Massassi Forums Logo

This is the static archive of the Massassi Forums. The forums are closed indefinitely. Thanks for all the memories!

You can also download Super Old Archived Message Boards from when Massassi first started.

"View" counts are as of the day the forums were archived, and will no longer increase.

ForumsDiscussion Forum → Sony's Digital Rights Management
Sony's Digital Rights Management
2005-12-09, 1:43 AM #1
Many of you may have read the thread concerning a class action lawsuit against Sony Corp.
http://forums.massassi.net/vb3/showthread.php?t=37212&highlight=sony
The situation has become very in-depth.

It started October 31 when a man name Mark Russinovich posted on his Sysinternals Blog that he had found a rootkit installed on his PC using RootKit Revealer. He was able to trace it back to a CD he had bought off Amazon.com of the Van Zant brothers that was produced by Sony BMG(a joint venture between Sony and the German company Bertelsmann Music Group). This DRM rootkit, also known as the Extended Copy Protection(XCP) software, developed by First 4 Internet, was included on Sony BMG's new cds, which, unbeknownst to the user, automatically installed it into the Windows registry when the cd was inserted into the drive. It ensured that the cd could only be played on the media player that was shipped with the disk, and also limited the user to making 3 copies of the cd. In addition, it would "phone home" and reveal information such as what songs you were listening too and how many times the cd was played; by definition a form of spyware. However, it also included many security holes, effectively allowing any third-party to access and control your computer or install hidden trojans and viruses(such as the WoW hack). Because of its depth in the system, if an attempt was made to delete the rootkit, it would disable the cd drive or even crash Windows.

On November 2nd, Sony announced it would be releasing a patch to remove the rootkit vulnerability from any infected system. This patch was made available over Sony's website and was hoped to fix the problem. Unfortunately, it was found that the ActiveX component of the patch allowed for another, even more seroius security breach:

Quote:
by J. Alex Halderman and Ed Felten

The consequences of the flaw are severe. It allows any web page you visit to download, install, and run any code it likes on your computer. Any web page can seize control of your computer; then it can do anything it likes. That’s about as serious as a security flaw can get.


One Tuesday, November 8th, Thomas Hesse, Sony President of Global Digital Business, made the statement during a BBC interview:

Quote:
Most people, I think, don’t even know what a rootkit is, so why should they care about it?


On November 11th, Symantec offered another patch that effectively fixed the security hole in the rootkit, but did not uninstall it. At this point Sony halted production of the cds containing the rootkit and recalled the ones already in stores. Two days later Microsoft announced that it would take steps to wipe the rootkit from infected Windows systems, and on the following Monday, Sony publically apologized and withdrew its flawed uninstaller.

The Chicago Tribune reported on November 25th that cds contaning the rootkit were still on shelves even after the recall two weeks before. Incidently, the same day First 4 Internet, the company that originally developed the rootkit, removed its website from the internet and replaced it with a page containing some simple contact info.


In addition, sections of the code contained in the original rootkit seem to have been stolen from a variety of different sources outside of the Sony Corporation.


There is another distribution of DRM software, MediaMax, produced by SunnComm, and used on another set of Sony cds that is causing problems. This DRM, though not including a rootkit, performs many actions consistant with spyware.

Quote:
Like XCP, recent versions of MediaMax engage in spyware-style behavior. They install software without meaningful consent or notification, they include either no means of uninstalling the software or an uninstaller that claims to remove the entire program but doesn’t, and they transmit information about user activities to SunnComm despite statements to the contrary in the end user license agreement and on SunnComm’s web site.


It was also found that the MediaMax installer can permanently activate and run the copy protection driver even if the user never agrees to the EULA.

In addition, the uninstaller for the MediaMax software includes a similar web browser security breach to the original XCP rootkit patch that is even easier to execute.

Most recently, another exploit was found in the MediaMax software. The problem is MediaMax installs itself into a directory that anyone is allowed to modify. Therefore it is possible for anyone to add malicious software to MediaMax files, which executes the next time the program is run.

Another patch was released to fix this new problem, yet:

Quote:
SonyBMG has released a patch that purports to fix the problem. However, our tests show that the patch is insecure. It turns out that there is a way an adversary can booby-trap the MediaMax files so that hostile software is run automatically when you install and run the MediaMax patch.


