Sony halts production of 'rootkit' CDs

Joris Evers, CNET News.com
14 November 2005 08:23 AM
Tags: sony, virus, protection, copy, drm, bmg, rootkit, cds
Sony BMG Music Entertainment said on Friday that it will suspend production of CDs with copy-protection technology that has been exploited by virus writers to try to hide their malicious code on PCs.

The decision by the music label comes after 10 days of controversy around the technology, which is designed to limit the number of copies that can be made of the CD and to prevent a computer user from making unprotected MP3s of the music.

Security experts blasted the technology because it uses "rootkit" techniques to hide itself on hard drives and could be used by virus writers to make their malicious code invisible. The first remote-control Trojan horses that took advantage of the cloak provided by Sony BMG surfaced this week.

"We are aware that a computer virus is circulating that may affect computers with XCP content protection software," the record label said in a statement on Friday. "We stand by content protection technology as an important tool to protect our intellectual property rights and those of our artists. Nonetheless, as a precautionary measure, Sony BMG is temporarily suspending the manufacture of CDs containing XCP technology."

The company said it is not halting production of all discs that contain additional copy-protection technologies. It also uses antipiracy technology from SunnComm and will keep manufacturing CDs carrying that software, a Sony BMG representative said.

The XCP software, created by UK-based First 4 Internet, is included on a limited number of Sony BMG titles, including recent releases from My Morning Jacket and Southern rockers Van Zant. When the discs are played on a computer, the listener is asked to click through a consent form and install the copy-protection software.

In response to the firestorm of criticism around the copyright protection software, Sony BMG has also provided a patch to fix the security problem and still allow CDs to be played on computers. Some antivirus software also detects the Sony BMG tool and can help users protect their PCs.

Advertisement

Talkback 1 comments

    Sony understates the problem - a matter of national security (US)Anonymous -- 14/11/05 (in reply to #120123243)

    The details are slowly emerging, and it is not pleasant.

    There are already at least two exploits in the wild that take advantage of the cloaking abilities of this rootkit to hide any file on a Windows machine that starts with the letters $sys$.

    It has been identified as a matter of national security in the US.

    Some details of this at http://www.technutopia.com/forum/showthread.php?t=1321.

    It leaves a calling card for Apple Macs too (just so they don't feel left out)!!!

    Be afraid, be very afraid - anybody with one of these popular widely available music CDs can infest your system, at home or at work.

    The only effective cure is a total product recall of all infested CDs.

    Shame Sony, shame!


Latest Videos

Blogs

  • Renai LeMay Datacentre disaster lessons
    As a system administrator, the health and status of your datacentre is at the forefront of your mind. But how often do you think about the needs beyond server status and bandwidth?
  • Array E-health too unsexy for COAG
    There will always be something more politically sexy than e-health for state governments, meaning the National E-Health Transition Authority's business case for a national electronic medical record might just sit on the shelf gathering dust forever.
  • Array TelstraUnClear
    Telstra's New Zealand arm TelstraClear is one strange company ...
  • More blogs »

Tags

Back to top

Featured