Technology Review - Published By MIT
Log in to My.TechnologyReview.com | Register
Advertisement

May 2006

Rootkits Cross the Line

When a company trespasses upon its customers' privacy, it should expect outrage.

By Jason Pontin

smaller text tool iconmedium text tool iconlarger text tool icon

Last year, anonymous executives at Sony BMG Music Entertainment blundered. They hid a "rootkit" on around two million compact discs.

As senior editor Wade Roush explains in this month's cover story, "Inside the Spyware Scandal," rootkits are a kind of software more often exploited by mischievous hackers than by multinational media companies: a rootkit is capable of exposing an operating system's core functions to worms, viruses, or other programs, without anyone knowing about the subterfuge. In this case, computer users were asked to launch a Sony music player when they tried to play a Sony CD; if they did, they unwittingly downloaded a rootkit intended to hide components of a digital rights management (DRM) program. The DRM program also secretly contacted Sony every time a user played copy-protected music.

Sony's executives thought they were within their rights: they wanted to discourage piracy. But when security experts discovered the rootkit and blogged about it, a scandal followed. Many computer users said they felt "violated." According to John Guarino, the computer consultant who first identified the rootkit, "It's total lawlessness, and it's unacceptable."

Why were computer users so angry? In explaining themselves, most seemed to fret about trespasses upon their private property. But the complaints were much more heated than any damage to users' computers warranted (until Sony provided an uninstall program, removing the rootkit disabled users' CD-ROM drives). Sony's customers felt that the company had abused an interest related to property but distinct: they thought their privacy had been invaded.

The ambiguity of their complaints should not surprise. Privacy resists easy description. Philosophers or jurists eager to champion privacy as a coherent interest have nonetheless struggled to define it; others, less friendly to the idea, have argued that any interest we might protect as private can be more usefully defended by appeal to other interests, such as property, without the inconvenience of creating a new right or providing a cloak for illicit behavior. And certainly, people use "privacy" to describe very various interests.

This general confusion about what constitutes privacy has been much exploited by companies and governments in recent years. Indeed, as Sony's rootkit makes clear, much of our behavior in digital space is now potentially subject to observation, data collection, and coercion.

Yet privacy is real. There is a distinctive characteristic to all private experiences, although no one thing can be said to define privacy. But most of us recognize privacy when we experience it. Privacy is the space where we are free from interference. It is the neces-sary condition for intimacy, trust, and all contracts, including citizenship. And while the territory claimed for privacy will vary according to culture or historical circumstance, most feel aggrieved when we feel that territory shrink.

Sony's rootkit was not a trivial irritation, of importance only to geeks. The harm computer users suffered was limited (perhaps because the rootkit was discovered), but the offense was actual and new. Sony's customers objected on a point of principle: they believed they saw the chill expansion of corporate interests at the expense of privacy. They were right.

May/June 2006

Would you like to read more articles from the May/June 2006 issue?

This article is from the May/June 2006 Issue of Technology Review. To read other articles from this issue simply register for My.TechnologyReview.com. It's free.

Subscribe today and save up to 41% »

Comments

  • Rootkits Cross the Line
    Guest (antirootkit.com) on 05/15/2006 at 12:00 AM
    Posts:
    1
    There were many users who were adversely affected by the Sony Rootkit saga. As soon as it was discovered and made public, hackers started to write code that could be hidden by the Sony rootkit. If Sony had acted faster the damage would have been less. The very CD's that Sony created were still on sale in some shops after Christmas.
    It is an awful shame.

    regards
    Steo
    Rate this comment: 12345
  • Real Damage was Done
    Guest (Charles Wenzel) on 05/15/2006 at 12:00 AM
    Posts:
    1
    I don't agree that the damage was minor. I spent a whole weekend removing the rootkit after our babysitter installed it on almost every computer in the house. One computer required a Windows re-install (I probably goofed up) and our dial-up router was continually grabbing the line for no apparent reason (and not letting go). It was a mess. I lost one of my favorite electronics vendors, too.
    Rate this comment: 12345
Advertisement

Current Issue

Technology Review September/October 2008
How Obama Really Did It
Social technology helped bring him to the brink of the presidency.
•  Subscribe
Save 41%
•  Table of Contents
•  MIT News

Magazine Services

Career Resources

MIT Technology Insider

Stories and breaking news from inside MIT about the latest research, innovations, and startups--in a convenient monthly e-newsletter. Subscribe today

Follow us on Twitter

Twitter

Get Technology Review updates via the web, cellphone, or Instant Messager – Follow techreview on Twitter!

Advertisement

More Technology News from Forbes

Advertisement
Advertisement
Advertisement
TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology