Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Community > MacNN Lounge > Sony Rootkit Revisited: It Sure Didn't Take Long...

Sony Rootkit Revisited: It Sure Didn't Take Long...
Thread Tools
Mac Elite
Join Date: Jan 2003
Location: 127.0.0.1
Status: Offline
Reply With Quote
Nov 10, 2005, 01:05 PM
 
http://www.theregister.co.uk/2005/11...ny_drm_trojan/

I wonder how the anti-virus industry is going to label this one.
     
Addicted to MacNN
Join Date: Oct 1999
Location: The Tollbooth Capital of the US
Status: Offline
Reply With Quote
Nov 10, 2005, 01:08 PM
 
I just posted right after you did. GO figure.
"Evil is Powerless If the Good are Unafraid." -Ronald Reagan

Apple and Intel, the dawning of a NEW era.
     
Moderator
Join Date: Feb 2000
Location: Night's Plutonian shore...
Status: Offline
Reply With Quote
Nov 10, 2005, 01:17 PM
 
Sony really screwed the pooch on this one. For the first time, I find myself wondering "Do I really need the products distributed by a company like this?". It's also made me reevaluate my position on DRM; where as I used to find it mildly annoying, I now find myself against it and all it's forms.

At this point I would rather steal the music as opposed to spending my hard earned money to allow some corporation to invade my machine, violate my privacy, and leave the thing open to untraceable viruses and trojans. No thanks Sony, **** you.
Nemo me impune lacesset
     
Administrator
Join Date: Apr 2001
Location: San Antonio TX USA
Status: Offline
Reply With Quote
Nov 10, 2005, 01:27 PM
 
I like BMG. And Warner. And even Capitol. But I'm staying away from any new Sony-labeled stuff. CD Exchange, here I come! (And yes, I know what the RIAA and probably Sony execs think about buying used CDs-that's one reason I do it!)
Glenn -----
OTR/L, MOT, Tx
     
Caffeinated Theme Master
Join Date: Nov 1999
Location: hell (says dakar)
Status: Offline
Reply With Quote
Nov 10, 2005, 01:38 PM
 
Originally Posted by alphasubzero949
... I wonder how the anti-virus industry is going to label this one.
Not only does this virtual pest boil pave the way for a "new" way of hiding poopware (trojans, etc.), it also phones home. And while the first class-action lawsuit has been filed against Sony in CA, Sony/BMG announced today that it'll be including their XPC DRM-software on CDs sold in Europe beginning early next year.

Fudge- -s, the lot of them.
...
     
Caffeinated Theme Master
Join Date: Nov 1999
Location: hell (says dakar)
Status: Offline
Reply With Quote
Nov 10, 2005, 01:54 PM
 
Originally Posted by ghporter
I like BMG. ...
At least as far as music is concerned, BMG is Sony is Bertelsmann is Sony, etc. The footer on the home page of Sony Music USA (www.sonymusic.com) states: "Copyright © 2005 SONY BMG MUSIC ENTERTAINMENT"

...
     
Banned
Join Date: Jun 2005
Location: Indy.
Status: Offline
Reply With Quote
Nov 10, 2005, 10:25 PM
 
Originally Posted by ThinkInsane
Sony really screwed the pooch on this one. For the first time, I find myself wondering "Do I really need the products distributed by a company like this?". It's also made me reevaluate my position on DRM; where as I used to find it mildly annoying, I now find myself against it and all it's forms.

At this point I would rather steal the music as opposed to spending my hard earned money to allow some corporation to invade my machine, violate my privacy, and leave the thing open to untraceable viruses and trojans. No thanks Sony, **** you.
I am in the market for a new TV. I was looking at the Sony HDTV LCD TVs, but now they are off my list. Probably get a Phillips, Sharp, or someother brand now.

Yup, Sony is shooting them selves int he foot on this one.
     
Professional Poster
Join Date: Jul 2005
Location: Winnipeg, MB
Status: Offline
Reply With Quote
Nov 11, 2005, 12:10 AM
 
Sony's been off my list since the Playstation the only money they'll be getting from me is for the next Switchfoot CD which if it's only available with this sort of DRM will be being pirated by myself.
     
Mac Elite
Join Date: Jan 2003
Location: 127.0.0.1
Status: Offline
Reply With Quote
Nov 11, 2005, 05:54 AM
 
Guess what? Sony has hidden DRM for the Mac as well.

