Sony to Help Remove its DRM Rootkit
By Nate Mook | Published November 2, 2005, 4:04 PM
When Mark Russinovich was testing his company's security software last week, he came across a disturbing find: a Sony BMG CD he purchased from Amazon had secretly installed DRM software on his PC and used "rootkit" cloaking methods to hide it. With the story sweeping across the Net, Sony is attempting to clean up its mess.
DRM, or digital rights management, is nothing new to CDs. Record companies began employing software to prevent users from easily transferring tracks to a PC after the explosion of file sharing activity that followed Napster's debut in 1999. But for the most part, the DRM was quite rudimentary and only required the pressing of the "shift" key to bypass.
Not so with Sony's latest batch of CDs from Switchfoot, Van Zant and others. Using technology developed by British software company First 4 Internet, the CDs limit the number of copy-protected backups that can be made. To enforce the restriction, software and drivers are installed without a user's knowledge when the CD is accessed.
Russinovich first discovered a hidden directory and several hidden device drivers -- none of which would show up in Windows Explorer. He soon found the driver responsible for the cloaking, which was designed to hide every file and location that begins with: $sys$.
After tracing the rogue software back to his recently purchased Van Zant CD, Russinovich attempted to uninstall the DRM, but to no avail.
"I didn't find any reference to it in the Control Panel's Add or Remove Programs list, nor did I find any uninstall utility or directions on the CD or on First 4 Internet's site. I checked the EULA and saw no mention of the fact that I was agreeing to have software put on my system that I couldn't uninstall," he wrote on his company's blog. "Now I was mad."
When he forcibly removed the software and registry entries by hand, Russinovich found his CD player was no longer functional. Further advanced registry hacking fixed the problem, but he noted that the vast majority of computer users would simply "cripple their computer" if they tried to delete the First 4 Internet DRM.
Although cloaking files and not providing a method of removal is not dangerous in and of itself, the case sparked a flurry of discussion online. Most users agreed that the actions of Sony and First 4 Internet questionable at best, and security experts warned of potential threats. For example, a virus writer could simply hide files by naming them using the $sys$ prefix.
For its part, First 4 Internet claimed the technology was only found on CDs from earlier this year and said it had created new methods to hide the DRM. Nonetheless, the company has decided to issue a patch to eliminate the cloaking and "allay any unnecessary concerns."
The patch will be made available for download from Sony BMG's Web site, with another offered directly to antivirus vendors. The DRM software will not be removed, however, only uncovered; that means users will still be unable to delete it without risk of rendering their CD drive inoperable.
Customers must contact Sony BMG support for removal instructions.
"While I believe in the media industry's right to use copy protection mechanisms to prevent illegal copying, I don't think that we've found the right balance of fair use and copy protection, yet," said Russinovich. "This is a clear case of Sony taking DRM too far."
OKAY!, OKAY!, OKAY! they're fixing the problem!! so what!!?! if I'm not wrong this is something a bit familiar with "The Blue Screen of Death" and yet still... ALL OF YOU including me are still using MICROSOFT products...sorry it just sounds a bit like hypocricy to me...reading some of these comments.
Score: 0
|I removed the program by hand, my DVD/CD drive became inoperable - I thought it died, replaced it, but now have an extra, perhaps operable DVD drive? Now I am steamed - hopefully Sony can correct this.
Score: 0
|The true pirates find a way to get around the DRM and average people who buy music will be adversely affected. DRM is bad any way you look at it.
Rufus J, SystemDisc Linux CDs shop.
Score: 0
|This is yet another example of the music (& now vidio) industry taking things too far. For the past three years we couldn't purchase any CD's or even DVD's and with the current industry attitude, it is very unlikly that we will resume purchasing any of their products now that I'm working again either!
Is it any wonder that CD sales have dropped off so dramatically? With the music industry taking their key future customers to court over the sharing of a few songs that don't even have the sound quality of a full CD, they are basically killing off their future customer base.
And the recent nows that the video industry is up to the same tricks is going to cause sales of DVD's to fall off nearly as dramatcially as CD sales have fallen!
Eric & Genieve
Score: 0
|Just incase many of you aren't thinking about this yet, but I'll bet there many other music/companies/lables are employing the same tactic. It's totally dishonest of them.
Although it's a rare occasion for me to insert someones cd/dvd in my computer, now it went to a 100% HALT. I'll never use anyones cd's anymore, especially if they're not computer/security saavy.
I suspect EVERY disc will have some type of protection on it afterwhile, and the cd/dvd buying software will quickly come to a stop, or at least they'll divert their methods.
To be honest with you, the safest cd's & dvd's you can get hold of are the ones you download. They have been stripped of their deceitfulness.
And speaking of deceitfulness, have anyone ever noticed this:
When we buy dvd's we are "paying" for the production cast/crews "MISTAKES" they cramm all that extra crap onto the dvd's and then they charge us for it. I don't care how they made the movie. I don't care that they forgot their script. I just want the move.. no more, no less. Are these companies willing to make versions of their movies without all that crap? and charge less?
A classic case of deceitfulness by the entertainment industry:
you go to the movies and you see a movie, then when the movie comes out on DVD, it's NOT what you went and seen in the theatre. My complaint would be of the movie "Eraser" with Arnold Swartssennager & Vaness Williams. At the end of the movie (IN THE THEATRES) the "soundtrack "Erase" by Vanessa Williams was played. On the radio it was said that you will NOT get that song ANYWHERE, because it wasn't packaged anywhere. It was also said the "soundtrack" is not in stores and it won't be.
Nevertheless, I bought the VHS copy of it, JUST for the soundtrack at the end. Well, fast forwarding to the end, where the credits are shown, there was not even a 10 second piece of the song at all. It was in the movies with it, but not on my PAID version. Was I deceived? Well, I did download the song, (I wanted what I paid for) and I still have it. They cheated me, so I took action.
Why are we being deceived & having to pay for versions of a movie that we didn't ask for?
Theatre Version = Maybe You'll Get One
Director's Version = Was that the one in the theatres?
Special Edition Version = What's so special about it? I would need to compare it to the "CAM" shot taken from the theatre.
and all the other versions. Why aren't we getting exactly what we pay for from the entertainment industry?
Do they tell us we have an option to buy what we saw before? nope. They think they know perception of viewers, and that is... "About time this comes out, they won't remember all that they saw in the movies months ago." That wouldn't be a bad idea,,,, a central "CAM" station where you can comapare your bought movie from the one that was shown in theatres.
If these companies took away all of their sneaky practices, lowered their prices and remained honest to "buyers/supporters", and get rid of the RIAA and other organizations, and just simply put a "Please Donate" for their works/causes, I'm sure they would surpass their expected "profit margin"
One Man's Opinion
Score: 0
|What Sony did by unauthorized access cloaking software without your knowlege would be considered a felony if a private citizen had tried this. How does Sony legally escape legal jeopardy?
Score: 0
|This is how it begins:
http://www.theregister.c.../11/04/secfocus_wow_bot/
Score: 0
|And all this damage is done only to the real buyers, I mean, those that have the legal CD and had to pay for it, are the ones get hurt with this.
Score: 0
|stop stop stop-- beware beware beware
Sony did this thinking no one would ever find out or at least it would be a secret for a long
time. With that in mind ask yourselves this,Would Sony put more "malware" on their website
for you to download along with the supposed removal tool for the rootkit? I would not even
log into their website as downloading any fix requires you to accept the file and who knows
what they will do next? Add malware to a root fix? They have shown us they
are not to be trusted. Who is next and what devious method will be used next time? Sony
should have been straight up and put a warning on the jewel case stating that using the disc
in a computer would automatically install drm software on your computer. At least users would
have been able to make an informed desicion as to whether or not to purchase the disc. They
did not offer the consumer a choice because knowing the software would be automatically
installed on computers would have alerted people to use some other method to copy the
disc if they so chooose. Sony has shown they are
not to be trusted! I will not purchase another sony product as a result of their actions. I use
my analog gear and it works well.
By the way Betamax was the superior format but cheap consumers opted for a cassette shell that
held an extra hour or so of recording time for the same price. You get what you pay for!
I don't promote stealing and I don't promote any body putting software on my computer without my
permission. It seems the only real fix is to reformat your hard drive and start over. When
you are done send Sony an invoice for the cost of the repairs to your system. Give Sony 45-60
days to pay and send them a second or third notice. If Sony fails to pay the invoice (keep
copies of everything)take them to small claims court in your local jurisdiction. When you win
do everything to collect the debt. Sony will get the message in their pocketbook when they have
to defend hundreds of lawsuits. Maybe they won't be so underhanded next time. Ed.
Score: 0
|can anyone post the removal directions or a direct link to their patch? at sony's web, one must submit a form verifying proof of purchase, i guess. i'd like to learn the uninstall process even though i haven't crippled any of my boxes with this p.o.s. DRM. from sony's web:
"Uninstalling the Software
How do I uninstall the software?
If at some point you wish to remove the software from your machine simply contact customer service through this _link_[http://cp.sonybmg.com/xcp/english/form14.html]. The only safe and proper way to uninstall the components is to follow these instructions exactly. You will, though, be unable to use the disc on your computer once you uninstall the components."
Score: 0
|Wait wait wait...
Don't get into a big hurry to remove that root kit! Well not until you have leveled up a bit.
;)
http://www.theregister.c.../11/04/secfocus_wow_bot/
Score: 0
|best reason yet to NOT buy sony products.
Score: 0
|Sony's DRM should be handled like any other virus,that is all it is. I plan to stay away from all Sony products. It is the only voice
consumers have left,even government represents
big money today, not the people.Buy the way, we do have laws to handle virus creators. I believe Sony and First 4 qualify. Also don't forget you only get this DRM virus if you buy it!
Score: 0
|It didn't take the bad guys long to figure out a new use for the Sony rootkit. I imagine that it will spread by people passing along a game cheat disk with this added.
http://www.theregister.c.../11/04/secfocus_wow_bot/
Score: 0
|Has anybody out there actually read this article? It appears not even the headline writer did when he wrote: "Sony to Help Remove its DRM Rootkit." Yet at the end of the article it says: "The DRM software will not be removed, however, only uncovered; that means users will still be unable to delete it without risk of rendering their CD drive inoperable." This is not a useable patch nor does it remove anything people! Their actions are outrageous; I NEVER go back to companies who have done me wrong unless they can step up and admit an honest mistake (we all make them) and do what's necessary to make it right. I'm a retired IBM Systems Engineer. IBM wasn't immune to screwups but they would stand on their head (sometimes mine) to make it right. This was a very dishonest mistake by sony and they're only digging in deeper. They're on my personal boycott list forever.
Score: 0
|i agree, the reason they don't make a patch that actually removes it is quite obvious, they want it to stay on your system.... and really many of the common users barely knows the difference between mouse button functions let alone how to remove drivers even when they are un-rootkitted. Sony knows what they are doing, and they don't care. And they will never care until they get slapped with some major class action suit. Otherwise, they are laughing in our face.
Score: 0
|Why does everyone avoid the real issue: it's MY hard-drive. I should have the right to have a line item veto on everything submitted to it. Maybe I'll start charging fees for cookies, malware, and spyware.
Score: 0
|Oh. Also.
I can't wait for the day Sony goes into software.
Sony Antispy!
Sony Security Center!
