News.com Mobile
for PDA or phone
Login: Forgot password? | Sign up

Sony fixes security hole in CDs, again

By John Borland
Staff Writer, CNET News.com
Published: December 8, 2005, 12:21 PM PST

Sony BMG is replacing a patch for its CD copy protection software after Princeton University researchers found a security flaw in the update.

Sony announced on Tuesday that a new risk had been found with a batch of 27 of its compact discs, which automatically install antipiracy software on hard drives when put into a computer's disc drive. Along with the Electronic Frontier Foundation, a digital rights group, the record label released a patch aimed at fixing that flaw.

However, Princeton computer science professor Ed Felten wrote in his blog on Wednesday that the patch itself could open computers to attack by hackers.

Sony executives said Thursday that they are working as closely as possible with security professionals to address the issues identified by Felten, and would have a new patch available by midday that day.

"The security space is a dynamic one, as we have learned," said Thomas Hesse, president of Sony's global digital businesses. "Our goal is to be diligent and swift, and we have gone to experts to handle this issue."

Sony's ongoing troubles with copy protection software highlight the delicate line that record labels and other content companies are walking in trying to protect their products from widespread duplication.

On the one hand, labels have watched their revenues decrease over the past several years, as more people swap songs online and burn CDs for friends and acquaintances.

However, the labels' technological attempts to create a copy-protected CD that retains compatibility with millions of old CD players have opened them up to the unfamiliar hazards of software development. Several of Sony's attempts to patch security holes in its antipiracy software over the past weeks have turned out to raise their own new problems, instead of quelling concerns.

The current security flaw in Sony's discs is related to software produced by SunnComm Technologies and affects 27 titles that remain on the market.

It's separate from an earlier vulnerability that affected 52 other titles and that related to antipiracy software written by another company, First 4 Internet. Those titles have been recalled from store shelves.

The flaw found by Felten could allow Sony's original patch to trigger malicious software on a computer, if that software was already in place when the patch was installed.

 18 comments
Post a comment

TalkBack

Shame on cnet

Mind your Own business   Dec 9, 2005, 8:07 AM PST

Strike 2!

Mind your Own business   Dec 9, 2005, 8:00 AM PST

At least Intel is doing something

Sql   Dec 8, 2005, 6:10 PM PST

Sony punishes people that actually buy CDs

Larry Laitner   Dec 8, 2005, 5:46 PM PST

Well, that's not possible

Jim Hassinger   Dec 8, 2005, 2:12 PM PST

Where does DMCA fit in with Rootkit DRM?

Bob Bob   Dec 8, 2005, 1:49 PM PST

Where's the fix?

Primaltrader   Dec 8, 2005, 1:28 PM PST

Boycott Sony

Alexander Trauzzi   Dec 8, 2005, 1:21 PM PST

Hey Sony -- it's easy

Ian Ameline   Dec 8, 2005, 1:17 PM PST

How about something....

Earl Benser   Dec 8, 2005, 1:16 PM PST

Oh well,

Ian Deal   Dec 8, 2005, 1:15 PM PST

Record labels shouldn't be guaranteed a profit

Bob Bob   Dec 8, 2005, 1:09 PM PST


Did you know?

Select a tab below to set your default view.

Scan the 15 newest and most read stories on News.com right now. Learn more

Updated: 8:43 PM PST
View as:
Unpatched Firefox 1.5 exploit made public Power could cost more than servers, Google warns Creative wants to make Apple pay Sober code cracked Sony says PS3 still on track for spring launch Sony fixes security hole in CDs, again Police blotter: Nude 'profile' yields Yahoo suit How tech billionaires live Intel calls MIT's $100 laptop a 'gadget' Consumers snap up LCD monitors Microsoft offers a new angle on maps Intel to battle rootkits Viacom nearing deal to acquire DreamWorks BellSouth, 8x8 launch VoIP service Cheers for Yahoo's move to a community-driven Web
Legend:
Older
Newer
Larger boxes indicate hotter stories.

Resource center from News.com sponsors

Concerned About Computer Security?

Education is the best defense

Computer security threats are part of daily life. But today's malware techniques present unprecedented challenges for businesses of all sizes. Learn how to protect yourself.

Learn from the experts>>

Daily spotlight

Video: A video slam-dunk

Here's a look at the tech behind those TV and online highlights of pro basketball games, in a narrated video produced by the NBA and Silicon Graphics Inc.

Photos: Gizmos made in Japan

Japan is still a leader in product design and innovation. Here are some new and notable gadgets.

Video: "The power to organize" online

Meetup.com founder and CEO Scott Heiferman says Meetup is spreading beyond America. The service, Heiferman says, is helping "make the world a friendlier place."

Innovations battle natural calamities

Scientists hope integrating cutting-edge technology projects will help predict and mitigate natural disasters.

Debating Wikipedia's open-source label

High Impact The online encyclopedia is a broadly communal effort, but it's not run the same way as open-source software.

Police blotter: Nude 'profile' yields Yahoo suit

Woman says ex-boyfriend posted nude photos and her phone number in a Yahoo Personals profile. She sued for $3 million.

High-tech animation in indies' grasp

Competing with digital toon powerhouses like Pixar isn't easy. But cheaper tech, outsourcing are making it possible.

Ogre to slay? Outsource it to China

Affluent online gamers are paying workers at Chinese game-playing factories to play games' early rounds for them.

Video: The incredible, shrinking glaciers

This NASA-produced video is a dramatic and colorful look at our planet from high above, and the changes that are taking place.

Image: AOL searches for the stars

TMZ.com, AOL's new online magazine promises inside scoops on Hollywood's hottest stars.

Clock's ticking on new Sober onslaught

Mass-mailing worm is programmed to download new instructions in January, which could indicate a new outbreak.

Photos: New animal discovered in Borneo

A creature that looks like a cross between a cat and a fox is photographed in the rainforest.

advertisement
CNET.com
Copyright ©2005 CNET Networks, Inc. All Rights Reserved. Privacy Policy | About CNET Networks | Jobs | Terms of Use