News.com Mobile
for PDA or phone
Login: Forgot password? | Sign up

Sony CD protection sparks security concerns

By John Borland
Staff Writer, CNET News.com
Published: November 1, 2005, 2:15 PM PST
Last modified: November 17, 2005, 4:41 PM PST

A correction was made to this story. Read below for details.

Mark Russinovich was doing a routine test this week of computer security software he'd co-written, when he made a surprising discovery: Something new was hiding itself deep inside his PC's guts.

It took some time for Russinovich, an experienced programmer who has written a book on the Windows operating system for Microsoft, to track down exactly what was happening, but he ultimately traced it to code left behind by a recent CD he'd bought and played on his computer.

The Sony BMG-produced Van Zant album had been advertised as copy-protected when he'd bought it on Amazon.com, and he'd clicked through an installation agreement when he put the disc in his computer. What he later found is that the software had used a sophisticated cloaking technique that involves a "rootkit"--something not dangerous in itself, but a tool often used by virus writers to hide all traces of their work on a computer.

News.context

What's new:
Copy-protection software on CDs produced by SonyBMG is cloaked by a technique that involves a "rootkit," which is designed to hide and protect the software on the user's computer.

Bottom line:
Rootkit tools often are used by virus writers to hide malicious software, and security experts say rootkit mechanisms used by recording companies could be misused by others. That threat is only theoretical so far, but the debate continues between consumers and record companies about what copy-protection technologies are necessary and appropriate.

More stories on this topic

"We're still trying to find a line between fair use and digital rights management, and it is going to take issues like this, with discussions between lawmakers and industry, to come up with what's fair and honest," Russinovich said. "But I think this has gone too far."

Russinovich posted a detailed step-by-step account of his findings on his blog, drawing immediate criticism of SonyBMG's technology from some inside the security software community. The passionate response underlines the power copy protection retains to inflame emotions and spark bitter debate, despite the growing string of chart-topping albums that have been released over the past year with the protections included.

A handful of security companies weighed in on the issue, saying the rootkit could present a possible--if still theoretical--risk to computers.

The creator of the copy-protection software, a British company called First 4 Internet, said the cloaking mechanism was not a risk. The company's team has worked regularly with big antivirus companies to ensure the safety of its software, and to make sure it is not picked up as a virus, he said.

In any case, First 4 has moved away from the techniques used on the Van Zant album to new ways of cloaking files on a hard drive, said Mathew Gilliat-Smith, the company's CEO.

"I think this is slightly old news," Gilliat-Smith said. "For the eight months that these CDs have been out, we haven't had any comments about malware (malicious software) at all."

A SonyBMG representative said the software could be easily uninstalled, by contacting the company's customer support service for instructions. Those instructions are not specifically available on the Web site that answers questions about the company's copy protection tools.

Rootkit realities
Rootkit software has been around for over a decade but has recently come to increased prominence as more writers of viruses and the like adopt it for their purposes. Essentially, rootkits are tools for digging deep into a computer's operating system to hide the fact that certain software files exist or that the computer is performing certain functions.

Unlike other, less-powerful means of hiding files on a hard drive, rootkits are created to be extraordinarily difficult to uninstall without specific instructions, rooting themselves in an operating systems' deepest recesses in order to prevent their deletion.

In the case of the SonyBMG software, trying to remove it manually could shut off access to the computer's CD player, researchers said.

Security researchers note that simply hiding something doesn't make it a threat, and the SonyBMG software is designed to hide the digital rights management tools that prevent unauthorized copies of the CD from being made.

However, it does remain active in the background of a computer, taking up a small amount of memory, even when the CD is not being played. Thus the rootkit software does have the potential to be misused by others, according to some researchers. The First 4 Internet software's technique for hiding files is broad enough that it could be adopted by virus writers, allowing them to hide their own tools on computers that have run the software from the CD, say some security experts.

That's an "academic" concern, but a real one, said F-Secure Chief Research Officer Mikko Hypponen, who wrote a warning on the issue Tuesday.

"Obviously there are a lot of people who don't like the technology, and we will take note if we need to."
--Mathew Giliat-Smith, CEO, First 4 Internet

"Right now if you have this on your system, there is no real-world risk just because of this," Hypponen said. "But it would not be too far-fetched that some virus writer would try to take advantage of this."

Giliat-Smith said his company is working with major antivirus software companies to help their software recognize the copy-protection tools and help guard against misuse.

A balancing act
The criticism over the protection technology highlights the careful balance record labels are trying to strike as they seek ways to guard their discs against copying.

Label executives have increasingly shifted their public piracy concerns from Internet file-swapping to the effect of widespread CD burning. The Recording Industry Association of America cites recent research from marketing specialist NPD Group showing that 29 percent of consumers' new music is acquired through ripping or burning a copy of a CD.

The CD copy protection tools now on the market do let consumers make copies of the music, both in the form of digital files on their computer and a limited number of backup CDs. Labels say they support both these activities, as long as they're for personal use.

The files that can be ripped to computers from these discs cannot be played on iPod MP3 players, however. The labels say they have not yet been able to persuade Apple Computer to include this capability.

Several earlier versions of copy protection were widely mocked online for being trivially easy to circumvent, by using techniques that included holding the computer's "shift" key down while starting, and coloring the rim of a CD with a magic marker.

Later versions of the technology, such as that produced by First 4 Internet, have made it more difficult to disable while still allowing the discs to be played on most computers.

"Obviously there are a lot of people who don't like the technology, and we will take note if we need to," Gilliat-Smith said. "Our approach is to make the balance between protection and the consumer experience the best that we can make it for our customers."

