About RSS
Search for: in 

Windows Watch - an XP & Vista blog

Trojan horse
Sony BMG's anti-piracy software is allegedly based on stolen code
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

Sony rootkit accused of licence violation

Nightmare darkens for troubled record label

Tom Sanders in California, vnunet.com 18 Nov 2005
ADVERTISEMENT

The technology used by Sony BMG to prevent piracy of audio CDs is allegedly based on stolen code, according to Sebastian Porst and Matti Nikki, two individuals from Germany and Finland who looked into the application. 

First 4 Internet, the English developer of the controversial XCP anti-piracy technology deployed on some of Sony's audio CDs, is believed to have included software that is governed by the General Public Licence (GPL). 

Under terms of that licence, First 4 Internet is obliged to release the software that uses the GPL code. It did not do so.

"Sony is infringing on open source programmers' copyrights by distributing code which they have no right to use. Even though the code in question was developed by [First 4 Internet], Sony has still been distributing it," Nikki wrote on a webpage where he explained the licence violations

The duo examined the binaries for the XCP software and claim to have found numerous references to functions that were taken from an application called mpg123 as well as other applications governed by open source licences. 

Mpg123 is a media player developed in part by John Lech Johansen, the famous DVD cracker. The application is governed by the GPL and parts of it have been made available under the Lesser GPL, which gives developers more liberty when reusing the code. 

The XCP technology came under fire after security experts unmasked the anti-piracy technology as a major security risk. After weeks of pressure Sony said last Friday that it would stop shipping CDs with the technology and would take back any CDs that consumers had purchased.

The record label has provided a list of 52 titles and item numbers to help consumers identity infected CDs. 

When a user inserts an infected audio CD in a Windows system, the CD installs a new media player, digital rights management technology and a so-called rootkit which hides the technology from the user and the system. The GPL code was found in the media player.

Sony BMG did not respond to a request for further information. First 4 Internet was unable to respond due to the time difference between California and the UK where the firm is headquartered. First 4 Internet has declined in the past to comment on the case.

Sony rootkitLawsuits filed in California and Italy and more to follow  11 Nov 2005
Trojan horseSony doomsday scenario becomes reality  10 Nov 2005
ZombieSony accused of undermining system stability in its crusade to protect copyright  07 Nov 2005
AOLTalk is not cheap  31 Oct 2005
Computer virusDodging the virus shield becomes big business as authors 'outsource' malware creation  19 Oct 2005

All Software Licensing & Piracy

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Reading, Berkshire, United Kingdom | EDS
Position # 397874 IP Network Administrator Location - Reading Job Description: There is a requirement for an IP network administrator to join the Infrastructure Services operational support team to manage the movement of network resources, ... more >
London, United Kingdom | The Moving Picture Company
Web Developer - London   MPC's continued success is dependent on a continued investment in technology so that its clients continue to enjoy the highest possible quality of work and service. Key to MPC's offering is ... more >
London, United Kingdom | City of London
ICT Project Officer - Guildhall, London EC2 18-month fixed-term contract Bring your project management expertise to one of the country's most prestigious institutions. The City of London is the local authority for the Square Mile, ... more >
Reading, Berkshire, United Kingdom | EDS
Position - EA Integrator Location - Reading Job Description: A skilled System Integrator to integrate application Test Harnesses to support business requirements. The Candidate will possess specific experience of enterprise systems, component validation and integrating ... more >
More job opportunities
Join our fight for a fair deal when shopping online
ADVERTISEMENT