funsec mailing list archives

Re: Sony to patch copy-protected,


From: Rob Thompson <my.security.lists () gmail com>
Date: Wed, 2 Nov 2005 14:29:21 -0800

Can you say "backpeddle" ?

Reading this stuff is almost enough to make me want to yank my Sony
DVD Burner out of my pc and drive over it a few times.  Just because
it's a Sony...

Sad part is the patch that they are pushing out via their website
attempts to install itself via ActiveX.  As far as I know, doing it
that way, doesn't that mean that they are taking away our ability to
see what exactly they are doing to our machine when they "patch" it? 
As there isn't an actual executable that can be taken apart and
analyzed?

Even worse than that, to get the removal tool, you have to apply for
it with Sony.  And then they will decide if you can have it?  What's
up with that.

Too little, too late.

On 11/2/05, Fergie <fergdawg () netzero net> wrote:
Via C|Net News.

[snip]

Sony BMG Music Entertainment and a technology partner are working with antivirus companies on a fix for a potential 
security problem in some copy-protected CDs.

Earlier in the week, security experts said that anticopying technology used by Sony BMG could be adapted by virus 
writers to hide malicious software on the hard drives of computers that have played one of the CDs. The antipiracy 
tool is included on many of Sony BMG's latest music releases, from Van Zant to My Morning Jacket.

Sony BMG's technology partner First 4 Internet, a British company, said Wednesday that it has released a patch to 
antivirus companies that will eliminate the copy-protection software's ability to hide. In consequence, it will also 
prevent virus writers from cloaking their work using the copy-protection tools.

The record label and First 4 Internet will post a similar patch on Sony BMG's Web site for consumers to download 
directly, the companies said.

[snip]

http://news.com.com/Sony+to+patch+copy-protected+CD/2100-7355_3-5928608.html

- ferg

--
"Fergie", a.k.a. Paul Ferguson
 Engineering Architecture for the Internet
 fergdawg () netzero net or fergdawg () sbcglobal net
 ferg's tech blog: http://fergdawg.blogspot.com/


_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.



--
Rob

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: