Administrative Contact:
    Alfaro, Jay alfaro@hushmail.com
    Permissioned Media Inc.
    Sun Towers, 1st Floor, Office #39
    Ave. Ricardo J. Alfaro
    Panama City, El Dorado Zona 6
    PA
    571-628-5535
    571-628-5535

    Technical Contact:
    Alfaro, Jay alfaro@hushmail.com
    Permissioned Media Inc.
    Sun Towers, 1st Floor, Office #39
    Ave. Ricardo J. Alfaro
    Panama City, El Dorado Zona 6
    PA
    571-628-5535
    571-628-5535
  • more insane to come by u19925 (Score:2) Friday October 25 2002, @01:58PM
  • Happy Fun Ball by CVaneg (Score:1) Friday October 25 2002, @02:01PM
  • They are not the only ones... (Score:5, Interesting)

    by TeddyR (4176) on Friday October 25 2002, @02:04PM (#4532131) Homepage Journal
    The one that I loathe is the "hotbar" IE/outlook menu customiser (http://www.hotbar.com) which allows someone that has hotbar to send a card to a friend... but what the card does is download the hotbar and install it on the unknowning friends system...

    It also contains some social engineering.. "Upgrade outlook - add COLOR to your Emails" link...

    bah..

    just had to remove these from about a gazillion corp machines... and the virus scanners dont see it as a virus...

    even though it KILLS the systems efficency....

  • Don't forget GoHip! (Score:4, Interesting)

    by CaptainPhong (83963) on Friday October 25 2002, @02:06PM (#4532161) Homepage
    Gohip, I think is actually the first worm with an EULA (though I don't know if it still works that way.) Someone infected with it would have a signature attached to the end of all their e-mails saying something like "Get a free movie" with a link that installed (after, I believe, a click-through license) the GoHip scumware. It then attached itself to your outgoing e-mail, forced your homepage to gohip, and did other mangling to your browser.

    It's the oldest piece of scumware like that that I'm aware of (perhaps Bonzi buddy is similar age).

  • by 1984 (56406) on Friday October 25 2002, @02:06PM (#4532162)
    I'd be suprised if anyone has the desire and wherwithall to go challenging questionable EULAs throught he legal system. But perhaps that's not necessary -- the onerous terms sneaking in depend largely on the fact that nobody notices them, or that most people installing the software are ignorant of their implications.

    So I've registered:

    badlicense.org (and badlicence.org)

    I'd be happy to let that be used for a site dedicated to explaining the EULAs of software. Perhaps an overview, and details on particular products.

    Reasonably carefully worded it wouldn't even matter if the EULA had been interepreted in detail by a lawyer. Just highlighting the apparent detail should be enough to raise eyebrows and invite some clarification (perhaps, even, modification) from those issuing the EULA.

    So, anyone interested?
  • This is perfect!!! by qzulla (Score:2) Friday October 25 2002, @02:08PM
  • Too late to the party, but... (Score:5, Interesting)

    by Anthony Boyd (242971) on Friday October 25 2002, @02:10PM (#4532213) Homepage

    ...okay, so no one will read this at this late point, but for any and all software developers who are hunting for a useful product to build, why not create an EULA-distiller? Let it run in the background, and watch for installations. When it sees an EULA appear, it can display 2 or 3 bullet points that succinctly explain what the hell all the legal text means.

    To get really tricky, you could create a Web site that allows users to upload the text of each EULA, and a distilled summary. Perhaps other people could even vote on the most accurate, most understandable summaries. Then your app could be constantly up-to-date. Perhaps by doing this, people who blindly click through these things will be made aware of what the real consequences will be.

