Welcome | Sign In
ECommerceTimes.com
Security

Sony's Digital Woes Growing Heavier

Print Version
E-Mail Article
Reprints
Sony's Digital Woes Growing Heavier

"You can't help but feel sorry for Sony, as all they were ever trying to do was protect the work of their musicians and artists," Graham Cluley, senior technology consultant for Sophos, said. "But this sad tale acts as a salutory reminder to anyone putting copy protection onto music CDs to think carefully of the possible security repercussions."


Just days after Sony (NYSE: SNE) decided to drop its controversial anti-piracy software on its CDs, more bad news has surfaced for the music giant: Sony's uninstall program makes the computer even more vulnerable to malware.

Princeton researcher J. Alex Halderman posted instructions for how to find out if your PC is infected at the Freedom Tinker blog, but recommends that consumers leave the Digital Rights Management (DRM) software on their computer until Sony works out all the kinks. Sony said it is working on a new uninstall program.

Graham Cluley, senior technology consultant for Sophos, told TechNewsWorld that the problem is with Sony's/First4Internet's ActiveX implementation of their uninstaller.

"Security researchers have determined that this code is left on the user's PC after it has finished running and is marked as 'safe for scripting,'" Cluley said. "The upshot of this is that a malicious hacker could create a Web site which would direct Sony's/First4Internet's code to download and install malicious code from any Web site without asking for permission."

Reliving the Nightmare

Sony's woes began last week when SophosLabs detected a new Trojan horse that exploits the controversial DRM software. The Troj/Stinx-E Trojan horse appears to have been deliberately spammed out to e-mail addresses, posing as a message from a British business magazine, according to Sophos' November 10 report.

If the attached program is run, the Trojan horse copies itself to a file called $sys$drv.exe. Any file with $sys$ in its name is automatically cloaked by Sony's copy-protection code, making it invisible on computers which have used CDs carrying Sony's copy protection.

Cluley said Sony appears to be getting dragged down into a security whirlpool at the moment, as bad story after bad story about their software reaches the press.

"You can't help but feel sorry for Sony, as all they were ever trying to do was protect the work of their musicians and artists," Cluley said. But this sad tale acts as a salutory reminder to anyone putting copy protection onto music CDs to think carefully of the possible security repercussions."

Get the Lawyers Out

Phil Leigh, Senior Analyst at Inside Digital Media, blames lawyers. Leigh told TechNewsWorld that attorneys are pursuing a white whale and if they don't stop then they will destroy everybody connected to the digital music business.

"This whole fiasco is the consequence of lawyers trying to take over a technology," Leigh said. "The record labels have pursued piracy on legal grounds and what they really ought to be doing is focusing on eliminating the incentive for piracy. The way to eliminate the incentive for piracy is to offer the consumer music for a reasonable value."

Sony is recalling nearly 5 million of its copy-protected CDs with the controversial code. Sophos' Cluley, for one, is glad to hear that the company is "seeing sense" and making moves to correct the problem.

"Of course, that's not much help to those poor souls who have already bought the CDs and may have unknowingly opened up their home PCs and company computers to potential attack," Cluley said.


Print Version E-Mail Article Reprints More by Jennifer LeClaire


More by Jennifer LeClaire

The Digital Car: Cool Automotive Accessories, Part 2
January 16, 2007
Not all the latest high-tech automotive electronics are built to entertain. Many give the driver more information and more control. Vehicle tracking devices can tell where the car is at any time, software installed in a smartphone can turn off a vehicle's security system whenever the owner approaches, and diagnostic tools can tell what's wrong with the engine -- and how much it'll be to fix it.
'World of Warcraft' Wows 8 Million Subscribers
January 12, 2007
"World of Warcraft," the massively multiplayer online role-playing game, has reached the 8 million subscriber mark. Since debuting in North America in Nov. 2004, "World of Warcraft" has become the most popular MMORPG in the world. The franchise is available in seven different languages and is played on at least four continents.
AT&T Bids Goodbye to Cingular Brand
January 12, 2007
Starting Monday, AT&T will launch a multimedia campaign to transition the Cingular Wireless brand name into its advertising and customer communications. The campaign will integrate popular imagery, phrases and icons from Cingular's traditional advertising, including the "raising the bar" tagline, the "Jack" character and the color orange.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network