2005 Sony CD copy protection controversy
Posted: Thu Nov 17, 2005 2:27 am
The 2005 Sony CD copy protection controversy was a public controversy relating to copy protection software known as Extended Copy Protection (XCP), created by First 4 Internet and used by the media company Sony BMG Music Entertainment on audio CDs. The software monitored the computer's activity to ensure that only a maximum number of copies of the CD can be made. The controversy ensued because the software installed without the user's consent, hid from the operating system via a rootkit, and did not offer a means for removal. The XCP copy protection software was on about 50 CDs distributed by Sony-BMG.
Timeline
On October 31, 2005, Mark Russinovich posted to his blog an extremely detailed and technical analysis of the behaviour of the software contained on Sony music CDs. The article asserts vocally that the software is illegitimate and that digital rights management had "gone too far". He further sheds light on shortcomings in the software design that manifest themselves as security holes and could be exploited by malicious software such as worms or viruses. Several comments to the entry recommended a lawsuit against Sony.
In a November 7, 2005 article, vnunet.com summarised Mark's finding in a less technically detailed way, and urged consumers to avoid buying Sony music CDs for the time being. The following day, boston.com classified the software as spyware and alleged that it communicates personal information from consumers' computers to Sony. The methods used by the software to avoid detection were likened to those used by data thieves.
After the first virus which made use of Sony's stealth technology to make their malicious files invisible to both the user and anti-virus programs surfaced on November 10, 2005, Yahoo! News announced on November 11, 2005 that Sony has suspended further distribution of the controversial technology.
According to BBC News on November 14, 2005, Microsoft has decided to label Sony's software as "spyware" and provide tools for its removal. In both this and the previous Yahoo! News announcement, Mark Russinovich is quoted as saying, "This is a step they should have taken immediately."
On November 15, 2005, vnunet.com finally announced that Sony is backing out its copy-protection software, recalling unsold CDs from all stores, and offering consumers to exchange their CDs with versions lacking the software. Sony is quoted as maintaining that "there were no security risks associated with the anti-piracy technology", despite the earlier virus and malware reports.
The US states California and New York are now pursuing legal action against Sony and a larger class action lawsuit over this matter is being developed.
Sony released a software utility to remove Extended Copy Protection from affected Microsoft Windows computers, but this removal utility was soon attacked as only exacerbating the privacy and security concerns. In addition to removing the rootkit, this program was reported to install additional software that cannot be uninstalled. In order to download the uninstaller, it is neccessary to provide an e-mail address, and to install an ActiveX control containing backdoor methods (marked as "safe for scripting", and thus prone to exploits). Opponents of Sony's actions, especially Slashdot.org, later accused Sony of violating the privacy of its customers to create a backdoor onto their machine using code that violates an Open Source license. They claimed that this DRM program, designed to give Sony control over the customer's machine in the name of copyright protection, is itself infringing copyright by including code from the LAME MP3 library. It appears that, since LAME is under the lGPL, this situation could be rectified by SONY offering a copy of the LAME source code; additionally it appears that the LAME code was added only to permit detection of attempts to rip the CD using LAME (not to actually implement LAME or call functions from it). On November 16, 2005 Sony-BMG bowed to pressure from consumers and recalled all CDs with XCP. Sony said customers will be able to exchange any discs with XCP. They also said they had instructed retailers to remove any unsold music discs containing the software from their shelves.
source wikipedia
More info on Extended Copy Protection (ECP) software from wikipedia.
Also check out Marks Sysinternals Blog exposing Sony's DRM RootKit.
I also found this online too.
World of Warcraft hackers using Sony BMG rootkit
Want to cheat in your online game and not get caught? Just buy a Sony BMG copy protected CD.
World of Warcraft hackers have confirmed that the hiding capabilities of Sony BMG's content protection software can make tools made for cheating in the online world impossible to detect. The software--deemed a "rootkit" by many security experts--is shipped with tens of thousands of the record company's music titles.