Looks like a Sony BMG CD asking for an admin password after sticking it in isn't so innocent anymore.
     
Mac Elite
Join Date: Feb 2003
Status: Offline
Reply With Quote
Nov 11, 2005, 06:33 AM
 
I love how the DRM company advertises its OSX compatibility:

For the first time, content can be played and protected on a Mac with the same experience enjoyed on a PC
Finally!
     
Professional Poster
Join Date: Sep 2005
Location: Rochester, NY
Status: Offline
Reply With Quote
Dec 6, 2005, 02:18 PM
 
News.com had something interesting here. It's in a silly blog format that doesn't say much of anything, but links to this post at freedom-to-tinker.com which explains why Sony may have had that itunes DRM decryption code in their rootkit. It seems that the decryption process and the encryption process are similar enough that the same code will do both, with some tweaking. And this enteprising hacker has found out that there's a function embedded in the rootkit that will take an ordinary MP3 file and "turn it into" a protected AAC file. This code isn't called by anything in the rootkit, but it's there, and anyone with a debugger can use it to turn an ordinary MP3 into something that looks, to iTunes, like it's protected AAC.

So, Sony was distributing software that actively screws with Apple's FairPlay DRM scheme, not to crack it necessarily, but to put its own music on the iPod in a protected format without Apple's blessing. At the same time, they are distributing the same code that could be used to decrypt Apple FairPlay songs into unprotected AAC files, including those sold by Sony. Is it a DMCA violation to distribute software to circumvent access controls to content you own?

They were probably going to blackmail Apple into licensing FairPlay by threatening to activate millions of zombie computers that could have encoded any arbitrary media file from any source into the Apple Protected format, making Sony CD's "iPod-compatible" without having to convert the songs into unencumbered MP3 of AAC first, and turning Sony into an iTMS clone. Heh. There's gotta be a lawsuit in there somewhere.
     
Mac Elite
Join Date: Mar 2005
Location: LV-426
Status: Offline
Reply With Quote
Dec 6, 2005, 02:28 PM
 
Originally Posted by effgee
Not only does this virtual pest boil pave the way for a "new" way of hiding poopware (trojans, etc.), it also phones home. And while the first class-action lawsuit has been filed against Sony in CA, Sony/BMG announced today that it'll be including their XPC DRM-software on CDs sold in Europe beginning early next year.

Fudge- -s, the lot of them.
Sony are a bunch of bastards. However they've recalled all the DRMed CDs in the US, no? I suspect they will have to back out of this in EU too.

Also remember Steve Jobs wanted Apple to become the Sony of the computer industry for a while. Then he decided he wanted Apple to become the Apple of the computer industry.

A wise choice.

cheers

W-Y

“Building Better Worlds”
     
Addicted to MacNN
Join Date: Sep 2001
Location: Toronto
Status: Offline
Reply With Quote
Dec 6, 2005, 02:44 PM
 
Originally Posted by Railroader
I am in the market for a new TV. I was looking at the Sony HDTV LCD TVs, but now they are off my list. Probably get a Phillips, Sharp, or someother brand now.

Yup, Sony is shooting them selves int he foot on this one.

We were looking for a kitchen TV a couple of weeks back. The Sony model looked nice, but in the end we decided on a Toshiba. Sony won't be seeing any of my money anytime soon.
     
Addicted to MacNN
Join Date: Apr 2001
Location: The bottom of Cloud City
Status: Offline
Reply With Quote
Dec 6, 2005, 02:46 PM
 
This is why I never buy any sort of copy protected CD.

"Ahhhhhhhhhhhhhhhh"
     
Administrator
Join Date: Apr 2001
Location: San Antonio TX USA
Status: Offline
Reply With Quote
Dec 6, 2005, 05:52 PM
 
Originally Posted by Severed Hand of Skywalker
This is why I never buy any sort of copy protected CD.
That's a good policy. This debacle is costing Sony a LOT of money; they're making UNPROTECTED CDs available (at least to Texans, due to the state suing the company) along with MP3s of the songs, they've posted uninstallers for the code, they say they're working with the AV companies to properly protect users who they've hacked, and they're basically bowing and scraping and saying "we're very, very sorry" all over the place because of their ham-handed copy protection effort. AND I see anyone who manages to get bit by the trojan that ties into the copy protection code as having some hellacious grounds for lawsuits against them.
Glenn -----
OTR/L, MOT, Tx
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 11:14 AM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2