Sony Quits Shipping Controversial Code

Mon, November 14, 2005CIO One day after hackers released malicious software that used controversial Sony BMG Music Entertainment copy-protection software to attack computers, Sony has decided to stop shipping the product, the company said Friday.
Sony has temporarily suspended the manufacture of CDs that contain the software, called XCP, (Extended Copy Protection) said John McKay, a Sony spokesman.
McKay did not say when Sony planned to resume the use of XCP, but XCP’s developers have previously stated that they are in the process of writing new copy protection software that does not use the same controversial cloaking techniques that have stirred up bad so much publicity for Sony.
XCP was developed for Sony by U.K. software vendor First 4 Internet Ltd. It has been shipping since early 2005, and is included on about 20 of Sony music titles, including country music duo Van Zant’s "Get Right with the Man." It is designed to limit the number of copies that CD owners can make of their music.
The software first popped into the public eye two weeks ago when a Windows operating system expert named Mark Russinovich described how XCP used "rootkit" cloaking techniques to hide itself on his computer. (http://www.sysinternals.com/blog/) At the time, Russinovich described the software as "digital rights management gone too far," and criticized it for not warning users that it would become virtually undetectable and extremely difficult to remove.
Rootkit software uses a variety of techniques to gain access to a system and then cover up any traces of its existence so that it cannot be detected by system tools or antivirus software. Russinovich and other computer experts were concerned that hackers might somehow use XCP’s cloaking ability to hide their software from antivirus products.
That prediction came true Thursday when the first variations of a malicious ’Trojan’ program that exploited the XCP software began circulating on the Internet. Trojans are malicious programs similar to viruses that often appear to be legitimate software.
One of these Trojan programs, called Stinx-E, masquerades as a photo sent from a U.K. Business magazine, security vendor Sophos PLC said in a statement. Once clicked on, the malicious software uses Sony’s rootkit techniques to hide itself on the system, Sophos said.
By Robert McMillan, IDG News Service

Loading...
Applications MarketSpace
Service Level Reporting and Communication
Service level reporting is the most visible output and often the most time-consuming activity in SLM. Learn more »
Lower IT Costs with Oracle Database 11g Release 2
Learn how upgrading to Oracle Database 11g Release 2 can transform your business, budgets, and service levels Learn more »
Managing Your SAP System
Learn how to more effectively manage your SAP system. Learn more »
 
SPONSORED LINKS
 

White Paper: 4 Customer Service Myths

White Paper: Improve Agility with Operational Responsiveness

Removing the Barriers to IT Governance: How On-Demand Software Changes the Game

Cloud Computing--Latest Buzzword or a Glimpse of the Future?

A Balanced Approach to an Application Development Platform

Adobe® LiveCycle®solutions for intuitive user experience

10 Ways Excel Drives More Value from Your SAP Investment

What's New in SOA Suite 11g?

Unleash the Power of Java with Oracle JRockit Real Time

SOA Best Practices and Design Patterns

Application Grid: Ideal Platform for IT Consolidation

Ready to virtualize tier one applications? Check your virtualization maturity.

Learn how to provide complete Business Service Management.

Increase ROI of Your Application Portfolio

See how AT&T can help protect your network.

Top Five CIO Challenges

Streamline IT Costs. Boost Performance with WAN Optimization.

Want to know how you can maximize employee productivity?

Build your 1st app FREE with Force.com

TDWI checklist helps define data readiness for analytics. Download report.

A new fleet of PCs with a total ROI in 10 months. Find your ROI.

eZine: A Roadmap to Reducing IT Complexity

Reduce risk, gain agility. See how Progress can help your business.

Virtualization Technology as a Business Solution

eZine: A Roadmap to Reducing IT Complexity

White Paper: Managed Security for a Not-So-Secure World

SharePoint - Unchecked growth of content is unsustainable.

Focus Under Pressure: Why IT Governance Becomes Mission-Critical in a Down Economy

Should Your Email Live In The Cloud? A Comparative Cost Analysis

Adobe® LiveCycle® solutions for business process automation

Architecting Business Intelligence Applications for Change: The Open Solution

Increase UPS efficiency without sacrificing protection.

Unlocking the Mainframe: Modernizing Legacy System to SOA

State of the Data Integration Market

Enhance Customer Loyalty through Higher Responsiveness

Achieving Business Agility with Application Grid

Seven Ways ITIL Can Help You in an Economic Downturn

Four steps to populate your CMDB.

"Enterprise-Proven" is the Prerequisite for Enterprise SaaS Portal Solutions

Join us at the US-Brazil IT-BPO Summit, on November 10th in New York.

Unified Communications: Thoughts, Strategies and Predictions. Join the discussion

Read the RSA report: Security for Business Innovation

Webcast: Looking to the Cloud for Email and Collaboration Services

64-page prescriptive guide to security, compliance, and IT operations.

Keep your IT expertise up to date. Join the Intel Premier IT Professionals.

A Clear View Toward Virtualization

Virtualization Technology as a Business Solution

The rules of infrastructure management just changed.

A Clear View Toward Virtualization

Interactive Q&A helps you discover key ways to maximize IT assets.

 
 
RESOURCE CENTER