Network World
Thursday, November 26, 2009
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Are rootkits really all bad?

Settlement in Sony CD case resurrects rootkit debate.

When a security researcher late last year discovered Sony was using hidden software-cloaking and monitoring techniques to protect copyrights on its music compact discs, public backlash prompted lawsuits against the company and a debate ensued about using such “rootkits” in commercial software.

Related links
NY testing emergency broadcast network on Live, PSN 11/25/2009
NSA helped with Windows 7 development 11/18/2009
National Cybersecurity Awareness Month: Wait until next year! 11/16/2009
Powered by Inform

Chinese eBay rival branches out with branded mobile phone
11/26/09
China's biggest online auction and retail Web site plans to stamp its brand on a new mobile phone, the first time it's name will be put on a device, according to a source with knowledge of the situation.

Taiwanese researchers show several flexible e-reader screens
11/26/09
Taiwan's Industrial Technology Research Institute (ITRI) showed off a number of flexible display screen technologies in Taipei on Thursday as part of a show promoting e-readers and e-paper.

Wipro sets up global services delivery from China
11/26/09
Indian outsourcer Wipro has set up a global services delivery center in Chengdu in southwest China, targeting customers in the U.S., Europe, and other markets outside the country.

The lawsuits wound down with a court-ordered settlement that has Sony BMG Music Entertainment offering $7.50 and a free album download to those who bought any of the 15 million rootkit-infested CDs it sold. But the broader rootkit debate seems far from over.

Opponents say rootkits should never be used because they introduce potential vulnerabilities and are deceptive, while others contend there can be a legitimate use for deep-stealth technology in both the enterprise and home.

The Electronic Frontier Foundation (EFF), which declared it was satisfied with the Sony settlement, is not among those envisioning a positive role for rootkits.

“I have yet to see a rootkit which did not raise security concerns, and am skeptical that there can be legitimate use of technologies that hide files from the user in an effort to thwart user control of their own computer,” says Kurt Opsahl, staff attorney at EFF.

Security expert Bruce Schneier, founder of managed security services firm Counterpane, is equally adamant.

“Can there be benevolent rootkits? That’s similar to the question of benevolent worms. The answer is ‘no’,” he says. “Rootkits use stealth to hide payloads, and that can cause problems. A user loses control with what’s going on in their machines.”