Interview with Sam Curry, CA re: Sony BMG DRM

Opinion
Nov 15, 20058 mins

Following my Network World Backspin column “Is Sony’s CD DRM malware?” (also see “More on Sony’s rootkit”) I got the chance to have a telephone conference with Sam Curry, vice president of eTrust Security Management for Computer Associates. CA researchers analyzed the Sony DRM software and concluded that:”The media player that Sony ships with the CD is spying on the user, sending the IP address and listening habits back to Sony and potentially to Sony partners, without notice, consent, or choice.” In other words, the Sony BMG DRM system is spyware! It turns out that there’s even more wrong with Sony’s DRM than stealth installation and reporting on the user. We had such an interesting conversation that I asked whether we could recap by e-mail and expand on a few of the themes for Gibbsblog. Here’s our e-mail exchange …

[Mark Gibbs] Sam, could you explain in detail what CA found when you examined the Sony rootkit? [Sam Curry] The work of Mark Russinovich and colleagues brought this to our attention initially when he identified some peculiar behavior in the First4Internet software, and we promptly went and acquired copies of the software. This was on Thursday of last week. Our initial research found that the first program, the one accused of Rootkit behavior, failed our scorecard, and we posted this basic information to the CA Security Advisor website. We also found that [Sony’s] patch and uninstall [program] and some ActiveX Controls needed testing and proceeded to test those too through the weekend, while also trying to contact Sony BMG to share our results with them. On Friday, November 11th, 2005, we will update eTrust PestPatrol to detect and remove this software if users choose to remove it. [MG] Could you explain what your scorecard is and what it means to say that Sony’s DRM software failed? [SC] The scorecard is a clear, public statement about what [software] behaviors are acceptable and, more importantly, which are not acceptable from a public point-of-view. The score card is revised on a regular basis and has formed the basis for our behavioral analysis of spyware. It doesn’t come down to opinion or motivation or anything like that – there are right ways and wrong ways for software to behave. A copy of the scorecard can be found here. [MG] An article on NPR’s “Morning Edition” on November 4th featured an interview with Thomas Hesse, President of Sony BMG’s global digital business division, who said that “Most people, I think, don’t even know what a rootkit is, so why should they care about it? … The software is designed to protect our CDs from unauthorized copying, ripping.” Obviously Mr. Hesse lives in an alternate universe where ethics are different than they are here on earth. But what really surprised me about Hesse’s comments was his contention that no data is sent back by the software when all of the research including yours indicates otherwise. What information does the Sony DRM send and to what use might it be put? [SC] My first response to Mr. Hesse is straightforward: the people who don’t know what Rootkits are also don’t know what DRM stands for or what Intellectual Property Rights are about. That’s no reason to be scornful of them because they do indeed know what spying means, they know what privacy means and they know what it means to have to replace a prematurely worn out hard drive. The no data is sent back contention is a typical misunderstanding of Internet traffic (specifically http). All traffic is bi-directional. What he probably meant (and I am guessing here) is that they weren’t collecting the information or at least not intentionally. I am willing to extend the benefit of the doubt here and say that in so much as he knows how this works that they are not intentionally or for malicious purposes mining this information. However, it’s incontrovertible that the communications from the Rootkit as it phones home include IP addresses and album names, and a standard Web server would naturally log this. It’s a matter of a little effort to realize what they have and to mine it, and we have to take them at their word that they aren’t doing so. [MG] There have been reports of the Sony DRM system making it easy to hide any system software by the simple expedient of adding the prefix “$sys$” to its file name. This apparently allowed hackers to defeat Blizzard Entertainment’s World of Warcraft”Warden” system that tries to detect attempts to cheat in the game. While that may not seem to disruptive (at least, if you don’t work for Blizzard) there are now reports that a variant of the Breplibot Trojan that uses the Sony BMG rootkit! For network administrators this is a nightmare scenario. What can network administrators do to keep their networks free from these kinds of threats? [SC] Breplibot is another name for Brepibot, for Stinx-E and what we call”Outsbot.” You have to admit at least that in spite of the confusion, these are at least colorful names (try saying Stinx-E out loud for instance). We are identifying this as Outsbot.u and as Outsbot.v. Most of what the others are talking about is actually a non-functional Trojan that is identical to Outsbot.u. We identify this because it is actually just a minor variation on an already known Trojan with many other variants. The write is merely being opportunistic here and taking advantage of the $sys$ weakness, which is only the most obvious one discovered to date. This is the same thing that the cheats (warez) for Blizzard’s WoW Warden used and for the same reasons. The most important thing that network administrators can do is to make sure that the helpdesk knows about this and that any asset management and compliance software can look for telltales of the Sony Rootkit in the environment, as we can with our eTrust and Unicenter products. Security administrators need to make sure that their Anti-Spyware (or if they don’t have that that their Antivirus) vendor can detect and remove the Rootkit. Most can’t, so be patient. Contact your vendor and tell them you want it added. Priorities are determined based on risk level and on existing customer demand – so go demand it. When our customers ask for these things, we get it to them for eTrust Antivirus and eTrust PestPatrol; and I believe there’s no excuse to not accelerate detection at customer behest. Then again, I also don’t understand why some security vendors aren’t taking this seriously unless they don’t have a clear definition for spyware. For information on the Outsbot family, we have data posted here. For Outsbot.u; For Outsbot.v. [MG] Obviously I’m asking you to theorize but how do you think Sony came to make such a bad decision and how do you think they made such a bad choice of software to implement DRM? [SC] I think the most important point here is that we can’t infer the motives or meanings; all we can do is observe and classify behavior. That’s what we have sought diligently to do, and it’s why a public, critique-able scorecard is so important. This isn’t about bizarre or Byzantine rules. It’s about clear, unquestionable standards and tests. Sony may not have thought about this at all, thinking only to protect its intellectual property. Then again, they may have been intentional. We simply don’t know at this point. However, I proceed on the assumption that they can always find ways to pursue their aims without violating end user PC rights, and we would love to work with Sony BMG to help them clean up this software so it passes our scorecard. Addendum: [MG] It seems that Sony BMG doesn’t want to engage with its critics other than to argue that their software is safe (see here) or as in the NPR interview to try to spin the issue. This makes me think that it seems unlikely that Sony BMG will work with you to clean up their act. Sony BMG now faces a number of class action lawsuits but much depends on their outcome. If Sony isn’t dealt with harshly what impact do you think it will have on digital media and the lengths to which media publishers such as Sony BMG will go to control their markets? [SC] Much has changed in the week since we last spoke: Sony BMG has announced that it will pull software from distribution (a tacit acknowledgement of the issues), two Trojans that exploit the Rootkit have surfaced and other companies have joined CA in the detection and removal of XCP.Sony.Rootkit. I wouldn’t speculate as to motivation or future courses of action by Sony BMG. However, as you point out, it would verge on madness to pursue DRM initiatives without increased awareness of all the issues and stakeholders: companies, end-users, rights activists. I believe it would be in their best interests to listen and make the process inclusive. The Internet is such a complex place that blundering through is ill-advised. A certain delicacy and attention is required here; brain surgeons don’t operate with boxing gloves on, and neither should any company blunder into networks and PCs without respect for the people involved. Sony’s most recent actions show an appreciation for this.