Non-Genuine Software-Not So Cost-Effective After All

author-image
DQC News Bureau
New Update

Arecent KPMG study has shown that the security implications of deploying
non-genuine software includes threats that directly affect the end-user and an
organization's security as well as indirect threats leading to increased cost of
protection and remediation.

Advertisment

Considering these serious implications, the government is working towards
ensuring effective implementation of the legal and regulatory framework, and
facilitation of faster and punitive action for non-compliance. President
Pratibha Patil has already provided approval to a proposal that makes
Maharashtra the first state where not just selling but even buying pirated CDs
and DVDs can land one in prison.

It is the price difference between pirated/counterfeited ones and original
programs that attract consumers to purchase the non-genuine copy. Imagine having
to spend thousands of rupees for a license of a high-end picture editing
software such as the latest Adobe Photoshop CS3 when the pirated copy is
available at a mere Rs 150. Pirated versions are not only easily available
through physical media like CDs and DVDs, but also through the Internet. In fact
with its global reach, and continuously increasing penetration, Internet has
become one of the leading channels for acquiring non-genuine software. Several
websites and peer-to-peer (P2P) networks offer installable non-genuine software,
product keys and key generators.

Akhilesh Tuteja, Executive Director-IT Advisory
Services, KPMG India

One needs to think of long term effects

Using non-genuine software may be tempting to those who are not familiar
with the risks. What customers generally miss out, is the fact that it may be
cost effective in short term, but can turn out to be a lot more expensive when
one considers the long-term effects. At the very least, it can lead to software
incompatibility and viruses, driving up maintenance costs, and at the worst, it
can cost ordinary consumers hundreds or thousands of rupees and lost time due to
identity theft and the exposure of personal information.

Advertisment

A recent KPMG study has shown that in the context of individuals and
businesses, increased vulnerability to malware, damage to reputation, reduced
operational efficiencies and increased total cost of ownership (TCO) are some of
the downfalls of deploying non-genuine software.

The security implications of deploying non-genuine software are
multi-dimensional for individual computer users, such as directly impacting
security threats like loss of privacy and data confidentiality arising from
phishing attacks, malware and botnets, and ransomware.

From a broader macro-economic perspective, the use of non-genuine software
has the potential to adversely affect employment, tax revenues, industry growth
as well as national security.

Advertisment

Possible Implications of Using Non-Genuine Software

It is a common misconception that the use of non-genuine software leads to
cost reduction. Using non-genuine software can put one's personal information,
reputation, and financial security at risk.

Recent report from Symantec reveals that 82 percent of threats to
confidential information in Asia Pacific Japan (APJ) region were classified as
threats that export user data.

Owing to marginal cost of production, software piracy remains a high margin
business and thus a lucrative mean of generating revenue for anti-social
elements. The profit from selling non-genuine software is often used up to fund
counterfeit products, prostitution, weapons trading, and possibly even
terrorism.

Advertisment
KPMG study

  • 60 percent websites providing cracks, keygens, warez or counterfeits
    have potential threat vectors
  • 39 percent organizations surveyed reported security incident of
    non-genuine software detection in their IT environment
  • 35 percent organizations cited 'ready availability' as the reason for
    employees to use non-genuine software
  • Correlation coefficient between software piracy rates and malware
    attacks in a strong 0.74

  •  

    Internet has become one of the most common means of obtaining non-genuine
    software. But most of these products do not come free. Malicious software, or
    malware, comes as a packaged deal with them.

    Students often spend a lot of time on P2P sharing networks. These networks
    are a common medium of sharing software and other tools. However, most of the
    files contain trojans and worms which can lead to security issues for the
    academic institutions.

    Advertisment

    In recent times we have seen the government's share of IT spending increase
    consistently. If one of the departments decides to install a non-genuine
    software, significant amount of important information would be accessible to the
    outside community.

    Any organization or individual caught in the act of copyright infringement
    can be criminally prosecuted. They can be fined anything from Rs
    50,000-2,00,000, and a minimum jail sentence of seven days going up to three
    years can be levied.

    The Road Ahead

    Even though the IT Act, 2000 (and now the IT Amendment Act, 2008) relating
    to data security and data integrity and the Copyright Act, 1957 provides
    protection of intellectual property rights (IPR) in software, implementation
    continues to pose challenges. A satisfactory solution to the business software
    piracy problem has proven elusive to the software industry. But it doesn't mean
    that the concerned authorities have given up.

    Advertisment

    The Indian government has set up CERT-IN (Computer Emergency Response Team
    India) with the charter to become the nation's most trusted referral agency of
    the Indian community for responding to computer security incidents as and when
    they occur. Many businesses today have created special roles in the ranks of
    Chief Security Officers (CSO) / Chief Information Security Officers (CISO) to
    limit the hazards of information security threats. By educating users about
    copyright laws and the benefits of legal software, third-party organizations are
    striving to create an environment that respects intellectual property rights.

    Despite all measures a pandemic cannot be controlled if the subjects don't
    take adequate precautions. Usage of non-genuine software is similar to a
    pandemic which cannot be controlled adequately if we all-the end users-don't
    exercise restraint.