Feeds

Sony digital boss - rootkit ignorance is bliss

But IT Depts beg to differ

Top three mobile application threats

The President of Sony BMG's global digital business division Thomas Hesse has weighed into the storm over the 'rootkit'-style copy restriction software introduced on some recent audio CDs.

Sony's software installs itself by stealth, conceals itself, then intercepts low level Windows systems calls. Removing it causes the CD drive to be rendered inoperable. The only cure is to reformat the disk and reinstall Windows.

What responsibility did Hesse feel for the havoc his CDs had caused?

"Most people, I think, don't even know what a rootkit is, so why should they care about it?" he huffed.

I think we can take that as: "No responsibility at all."

(Hesse made his comments on NPR radio on Friday - you can hear them here, 1m:50s into the short report.)

But IT departments beg to differ.

A support manager at an IT department in a medium sized corporation told us that a CD-borne infection of Sony DRM is already causing his team headaches.

A major antivirus vendor diagnosed the problem as a nasty case of DRM, he told us, but the problem didn't end there. The Sony 'root kit' causes the antivirus software to go haywire, popping up alerts at the rate of one a second.

Three systems have so far been flattened, he said. The original culprit was a Van Zant CD - from Sony BMG.

And it gets worse.

On Sunday Mark Russinovich of Sysinternals.com, whose forensics last week identified the DRM as a 'rootkit' style infection, has been taking a look at the patch subsequently issued by First4Internet, the British company which wrote the crippleware.

All the patch does is force XP to issue Windows commands (eg, "net stop") that disable the driver. Because XP is a multithreaded OS, this is a brute force procedure that can cause the system to crash if resources are in contention.

Russinovich also notes that the Sony DRM software still contains vulnerabilities that expose a system to a potential blue screen of death. Instead of exiting gracefully and returning standard Windows system errors, the DRM exits disgracefully.

Which, we suggest, is exactly what Sony's Herr Hesse should be considering right now.

Have you had problems with Sony in your IT support department? Write and let us know. ®

The Essential Guide to IT Transformation

More from The Register

next story
BBC goes offline in MASSIVE COCKUP: Stephen Fry partly muzzled
Auntie tight-lipped as major outage rolls on
iPad? More like iFAD: We reveal why Apple ran off to IBM
But never fear fanbois, you're still lapping up iPhones, Macs
Nadella: Apps must run on ALL WINDOWS – PCs, slabs and mobes
Phone egg, meet desktop chicken - your mother
ITC: Seagate and LSI can infringe Realtek patents because Realtek isn't in the US
Land of the (get off scot) free, when it's a foreign owner
HP, Microsoft prove it again: Big Business doesn't create jobs
SMEs get lip service - what they need is dinner at the Club
Samsung threatens to cut ties with supplier over child labour allegations
Vows to uphold 'zero tolerance' policy on underage workers
Dude, you're getting a Dell – with BITCOIN: IT giant slurps cryptocash
1. Buy PC with Bitcoin. 2. Mine more coins. 3. Goto step 1
There's NOTHING on TV in Europe – American video DOMINATES
Even France's mega subsidies don't stop US content onslaught
You! Pirate! Stop pirating, or we shall admonish you politely. Repeatedly, if necessary
And we shall go about telling people you smell. No, not really
prev story

Whitepapers

Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.