For all those pesky viruses you pick up, and those damn trojans.
Lol, under the detection I could so see them identifying their rootkit as some microsoft spying technique, or evern better, wal mart. Yes:
Wal-Mart is spying on you, get your Sony Antispy Today! We love our consumers *cackle*
Damn you.
Score: 0
|They have gone into software. It sucks, and it's usually contracted out to the lowest bidder.
About the only thing Sony is *really* good at is user interface design for their hardware.
Score: 0
|Wow, i can't wait til the day Sony prints books.
*prick*
*boys finger bleeds from a small needle found hidden in the cover of his book*
*boy reads in fine print at top of book cover*
"By opening this book you accept the terms of service by which Sony International press claims all rights to your bodily functions. You may not read said book without consent of Sony Intl. Press, and you may not speak of reading said book without prior consent. You may also not urinate, just because we said so."
Score: 0
|I haven't bought a CD is 5 years and don't plan on buying any in the future for this very reason. Thanks Sony for reminding me why. And also, giving me reason to not buy Sony products of any kind.
Score: 0
|No. The reason you don't buy CDs is because you are greedy. This case just adds to your screwed up excuse for a logical justification of it.
Score: 0
|well we really must learn to excuse people's ignorance wincement. All i know is I would rather buy a cd than this garbage they sell online at Itunes and the like. They don't have a quality product because the sound quality is drgraded because of the compression.
Score: 0
|Yup. That's why I still buy CDs too. And since I've had autorun disabled forever, this isn't a threat to me, fortunately.
Score: 0
|I still keep a copy on my computer mind you, just bought one today for that matter so I decided to try out the WMA Lossless in WMP. The cd take up 304 megs (doesn't really matter when you have a 250GB hdd I guess) on my harddrive but i've never heard a better sounding encoded file.
Score: 0
|I Havent bought a music cd in 10 years, i listen to the radio in my car if i want to hear anything. besides there hasent been a good song made since the 60's anyways i could care less about all the groups and artists that have come out since then.
Score: 0
|Who Buys cds anymore? You buy a cd and you get one or two songs you like, one or two that more that you can stand to listen to and the rest are a waste of disc space. Better to purchase the one or two songs you like on line and save the money that you pay for the unwanted songs. As for bypassing drm on these sony cds, attach your stereo to your sound card and record the cd. There are several great programs for editing and burning the tracks. I use roxio for recording cassettes and burning them to cd. I works great for them and I imagine would work for cds also.
Score: 0
|Sony and First 4 Internet should be sued for this without hesitation. These companies cannot be allowed to violate consumer rights by installing and hiding potentially harmful software on consumer PCs without consumer consent. First 4 Internet supplied a patch to unhide the files from Windows but does not remove it. What a joke! Are they technically incompetent or just arrogantly ignorant? They should be forced to fix their mess by Sony or be made to pay the price. Plus, I checked out the patch for this...it is over 3M in size. Do they really need 3M worth of code to unhide these files? More ridiculous mayhem!!!
Score: 0
|Called Japan today and the hold music was from the Mario brothers game lol. I was trying to voice a complaint and they had no idea what to do.
EDIT: Nov 04 01:48 +81354483533 €0.019 07:37 €0.152
Score: 0
|Oh yeah...this is going to make you buy fewer CDs and is going to encourage you to download more. Bullsh*t, if you download now, you'll continue, you don't need a reason, just a rationalization.
Sony has a right to protect their intellectual property, just not the way they did so. I have a real problem with the music industry and the RIAA and their heavy-handed ways. I hate their guts becaue they automatically treat everybody like a criminal.
But, CD or download, if you use their music, you should have to pay for it. I prefer CDs to downloads, because they are higher quality than MP3s and it is more convenient. I don't have to worry about a disk crash or using up 100 GB for MP3s.
Score: 0
|Now we know Sony BMG can write virus's. Maybe the MPAA writes the ones that attack P2P networks??
Score: 0
|What Sony has done is unforgivable!! I don't file swap yet my PC has been violated!! My son requested a PS3 for his next game system and I hate decline him but it will not be on his shopping list any longer. Also I was wondering which $3000.00 projection TV to buy Samsung or Sony. That choice just got easier.
Score: 0
|Sony and BMG Music are acting like a little kid who doesn't understand that having killed the kitty was a bad thing. I would suggest if anyone wants to vent their anger they should send a fax (Sony doesn't seem to be advanced enough to provide a contact e-mail address) to these guys.
Corporate Social & Environmental Affairs
Law & Compliance Division
Sony Corporation
6-7-35, Kita-Shinagawa
Shinagawa-ku, Tokyo 141-0001
TEL : +81-3-5448-3533
FAX : +81-3-5448-7838
Score: 0
|See http://news.bbc.co.uk/1/hi/technology/4400148.stm
In Europe this would be a breach of data protection
Score: 0
|what u have done is reprehensable. i believe sony is responsible for all financial costs and loss of computer security and privacy due to this action. your efforts in this have lowered my opinion of sony and its products.
Score: 0
|So, what are your financial costs? Did you detect a rootkit? Did it cause damage? Did it cost you to repair the damage or remove the rootkit? Just curious?
Score: 0
|I'm glad I didn't buy a PS2 now. Who knows what invisible bugs they installed in those, and now the PS3 will probably have some DRM software that refuses to play a music CD unless it has been enfused with their trojans. I wasn't going to buy a PS3, and I definitely won't buy one now, unless it comes with a mod-chip pre-installed and all DRM modifications removed completely. That darn thing better be able to play everything but a slice of bologna, else I won't be buying. The last Sony product I purchased was a Playstation 1, and it will probably be my last until all of their products are certified DRM and trojan free. I just hope they know that their profits are going to suffer greatly because of this.
Score: 0
|The last sony product I bought was a Walkman.
That was quite a while ago =)
Score: 0
|I can see it now. This has the distinctive odor of a class-action suit painted on it. In the end, the software will be resolved, the lawyers will get $1B dollars in fees and the plaintiffs will receive a $10 discount on their next purchase of $100 or more from Sony. God Bless America!!
Score: 0
|Normally, I disagree with the whole sue-a-company and get-rich-quick methodology. I think Sony deserve it in this case! A few lawsuits and they might think again and stop considering all CD buying customers pirates.
Score: 0
|LOL
Score: 0
|I think taking up my hard drive space that I pay for without asking me no matter how small the application is THEFT. Removing the application and fixing anything it breaks is again THEFT of my time and time is MONEY. As a PC tech I offten have to Format a drive to fully get a system back to its potential after things of this nature. Boycott Sony and all the rest of them that employ these tactics. And to think the guy PAID for the software...in more than one way it seems. The market needs to make companies feel it when they try to pull this behind our back sh!t.
Score: 0
|HD-DVD aaaaallll the waaaaaay ......
Score: 0
|Just the reason I haven't bought a CD in years. And while I may have tried P2P, I also haven't done that in a long time. I simply subscribe to emusic.com. Their music comes in non-DRM'd .mp3 format, and averages about $0.25 US per song. I don't hear much radio crap, but almost without fail, whenever I hear of a new band that is not so well known, they have it. Early Man, Jolie Holland, My Morning Jacket, Ladytron, etc. So I support digital format, but don't have nagging feelings of guilt that I am not supporting the artists either.
And please note, I am not an emusic.com shill. It simply happens to be the .mp3 service I selected. Mainly because it AIN'T DRM'd!
Score: 0
|Yeah, I prefer vinyl, myself...
Score: 0
|I was reading that the vinyl is the same as the cd's now. Yep, they've limited your "album" coping too.
Score: 0
|We need to start a class action lawsuit against Sony for crippling our computers and a boycott of Sony albums until they agree to remove this illegal software from their CD's.
We should also ask the DOJ to investigate Sony for violations of the Computer Fraud and Abuse Act as this likely constitutes a violation.
Score: 0
|I'm with you 100% on this. They have GOT to be crossing some lines with this.
Score: 0
|cripple?
Score: 0
|What we need is consumer protection LEGISLATURE to muzzle companies like Sony and prevent crap like this from happening in the first place.
Score: 0
|Maybe we should all go buy that CD and sue Sony for say $600,000 !!! that is a good number for one CD. But we don't have the legal team and have not purchased our congressmen. So you would not have a real chance in winning.
Score: 0
|Ah, and I be willing to bet they wonder why people like myself still prefer to just download it and make as many copies as I want. Makes me wonder what kind of stuff they have in my Vaio.
Score: 0
|Also stands to reason, why people like myself will buy les and less CDs and go the download route. Sick
Score: 0
|I don't know if this works or not, but if you are logged on to WinXP as a limited user (that is, without administrator rights) you can't install software, right?
Would that prevent the DRM software from being automatically installed? Antivirus companies tell us it is supposed to help protect us from trojans and that sort of thing.......
Score: 0
|That's an excellent point... didn't think of that. Can somebody try and see if it works? "unfortunately"* I don't have one of the new DRMed CDs from sony.
*Before I start getting abuse - that was sarcasm.
Score: 0
|The admin/root use for any OS should only be used for admin purposes. You shouldn't run in admin mode.
Score: 0
|While I agree I find it impossible to work as a Limited user in XP. I mean you can't do anything! If installers and the sorts at least asked for admin credentials for the install instead of just saying 'Contact an administrator to install this software' then maybe I could use that. In Linux I would agree with you, in XP there are too many drawbacks.
Score: 0
|Simple solution? Enable fast-user switching and use the admin account (no pwd) to install software.
As long as you are sure the system is safe from physical intrusion, leaving the admin pwd blank and only using the account for installs and such should leave you much better protected than running as admin 100% of the time.
Only problem is, this DRM installs when you put the disk in. If they branch to software with this stuff, then installing the program in any account will screw you.
Score: 0
|Try the right click and run as.
Score: 0
|Yeah - same stuff as with games installers that will install their stuff even if you'r not logged in as admin. So they will have a way around all this for sure.
Score: 0
|Thing is, Drivers MUST be installed as admin. Meaning, no admin, no cloaking, no DRM.
Also, some programs (most?) can be installed into My Documents
I agree that it clutters the My Documents folder, but it is a quick work around :)
Make sure your admin account in passworded, as i'm sure it's possible for virus makers (like Sony) to force it to run as a un-passwored admin user.
Score: 0
|Even limited users have some access to the registry and can install some software. Also, there are several ways to defeat the security system, which are used by spyware and other malware creators to install their crap without the knowledge or permission of the owner of the machine.
I wouldn't count on having a restricted user account preventing the software from loading.
Not putting a Sony CD in your computer will do the job. Not buying any Sony CD's will (eventually) be even more effective. This is why they didn't tell you the software was there in the first place, and wouldn't have if someone hadn't found it.
Score: 0
|well nice try, won't affect me at all since i only listen to old (paid for) cd's and new music in mp3 format which suits most of of us.
why spend oil and other crap pressing 11 tracks onto a cd that holds more. the case get, or is already scratched enough from the record store. i won't pay for that.
if i pay for something i use it as i please.
Score: 0
|Has anyone looked into the removal tool that sony provided? Apparently, the tool will remove the DRM software "You will, though, be unable to use the disc on your computer once you uninstall the components"
I wonder if this will go down the line of the previous generation of copy protection. Fair enough, it might remove the RootKit, but I wouldn't trust them not to install some other piece of software to prevent the CD's playback on your computer. I'd be very interested to find out if someone had taken apart that application too...
