IT security
Worm authors could exploit the Sony feature to hide malicious applications
R E L A T E D   C O N T E N T
ADVERTISEMENT

Sony rapped over music CD rootkit

Record label backtracks after public outrage over cloaking technology

Tom Sanders in California, vnunet.com 03 Nov 2005
ADVERTISEMENT

Sony has released a patch for a music CD anti-piracy technology after security experts warned that it represents a potential security risk. 

The copyright protection software would automatically install when a consumer inserted a music CD with the XCP digital rights management technology in their computers.

The software is designed to limit the number of copies that users can make of the CD and restrict ripping of the disk.

Software developer Mark Russinovich, of Sysinternals, reported on Monday that he had detected a secretly installed rootkit on his system. 

Russinovich traced the software back to Sony and the XCP technology back to First 4 Internet, an English software developer. 

The rootkit served to hide the digital rights management technology from the user as well as the system itself, including from antivirus software. When Russinovich tried to remove the application, he found that his CD drive was disabled.

Sony uses the rootkit to prevent the user from removing the copyright protection technology and violating Sony's copyright. But worm authors could exploit this feature to hide malicious applications.

The patch will remove the cloaking capability of the software to enable users to remove the Sony tool. But this will render their systems incapable of playing the CD.

See also:

AOLTalk is not cheap  31 Oct 2005
TrustedFlash MicroSD memory cardsConsumers will be able to buy music on Flash memory cards this autumn  28 Sep 2005
Open digital rights technology aimed at furthering digital content  23 Aug 2005
MicrosoftDocument-level digital rights management in the pipeline  06 Jul 2005
Microsoft and Philips sign 'long-term non-exclusive agreements'Integration of Media player and Nexperia semiconductors  12 May 2005

All Software Licensing & Piracy

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| JAM Recruitment
Software Test Engineer 6 Weeks Contract £ 35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements ... more >
| JAM Recruitment
Software Test Engineer 3 Months Contract £35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements based ... more >
| Aston Carter
Major Investment Bank requires a Business Analyst to work within reference data IT. The reference data IT function is responsible for the three internal systems. One of the systems is a strategic repository for Client ... more >
| JAM Recruitment
Job Ref: CY - 27021979 Package: £25 – 42,000 +Bens Location: YORKSHIRE Job type: Occupational Health Position type: Permanent Hours: Full time Contact name: Mr Colin Youle Contact Company: JAM HUMAN RESOURCES Are you a ... more >
More job opportunities