News.com Mobile
for PDA or phone
Login: Forgot password? | Sign up

New Sony CD security risk found

By John Borland
Staff Writer, CNET News.com
Published: December 6, 2005, 4:58 PM PST

Sony BMG Music Entertainment and the Electronic Frontier Foundation digital rights group jointly announced Tuesday that they had found, and fixed, a new computer security risk associated with some of the record label's CDs.

The danger is associated with copy-protection software included on some Sony discs created by a company called SunnComm Technologies. The vulnerability could allow malicious programmers to gain control of computers that have run the software, which is typically installed automatically when a disc is put in a computer's CD drive.

Sony's rootkit fiasco

The issue affects a different set of CDs than the ones involved in the copy-protection gaffe that led Sony to recall 4.7 million CDs last month, and which has triggered several lawsuits against the record label.

"We're pleased that Sony BMG responded quickly and responsibly when we drew their attention to this security problem," EFF staff attorney Kurt Opsahl said in a statement. "Consumers should take immediate steps to protect their computers."

The announcement is the latest result of the detailed scrutiny applied by the technical community to Sony's copy-protected discs, after a string of serious security issues were found to be associated with the label's antipiracy efforts.

The record label's copy-protected discs have been on the market for more than eight months. But in late October, blogger Mark Russinovich discovered that they surreptitiously installed a "rootkit" programming tool. Rootkit tools are typically used by hackers to hide viruses on hard drives, so Sony's move opened up a potentially serious security hole.

The controversy escalated as other researchers discovered new security flaws associated with the copy-protected CDs, which used technology from British company First 4 Internet. Virus writers began distributing malicious code that took advantage of the holes. The label recalled all the discs with the First 4 Internet technology installed, offering an exchange program for consumers who had purchased any of the 52 CDs affected.

Following those revelations, the EFF asked computer security company iSec Partners to study the SunnComm copy protection technology, which Sony said has been distributed with 27 of its CDs in the United States. iSec found the hole announced Tuesday and notified Sony, but news of the risk was not released until SunnComm had created a patch.

Sony said another security company, NGS Software, has tested the patch and certified that it addresses the vulnerability.

The patch can be downloaded from Sony's site. A list of the CDs affected in the United States, and a slightly different list in Canada, is also posted on the site.

Sony said it will notify customers though a banner advertisement directly in the SunnComm software, as well as through an Internet advertising campaign.

 18 comments
Post a comment

TalkBack

The really bad part is...

J. C.   Dec 9, 2005, 7:59 AM PST

Too late, I'm done buying any Song or BMG products

Johnq Public   Dec 9, 2005, 7:54 AM PST

Message has been deleted.

John Doe   Dec 7, 2005, 8:41 PM PST

Will PS3/Blueray contain Rootkit in any way or form?

Bob Bob   Dec 7, 2005, 7:55 AM PST

Let em sit on their disks..and spin

Donald King   Dec 7, 2005, 7:33 AM PST

What Did You Expect From Sony BMG Payola?

Keith J.   Dec 6, 2005, 10:00 PM PST

Boycott Sony/Blu-ray

Joe Schmoe   Dec 6, 2005, 7:48 PM PST

What price a customer?

Ian Deal   Dec 6, 2005, 7:35 PM PST

sony crossed the line this time

Digitally Sick   Dec 6, 2005, 7:02 PM PST

ads too?

Newsdotcom Commenter   Dec 6, 2005, 5:41 PM PST

Sony CDs

David Fryauf   Dec 6, 2005, 5:40 PM PST

Sorry Sony...I'm done with your CD's.

No User   Dec 6, 2005, 5:19 PM PST

advertisement

Did you know?

Select a tab below to set your default view.

Scan the 15 newest and most read stories on News.com right now. Learn more

Updated: 7:51 PM PST
View as:
Unpatched Firefox 1.5 exploit made public Power could cost more than servers, Google warns Creative wants to make Apple pay Sober code cracked Sony says PS3 still on track for spring launch Sony fixes security hole in CDs, again Police blotter: Nude 'profile' yields Yahoo suit How tech billionaires live Intel calls MIT's $100 laptop a 'gadget' Microsoft offers a new angle on maps Consumers snap up LCD monitors Intel to battle rootkits Viacom nearing deal to acquire DreamWorks BellSouth, 8x8 launch VoIP service Cheers for Yahoo's move to a community-driven Web
Legend:
Older
Newer
Larger boxes indicate hotter stories.

Resource center from News.com sponsors

Concerned About Computer Security?

Education is the best defense

Computer security threats are part of daily life. But today's malware techniques present unprecedented challenges for businesses of all sizes. Learn how to protect yourself.

Learn from the experts>>

Top picks from News.com readers


Daily spotlight

Video: A video slam-dunk

Here's a look at the tech behind those TV and online highlights of pro basketball games, in a narrated video produced by the NBA and Silicon Graphics Inc.

Photos: Gizmos made in Japan

Japan is still a leader in product design and innovation. Here are some new and notable gadgets.

Video: "The power to organize" online

Meetup.com founder and CEO Scott Heiferman says Meetup is spreading beyond America. The service, Heiferman says, is helping "make the world a friendlier place."

Innovations battle natural calamities

Scientists hope integrating cutting-edge technology projects will help predict and mitigate natural disasters.

Debating Wikipedia's open-source label

High Impact The online encyclopedia is a broadly communal effort, but it's not run the same way as open-source software.

Police blotter: Nude 'profile' yields Yahoo suit

Woman says ex-boyfriend posted nude photos and her phone number in a Yahoo Personals profile. She sued for $3 million.

High-tech animation in indies' grasp

Competing with digital toon powerhouses like Pixar isn't easy. But cheaper tech, outsourcing are making it possible.

Ogre to slay? Outsource it to China

Affluent online gamers are paying workers at Chinese game-playing factories to play games' early rounds for them.

Video: The incredible, shrinking glaciers

This NASA-produced video is a dramatic and colorful look at our planet from high above, and the changes that are taking place.

Image: AOL searches for the stars

TMZ.com, AOL's new online magazine promises inside scoops on Hollywood's hottest stars.

Clock's ticking on new Sober onslaught

Mass-mailing worm is programmed to download new instructions in January, which could indicate a new outbreak.

Photos: New animal discovered in Borneo

A creature that looks like a cross between a cat and a fox is photographed in the rainforest.

CNET.com
Copyright ©2005 CNET Networks, Inc. All Rights Reserved. Privacy Policy | About CNET Networks | Jobs | Terms of Use