View Full Version : Sony Facing the Music over Rootkits



ibda12u
11-03-2005, 09:42 AM
http://www.techtree.com/techtree/jsp/article.jsp?article_id=68978&cat_id=582.


According to reports, Sony has been stealthily installing hidden software on PCs, when people try to play Sony BMG music albums on their computers.

This software installs automatically, when users insert music CDs with XCP digital rights management technology in their computers. The software is geared towards limiting the number of copies that users can make from CDs, plus restricting ripping of the disk.

Software developer, Mark Russinovich, discovered that Sony had secretly installed a rootkit on his system. He traced the software back to Sony and the XCP technology, from First 4 Internet, an English software developer.

The rootkit helped to hide the digital rights management technology, both from the user as well as the system, including the anti-virus software. When Russinovich tried to remove the application, he found that his CD drive was disabled.

Sony's new software, called Extended Copy Protection (or XCP), uses rootkit techniques to prevent users from removing copyright protection technology, and violating Sony's copyrights. However, this feature can also be abused by worm authors to hide malicious applications.

For example, Botnet operators are increasingly using rootkits to prevent detection of their malware; a phenomenon which has given birth to an entire industry building and updating anti-virus tools for combating this malware.

From Sony's point of view, its motives are reasonable; but security experts say this is a potential threat to security. Sony however has denied that the technology is malicious, or compromises on security in any way.

Meanwhile analysts are of the opinion, that Sony has dealt itself a serious blow, and the best thing that the company, and all the rest of the music publishers could do right now, is to condemn the practice and apologize to the affected customers.

windowphobe
11-03-2005, 05:21 PM
It does, however, mean that I will never buy another Sony/BMG title until I have some assurance that it won't screw around with my hardware.

And I can carry a grudge for a long, long time.

okcpulse
11-22-2005, 07:56 AM
I really don't listen to today's music, so most of what I want to buy doesn't have XCP. Any recording guru knows there are ways around this crap. My problem is, and always will be, that when an album goes out of print, it's impossible to get. And since most of my collectible CDs were stolen, there is no way to replace those. Two of those albums aren't even on legal downloading sites (good job, morons from the music industry) so my only option is illegal downloads. Where the hell else am I supposed to replace my collection?!

Sony can claim it's safe all they want. It's the same rootkit used for malware and viruses. All they care about is protection.

MadMonk
11-22-2005, 09:09 AM
http://www.userfriendly.org/cartoons/archives/05nov/uf008519.gif (http://www.userfriendly.org/)

I hope it bites 'em in the arse like that.

Julie
11-27-2005, 08:39 PM
Great.. is this stuff spyware or just normal software?
Thats a worry though..