iTnews

FTC closes probe into LimeWire inadvertent file sharing

By Dan Kaplan on Aug 31, 2010 2:02PM

P2P site's security controls may have been vulnerable.

The US Federal Trade Commission (FTC) will not take any action against LimeWire following an investigation the agency opened into the popular file-sharing program's security controls.

The FTC was probing reports that some older versions of LimeWire allowed users to accidentally share sensitive information stored on their computers, according to a letter addressed to LimeWire CEO George Searle.

The letter, written by FTC Associate Director Mary Koelbel Engle, said the agency was satisfied with LimeWire's adoption of safeguards to prevent the inadvertent sharing of personal data and the understanding that the company is unable to force users to upgrade to new versions. In addition, the agency accepted that some older versions were "able to avoid" disclosing confidential data and that many users upgraded anyway.

"We remain concerned, however, about consumers who are still using insecure legacy versions and are therefore subject to a risk of inadvertent sharing of sensitive, personal information," Engle wrote. "We expect LimeWire to continue to advise consumers to upgrade legacy versions of its software because of the potential safety benefits of doing so, and to participate in industry efforts to inform consumers about how best to avoid the inadvertent sharing of sensitive documents. Based on that expectation, it appears that no further action by the FTC staff is warranted at this time, and the investigation is closed."

Minaxi Gupta, an associate professor of computer science at Indiana University who has studied the risks of peer-to-peer (P2P) networks, said she doesn't know the specific reason for the FTC's investigation, but assumes it was the result of vulnerable software.

"Peer-to-peer networks generally only serve things available in the shared directory," she said. "However, it's quite conceivable that some of these older versions had vulnerabilities. [Cybercriminals] certainly can use those vulnerabilities to get out of the shared directory and look around on [someone's] machine."

Gupta likened such an exploit to an attacker changing DNS records on a victim's PC and forcing them to visit a website of their choosing.

But she said she understands that LimeWire was limited in what it could do to resolve the issue after the fact.

"People don't apply patches and it's difficult to get everyone to comply," Gupta said.

LimeWire applauded the FTC's decision to drop the investigation.

“The factors noted by the FTC in voluntarily closing the investigation speak for themselves," said a statement. "We have incorporated many safeguards and have taken active steps to educate users of current and older software versions to avoid disclosure of sensitive information. We will remain dedicated to ensuring the security and serving the needs of our global user base."

See original article on scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:
closes file ftc inadvertent into limewire probe security sharing

Partner Content

Resetting cyber security for the new threat landscape
Partner Content Resetting cyber security for the new threat landscape
MSI launches business laptops with impressive battery life, style
Partner Content MSI launches business laptops with impressive battery life, style
What is zero trust cybersecurity?
Partner Content What is zero trust cybersecurity?
Shut the door on ransomware
Promoted Content Shut the door on ransomware

Sponsored Whitepapers

Customer Identity and Access Management for Dummies
Customer Identity and Access Management for Dummies
Empowering workforces in the new environment
Empowering workforces in the new environment
Is the technology refresh dead?
Is the technology refresh dead?
DevSecOps: A framework for digital innovation
DevSecOps: A framework for digital innovation
Encryption: Protect your most critical data
Encryption: Protect your most critical data

Events

  • On-Demand Webinar: How Poly and Microsoft are Embracing Future Work Environments
  • [Webinar] - Transformation versus compliance – a guide for CXOs
  • "How Digital Transformation can solve the cyber challenge"
  • Masters of Microsoft Licensing
  • Is your DevSecOps stuck in first gear?
By Dan Kaplan
Aug 31 2010
2:02PM
0 Comments

Related Articles

  • Senate committee red-flags govt data sharing bill
  • ASIC joins Reserve Bank NZ as victim of Accellion hack
  • Govt's public sector data sharing bill enters parliament
  • South Korean watchdog fines Facebook $8.2 million
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Kmart Australia and NZ will put a robot called TORY into every store

Kmart Australia and NZ will put a robot called TORY into every store

Aussie Broadband says some customers are switching providers to get high-speed NBN discounts

Aussie Broadband says some customers are switching providers to get high-speed NBN discounts

Swinburne University data breach exposes details of 5000 staff, students

Swinburne University data breach exposes details of 5000 staff, students

NAB sacked tech worker behind 2019 data breach

NAB sacked tech worker behind 2019 data breach

You must be a registered member of iTnews to post a comment.
Log In | Register
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.