Score: 0
|And Again: The SONY tool does not remove the DRM Software itself, It just removes the Cloaking of the Software...for now
Score: 0
|Yeah, but if you use the contact form, they let you download a tool that removes the DRM software completely... apparently.
Score: 0
|It's odd, but the question seems to come down to whether media can be put in a duplicative form with a protection scheme. Well, the simple answer to me is that the protection schema has to be at the option of a user. If a studio sells its media on a digital format, it waives its rights to assume that you may not use the media digitally. In other words, if you dub a tape onto a CD and distribute it, that's bad. But if a studio sells you a digital copy of a song, they no longer have a right to tell you what to do with the bits. They can only tell you that it is illegal to distribute it. OK, so the RIAA goes after P2P, and it irks people, but it's a separate argument. If the analogy were to cars, a cassette tape is an old Pinto. Drive it around all you want on the roads, and hope it doesn't burst into flames. Buy a CD, and you have a Porsche. A Porsche is fast, so therefore, we need to add speedbumps on the roads a Porsche will use. That way, it won't speed. No need for the Pinto, however, since it can't really get that fast.
Uh uh. Distribute digitally, and you take your chances. If you don't like it, start distributing on cassette again.
Score: 0
|Sony's Blu-Ray copy protection can render a set top Blu-Ray player (and for all I know a computer Blu-Ray burner) inoperable if you attempt to circumvent the copy protection in any way.
Score: 0
|Does any one know whether or not this thing sends anything "interesting" back to sony's server? I won't be surprised if it really does.
Score: 0
|that is a violation of european law better better bring it to their attention ,
Score: 0
|ok it's illegal to spam people or install spyware with out your permission. Computer Virri are illegal. Sony can install malware on my compter and it's ay ok............ can any one say "Does Not Compute"
Score: 0
|You're right, it's illegal to spam people, illegal to install spyware, illegal to distribute viruses. Why aren't most of these people caught? They're not traceable.
Sony, on the other hand...
Sony Corporation
6-7-35, Kita-Shinagawa
Shinagawa-ku, Tokyo 141-0001
Score: 0
|Well that's my point. When a corporation like this does it, it's tracable yet nothing is done about it.
Score: 0
|I called Song/BMG and told them I would not be buying any more of their CDs or any other Sony products until they remove these types of intrusive and potentially damaging routines. I explained that there are lots of other manufacturers and products out there just as good. I hope enough people do the same to have an impact.
Score: 0
|Arrgh, Sony or MS, Blu-ray or HD-DVD, PS3 or XBox360?
....Windows or Mac?
My list of companies to ban is slowly growing...I think I'll start learning about Gentoo.
Score: 0
|Ubuntu, man. :P
j/k
Score: 0
|Mandriva, or Suse ...
(... he says, knowing he has FC-1 install waiting on the bench at the part-time gig. GACK!!!)
Score: 0
|yeah - and if you care about your freedom, nature and your fellow human beings' in the 3rd world being abused as working force for 30 Cents an hour - your list would grow so big that you'd end up by asking yourself: Gosh! Where am I going to buy anything now?!
Score: 0
|Score: 0
|I WAS waiting for the blue ray burner to come out.... Guess they cut my wait time down...and out... no-blue ray ---no day----no way--- it's user friendly ;-)
Score: 0
|Agreed- seeing this smoking gun is enough to kill any interest any knowledgeable user would have in Sony's blu-ray. I'm sure it will prove to be just as consumer unfriendly as everyone says it is. Just like Beta vs VHS, their own greed will destroy them.
Score: 0
|Who the hell is Switchfoot?
Score: 0
|Switchfoot is a music group. Unfortunately, it's their CD that has made this "rootkit" malware news. One of the members was also "blasted" for listing out a method of "by-passing" this DRM.
THIS WILL NOT BE THE LAST WE HEAR OF THESE TYPE OF DIRTY TRICKS!!!!!!!!
Score: 0
|WoW....funny to see everyone sooo mad at song for protecting their assets.
Why isn't anyone mad at the 14 yr old nerd that sent you an IM with a link to watch 2 girls showering together, only to find out you have the latest backdoor hidden by a rootkit and all your passwords have been sent to his email and your network is now a spam sending machine.
Sony's intent wasn't to leave a hole for hackers to take advantage of, it was to trust a 3rd party to protect the music and keep people from abusing it.
Do I blame Sony? No, they trusted someone to protect it for them...First 4 Internet, they screwed up, if someone moves away from them, they are good in my book, if they stay with First 4 Internet for protection, it's another story.
Score: 0
|Sony's intent WAS to to "create a hole for hackers to take advantage of" THEIR own personal hackers.
What they did was illegal. A violation of trust.
If I'd been dumb enough to be infected by something from some 14 year old nerd I would be pissed at him. It wasn't some little dweeb though. It was SONY.
Score: 0
|I can't believe anyone would even defend Sony over this BS. Jeez.
Nothing like companies ripping off paying customers, and taking control over their computer. I'm really getting dang sick of all the companies that rip us off, yet a few people seem to think thats just fine. Its called stealing from customers.
Score: 0
|i like to watch 2 girls shower together...
Score: 0
|Nope you couldn't be any more wrong...If a kid buys a gun and shoots someone with it...do you blame the kid or the guy that sold him the gun?
Believe me, sony KNEW what was being done, they didn't "trust" this company blindly...the company produced the DRM, sony liked what they heard, and went with it. It's 100% their fault. There were all kinds of presentations and technical notes on exactly what's being done to sony's CD's and Sony knows every little detail of it, I don't understand how you say it's not their fault...makes no sense.
