Malwarebytes may not be allowed to label rival's app as 'potentially unwanted'
- Reference: 1686081370
- News link: https://www.theregister.co.uk/2023/06/06/malwarebytes_enigma_pup/
- Source link:
Florida-based Enigma has been trying to hold Malwarebytes accountable for blocking its programs since 2017 when the firm initially sued Malwarebytes for [1]tortious interference , violation of New York business law, and [2]false advertising under the Lanham Act.
This suit was filed in response to antivirus maker Malwarebytes labeling Enigma's anti-spyware tool a PUP – soft, supposedly legally safe industry jargon for malware or almost-malware. That labeling caused Malwarebytes' software to automatically quarantine and remove Enigma's Spyhunter from PCs. Enigma objected to the classification.
[3]
A district court judge hearing the complaint in California [4]dismissed the claim , citing the 2009 [5]Zango v. Kaspersky decision, which affirmed that security firms have some latitude to classify software as harmful. The judge dismissed the case on [6]Section 230(c)(2)(B) grounds, which exempts interactive service providers from liability for content moderation decisions.
[7]
[8]
But Enigma appealed and the Ninth Circuit in 2019 [9]reversed the district court's decision, creating in the process an anticompetitive animus exception to Section 230 of the Communications Decency Act that generally shields online service providers.
That appellate ruling meant that Malwarebytes may be liable for characterizing Enigma's software as PUPs if it's deemed to be a competitor – a decision that has the potential to discourage security companies from characterizing software as harmful.
Fight back
Malwarebytes, supported by advocacy groups and other security outfits, [10]asked the Supreme Court to review the case but was denied in 2020.
In 2021, the California district court, having been told by the Ninth Circuit to reconsider Enigma's lawsuit, again dismissed the complaint. So far, Malwarebytes has been generally winning, and Enigma losing.
When a company in the computer security business describes a competitor’s software as 'malicious' and a 'threat' to a customer’s computer, that is more a statement of objective fact than a non-actionable opinion
At the time, Malwarebytes' outside counsel, Moez Kaba of Hueston Hennigan, [11]celebrated the judgment by noting the district court’s ruling "validates the right of cybersecurity firms to identify potentially unwanted programs and recognizes the rights of users to choose whether or not to enable those programs on their devices."
But Malwarebytes' victory lap was premature. Enigma appealed again, and the Ninth Circuit last week [12]revived the case [PDF], except for Enigma's claim of tortious interference with contractual relations. The case now heads back to the district court, subject to the appeals court's direction that New York law also needs to be considered alongside the false advertising claim.
[13]
"In the context of this case, we conclude that when a company in the computer security business describes a competitor’s software as 'malicious' and a 'threat' to a customer’s computer, that is more a statement of objective fact than a non-actionable opinion," the appeals court decision reads. "It is potentially actionable under the Lanham Act provided Enigma plausibly alleges the other elements of a false advertising claim."
Enigma in [14]a statement cited the appeals court's rejection of a First Amendment free speech defense: "Enigma has alleged that Malwarebytes disparaged Enigma's products for commercial advantage by making misleading statements of fact. If those allegations are true, and at this state we must presume that they are, trying to wrap them in a First Amendment flag does not make them any less offensive or any less actionable."
[15]Microsoft takes PUPs behind the shed with gun in hand
[16]Let adware be treated as malware
[17]Avira turns tables to launch lawsuit against ‘crapware’ slinger
[18]ESET rushes to defend rival Malwarebytes in legal war over 'unwanted program' labeling
Eric Goldman, professor at Santa Clara University School of Law, told The Register in an email, "This case is like a wrecking ball for internet law."
"The Ninth Circuit already damaged Section 230 by creating an exception to its coverage (for 'anticompetitive animus') that no one understands and has not benefited anyone. Then, when the Supreme Court denied the appeal, Justice Thomas wrote a gratuitous error-riddled statement about Section 230 that spurred many regulators to pursue their censorship agendas. Now, the Ninth Circuit has redefined the standards for what constitutes a statement of 'fact' as opposed to an opinion in a way that hurts businesses in the anti-threat software space and well beyond."
The Ninth Circuit has redefined the standards for what constitutes a statement of 'fact'
Goldman said the majority's decision to treat the terms "malicious" and "threats" as simple true or false classifications doesn't fit with the way the security industry actually works. And by doing so, he argues, the court has made disputes about classifications more likely and has raised the costs and risks of making such classifications.
"If each classification could similarly support weaponization in court by businesses unhappy with the classifications, then anti-threat software vendors will avoid the financial and legal risks by lowering their cybersecurity standards or exiting the industry," said Goldman. "That puts all of us at greater risk."
In his dissent from the majority, Ninth Circuit Judge Patrick Bumatay took a similar position: "By treating these terms as actionable statements of fact under the Lanham Act, our court sends a chilling message to cybersecurity companies – civil liability may now attach if a court later disagrees with your classification of a program as 'malware.'"
[19]
Goldman said he believes the case is a good candidate for an en banc review by the Ninth Circuit, which involves all of the judges instead of just three of them.
Malwarebytes did not immediately respond to a request for comment. ®
Get our [20]Tech Resources
[1] https://www.law.cornell.edu/wex/tortious_interference
[2] https://www.law.cornell.edu/wex/false_advertising
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZH@sgRwrTZ7UTjqK6TtsxQAAANI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.theregister.com/2017/11/10/malwarebytes_enigma/
[5] https://www.theregister.com/2009/07/01/kaspersky_zango_win/
[6] https://www.law.cornell.edu/uscode/text/47/230
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZH@sgRwrTZ7UTjqK6TtsxQAAANI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZH@sgRwrTZ7UTjqK6TtsxQAAANI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2019/09/13/malwarebytes_enigma_blocking/
[10] https://www.theregister.com/2020/06/15/eset_malwarebytes_enigma_supreme_court/
[11] https://press.malwarebytes.com/2021/09/29/malwarebytes-wins-dismissal-of-enigma-lawsuit-in-final-ruling/
[12] https://storage.courtlistener.com/recap/gov.uscourts.ca9.334061/gov.uscourts.ca9.334061.38.1.pdf
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZH@sgRwrTZ7UTjqK6TtsxQAAANI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[14] https://www.prnewswire.com/news-releases/enigma-software-group-prevails-over-malwarebytes-at-the-ninth-circuit-301843038.html
[15] https://www.theregister.com/2015/11/30/microsoft_potentially_unwanted_programs_nixed_in_forefront_and_systemcentre/
[16] https://www.theregister.com/2019/05/20/wajam_malware_claims/
[17] https://www.theregister.com/2015/10/29/avira_sues_alleged_nuisanceware_vendor/
[18] https://www.theregister.com/2020/06/15/eset_malwarebytes_enigma_supreme_court/
[19] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZH@sgRwrTZ7UTjqK6TtsxQAAANI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[20] https://whitepapers.theregister.com/
I'd be interested to hear Malware Bytes' justification for labelling Enigma's software as a PUP.
History
It's a bit messy but it goes back to 2016 when Enigma [1]sued a blog for posting a negative review of Enigma's Spyhunter. Enigma then, in a lawsuit against Malwarebytes, claimed the blog was affiliated with Malwarebytes, and the classification of its Spyhunter as a PUP was in part a retaliatory move.
MB [2]said at the time Spyhunter simply met its criteria of a PUP. Enigma says its tools aren't PUPs.
C.
[1] https://www.theregister.com/2016/02/25/bleeping_computer_asked_to_bleep_out_post/
[2] https://www.malwarebytes.com/blog/news/2017/11/winning-the-battle-against-pups-on-your-computer-and-in-u-s-district-court
What does this say about Microsoft ...
not just labelling Firefox as bad but actively replacing it as the user chosen web browser and setting Edge as default ?
Legal definition of malicious software
I'd love a rule that allows any functionality that is installed without the device administrators informed consent to be called malware.
Even if it does not anything bad it should not be there if it comes as a surprise - especially (but not limited to) when it is automatically installed with some 3rd party software.