  • People are so profoundly stupid and gullible by A55M0NKEY (Score:1) Friday October 25 2002, @02:12PM
  • The Devil and EULA's by Easy2RememberNick (Score:1) Friday October 25 2002, @02:12PM
  • 95% yeah right! by baincd (Score:1) Friday October 25 2002, @02:15PM
  • I claim... by paiute (Score:1) Friday October 25 2002, @02:17PM
  • What's next...? by Da Fokka (Score:1) Friday October 25 2002, @02:18PM
  • 95% of users? by solostring (Score:1) Friday October 25 2002, @02:20PM
  • Legal? I don't think they are cause. by Anonymous Coward (Score:1) Friday October 25 2002, @02:27PM
  • warning! by newr00tic (Score:1) Friday October 25 2002, @02:34PM
    • Re:warning! by The Bungi (Score:2) Friday October 25 2002, @05:18PM
      • Re:warning! by newr00tic (Score:1) Friday October 25 2002, @06:53PM
  • Nyet! Windows 95 was the first worm with a EULA by mdechene (Score:1) Friday October 25 2002, @02:35PM
  • False advertising! by Spaceman40 (Score:1) Friday October 25 2002, @02:42PM
  • How can you not call this a "worm"? by Anonymous Coward (Score:1) Friday October 25 2002, @02:44PM
  • Profit!! by obdulio (Score:1) Friday October 25 2002, @02:44PM
  • Talk about evil genius.... by Bvardi (Score:2) Friday October 25 2002, @02:45PM
  • From their deep linking policy... by Derkec (Score:2) Friday October 25 2002, @02:46PM
  • They are taking advantage of morons. by eric_ste (Score:1) Friday October 25 2002, @02:52PM
  • I will only use my powers for good, not evil... by ScooterBill (Score:1) Friday October 25 2002, @02:56PM
  • Don't Use M$ Outlook!! by bubba_ry (Score:1) Friday October 25 2002, @02:57PM
  • Too hard on Symantec? (Score:5, Insightful)

    by jasonditz (597385) on Friday October 25 2002, @03:02PM (#4532594) Homepage
    It seems like a lot of you guys are really down on Symantec and McAfee for not filtering this with their AntiVirus software, but consider this.

    By clicking "I agree" on the EULA you are telling your computer "I want to do X". If you tell your computer you want to do X and Symantec's software tells your computer "he can't" how is that any different from all the DRM crap like Paladium?

    I know the intention in this case would be to protect the user, but then again isn't that the tack that Microsoft is taking as well?
  • by TheViffer (128272) on Friday October 25 2002, @03:02PM (#4532600)
    3306/tcp open mysql

    Guess we know where all those email addresses are being fed into.

    Might make a great project for someone to pull the login/passwd from the executable, and start force feeding that thing.

    But dont let me give you any ideas.

  • Oxymoron? by joebagodonuts (Score:1) Friday October 25 2002, @03:13PM
  • Domains/netblocks by macdaddy (Score:2) Friday October 25 2002, @03:13PM
  • If you try to sue.... by Anonymous Coward (Score:2) Friday October 25 2002, @03:19PM
  • We just need the "right" address list by Anonymous Coward (Score:1) Friday October 25 2002, @03:19PM
  • What goes around... by Anonymous Coward (Score:1) Friday October 25 2002, @03:25PM
  • What if your address book is empty? by yuri benjamin (Score:1) Friday October 25 2002, @03:26PM
  • This is a good thing--here's why: by Anonymous Coward (Score:1) Friday October 25 2002, @03:40PM
  • This is my story... by friendofafriend (Score:2) Friday October 25 2002, @03:43PM
  • More Dangerous Scenario by soft_guy (Score:1) Friday October 25 2002, @03:53PM
  • Ok...here's what we do by sayerofno (Score:1) Friday October 25 2002, @03:59PM
  • Doesn't this sound like Gator? by fox8118 (Score:1) Friday October 25 2002, @04:54PM
  • Information is Expensive by zanerock (Score:2) Friday October 25 2002, @05:04PM
  • Probably not the case ... by tdelaney (Score:2) Friday October 25 2002, @05:09PM
  • I can think of another example... by Jace of Fuse! (Score:2) Friday October 25 2002, @06:07PM
  • Problem solved by rapca (Score:1) Friday October 25 2002, @06:21PM
  • Isn't this protected by the DMCA? by router (Score:1) Friday October 25 2002, @08:47PM
  • Assent is OK? by erc (Score:1) Friday October 25 2002, @09:10PM
  • Reading EULAs by T. Will S. Idea (Score:1) Saturday October 26 2002, @03:10AM
  • Hmm by rsax (Score:1) Saturday October 26 2002, @04:41AM
  • So.. by mindstrm (Score:1) Saturday October 26 2002, @07:21AM
    • Re:So.. by idiotnonsavant (Score:1) Wednesday October 30 2002, @10:04PM
  • SpamAssassin recipe to detect this... by lar3ry (Score:2) Saturday October 26 2002, @11:36AM
  • Re:Brilliant Sociology Experiment by iSwitched (Score:1) Friday October 25 2002, @02:00PM
  • Re:good lord by dAzED1 (Score:1) Friday October 25 2002, @02:25PM
  • Re:Let me guess...It's M$ in disguise by Dolemite_the_Wiz (Score:1) Friday October 25 2002, @06:34PM
  • 26 replies beneath your current threshold.
  • (1) | 2