I'm not at the 14yeard old nerd that send me an IM with a virus...he's not a responsible business that 'should' be trusted and I'm not legitimitly buying something from him. Sony on the otherhand, a giant business who is suddenly installing what I'd consider a virus on my computer without me knowing, using music I purchased from them?? Now that's BS...and people have every right to be mad.
Score: 0
|yes its there fault...they paid for the 3rd party product that they put on there CD and sold. Why hide it if you think its OK. Not that lame DRMs will ever stop anyone with any real ability. Sony needs to take responsibility for there product.. If they purchased the software and put it on there CD makes them responsible....abuse is steeling my hard drive space that I PAY for without asking me. Im PROTECTING MY ASSETS. Consumer First, make them understand where the money is coming from....
Score: 0
|Mainly because if someone sends me a link to some pornographic stuff or anything else - I do have the choice as to whether to perform the risky action or not. In this case the crime was perpetrated with full knowledge by a corporate entity as to what they were doing.
I agree that they have the right to LAWFULLY restrict fair rights usage of their media. However the end does not justify the means.
I will be amused, though as I watch the parade of attorneys that will be marching to feed at the trough of a tried and true pigopolist.
*sigh* - I chose the wrong profession. No picking corporate pockets in the guise of assisting those wronged for me. But as I stated earlier, when this is played out, it will be most interesting to note where the real money goes. Lawyers Win! Lawyers Win! and the plaintiffs get a 10% off their next purchase of $300 or more from Sony - woo hoo.
Score: 0
|You say this like Sony is some naive grandma. Sony has plenty of engineers that could have audited this before it went to production.
Score: 0
|In Chicago, they sue the gun manufacturer.
Score: 0
|jeez...public school education these days just ain't what it used to be.
Been abducted lately?
Score: 0
|abducted? Public school is the place to be molested these days.
It's in the news EVERY DAY.
Score: 0
|"For god sake someone somewhere give Russinovich a medal for showing the world what Sony is really like."
Amen. Hopefully someone can give him some sort of award.
Score: 0
|Really, a big honest thanks going out to him.
Score: 0
|His reward will be a lawsuit charging him with a DMCA violation!
There are a couple of Congresscritters out there who probably want to give *Sony* the medal for what they've done. It doesn't destroy your computer, but at least it FUBARs your CD-ROM, and that's a start, right?
Score: 0
|After MiniDisc, BetaMax, and several other stupid moves, you'd think they'd get a clue and just start making QUALITY stuff for the consumer. Sony had such a good name for quality at one time. Now all I can ever think of is that Sony is anti-customer. This just reinforces that belief yet again.
I had a trinitron, I had a minidisc player, and I will not buy Sony anything again on purpose until they state publicly that they are reversing course and becoming customer friendly again. Admit you are wrong, Sony. We all deperately want to like you, since most often your hardware is pretty good!
Damn shame.
Score: 0
|You really need to investigate before you post something stupid like BetaMax not being 'QUALITY'.
Of course with BetaMax being so low in 'QUALITY', it's obviously the reason why almost all TV news departments used it.....get your facts right, VHS is/was inferior to BetaMax.
Marketing killed Beta, that's all. The people who ran the video rental stores at the time also co-invented VHS, (JVC IIRC).
Sony's problem in this case is their complete arrogance to their customers with regard to music/video - their technical/electronic equipment is still among the best around.
Score: 0
|In the end it's what people use and what people want. Nobody wanted to use Beta, but Sony pushed it on the television studios and the like and it still died. Everything is digital now so none of that matters anymore.
Score: 0
|"...Nobody wanted to use Beta...none of that matters anymore."
Please don't post uninformed pseudo-analysis like this - it just further promotes myths and muddies the 'discussion'.
I realize that this sh*t went down twenty-something years ago [ancient history to many], but the prior post had it right:
Sony's Beta format was technologically superior but was 'out-marketed' by the VHS manufacturers, who sold inferior machines at lower prices.
B/c many ppl couldn't see / hear the difference [or didn't care], VHS 'won'.
"If you don't learn the lessons of history, you repeat them."
Score: 0
|For god sake someone somewhere give Russinovich a medal for showing the world what Sony is really like. So Sony is helping him remove their crapware. Sony should be doing the same for everyone else whose equipment they have done up.
The music rights issue has just dipped to a new low. Sony is more arrogant than I ever imagined, in thinking that it had the right to screw around with people's PCs in this underhand way.
I pay plenty of money for my PCs, and I go to great efforts to keep viruses, spyware and other crap off them. I don't share music and I don't like being treated like a criminal. Sony can forget me as a repeat customer. I just levered off the Sony badge on my TV. Right now I don't wanna even see that sorry arsed name in my house.
Score: 0
|As a long time proponent of Sony products, that changed when I read this.
On a personal level: This has stopped me from buying any CD that is released under Sony/BMG permanently. I was already teetering on the edge due to these issues anyway. It has also caused me to close my wallet to any Sony electronics purchases. When you look at my entertainment center you will see a Sony TV, Stereo system, PS1 and a PS2. I was planning on buying a PSP in the next 3-4 weeks, and I already have the money set aside for a PS3. Guess what....not now.
On a business level: We have long used/sold Trinitron Monitors for high end systems, DVD-RW and DVD/CDRW Combo drives. On average we spend about $20-40k yearly on Sony products. As of the release of this information, We cancelled an order of products and replaced them with Sony competitor products. When our current stock of Sony products run out, we will not order more.
Reason? This is taking DRM SOOOOOOOO far beyond what would be acceptable that it's laughable that they even THOUGHT they wouldn't get caught sooner or later. The security concerns alone warrant lawsuits gallore. I have a reputation to uphold with my customers and clients to offer only the best products for their money that WON'T screw up their systems. I simply can't trust Sony any longer.
