What did Congress do when folks started getting persnicketty about spam problems? Pass the CANSPAM Act, which both legalized certain (still irkstome) forms of spam and preempted state laws on the subject. The result was — well, how much less spam are you getting today than a year ago?
So Congress is now busy getting in a big uproar about spyware on PCs. The result, some fear, may be legitimizing spyware from big commercial vendors while not doing a heck of a lot to the folks who are already breaking the law.
And, of course, it will preempt any state laws on the subject. Swell.
H.R. 2929, currently called the Spy Act, is moving through the House so fast it’s hard to keep track of what it says. The version now headed to the House floor (after being approved by the same House committee that approved what became Can Spam) does at least have a requirement that the user be notified in plain English what the spyware/adware does. Unfortunately, it also very pointedly pre-empts the much stronger Utah law. Even worse is the fact that it leaves enforcement solely to the FTC, even though FTC officials have made it clear they have neither the will nor the means to go after any but the most criminal offenders.
It’s a good bet that, once the lobbyists are finished with it, the Spy Act will read more like the Sneakwrap-Sanctioned Spyware Protection Act. Software industry lobbyists are already attacking the law’s rather mild notice-and-consent requirement as being too burdensome. In fact, organizations that have long championed the sneakwrap licensing approach now claim they are trying to save users from having to read too many notices. For example, the Business Software Alliance issued a statement saying the notices the bill mandates won’t allow consumers to distinguish between legitimate vendors and the bad actors. “We are concerned that the ‘one size fits all’ notices approach will not help to inform consumers about how their personal information is being used, and will become just another screen to click ‘I agree.'” BSA CEO Robert Holleyman said in the statement.
I can’t begin to tell you how ironic it is for someone who watched UCITA’s creation to hear the BSA argue that users should not be required to mindlessly click OK.