Computing

The Root of the Problem

Sony BMG's disastrous use of rootkit software has taught us a valuable lesson: we're too trusting of commercial software.

  • Wednesday, December 7, 2005
  • By John Gartner

Sony BMG Music Entertainment's decision to include covert and potentially dangerous software on millions of its compact discs taught us two painfully important lessons: that people have placed too much faith in the safety of commercially distributed software and that the tools for protecting computers from malicious "rootkit" applications have been inadequate.

As the music and movie industries continue to put legal pressure on file-trading networks such as Kazaa and individual violaters, Sony BMG Music Entertainment made the decision to try to thwart file-sharing at the head of the problem: on the CD. To do that, the company included a software program called the Extended Copy Protection (XCP), a digital rights management (DRM) application developed by First4Internet. Among other problems, it caused a security hole to open that enabled other virus writers to covertly install malicious applications. Unlike a virus that propagates exponentially from system to system, and quickly draws attention, such "rootkit" applications often fly under the radar.

Advertisement

Making matters worse, consumers are understandably much less wary of commercial software than files they download or that are included as e-mail attachments. So it's not surprising that the discovery of Sony's placement of software containing a security vulnerability was inadvertent.

Windows expert Mark Russinovich was one of millions of music fans who purchased a CD from a SonyBMG artist and listened to it on his computer -- never imagining he was opening up a gaping security hole on his PC. It was only months after Russinovich first listened to a Van Zant brothers CD that he realized the CD had damaged his computer.

"The problem is that software coming from an established company like Sony will always be trusted by the consumer," says Russinovich, "even if they had software that popped up a warning that a driver was being installed, most [people] would likely allow it."

Russinovich posted his discovery of the unwanted "rootkit" software on his blog, along with the explanation of how it outsmarted the existing antivirus and spyware software. Since then, Russinovich has completed a free utility that identifies rootkits. But he acknowledges on his website that there will never be a universal rootkit scanner.

Even computer security companies have been naïve, though, in not closely scrutinizing commercial software for code that opens security holes. "We had not looked at this particular technology before," says Vincent Weafer, senior director of Symantec Security Response. The XCP software is not a virus itself, he says, but rather opens security holes that can be exploited.

"[There is a] difference between malicious code, as opposed to technology that can be used for malicious purposes," Weafer says. But hackers were quick to jump on the security risk. Weafer says a virus that exploits the XCP vulnerability called "Backdoor.Ryknos" was identified by Symantec on November 10, and the company posted a removal tool.

And within two weeks, Symantec will be updating its antivirus products to identify rootkits.

However, the cat-and-mouse game played by security companies and virus writers had a twist this time: antivirus companies were slow to create utilities to remove the Sony software -- out of fear of violating the Digital Millennium Copyright Act, according to security expert Dan Kaminsky. He says creating new software to remove DRM software is a violation of the DMCA, forcing antivirus companies to create patches that eliminate the software's dangerous behavior, but do not remove it.

Print

Related Articles

Losing the Right to Tinker?

The new year could see new challenges to hardware reverse engineering.

Who Should Own Ideas?

The courts and legislatures should preserve copyright -- but carefully.

The People Own Ideas!

Do we want music, software, and books to be free -- or not? By Lawrence Lessig

Close Comments

To comment, please sign in or register

Forgot my password

Guest (Lilia Mallik)

  • 2261 Days Ago
  • 12/07/2005

Hello.  I think we may need legal reform.

We might need legal tort reform.  Businesses and companies should have more of their resources freed up for consumers, employees, and investors.  I do not think that lawyers should be attacking legitimate businesses that are not breaking the law, hurting other people, or doing significant harm to society.

Thank you.

 

Reply

Guest (Scott)

  • 2261 Days Ago
  • 12/07/2005

sony, No Balony

Or better still, All sony all BULLSH*T

I quit purchasing sony products years ago because of POOR quality, HIGH prices for the name, which BTW does not deserve to be reconized as a proper name, so no capital S in their name and now trying to watch everyones movements on the web in th name of the DRM.
I personally hope sony gets sued into the ground and the name of sony will be used in past tense.

And maybe sony officials should learn some old ways and do a little Seppuku. Just in the way of honer, which they seem not to have any of.

Reply

Guest (Ed Weir)

  • 2254 Days Ago
  • 12/14/2005

Root Kit

Didnt one of the recent acts of U.S. software legislation make it a felony to load destructive software on someone elses computer ?

Reply

Guest (Lilia Mallik)

  • 2261 Days Ago
  • 12/07/2005

Hello.  I think we may need legal reform.

We might need legal tort reform.  Businesses and companies should have more of their resources freed up for consumers, employees, and investors.  I do not think that lawyers should be attacking legitimate businesses that are not breaking the law, hurting other people, or doing significant harm to society.

Thank you.

 

Reply

Guest (Scott)

  • 2261 Days Ago
  • 12/07/2005

sony, No Balony

Or better still, All sony all BULLSH*T

I quit purchasing sony products years ago because of POOR quality, HIGH prices for the name, which BTW does not deserve to be reconized as a proper name, so no capital S in their name and now trying to watch everyones movements on the web in th name of the DRM.
I personally hope sony gets sued into the ground and the name of sony will be used in past tense.

And maybe sony officials should learn some old ways and do a little Seppuku. Just in the way of honer, which they seem not to have any of.

Reply

Guest (Ed Weir)

  • 2254 Days Ago
  • 12/14/2005

Root Kit

Didnt one of the recent acts of U.S. software legislation make it a felony to load destructive software on someone elses computer ?

Reply

Advertisement

MAGAZINE

Can We Build Tomorrow's Breakthroughs?

Manufacturing in the United States is in trouble. That's bad news not just for the country's economy but for the future of innovation.

Sponsored Content

Technologies from National Instruments

Adding Data Logging
Log measured data to a file and open it in Microsoft Excel

> Click here for more National Instruments Videos <
Whitepaper

Temperature Measurements with Thermocouples: How-To Guide

This document is part of the “How-To Guide for Most Common Measurements” centralized resource portal. This tutorial provides a detailed guide for measurement and device considerations to take temperature measurements using thermocouples. Get an introduction to thermocouples, which are inexpensive sensing devices widely used with PC-based data acquisition systems. Also review some specific thermocouple examples and learn how thermocouples work and ways to integrate them into a data acquisition measurement system.

View full PDF > Listen to story >
Find us on Youtube

Videos

A Robot Recruit that Can Do It All

More

Advertisement

Technology Review Lists

TR50

Our list of the 50 most innovative companies, including the following:

IBM

Suntech

Netflix

Crowdcast

More

Advertisement

Facebook

Advertisement