Score: 0
|Switchfoot is a Christian Rock band which openly objects to SONY BMG using DRM on their CDs. FYI.
Forget DRM. Why does this fascist company sell millions of blank CDs, DVDs and the hardware to burn illegal copies of copyrighted material. Their new Dual Layer DVD burner is made for your bootleg collection of Hollywood movies.
SONY's hypocrisy speaks for itself! Will a corrupt US Congress demand answers to this double dealing and self-righteous b****ing about kids downloading music?
Score: 0
|Sony's crap manufacturing processes create many sub-par products. My uncle had a portable harddrive with 20 years of data on it. It melted roughly a year after purchase, and now all that data is gone. To recover it he'd have to send it to the opposite side of the continent to get specialists to "Attempt to recover the data.", for a measly cost of several thousand dollars.
Moral: Buying a Sony product costs you $10,000.
It's gonna take a hell of a lot of CD's to make up for that...
Score: 0
|very well said
Score: 0
|Umm... no offense, but that's what backups are for. Hard-drives fail. That's a fact. If the information was that important, appropriate precautions should have been taken.
Score: 0
|The correct moral should be: Backup your stuff.
Sorry, that's your uncle's own fault. If data is important, you back it up. As much as I may not like what Sony is doing here, you cannot blame that event on anyone other than your uncle.
Score: 0
|I've lost 3 harddrives in the last couple years, including the harddrive in the laptop I use every day. But I never lost a byte of important data.
Why are you blaming Sony for your uncle's failure to use common sense with his data?
Score: 0
|There are sooo many other uses for burners and blank media.
Open your eyes.
I disapprove of Sony's methods here, but making blank media and burners doesn't mean they cater to pirates.
Backups alone make the tech marketable and legit.
Score: 0
|Yeah, but he didn't really feel like buying 20 DVD's just to back stuff up when the HD was guarenteed to last years.
I've got the following HD's: (not all in the same comp)
6GB Fuji (was top of the line when I got it)
10GB Fuji
20GB Western Digital
120GB Seagate IDE 2mb Cache
120GB Seagate SATA 8mb Cache w/ NCQ
I've never had a harddrive die before. The only thing that died was our Sony TV, and some faulty sony memory which took a mobo with it.(it flaked - what the hell?) He's still got a Hitachi TV from 1980, and it looks better than every non-high-def TV I've seen. I guess he's just from the era where they made quality stuff. He's got one of those weird old mixing machines from 60 years ago, and it still works fine unlike all the mixers our house goes through.
Score: 0
|That was the backup.
So the correct moral should be: Backup your stuff...twice...or not on a Sony.
Score: 0
|Common sense is buying Raid 0+1 so you never lose anything. Most of us don't want to or can't spend $600 on harddrives though.
Score: 0
|Wrong again. RAID is NOT a replacement for backups. In addition to data, mirroring also mirrors file system errors and corruption as well.
Score: 0
|right on...back up your data...maroon...
Score: 0
|ARE YOU STUPID? I said that record companies, which belong to the RIAA/MPAA mafia; have no business selling hardware or blank media that can be used by thieves. What else you do with them is your business!
HYPOCRTITES have no right to complain any more. I know somebody, who rents NETFLIX and makes bootlegs with their SONY D/L DVD burner. The new Rolling Stones album is on the P2P networks; but VIRGIN Records doesn't sell blank discs or CD burners; so we can make illegal copies. Big difference...
Score: 0
|All I use my CD/DVD burners and media for are burning backup data discs and Linux distros.
Try thinking a little harder before you call others stupid.
Score: 0
|"but he didn't feel like..."
Again, I'm sorry, but that's not Sony's fault. I don't care how much of a 'guarantee' a hard drive has. It will fail. Backups are a _must_.
Score: 0
|And now he knows, but I think I explained why he thought that way quite well.
Score: 0
|"Although cloaking files and not providing a method of removal is not dangerous in and of itself, the case sparked a flurry of discussion online."
What the hell Nate? It is VERY dangerous if only because of the precedent it sets.
What's the deal with BetaNews waiting to write this story until Sony said they'll fix it anyways? Something fishy's going on.
Score: 0
|Last straw. I'm done with Sony, in all it's shapes and forms, for good. I'll avoid their movies/music now, also, or find ways of watching them without payment.
Score: 0
|2 wrongs don't make a right....
Score: 0
|The RIAA: Working for YOU!
Oh wait...
Score: 0
|ahh linux never felt so good :)
Score: 0
|True enough right now.
Score: 0
|HowTo: If CDROM drive functionality goes away after manually removing the software, follow the same steps in this MS KB article: http://support.microsoft...px?scid=kb;en-us;270008
Works in many other cases for if device manager has a bang on the cdrom drives too, the Roxio example included.
Score: 0
|Sorry, double posted. Time to get rid of Opera.
Score: 0
|ROFLMAO!!!
Score: 0
|Awesome HAHA
Score: 0
|Amen!
Score: 0
|So by this Sony want to show us that buying CDs is dangerous and can damager your system? Well that should certainly help improve sales.
Stupid corporate monkeys.
Score: 0
|NO, it does not use ActiveX to install. You are referring to the built-in "Player" that they force you to use for the DRM side of things. It installs by use of the AUTORUN feature. If you turn it off, it will not install the rootkit. Then you just need to use a program to rip the audio from the CD to MP3/OGG/etc... and playback those files. Read his Blog for the 'full' details.
Score: 0
|That's awesome! Autorun has been disabled on my system for a while!
Score: 0
|Forgive my ignorance, but how does one go about disabling the Autorun feature on a computer?