Blizzard Entertainment, the maker of World of Warcraft, has created a controversial program that detects cheaters by scanning the processes that are running at the time the game is played. Called the Warden, the anti-cheating program cannot detect any files that are hidden with Sony BMG's content protection, which only requires that the hacker add the prefix "$sys$" to file names.
Source online.securityfocus
Timeline
On October 31, 2005, Mark Russinovich posted to his blog an extremely detailed and technical analysis of the behaviour of the software contained on Sony music CDs. The article asserts vocally that the software is illegitimate and that digital rights management had "gone too far". He further sheds light on shortcomings in the software design that manifest themselves as security holes and could be exploited by malicious software such as worms or viruses. Several comments to the entry recommended a lawsuit against Sony.
In a November 7, 2005 article, vnunet.com summarised Mark's finding in a less technically detailed way, and urged consumers to avoid buying Sony music CDs for the time being. The following day, boston.com classified the software as spyware and alleged that it communicates personal information from consumers' computers to Sony. The methods used by the software to avoid detection were likened to those used by data thieves.
After the first virus which made use of Sony's stealth technology to make their malicious files invisible to both the user and anti-virus programs surfaced on November 10, 2005, Yahoo! News announced on November 11, 2005 that Sony has suspended further distribution of the controversial technology.
According to BBC News on November 14, 2005, Microsoft has decided to label Sony's software as "spyware" and provide tools for its removal. In both this and the previous Yahoo! News announcement, Mark Russinovich is quoted as saying, "This is a step they should have taken immediately."
On November 15, 2005, vnunet.com finally announced that Sony is backing out its copy-protection software, recalling unsold CDs from all stores, and offering consumers to exchange their CDs with versions lacking the software. Sony is quoted as maintaining that "there were no security risks associated with the anti-piracy technology", despite the earlier virus and malware reports.
The US states California and New York are now pursuing legal action against Sony and a larger class action lawsuit over this matter is being developed.
Sony released a software utility to remove Extended Copy Protection from affected Microsoft Windows computers, but this removal utility was soon attacked as only exacerbating the privacy and security concerns. In addition to removing the rootkit, this program was reported to install additional software that cannot be uninstalled. In order to download the uninstaller, it is neccessary to provide an e-mail address, and to install an ActiveX control containing backdoor methods (marked as "safe for scripting", and thus prone to exploits). Opponents of Sony's actions, especially Slashdot.org, later accused Sony of violating the privacy of its customers to create a backdoor onto their machine using code that violates an Open Source license. They claimed that this DRM program, designed to give Sony control over the customer's machine in the name of copyright protection, is itself infringing copyright by including code from the LAME MP3 library. It appears that, since LAME is under the lGPL, this situation could be rectified by SONY offering a copy of the LAME source code; additionally it appears that the LAME code was added only to permit detection of attempts to rip the CD using LAME (not to actually implement LAME or call functions from it). On November 16, 2005 Sony-BMG bowed to pressure from consumers and recalled all CDs with XCP. Sony said customers will be able to exchange any discs with XCP. They also said they had instructed retailers to remove any unsold music discs containing the software from their shelves.
source wikipedia
More info on Extended Copy Protection (ECP) software from wikipedia.
Also check out Marks Sysinternals Blog exposing Sony's DRM RootKit.
I also found this online too.
World of Warcraft hackers using Sony BMG rootkit
Want to cheat in your online game and not get caught? Just buy a Sony BMG copy protected CD.
World of Warcraft hackers have confirmed that the hiding capabilities of Sony BMG's content protection software can make tools made for cheating in the online world impossible to detect. The software--deemed a "rootkit" by many security experts--is shipped with tens of thousands of the record company's music titles.
Blizzard Entertainment, the maker of World of Warcraft, has created a controversial program that detects cheaters by scanning the processes that are running at the time the game is played. Called the Warden, the anti-cheating program cannot detect any files that are hidden with Sony BMG's content protection, which only requires that the hacker add the prefix "$sys$" to file names.
Source online.securityfocus