
More risky music...
By John Borland
Published: 7 December 2005 08:35 GMT
Sony BMG Music Entertainment and the Electronic Frontier Foundation (EFF) digital rights group jointly announced Tuesday that they had found, and fixed, a new computer security risk associated with some of the record label's CDs.
The danger is associated with copy-protection software included on some Sony CDs created by a company called SunnComm Technologies. The vulnerability could allow malicious programmers to gain control of computers that have run the software, which is typically installed automatically when a CD is put in a computer's CD drive.
The issue affects a different set of CDs than the ones involved in the copy-protection gaffe that led Sony to recall 4.7 million CDs last month, and which has triggered several lawsuits against the record label.
EFF staff attorney Kurt Opsahl said in a statement: "We're pleased that Sony BMG responded quickly and responsibly when we drew their attention to this security problem. Consumers should take immediate steps to protect their computers."
The announcement is the latest result of the detailed scrutiny applied by the technical community to Sony's copy-protected CDs, after a string of serious security issues were found to be associated with the label's anti-piracy efforts.
The record label's copy-protected CDs have been on the market for more than eight months. But in late October, blogger Mark Russinovich discovered they surreptitiously installed a "rootkit" programming tool. Rootkit tools are typically used by hackers to hide viruses on hard drives, so Sony's move opened up a potentially serious security hole.
The controversy escalated as other researchers discovered new security flaws associated with the copy-protected CDs, which used technology from British company First 4 Internet. Virus writers began distributing malicious code that took advantage of the holes. The label recalled all the CDs with the First 4 Internet technology installed, offering an exchange program for consumers who had purchased any of the 52 CDs affected.
Following those revelations, the EFF asked computer security company iSec Partners to study the SunnComm copy protection technology, which Sony said has been distributed with 27 of its CDs in the US. iSec found the hole announced on Tuesday and notified Sony but news of the risk was not released until SunnComm had created a patch.
Sony said another security company, NGS Software, has tested the patch and certified that it addresses the vulnerability.
The patch can be downloaded from Sony's site. A list of the CDs affected is also posted on the site.
Sony said it will notify customers though a banner advertisement directly in the SunnComm software, as well as through an internet advertising campaign.
John Borland writes for CNET News.com
CDS). My North West based public sector client is currently looking for an experienced Senior Information Analyst to start a 3-6 month contract ASAP. ...
In particular, the London office is responsible for the trade blotters, trade reporting, Interest Rate Swaps (IRS), Credit Default Swaps (CDS) and a ...
Well experienced in multi-layer PCB layout for surface mount and through-hole technology ? Its major focus is on the design and production of safety ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead
Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy