You are here: silicon.com > Software > Security Strategy

Security Strategy

Sony unearths new copy-protection threat

More risky music...

Tags: copy-protection, sony bmg, eff, sony

By John Borland

Published: 7 December 2005 08:35 GMT

Sony BMG Music Entertainment and the Electronic Frontier Foundation (EFF) digital rights group jointly announced Tuesday that they had found, and fixed, a new computer security risk associated with some of the record label's CDs.

The danger is associated with copy-protection software included on some Sony CDs created by a company called SunnComm Technologies. The vulnerability could allow malicious programmers to gain control of computers that have run the software, which is typically installed automatically when a CD is put in a computer's CD drive.

The issue affects a different set of CDs than the ones involved in the copy-protection gaffe that led Sony to recall 4.7 million CDs last month, and which has triggered several lawsuits against the record label.

EFF staff attorney Kurt Opsahl said in a statement: "We're pleased that Sony BMG responded quickly and responsibly when we drew their attention to this security problem. Consumers should take immediate steps to protect their computers."

The announcement is the latest result of the detailed scrutiny applied by the technical community to Sony's copy-protected CDs, after a string of serious security issues were found to be associated with the label's anti-piracy efforts.

The record label's copy-protected CDs have been on the market for more than eight months. But in late October, blogger Mark Russinovich discovered they surreptitiously installed a "rootkit" programming tool. Rootkit tools are typically used by hackers to hide viruses on hard drives, so Sony's move opened up a potentially serious security hole.

The controversy escalated as other researchers discovered new security flaws associated with the copy-protected CDs, which used technology from British company First 4 Internet. Virus writers began distributing malicious code that took advantage of the holes. The label recalled all the CDs with the First 4 Internet technology installed, offering an exchange program for consumers who had purchased any of the 52 CDs affected.

Following those revelations, the EFF asked computer security company iSec Partners to study the SunnComm copy protection technology, which Sony said has been distributed with 27 of its CDs in the US. iSec found the hole announced on Tuesday and notified Sony but news of the risk was not released until SunnComm had created a patch.

Sony said another security company, NGS Software, has tested the patch and certified that it addresses the vulnerability.

The patch can be downloaded from Sony's site. A list of the CDs affected is also posted on the site.

Sony said it will notify customers though a banner advertisement directly in the SunnComm software, as well as through an internet advertising campaign.

John Borland writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
sales executive - manned guarding - 70K

You will be working on the most lucrative patch in the UK so your earning potential is gigantic. The company provides the full range of security ...

Sales consultant - Security - 40,000

You will be inheriting the best patch in the country and your earning potential is huge. They can handle the full range of security solutions from ...

ASP.NET, C# Developer - Global Record Label - London

.NET Developer (ASP.NET, C#, C#.NET, dot NET, Webforms). We are pleased to announce that our client, one of the largest and most recognised brands ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: