Trojan horse
CA's anti-spyware application refers to Sony's XCP as a Trojan horse

Computer Associates blacklists Sony DRM

Pressure mounts on Sony to abandon insecure technology

Written by Tom Sanders in California

Computer Associates has officially blacklisted the Sony BMG XCP Technology that the record label bundles with several of its audio CDs.

CA's PestPatrol anti-spyware application now offers users the ability to remove the application, which it refers to as a Trojan horse. 

The vendor justifies referring to the technology as a Trojan by pointing out on its spyware information website that XCP "installs without user permission, presenting only a vague and misleading end user licence agreement". 

XCP also changes the system configuration without the user's permission and silently modifies other program information or website content. CA has further alleged that Sony has failed to allow users to remove the tool.

The application is also accused of shortening the life span of the user's hard drive by performing a scan of system processes every 1.5 seconds.

Another widely publicised feature of the technology is a rootkit that hides the digital rights management technology from the system and the user.

The rootkit will actually hide any file, process or registry key that begins with the characters '$sys$', making it extremely easy for virus authors and hackers to hide malicious applications from virus and spyware scanners.

Sony has always denied that there are any security issues associated with the software.

The technology was designed by First 4 Internet, and is bundled with several of Sony's audio CDs. Roughly two million of the CDs have been shipped.

The Electronic Frontier Foundation has compiled a list of some of the offending CDs with instructions on how to prevent getting infected.

Users who seek to play the CD on their computer CDRom drive on a Windows machine are presented with a licence agreement.

While the licence discloses that software will be installed, it does not give details and falsely suggests that it can be uninstalled. Upon agreement, the rootkit and DRM technology is installed.

Sony has released a patch that removes the cloaking feature of the rootkit, but CA pointed out that the patch failed to resolve all security concerns.

To obtain the Sony uninstaller, users are also required to give out personal information that will be used by Sony BMG and undisclosed third parties.

Tags:

Further reading

vnunet.com analysis: Sony CD rootkit could spell doom

Sony accused of undermining system stability in its crusade to protect copyright   More...

Sony rapped over music CD rootkit

Record label backtracks after public outrage over cloaking technology   More...

Rootkit creators turn professional

Dodging the virus shield becomes big business as authors 'outsource' malware creation   More...

Related articles

Sony BMG sues DRM software supplier

Former SunnComm accused of negligence and unfair business practices   More...

Rise of the rootkits

Stealth malware dodges popular security products   More...

Pirate Bay turns tables on media giants

P2P site complains to police about 'illegal' tactics   More...

Sony plans fix for 'rootkit' USB sticks

Patch promised later this month   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

16 May 2008

2.97 MBXP on OLPC, broken dreams and Yahoo fights back More...

15 May 2008

3.28 MBDark fibre, mobile TV and solar power More...

14 May 2008

2.66 MBOnline inequality, mobile thumbprints and corporate raids More...

Poll

HOME WORKING

HOME WORKING

Do you let any or all of your employees work from home?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

OLPC

OLPC to ship with Windows XP

Microsoft teams up with One Laptop per Child project   More...

The Sims

The Sims goes flat-pack with Ikea

Virtual world gets Swedish wood   More...

Advertisement

Microsoft-Yahoo

Yahoo board fights back at Icahn

Investor accused of 'significant misunderstanding' in Microsoft saga   More...

MySpace

Woman charged over MySpace suicide

Lori Drew indicted on federal charges   More...

Advertisement