Installing unauthorized software programs on your computer at work may seem harmless or even beneficial but there are risks
But, just like the speed limit, it is a law that is often broken.
Like speeding, the use of illegal software may be widely condoned but it can get you into trouble with the law.
With the increased use of networks and the Internet in daily business computing, the potential for encountering hostile code is higher than ever before.
People collaborate in more sophisticated ways by using e-mail, instant messaging, and peer-to-peer applications., As these collaboration opportunities increase, so does the risk of viruses, worms, and other hostile code invading your systems., Viruses and worms often use social engineering to trick users into activating them. With the sheer number and variety of forms that code can take, it can be difficult for users to know what is safe to run and what is not.
If left to their own devices, many PC users will happily load applications that the IT Department “thoughtlessly failed to provide them with.”
And laptop users will sometimes discover that their teenage children have seen fit “to enrich” their laptop with a computer game or two
It’s not about recognizing the bad software, it’s about authorizing the genuine applications and ensuring that they are the only software that can run.
What does a certified software manager at a manufacturing company do when he can't seem to stop his end users from bringing in software from home or downloading the beta of some cool new application off the Internet?
games to play during break time
media players for the same reason
maybe, signature files for email, weather programs
Pirated Software, warez, commercial software that has been pirated and made available to the public via the Internet or an electronic bulletin board., Widely used in cracker subcultures to denote cracked version of commercial software, that is versions from which copy-protection has been stripped. Hackers recognize this term but don't use it themselves., also called illegal software
Unknown Software, non-malicious, Hostile code is not the only threat—many non-malicious software applications also cause problems.
He goes to upper management and explains the business risks in terms they can understand -- unlicensed software can lead to audits by the Software Publishers Association and, ultimately, large fines
Freeware and low-cost software downloaded from the Internet or distributed on floppy disks or CDs can contain viruses that will infect your system and spread to other computers on the network.
lack of knowledge about the source
Unauthorized software may contain sypware that will capture information you type and send it to marketers or criminals.
Unauthorized software may be poorly written, intended for use with a different operating system, or have conflicts with currently installed software that can cause it to crash your computer or send unwanted messages on the network.
Any software not known and supported by an organization can conflict with other applications or change crucial configuration information
Unlicensed software may cause incompatibility between programs that would normally function together seamlessly.
"There are support issues, there are compatibility issues. With version control and all the things associated with managing the desktop come cost factors in terms of having stray software or different software out there,
Unauthorized software might be pirated (copied illegally), which could subject the University to penalties in case of a software audit.
impact, subject to legal action and penalties
Unauthorized software, once installed is seldom kept current. The software may not contain known security flaws when installed but hackers may discover and exploit flaws. The software company corrects these security flaws and releases an updated version. Most users never update the software once it is installed and is vulnerable to the security flaws.
you can expect no warranties or support for illegal software, leaving your company on its own to deal with any problems.
Impact, If you have a technical issue in need of resolution, often times a work-stopping issue, the district would not have the resources needed to rectify the situation. In addition, product upgrades – less expensive upgrades of existing products – are not available to the district., By violating or ignoring standard procedures, users create diversity among corporate desktops and ultimately cause help desk headaches, By violating or ignoring standard procedures, users create diversity among corporate desktops and ultimately cause help desk headaches, It's not unusual for a help desk to come to the aid of users complaining of applications that won't open, buggy versions of software, or machines that are out of memory, and then discover that a great deal of the software isn't even supposed to be there.
loss of data on disk
lanch an attack
flood network for DOS
send confidential information out to the Internet
compromise the security of a machine
Abuse of software licenses can result in financial penalties, legal costs, and damaged reputation. Additionally, administrative personnel of VBSD can be held individually liable, both criminally and civilly, for any copyright infringement that occurs within the district.
When using unlicensed software, the district will not be eligible for technical support from the software publisher.
some AV products, Sanctuary and Bit9 Parity provide different policy options on how to deal with unauthorized software
NetCensus, NetCensus asset recognition software from Tally Systems. NetCensus, which runs at boot time, takes a complete inventory of the hardware and software on a PC, including software manufacturer, name, version, and serial number., he and his staff can delete unauthorized files from the network from a centralized location
ActiveX for example
what does this mean exactly?
The first step is to try and make sure employees can't install applications--this will solve a big portion of the problem
can look up some eWP policies here
The second step is to realize that most of the unauthorized software and illegal software are downloaded from the Internet
filtering, blocking at different layers
threaten to log Internet download activities
Businesses should have a centralized managed policy to manage traffic or files that are going in or out of the enterprise
limit number of hours connected and at which time