Score: 0
|I'm not sure what the policy is on links in BetaNews comments. There's a tutorial on how to disable it here though: (It requires editing the registry though so be careful)
http://features.engadget.../entry/3239236478279892/
If that link doesn't work then just search Google for: disable autorun
Score: 0
|... or one could just turn it off using TweakUI from Microsoft :-)
Score: 0
|Holding down s*** should temporarily disable it when you put the CD in... according to the article, that shouldn't work. But if it's an autorun problem, the s*** key trick is a Windows feature, not CD dependant.
Anyway, as long as you don't hit the "I Accept" button, you should be able to use your own ripping program to get the music off the CD, then just eject it and don't put it anywhere near your computer after that.
Score: 0
|...or just use a linux box to rip it.
Score: 0
|gpedit.msc
Computer Configuration - Administrative Templates - System - Turn off Autoplay
Enable that for all drives.
BAM!
Score: 0
|So..to disable autoplay in Windows:
Repartition HD.
Install Linux.
Locate and install GUI ripping/burning tools.
Install them.
Rip CD.
Burn New CD.
Reboot.
Hope to God it works.
Hmmm...
I think I'll stick with Gpedit, but thanks. :P
(Yes, I know you were joking, so am I)
Score: 0
|I wasn't really joking.
I have another box here running Kubuntu. I could just rip the CD on that box, and transfer the files to my Windows machine (if I wanted to).
But yeah... I've had autorun disabled for a long time. I've tweaked a million things with gpedit lol.
Score: 0
|That doesn't disable it - the CD is still read and executed to determine what type it is.
Score: 0
|It uses ActiveX to install? Hurrah! IE is totally gone from my system, which broke lots, but apparently may leave me protected? :P
Score: 0
|The ONLY reason I still have IE on mine, is that UO needs it to patch.
EDIT: Oh, and betaplace needs it for some beta tests.
Score: 0
|LOL! like we should trust this "patch" from Sony BMG's Web site!!! The DRM software will not be removed, just uncloaked, for all we know it may install the new improved unclocked DRM software if you don't already have it. Anyway no more buying CD's for me!!
Score: 0
|I'm not buying CDs ever until these DRMs are removed. Till then, I will use P2P networks.
When they are removed, I will spend the money I have saved on the CD.
Score: 0
|People actually buy CDs still? Never, ever buy a modern CD folks — it's a trojan horse.
Score: 0
|To add insult to injury, you can only get the software if you're using IE because it relies on ActiveX to install.
Score: 0
|"To add insult to injury, you can only get the software if you're using IE because it relies on ActiveX to install."
Did you read the blog? It's the darn player software that uses that activeX control, not the DRM.
Score: 0
|He was likely referring to the removal procedure, which, yes, requires an ActiveX control to be downloaded and installed.
Score: 0
|Cool.
This is now a reason for me to only download music illegally. They are shooting their own feet off with this crap.
All this crap is so funny to me anymore. I just won't have anything to to with these bunghole brains.
Great Job Sony! Jack@$$es.
I would love to see them try to install software on my Linux box. Have fun.
Score: 0
|They can!
Score: 0
|Fascinating. Where can I read about actual rootkits installed on Linux
by DRM/RIAA/SONY, etc. I wasn't aware they could do this with an
ordinary user.
Score: 0
|Think about what you just said: "this gives me a reason to only download music illegally."
While there may be some reasons that would at least allow illegal activity (like stealing for a starving family), Sony's DRM debacle doesn't give you a reason, or a right, to engage in illegal activity. Not to mention that by downloading music illegally, you hurt more than just the record companies like Sony - and you encourage further attempts at the blocking of piracy (e.g. the DRM).
I agree that this was a bad move on Sony's part, and I agree that there is still a lot to be figured out in regards to copyright protection. However, in your case, two wrongs don't make a right; you're way off base.
Score: 0
|This is a disgrace. Sony is writing malware to stop your computer from doing what you want to with it. Keep in mind it's YOUR computer not Sony's and no one said that Sony had any rights to your computer or that they could install software on it. I will never buy another CD and if I want a song I will just get it from the radio if it is that important to me.
Score: 0
|[sarcasm]WAIT! BUY CD'S! RIAA WANTS TO MAKE A PROFIT TOO YOU KNOW![/sarcasm]
Add this to the list of why people won't buy CD's anymore.
Score: 0
|Not only that but they sue you for 4000 for about 100 songs, but they screw up your $4000 computer and what do YOU get for it? Lost data, a messed up PC and/or a $150 Geeksquad bill (or just the hour or 10 it takes to get your PC back to it's 'comfort spot'). Quite a b****slap in the consumers face if you ask me.
Score: 0
|Sue $4000 for 100 songs? Oh heck no, at least $8,000,000! :P
Now fine maybe...
Score: 0
|If you're using the geek squad, I'm surprised your system is working at all....no offense, but I get LOTS of repairs because of them. Usually end up making twice as much because of what they screw up too. Things like it would have been $75 repair if they brought it to me in the first place, but because GeekSquad worked on it and made matters worse, it now costs $150 and there's data loss.
I wouldn't be surprised if the data loss comes from Geek Squad and now the RootKit. They aren't known for taking extra special care of customers...that's for sure.
Score: 0
|Well, prior to being owned by BestBuy, they were actually decent. They'd *gasp* fix things.
Now they just tell ya to come into BestBuy and buy a new one.
Score: 0
|This is rediculous. I'm so annoyed from reading this, especially the systernals blog article. Mark has a point for getting mad. I hope they lose money and never make a hint of profit by pulling crap like this.
Score: 0
|A point of interest is will this kit install an Apple running OSX 10?
Score: 0
|Is there a list anywhere of the CDs that have this "feature".
As a music lover who buys CDs, I will boycott any of these titles, IF I KNOW WHAT THEY ARE.
Those of us who buy CDs are the ones who got hurt from this, and I want them to hurt.
Score: 0
|