Settlement in Sony CD case resurrects old debate.
When a security researcher late last year discovered Sony was using hidden software-cloaking and monitoring techniques to protect copyrights on its music CDs, public backlash prompted lawsuits against the company and a debate ensued about using “rootkits” in commercial software.
When a security researcher late last year discovered Sony was using hidden software-cloaking and monitoring techniques to protect copyrights on its music CDs, public backlash prompted lawsuits against the company, and a debate ensued about using “rootkits” in commercial software.
The lawsuits wound down last week with a court-ordered settlement that has Sony BMG Music Entertainment offering $7.50 and a free album download to those who bought any of the 15 million rootkit-infested CDs it sold. But the broader rootkit debate seems far from over.
| The rootkit debateRootkits are always bad because they are: | ||||||||||||||||
|
Opponents say rootkits should never be used, because they introduce potential vulnerabilities and are deceptive, while others contend there can be legitimate use for deep-stealth technology in both the enterprise and home.
The Electronic Frontier Foundation (EFF), which declared it was satisfied with the Sony settlement, is not among those envisioning a positive role for rootkits.
“I have yet to see a rootkit which did not raise security concerns and am skeptical that there can be legitimate use of technologies that hide files from the user in an effort to thwart user control of their own computer,” says Kurt Opsahl, staff attorney at EFF.
Security expert Bruce Schneier, founder of managed security services firm Counterpane, is equally adamant.
“Can there be benevolent rootkits? That’s similar to the question of benevolent worms. The answer is ‘no’,” he says. “Rootkits use stealth to hide payloads, and that can cause problems. A user loses control with what’s going on in their machines.”
Antivirus vendors CA, Trend Micro and McAfee say they reject use of rootkits as a way to protect security software. “We call it stealth technology rather than rootkit technology, and by and large it’s a negative thing,” says Stuart McClure, senior vice president of global threat at McAfee.
But some say stealth technologies can be ethical and shouldn’t be dismissed as absolutely evil.
“Rootkits are inherently deceptive, of course,” says Christine Olson, project manager with StopBadware.org, the Cambridge, Mass., group formed by Harvard University and Oxford University to provide the public with a detailed list of software programs deemed to be unethical, deceptive or dangerous. “But there are instances where the owner of the machine might want to deceive others using the machine” and would have the right to do so, she says.
James Butler, CTO at Komoku, a start-up funded by the Defense Advanced Research Projects Agency to develop ways to detect rootkits, says the debate that started after security researcher Mark Russinovich discovered the Sony rootkit remains murky.
“The debate centers around whether it’s acceptable for a company to install software that uses stealth in order to protect the company’s software from being detected,” he says.
In Sony’s case, the way the software was written would let an attacker also use the stealth abilities to hide programs. “In the end, rootkits can be good or evil. It’s all in how they’re used,” he says.
Gartner security analyst John Pescatore asserts corporations could benefit from more rootkitlike applications, such as those used to monitor employees. “Yes, there is a role for stealth in the enterprise world,” he says, adding that in the home PC environment, parents might want rootkitlike ways to monitor what their kids do on a home PC.
Some IT and network professionals say rootkitlike technologies could play a valuable role in the enterprise.
Enzo Micali, CIO at 1-800-Flowers, where flowers can be ordered online or by phone for delivery, says: “I’d consider stealth technology to monitor employees. The company owns the computers.”
1-800-Flowers, which has 2,500 employees, uses the Securify product to watch for unauthorized network activity by employees, such as downloading large files unrelated to work or pinging servers.
Martin Lapointe, network manager at Canadian retailer Reitmans, concurs that “there is a role for stealth in the enterprise.” But using any rootkitlike technologies would depend, at the very minimum, on ensuring their use conforms with user-consent and data privacy laws of the countries in which they’re used, he says.
Sam Curry, vice president of threat management at CA, says rootkits in commercial software could be compromised, with devastating results. Plus, antivirus and antispyware software would look too much like the evil code it’s trying to find and eliminate.
David Perry, Trend Micro’s global director of education, says: “We don’t want to look like the opposition” even though hiding software components from attack has appeal, he says.
But public opinion seems so firmly wedged against the idea of rootkits that security vendors shy away from any association.
Symantec, which declined to comment, endured its own public backlash and cries of “Rootkit!” when Russinovich discovered Symantec’s Norton SystemWorks was using a cloaking technique to hide its NProtect directory for storing temporary copies of files the user has deleted or modified.
Bowing to public criticism, Symantec reevaluated the practice of hiding the directory – which it said it did to keep users from deleting files in it – and released an update in January so the directory could be scanned through manual or scheduled scans, not just an on-access scanner.
Some say there is plenty of commercial software that already uses stealth techniques, including that of most antivirus vendors.
“Most antiviral software and virtualization software, like VMware, are essentially rootkits,” Gartner’s Pescatore says. “Good rootkitlike software gives the user choice and informs the user, and the user purposefully and knowingly installs it.”