The story to date:

An estimated 24 million cds were produced containing either the First 4 Internet rootkit or the SunnComm MediaMax software. Though the Sony BMG cds were pulled off the shelves, MediaMax is still on the market in the hopes that Sony can fix the problems. This does not seem likely seeing as how MediaMax, its patch, and its uninstaller all contain serious exploits. Sony now finds itself in several class action lawsuits, initiated by parties including the Electronic Frontier Foundation, groups in Oklahoma, Washington D.C., and New York, and the state of Texas.

It has been a complete disaster for Sony and is an example against copyright control systems such as DGM. I personally disagree with what Sony attempted to do and am glad it blew up in there face.

Here is a list of the cds containing the XCP:
Most of them are not big names, but just in case:
Sony BMG CDs

[http://craphound.com/images/foxtrotrootkit.jpg]
Your skill in reading has increased by 1 point.
2005-12-09, 6:29 AM #2
Yeah, I've been following these clowns since the rootkit was announced. ****ing idiots.
$do || ! $do ; try
try: command not found
Ye Olde Galactic Empire Mission Editor (X-wing, TIE, XvT/BoP, XWA)
2005-12-09, 7:45 AM #3
They need to quit wasting time and money, no matter what they do, their stuff will get pirated.
gbk is 50 probably

MB IS FAT
2005-12-09, 9:50 AM #4
How many times has Sony done this? They piss me off... they are one greedy company.
"I'm afraid of OC'ing my video card. You never know when Ogre Calling can go terribly wrong."
2005-12-09, 10:54 AM #5
Originally posted by thauruin:
Many of you may have read the thread concerning a class action lawsuit against Sony Corp.
http://forums.massassi.net/vb3/showthread.php?t=37212&highlight=sony
The situation has become very in-depth.

...stuff...

[http://craphound.com/images/foxtrotrootkit.jpg]


That was incredibly well written. Good show. Would you be interested in perhaps participating in RTfM some time?
-=I'm the wang of this here site, and it's HUGE! So just imagine how big I am.=-
1337Yectiwan
The OSC Empire
10 of 14 -- 27 Lives On
2005-12-09, 10:57 AM #6
Edit: Nevermind, I'm a moran.
Bassoon, n. A brazen instrument into which a fool blows out his brains.
2005-12-09, 10:59 AM #7
... if you didn't write that "essay" of sorts, then the offer is less withstanding. We just need people who are interested and good at speaking... writing often portrays a good thinker / speaker.
-=I'm the wang of this here site, and it's HUGE! So just imagine how big I am.=-
1337Yectiwan
The OSC Empire
10 of 14 -- 27 Lives On
2005-12-09, 12:31 PM #8
Originally posted by Yecti:
... if you didn't write that "essay" of sorts, then the offer is less withstanding. We just need people who are interested and good at speaking... writing often portrays a good thinker / speaker.

Yeah, nevermind what I wrote. I completely missed like everything you were trying to say. However, I may be interested in writing. I did some heavy critiquing of happydud's college essay, if that means anything to you.
Bassoon, n. A brazen instrument into which a fool blows out his brains.
2005-12-09, 12:55 PM #9
You can hash it out with MB if he can stand speaking with you on the show. :p j/k we'll have rotating people in and out either adding to the four of us (that is if all four of us want to keep on as "regulars") or to supplement when there's a limited number of "regulars" I know that maxis wants to join in too... And I'm still interested in the author's input if he'd like..
-=I'm the wang of this here site, and it's HUGE! So just imagine how big I am.=-
1337Yectiwan
The OSC Empire
10 of 14 -- 27 Lives On
2005-12-12, 7:19 AM #10
Yecti, did you get my my pm?
Your skill in reading has increased by 1 point.
2005-12-12, 9:44 AM #11
More like Sony Digital WRONGS Management!

[http://images.mzzt.net/burnsauce.gif]

2005-12-12, 5:08 PM #12
this is why i almost exclusively use iTunes... actually it's not... it's really cause i'm too lazy to drive to the store.
"Those ****ing amateurs... You left your dog, you idiots!"

↑ Up to the top!