 

Correction: This story originally implied that Symantec approved First 4 Internet's "rootkit" software. It did not.
 58 comments
Post a comment

TalkBack

Sony's crimnal intent

James Gromoll   Nov 23, 2005, 2:10 PM PST

Article modified without revision notice

Squidboy Squidboy   Nov 17, 2005, 2:45 PM PST

Symantec is in on this?

Darryl Snortberry   Nov 3, 2005, 9:46 PM PST

class action

Kevin Ross   Nov 3, 2005, 3:08 PM PST

I guess I'll start stealing music again?

Matt Hancock   Nov 3, 2005, 12:25 PM PST

What should I say???

Humberto Pereira   Nov 3, 2005, 6:54 AM PST

Let's call it w32.RootBySony.1 as the malware

Bob Smith   Nov 3, 2005, 3:17 AM PST

Rewarding those who buy CDs with a rootkit...

My Self   Nov 3, 2005, 12:01 AM PST

"No comments" - baloney

Wally Bass   Nov 2, 2005, 7:23 PM PST

I don't buy media from companies that treat me like a criminal.

William Cattey   Nov 2, 2005, 1:05 PM PST

AnyDVD

Andrew Bright   Nov 2, 2005, 11:29 AM PST

that's why i don't buy anymore

Todd Hughes   Nov 2, 2005, 9:54 AM PST

Sony, now hiding malware like programs

Bob Bob   Nov 2, 2005, 8:02 AM PST

So that's what that unidentified program was

H Voyager   Nov 2, 2005, 7:57 AM PST

Possibly underestimating the threat

Bruce Hayden   Nov 2, 2005, 7:38 AM PST

I don't buy anything Sony anymore!

Kevin Krause   Nov 2, 2005, 7:02 AM PST

How to disable autorun...

Joe Computer   Nov 2, 2005, 5:52 AM PST

What Else Will Sony Do?

Keith J.   Nov 2, 2005, 12:07 AM PST

How about this.....

Marius Thull   Nov 1, 2005, 10:45 PM PST

Typical: Hurt the consumer, not the theif.

Zaz.net Zaz.net   Nov 1, 2005, 9:54 PM PST

I disagree

Felipe Oxtail   Nov 1, 2005, 9:08 PM PST

Sony has LOST its DIRECTION as an ELECTRONICS company

John Glenn   Nov 1, 2005, 8:51 PM PST

Taking the law into their own hands....

Aaron Karp   Nov 1, 2005, 8:18 PM PST

Rootkit requires root, duh...

Rafe H.   Nov 1, 2005, 7:39 PM PST

This is more than a mis-step... It is a criminal-offense.

Had_to Be_said   Nov 1, 2005, 5:26 PM PST

advertisement

Did you know?

Select a tab below to set your default view.

Put this story in perspective with this unique visual tool (full screen). Learn more

Powered by Liveplasma.com

Scan the 15 newest and most read stories on News.com right now. Learn more

Updated: 9:02 AM PST
View as:
Hottest story: What's the buzz? Teens can't stand it Reality check on Xbox 360 Mozilla takes wraps off Firefox 1.5 New high-definition DVDs to use old video technology? A.com, B.com, C.com on the way? Smash my Xbox 360 Samsung unveils largest flexible LCD Maxell focuses on holographic storage Cost questions dog Blu-ray DVD's lead Hello, this is Google, your operator, speaking Banking on a virtual economy PSP update adds audio goodies Judge files sealed opinion in RIM case Apple may launch Intel laptops, analyst says New: A warehouse of Google map mashups
Legend:
Older
Newer
Larger boxes indicate hotter stories.

Resource center from News.com sponsors

Concerned About Computer Security?

Education is the best defense

Computer security threats are part of daily life. But today's malware techniques present unprecedented challenges for businesses of all sizes. Learn how to protect yourself.

Learn from the experts>>

Top picks from News.com readers

Readers who read Sony CD protection sparks security concerns also read...

More Info

Markets

Market news, charts, SEC filings, and more

Related quotes

  Symbol Lookup

Daily spotlight

CNET's Holiday Helpdesk: Still have questions?

Chance are our helpdesk answered it. Take a look.

Perspective: India's next big business?

Possibly oil, says CNET News.com's Michael Kanellos. The country's deposits are twice the size of Iraq's.

Newsmaker: Banking on virtual economy

Online gamer Jon Jacobs recently spent $100,000 in real-world money to buy a virtual space station. Is he nuts?

Cost questions dog Blu-ray DVD

By all accounts, Sony's high-definition discs are being tapped as the successor to standard DVD. But serious production questions remain.


<img src="http://ad.doubleclick.net/ad/N815.zdnet.com/B1695829.2;sz=1x1;ord=373067302548394800?" border=0 width=1 height=1 style="position:absolute;width:1px;height:1px;top:0px;left:0px;"><img src="http://kt4.kliptracker.com/klipinsert4.gif?campid=10437&ktaction=2&ad_id=1" border=0 width=1 height=1><A href="http://kt4.kliptracker.com/klipinsert4.tux?campid=10437&ktaction=100&ad_id=1&redir=http%3A//ad.doubleclick.net/clk%3B21333710%3B11919759%3Bf%3Fhttp%3A//www-1.ibm.com/businesscenter/smb/us/en/iems%3FS_TACT%3D6N3FJ44W%26ca%3D6N3FJ%26me%3DW%26met%3Dexba%26re%3DzdnetRON300x250http%3A//" target="_blank"><img src="http://gfx.dvlabs.com/klipmart/campaigns/ibm009/a/ibm009a_still.jpg" border=0 width=300 height=250 alt="Security"></a>
CNET.com
Copyright ©2005 CNET Networks, Inc. All Rights Reserved. Privacy Policy | About CNET Networks | Jobs | Terms of Use