or typed on a computer is vulnerable to client-side surveillance, though most client
surveillance tools collect all possible data. Malware mostly targets various sorts of directly profitable data, including e-mail addresses and bank account information. The
most sophisticated anti-virus tools monitor all data stored on and transmitted to the
computer, checking the data for malware signatures, but not keyboard or screen activity. Market research tools like ComScore typically monitor all network traffic, whether
encrypted or not, but not stored data or keyboard or screen activity. Workplace and
family monitoring tools usually monitor keystrokes and periodic screenshots of the
activity on the computer screen but not stored or network data. The GhostNet report
demonstrated that active malware is even capable of activating and recording the webcams and microphones of infected computers.
Indeed, the biggest problem for client surveillance tools is often dealing with the
sheer amount of data. For example, even one screenshot a minute on a single computer can generate a daunting amount of data. This problem is magnified when applied over a large set of monitored clients. Botnets (networks of malware-infected
computers controlled from a single point) only search for a limited set of data, like
credit card numbers, which they can easily sell, presumably because of the difficulty
(and therefore unprofitability) of sifting through the vast trove of other sorts of data
on infected computers. Likewise, a primary challenge of corporate anti-virus systems
that must manage entire networks of clients is to manage the resulting flood of data
about infections and vulnerabilities in a network of clients.
Nonetheless, any client-side program has at least the potential to access every sort
of data that resides on or passes through the computer. So, a keylogger may only monitor keystrokes, but that restriction is mostly the choice of the tool (and its developers)
once it has been installed. Even non-surveillance-oriented programs (screen savers,
games, chat programs, and so on) potentially have complete access to data once they
have been installed. Most computers try to make it difficult for an arbitrary program to
take over a computer, but a constant stream of vulnerabilities gives client programs access to the entire computer. And this same level of access applies to most hardware
devices installed on the computer as well. Even devices that do not directly have the
ability to access a shared bus or run a driver may have the ability to infect clients with
malware, as shown by cases like virus-carrying digital photo frames. 46
Unlike server and network surveillance, client surveillance is always theoretically
detectable. Any change in the client behavior (whether processing data, storing it, or
sending it over a network) requires some detectable change to the client. In practice,
there is a long history of surveillance tools using increasingly sophisticated methods
to hide themselves, including through rootkits that embed themselves into the deepest
layers of the client operating system. But even with these sophisticated methods, there
are always small changes in behavior that at least theoretically make the tools detectable. But detecting these small changes in the large number of malware, spyware, and
other surveillance tools is beyond the capabilities of even the most sophisticated user.
48
Hal Roberts and John Palfrey
surveillance tools collect all possible data. Malware mostly targets various sorts of directly profitable data, including e-mail addresses and bank account information. The
most sophisticated anti-virus tools monitor all data stored on and transmitted to the
computer, checking the data for malware signatures, but not keyboard or screen activity. Market research tools like ComScore typically monitor all network traffic, whether
encrypted or not, but not stored data or keyboard or screen activity. Workplace and
family monitoring tools usually monitor keystrokes and periodic screenshots of the
activity on the computer screen but not stored or network data. The GhostNet report
demonstrated that active malware is even capable of activating and recording the webcams and microphones of infected computers.
Indeed, the biggest problem for client surveillance tools is often dealing with the
sheer amount of data. For example, even one screenshot a minute on a single computer can generate a daunting amount of data. This problem is magnified when applied over a large set of monitored clients. Botnets (networks of malware-infected
computers controlled from a single point) only search for a limited set of data, like
credit card numbers, which they can easily sell, presumably because of the difficulty
(and therefore unprofitability) of sifting through the vast trove of other sorts of data
on infected computers. Likewise, a primary challenge of corporate anti-virus systems
that must manage entire networks of clients is to manage the resulting flood of data
about infections and vulnerabilities in a network of clients.
Nonetheless, any client-side program has at least the potential to access every sort
of data that resides on or passes through the computer. So, a keylogger may only monitor keystrokes, but that restriction is mostly the choice of the tool (and its developers)
once it has been installed. Even non-surveillance-oriented programs (screen savers,
games, chat programs, and so on) potentially have complete access to data once they
have been installed. Most computers try to make it difficult for an arbitrary program to
take over a computer, but a constant stream of vulnerabilities gives client programs access to the entire computer. And this same level of access applies to most hardware
devices installed on the computer as well. Even devices that do not directly have the
ability to access a shared bus or run a driver may have the ability to infect clients with
malware, as shown by cases like virus-carrying digital photo frames. 46
Unlike server and network surveillance, client surveillance is always theoretically
detectable. Any change in the client behavior (whether processing data, storing it, or
sending it over a network) requires some detectable change to the client. In practice,
there is a long history of surveillance tools using increasingly sophisticated methods
to hide themselves, including through rootkits that embed themselves into the deepest
layers of the client operating system. But even with these sophisticated methods, there
are always small changes in behavior that at least theoretically make the tools detectable. But detecting these small changes in the large number of malware, spyware, and
other surveillance tools is beyond the capabilities of even the most sophisticated user.
48
Hal Roberts and John Palfrey
