Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article

Skip to comments.

Sony to Help Remove its DRM Rootkit
Beta News ^ | 11/02/05 | Nate Mook

Posted on 11/02/2005 7:04:33 PM PST by Cicero

Sony to Help Remove its DRM Rootkit By Nate Mook, BetaNews November 2, 2005, 4:04 PM When Mark Russinovich was testing his company's security software last week, he came across a disturbing find: a Sony BMG CD he purchased from Amazon had secretly installed DRM software on his PC and used "rootkit" cloaking methods to hide it. With the story sweeping across the Net, Sony is attempting to clean up its mess.

DRM, or digital rights management, is nothing new to CDs. Record companies began employing software to prevent users from easily transferring tracks to a PC after the explosion of file sharing activity that followed Napster's debut in 1999. But for the most part, the DRM was quite rudimentary and only required the pressing of the "shift" key to bypass.

Not so with Sony's latest batch of CDs from Switchfoot, Van Zant and others. Using technology developed by British software company First 4 Internet, the CDs limit the number of copy-protected backups that can be made. To enforce the restriction, software and drivers are installed without a user's knowledge when the CD is accessed.

Russinovich first discovered a hidden directory and several hidden device drivers -- none of which would show up in Windows Explorer. He soon found the driver responsible for the cloaking, which was designed to hide every file and location that begins with: $sys$.

After tracing the rouge software back to his recently purchased Van Zant CD, Russinovich attempted to uninstall the DRM, but to no avail.

"I didn't find any reference to it in the Control Panel's Add or Remove Programs list, nor did I find any uninstall utility or directions on the CD or on First 4 Internet's site. I checked the EULA and saw no mention of the fact that I was agreeing to have software put on my system that I couldn't uninstall," he wrote on his company's blog. "Now I was mad."

When he forcibly removed the software and registry entries by hand, Russinovich found his CD player was no longer functional. Further advanced registry hacking fixed the problem, but he noted that the vast majority of computer users would simply "cripple their computer" if they tried to delete the First 4 Internet DRM.

Although cloaking files and not providing a method of removal is not dangerous in and of itself, the case sparked a flurry of discussion online. Most users agreed that the actions of Sony and First 4 Internet questionable at best, and security experts warned of potential threats. For example, a virus writer could simply hide files by naming them using the $sys$ prefix.

For its part, First 4 Internet claimed the technology was only found on CDs from earlier this year and said it had created new methods to hide the DRM. Nonetheless, the company has decided to issue a patch to eliminate the cloaking and "allay any unnecessary concerns."

The patch will be made available for download from Sony BMG's Web site, with another offered directly to antivirus vendors. The DRM software will not be removed, however, only uncovered; that means users will still be unable to delete it without risk of rendering their CD drive inoperable.

Customers must contact Sony BMG support for removal instructions.

"While I believe in the media industry's right to use copy protection mechanisms to prevent illegal copying, I don't think that we've found the right balance of fair use and copy protection, yet," said Russinovich. "This is a clear case of Sony taking DRM too far."


TOPICS:
KEYWORDS: bmg; cd; drm; sony
Navigation: use the links below to view more comments.
first previous 1-2021-4041-48 next last
To: oceanview
except that congress has passed so many laws changing copyrights - the industry can do almost anything they want and get away with it legally. and its only getting worse. fair use is gone, and soon enough, your PC and your digital TV will simply be something you "rent" from MSFT, the RIAA, and the MPAA.

Distruction of Private Property is still illegal and Sony is guilty of doing that to millions of their customers.

21 posted on 11/02/2005 7:18:44 PM PST by Paul C. Jesup
[ Post Reply | Private Reply | To 10 | View Replies]

To: Cicero

And the music industry wonders why people don't want to buy their products? Well, duh!!


22 posted on 11/02/2005 7:24:34 PM PST by TommyDale
[ Post Reply | Private Reply | To 1 | View Replies]

To: Cicero
This is reminiscent of what some software co's tried to do in the 1980's. Lotus1-2-3 required the Lotus disk be in the floppy drive, even if the program was installed on a hard drive.

Soon, software co's found themselves losing business because users were turning away from such restrictive products.

Even in those early years, MS tried to remain highly proprietary. They discovered that users demanded compatibility and conversion capabilities with non-MS software. MS gave in. Otherwise, Word and Excel would have gone the way of Lotus123 and Wordstar.

CD companies may find the same thing. If a purchaser doesn't have universal use capabilities, the user may quit purchasing. Such things are market driven.
23 posted on 11/02/2005 7:24:34 PM PST by TomGuy
[ Post Reply | Private Reply | To 1 | View Replies]

To: Spktyr

My Condolences...


24 posted on 11/02/2005 7:25:25 PM PST by AmericaUnited
[ Post Reply | Private Reply | To 6 | View Replies]

To: Izzy Dunne
Beware that rouge software.

I prefer lipstick and eyeshadow software. They're so sexy.

25 posted on 11/02/2005 7:26:02 PM PST by Right Wing Assault ("..this administration is planning a 'Right Wing Assault' on values and ideals.." - John Kerry)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Cicero

Here's a good one -- go to the Sony/BMG site and download the removal software. Oh, surprise! If you are using Firefox, you can't get it...you will need to use the ActiveX and Internet Explorer. That will make some more friends for Sony!


26 posted on 11/02/2005 7:27:01 PM PST by TommyDale
[ Post Reply | Private Reply | To 1 | View Replies]

To: Cicero

I am tempted to actually go out and buy one of these CDs from Sony/BMG, just to qualify for participation in the class action lawsuit. Of course, in these cases, the actual victims would get a $2 coupon toward the purchase of a Sony CD, while the lawyers make trillions of dollars.


