NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Interviews

Interviews


Malwarebytes Accuses, IObit Plays Dead

Exclusive interview with Malwarebytes

By Lucian Constantin, Web News Editor & Stefan Fintea, Software News Editor

8th of November 2009, 11:51 GMT

Adjust text size:


Exclusive interview with Malwarebytes CEO, Marcin Kleczynski
Enlarge picture
Malwarebytes burst the bubble this week and came out accusing IObit of copying their database, thus providing through their IObit Security 360 product the same protection as Malwarebytes' Anti-Malware. The copyright infringement implications led to DMCA serving of the latter to a number of software download websites in US.

Both security vendors have engaged in a war of statements on their respective blogs, stirring up heated discussions among users on their forums. Speculations have been made, opinions expressed, but no official answer to clear all haze has been given. We tried to learn about the sparks that lit the scandal and the elements fueling it.

Before we begin, we'd like to note that, in order to be fair and give everyone involved a chance to express their point of view, we also sent a set of questions to IObit for a similar interview. We have received a short response from one of the company's representatives, making it clear that the vendor had more important software development-related tasks on hand than to continue responding to Malwarebytes' accusations.

From the reply we got, we conclude that IObit's position regarding this issue remains unchanged. The company describes Malwarebytes' claims as mere rumors and its actions as unwarranted attacks.

On the matter of other antivirus vendors possibly making similar accusations in the future as a result of this incident, the IObit spokesperson stressed that the company did not steal signatures from anyone and noted that everyone was encouraged to test their database.

Here is how Malwarebytes CEO Marcin Kleczynski responded:

Softpedia: How did you learn about IObit's inclusion of Malwarebytes signatures in their database in the first place? Should you have missed the post on their forum showing IObit 360 flag the Malwarebytes keygen under the name you gave it, would all this have been blown to the public?

Marcin Kleczynski: We began to suspect IObit had stolen Malwarebytes' database when we noticed a pattern of similarity between IObit scan results and our own Malwarebytes' Anti-Malware scan results. One clear example of this pattern of similarity occurred when IObit flagged a key generator for our own Malwarebytes' Anti-Malware software under the same name "Don't.Steal.Our.Software.A" we use to flag such keygens. Why would IOBit detect a keygen for our software and refer to it using our database name? If we had not noticed this particular incident, we are confident we would still have uncovered the theft with time, but it might have taken a little longer.


Softpedia: What are the legal actions you are willing to take against IObit, considering that they are based in China? Also, United States Digital Millennium Copyright Act covers only websites in US, do you think other websites in the world will join your fight?

Marcin Kleczynski: While we are not going to comment on our legal strategy, we can tell you we are taking every measure within our power to enforce our intellectual property rights. IObit is hosted by a number of American website including CNET's Download.com and MajorGeeks.com; we have served DMCA infringement notices to both of these websites and they have removed IObit files already. IObit's website iobit.com is also hosted by an American company (Softlayer Technologies), who we have also served with a DMCA notice. We have seen an incredible outpouring of support for Malwarebytes from the security community around the world and are confident the situation will be resolved.


Softpedia: Did you receive any official explanation from their camp, except from the public declaration on their blog?

Marcin Kleczynski: We have no comment on that at this time.


Softpedia: How do you cope with their statement that "Until now, Malwarebytes cannot provide any convincing proof to support its fallacy. We hope Malwarebytes immediately stop spreading malicious rumors for hyping itself. We have many independent and objective reviewing tests and reports from users. You can download and view them from this link. We believe that, after viewing these test reports, you can judge - we never stole database from Malwarebytes." and "In consideration of Malwarebytes’ fallacy and calumniation, and its terrible effect to our company, products and reputation, we hereby demand that Malwarebytes immediately discontinue to spread all rumors regarding this issue. Otherwise we will consider all appropriate action to protect our rights."

Marcin Kleczynski
:
We issued a reply statement explaining precisely how IObit's denials have failed to explain the evidence presented. We invite you to consider the arguments we presented; we believe the evidence to be incontrovertible.

Softpedia: The average user may think that it was simply human error from IObit's part ("a mistake that one of our analyzer [IObit's] carelessly and directly used the sample “Don’t.Steal.Our.Software.A.” submitted by the user"), although you managed to prove quite the contrary. How do you feel about IObit's response?

Marcin Kleczynski: Again, we issued a reply statement explaining precisely how IObit's denials have failed to explain the evidence presented. We invite you to consider the arguments we presented. There is no way human error can explain how IObit detected an in-house dummy tool we built, never released to the Internet, and added as a trap definition to our own database.

The only explanation is that IObit must be stealing the definitions directly from our database. In the case of the keygen detected as "Don't.Steal.Our.Software.A", perhaps if this were a single isolated match, perhaps it could be written off as a coincidence, a mistake, an accident. But this is a repeated pattern, as we have demonstrated in our reports. It is no accident.


Softpedia: As some security professionals have pointed out, the theft of virus signatures is not really new to the antivirus industry, with other similar incidents having transpired in the past. Granted, maybe they were not as obvious as this one, but the vast majority of them were settled privately by the involved parties. Did you attempt to contact IObit and sort this out before going public with it? If yes, what was their response and if not, what determined you to conclude that this is the best approach?

Marcin Kleczynski: A theft of this magnitude, where tens of thousands of definitions were lifted from Malwarebytes' database and added literally byte-for-byte verbatim to IObit's, is unprecedented. We do not take such abuse lightly! We pour our heart and soul into making Malwarebytes Anti-Malware the best security software we can, and it makes us angry to see our hard work ripped off. IObit's actions are unethical and criminal and we thought it was relevant for the public to know that.


Softpedia: Both MalwareBytes and IObit are financially involved with download websites, which, in spite of all the evidence you provided, still promote IObit. How would you comment their decision?

Marcin Kleczynski: As we mentioned above, CNET Download.com and MajorGeeks.com have both removed IObit files from their servers. Softpedia has removed them as well. These are the major hosts we and IObit use, and we view these removals as constructive first steps. IObit have also themselves removed the installer for IObit Security 360 from iobit.com.


Softpedia: What is your goal in this matter? What exactly do you hope to gain by taking legal action? It's obvious that immediate take-down from download portals and removal of stolen signatures will not be enough.

Marcin Kleczynski: We want our software to be our software. Malwarebytes is run by ethical people who want the security software world to be an ethical place. We have strong senses of right and wrong, and what IObit did was wrong. They stole our intellectual property. They damaged our business and our reputation. We want that to be remedied.


Softpedia: Do you suspect IObit of cheating their way through other obstacles as well? In-depth analysis has demonstrated a much lower quality in IObit products but, still, their security solutions are often a match for your own when it comes to user download numbers and ratings.

Marcin Kleczynski: We are not going to comment on any other unethical behavior by IObit. We can only comment on what we researched ourselves thoroughly, which is the theft of our database.


Softpedia: In light of recent events, have you considered implementing in MBAM other, more efficient ways of detecting this type of theft?

Marcin Kleczynski: We are exploring ways to ensure this does not happen again in the future.


Softpedia: Did you receive any serious negative feedback from IObit users and fanboys? How would you comment the impact your declaration had on the “masses”?

Marcin Kleczynski: The response has been almost entirely positive, from Malwarebytes and IObit users alike. We have witnessed an incredible outpouring of support for Malwarebytes and the hard work we put into our research and products, and we are humbled and grateful for it. We presented our case objectively and clearly, laid out all the evidence, and people have responded to that. In our view the evidence is incontrovertible and readers have agreed.


Softpedia: You pointed out that during your investigation you uncovered evidence of IObit stealing the signatures of other antivirus vendors as well. You also mentioned that you have contacted these companies. We understand if you cannot gives names, but can you tell us how these affected companies reacted in general and if their response was favorable to your cause or not? Is any of them preparing to take actions?

Marcin Kleczynski: We will let the other companies comment on that.

TAGS:

Malwarebytes | IObit | anti-malware
Read by 2,654 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Excellent (4.8/5) 17 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Hackers of Kaspersky, Bitdefender, F-Secure and Symantec Speak Up

The Insides of Panda Cloud Antivirus

SPAMfighter: 6 Million Users Fighting Spam

User opinions:


Comment #1 by: wildman on 09 Nov 2009, 19:34 GMT reply to this comment

If I am reading this correct, I hope this means that all IoBit products have been removed from U.S. outlets and just not selected ones. Some outlets forum posts could be viewed as indicating a reluctance on their part to be willing to remove all IoBit products. Please clear this up. Have all IoBit products been removed or only a selected few?

Thanks
Wildman

Comment #1.1 by: Lucian Constantin on 10 Nov 2009, 08:58 GMT

Hello and thank you for taking an interest into our article.

We can only tell you with 100% certainty what Softpedia did, which was to remove the download links (not the entire listing) for the IObit Security 360 product.

It did not remove download links for other IObit programs from its website, as they are not the subject of copyright infringement allegations and to our knowledge, there is no evidence to support such claims. As far as we can tell, none of the software listing websites mentioned in this article have removed other IObit products in addition to IObit Security 360.

Furthermore, we would like point out that the company operating Softpedia.com is not based in the United States and as such, was not served with a cease-and-desist letter under the Digital Millennium Copyright Act. Therefore, Softpedia did not remove the IObit Security 360 download links because it had a legal obligation, but because it decided it is the right and ethical thing to do. This is a temporary decision until things clear up.


Comment #2 by: doug on 09 Nov 2009, 22:05 GMT reply to this comment

Well stated.
Hopefully this matter will now be handled at a higher level, in keeping with the professionalism and civility demonstrated in this article.


Comment #3 by: pcbutts1 on 10 Nov 2009, 00:14 GMT reply to this comment

" Malwarebytes is run by ethical people who want the security software world to be an ethical place. We have strong senses of right and wrong, "

Ethical? you added definitions to detect and remove my software which is not malicious simply because you don't like me, and you come here and talk about ethics?. Look in the mirror.

As far as IOBit is concerned yes I know for a fact they have stolen your database because now theirs detects mine.


Comment #4 by: MC on 10 Nov 2009, 19:59 GMT reply to this comment

Age has nothing to do with it. Look where relying on so called civilized adults has got the world recently. If I was Malwarebytes CEO then I'd be jumping up and down too and I'm 58. If users really do care about ethics and not just talk about caring then now is the time to vote with your feet. Some of Iobit's stuff was good but none of it was ever exceptional. There are plenty of others alternatives both free and paid so I would invite everyone else to do what I did i.e. un-install their stuff and use something else.


Comment #5 by: Trisha on 12 Nov 2009, 17:36 GMT reply to this comment

" Malwarebytes is run by ethical people who want the security software world to be an ethical place. We have strong senses of right and wrong, "

Blah! Blah! Blah! Ethical hahaha

Open MBAM and in About dialog what do you see?
"This software contains components developed by VbAccelerator"

Please tell us who is this VbAccelerator? As per the license of vbAccelerator.com you should include this line : "This product includes software developed by vbAccelerator (http://vbaccelerator.com/)."

But you changed it to remove the web site address and changed vbAccelerator toVbAccelerator. And then you come here telling about ethics and strong sense of right and wrong?

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM