Feeds

Sony digital boss - rootkit ignorance is bliss

But IT Depts beg to differ

High performance access to file storage

The President of Sony BMG's global digital business division Thomas Hesse has weighed into the storm over the 'rootkit'-style copy restriction software introduced on some recent audio CDs.

Sony's software installs itself by stealth, conceals itself, then intercepts low level Windows systems calls. Removing it causes the CD drive to be rendered inoperable. The only cure is to reformat the disk and reinstall Windows.

What responsibility did Hesse feel for the havoc his CDs had caused?

"Most people, I think, don't even know what a rootkit is, so why should they care about it?" he huffed.

I think we can take that as: "No responsibility at all."

(Hesse made his comments on NPR radio on Friday - you can hear them here, 1m:50s into the short report.)

But IT departments beg to differ.

A support manager at an IT department in a medium sized corporation told us that a CD-borne infection of Sony DRM is already causing his team headaches.

A major antivirus vendor diagnosed the problem as a nasty case of DRM, he told us, but the problem didn't end there. The Sony 'root kit' causes the antivirus software to go haywire, popping up alerts at the rate of one a second.

Three systems have so far been flattened, he said. The original culprit was a Van Zant CD - from Sony BMG.

And it gets worse.

On Sunday Mark Russinovich of Sysinternals.com, whose forensics last week identified the DRM as a 'rootkit' style infection, has been taking a look at the patch subsequently issued by First4Internet, the British company which wrote the crippleware.

All the patch does is force XP to issue Windows commands (eg, "net stop") that disable the driver. Because XP is a multithreaded OS, this is a brute force procedure that can cause the system to crash if resources are in contention.

Russinovich also notes that the Sony DRM software still contains vulnerabilities that expose a system to a potential blue screen of death. Instead of exiting gracefully and returning standard Windows system errors, the DRM exits disgracefully.

Which, we suggest, is exactly what Sony's Herr Hesse should be considering right now.

Have you had problems with Sony in your IT support department? Write and let us know. ®

High performance access to file storage

More from The Register

next story
Audio fans, prepare yourself for the Second Coming ... of Blu-ray
High Fidelity Pure Audio – is this what your ears have been waiting for?
Dropbox defends fantastically badly timed Condoleezza Rice appointment
'Nothing is going to change with Dr. Rice's appointment,' file sharer promises
Nokia offers 'voluntary retirement' to 6,000+ Indian employees
India's 'predictability and stability' cited as mobe-maker's tax payment deadline nears
Apple DOMINATES the Valley, rakes in more profit than Google, HP, Intel, Cisco COMBINED
Cook & Co. also pay more taxes than those four worthies PLUS eBay and Oracle
It may be ILLEGAL to run Heartbleed health checks – IT lawyer
Do the right thing, earn up to 10 years in clink
France bans managers from contacting workers outside business hours
«Email? Mais non ... il est plus tard que six heures du soir!»
Adrian Mole author Sue Townsend dies at 68
RIP Blighty's best-selling author of the 1980s
Zucker punched: Google gobbles Facebook-wooed Titan Aerospace
Up, up and away in my beautiful balloon flying broadband-bot
Analysts: Bright future for smartphones, tablets, wearables
There's plenty of good money to be made if you stay out of the PC market
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.