27 posted on 11/02/2005 7:31:23 PM PST by TommyDale
[ Post Reply | Private Reply | To 1 | View Replies]

To: TommyDale
download the removal software

Next headline: "Sony Software Removal Tool Sending Credit Card Info to HQ - Scheme to Make Up Lost Music Revenue"

28 posted on 11/02/2005 7:32:50 PM PST by Right Wing Assault ("..this administration is planning a 'Right Wing Assault' on values and ideals.." - John Kerry)
[ Post Reply | Private Reply | To 26 | View Replies]

To: oceanview

Senator "Disney" Fritz Hollings probally can be found to have a hand in any and all such laws.


29 posted on 11/02/2005 7:37:42 PM PST by Sinner6 (http://www.digital-misfits.com)
[ Post Reply | Private Reply | To 10 | View Replies]

To: kingu

Yes, I suspect this stupid move was probably criminal, at least technically. And if it breaks people's CD drives or allows hackers to insert viruses disguised as Sony files, then there will be a good deal of very expensive damages to worry about.

What blows my mind is that I have always thought of Sony as a reputable company. I suppose this comes of having taken over a Hollywood outfit in the music and movie business.


30 posted on 11/02/2005 7:40:11 PM PST by Cicero (Marcus Tullius)
[ Post Reply | Private Reply | To 15 | View Replies]

To: TommyDale

That's about right. I occasionally get one of those mailings asking if I want to join a class action lawsuit because someone manipulated a stock I had bought during a certain period, or the like, but I can't say that I have ever seen a bean of it.

What I think probably will get Sony to move of the dime and fix this is fear of losing their reputation. They have a considerable reputation to lose. I would imagine they are not happy with the Hollywood hotshots who dreamed this one up.


31 posted on 11/02/2005 7:44:57 PM PST by Cicero (Marcus Tullius)
[ Post Reply | Private Reply | To 27 | View Replies]

To: oceanview
WHO BUY THE CD HONESTLY.

Guess I will just have to download my music off the net to be safe.

32 posted on 11/02/2005 7:47:56 PM PST by Joe Miner
[ Post Reply | Private Reply | To 2 | View Replies]

To: Joe Miner

I've had more problems playing CDs on my computer than someone else's mp3s.


33 posted on 11/02/2005 7:50:21 PM PST by July 4th (A vacant lot cancelled out my vote for Bush.)
[ Post Reply | Private Reply | To 32 | View Replies]

To: Cicero




A complete listing of Sony Music artists from A to Z can be found here;

http://www.sonymusic.com/artists/


34 posted on 11/02/2005 7:51:11 PM PST by seastay
[ Post Reply | Private Reply | To 1 | View Replies]

To: Spktyr

The Macs did pretty good when Sony was using the felt-tipped pen security. But time change--

Added to this heady mixture in recent weeks is a new generation of digital copy protection that's been showing up on music CDs distributed by Sony in Europe. Fast becoming known as the case of "Celine Dion Killed My iMac," initial reports indicate that these discs are not only unreadable by computers, but may actually crash them and prevent them from rebooting, necessitating a service call.
http://www.macopinion.com/columns/curmudgeon/

UHh, where's the CD eject button on my Mac??!!
Maybe my OSX86 will still work!


35 posted on 11/02/2005 7:52:14 PM PST by MilleniumBug
[ Post Reply | Private Reply | To 6 | View Replies]

To: Cicero
I have a friend that tells me that is why she gets her music exclusively from Kazza.
36 posted on 11/02/2005 7:53:13 PM PST by NavVet (“Benedict Arnold was wounded in battle fighting for America, but no one remembers him for that.”)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Cicero
While Sony fiddles and diddles with finding ways to screw their customers, Apple has eaten their lunch with the iPod, rendering the Walkman a historical curiosity.

Sony could have owned the MP3 player market and extended the dominance of the Walkman at least another generation. But NO!

37 posted on 11/02/2005 7:55:22 PM PST by SamAdams76 (What Would Howard Roarke Do?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: TommyDale
Oh, surprise! If you are using Firefox, you can't get it...you will need to use the ActiveX and Internet Explorer.

Of course. Didn't you read the whole story? They have a new, harder to find software they want to slip into your machine.

"and said it had created new methods to hide the DRM. "

38 posted on 11/02/2005 8:01:07 PM PST by PAR35
[ Post Reply | Private Reply | To 26 | View Replies]

To: SamAdams76

I have an iRiver MP3 player, which I bought before the iPod explosion. I agree that Sony was slow to get into that market.


39 posted on 11/02/2005 8:06:00 PM PST by Cicero (Marcus Tullius)
[ Post Reply | Private Reply | To 37 | View Replies]

To: Cicero
What I think probably will get Sony to move of the dime and fix this is fear of losing their reputation.

Sony's reputation has been tanking for the past few years anyway. They've become so obsessed with pushing their proprietary formats for everything as well as their DRM schemes that they've lost their edge in innovation. Many of Sony's products these days lack a lot of the features of their competitors' stuff, and are overpriced to boot.

This fiasco won't help them out of that ditch one little bit.

40 posted on 11/02/2005 8:14:32 PM PST by CFC__VRWC ("Anytime a liberal squeals in outrage, an angel gets its wings!" - gidget7)
[ Post Reply | Private Reply | To 31 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-48 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson