Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Is Sony's CD DRM malware?

Backspin By Mark Gibbs , Network World , 11/07/2005
Gibbs

One of the biggest challenges the computer industry faces is getting Joe and Josephine Enduser interested in the security, reliability and manageability of their machines.

It seems no amount of education will make them understand that as their lives become more defined by the use of PCs and the Internet, protecting their computers isn't just a cool, geeky idea. It is up there with filling out tax returns: Tedious and boring, but fail to deal with the issue properly, and really bad things are guaranteed to happen.

Along with this Sisyphean education effort is the problem of legislation. We've got laws that deal with spamming (as toothless as they are), laws that can be applied to hackers and virus writers (if we can catch them) and laws that protect our personal data (don't get me started).

The good news is that something happened recently that may lead to changes in consumer awareness and legislation.

The event was the discovery that Sony - yes, that's right, the huge, megacorporation Sony - not only has been installing software on people's PCs to enforce digital rights management (DRM) without telling them but also has installed software to hide the fact that they did so.

But wait; it gets better! The code Sony uses has been found to be naive and poorly engineered. It has a high possibility of crashing any PC it is installed on and soaks up processor cycles because of inefficient coding.

As far as I can determine, the first person to figure out what was going on was one of my heroes: Mark Russinovich of Winternals Software. He was testing the latest version of Winternals' RootkitRevealer, which can find a type of malware called a rootkit that can give an attacker full control over a PC and attempts to hide itself from detection, and noticed that his system apparently had a rootkit installed. This surprised him greatly, because he is really careful when it comes to avoiding risks such as malware.

To cut a long story short (see his posting), in the process of trying to find out what was going on, he dug deep using a variety of tools. Turns out that he had played a Sony BMG music CD that can be played only on a computer using the media player on the CD and which restricts the number of times you can burn CD copies.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.