Feeds

Sony unsinged by rootkit CD fiasco

Expect more exploits

Security for virtualized datacentres

Analysis What next for CD buyers?

For all the lawsuits, over-the fold-coverage in mainstream print and on primetime TV, and howls of anguish from the blogosphere, Sony Music has sailed through the rootkit CD fiasco largely unharmed.

The only figure that matters - the bottom line - appears to be unaffected by the fiasco. CNet's John Borland reports, and as retailers confirmed to The Register, that Sony hasn't lost sales from popular titles infected with the notorious XCP copy-restriction technology.

The poorly written software leaves a PC wide open to hackers, and attempts to remove it can disable the CD drive. Sony Music reluctantly announced a recall and exchange program for XCP-infected CDs last week.

But the CD buying public doesn't seem to care. One large retail store, Amoeba Records in tech savvy Berkeley hasn't seen a single infected CD returned to the store. Chart rankings and Gracenote lookups don't reflect a fall off in sales for the affected CDs.

Far from being a historic turning point in the public's perception of nefarious DRM tactics, that many hoped, it's proof that the CD buying public is impervious to technology warnings, or at least extremely slow to cotton on.

We may have feared as much. One in four PCs connected to the internet in the UK is "owned", in other words, fatally compromised by malware. And yet good technology advice isn't hard to find: news stand magazines and part-works offer lucid explanations, most newspapers feature weekly PC advice columns, and much more information is only two clicks away on the internet.

So more information in itself isn't the answer.

Will the lawsuits succeed where education has failed? Yesterday the Electronic Frontier Foundation and the state of Texas duly filed suit against Sony.

Don't hold your breath.

For all the angst in the US about 'tort reform' and the prominence given to excessive damages won by 'ambulance chasing' lawyers, the effect is negligable. If the Microsoft trial taught corporate America a lesson, it's that litigation can be considered a minor operational expense. Business treats it like a spot fine for littering.

Sony Music can also take heed from the limitations of internet based activism. The New York Times reports that over 700 Amazon.com reviews pointed out the dangers of XCP DRM, and that "... snarky Internet shoppers have quickly turned Amazon.com's tagging system into digital graffiti" - attaching the 'rootkit' warning tag to Sony XCP CD titles.

Why, then, has the saturation and uniformly negative coverage of Sony's DRM failed to harm sales?

Your guesses are as good as ours, but it's hard not to conclude that the WiReD myth of a 'Rip Mix and Burn' population has been somewhat overstated. Only a third of CD purchasers actually play music on a PC. And a vanishingly small number of them appear to want to take their music anywhere other than where it's directed to go by the manufacturer. If a CD plays in the home stereo and the car, then that's quite enough digital freedom already for most people.

This may have less to do with a public acceptance of artificial restrictions such as DRM than the fact that music tends to stay in hardware 'silos', and digital music tends to stay where it's bought, largely through apathy and forgetfulness.

And given an atomized tech savvy population, tagging and bleating in the safety and comfort of their own PCs, Sony's nefarious tactics have failed to harm the business.

Ultimately, there's little to change our view that DRM restrictions are an expensive and economically inefficient stop-gap, an absurd attempt to replicate the inconvenience of physical product in a digital form. But equally, the 'Chicken Little' scenario of DRM as the means of introducing a vast lock down is a paranoid fantasy. Sony now knows it only need keep the CDs playing in home and car stereos, and it can swat away the digital rights lobby like flies.

A better analogy, and one we've made many times, is that we're in a Prohibition era: this is a transitional age, one where the inconveniences of DRM are borne by a minority of the population. That happens to be us.

Ominously the Recording Industry Ass. of America president Cary Sherman congratulated Sony Music for its ethical behaviour, comparing it favorably to software companies.

"The problem with the SonyBMG situation is that the technology they used contained a security vulnerability of which they were unaware," Sherman told a forum of student journalists.

"They have apologized for their mistake, ceased manufacture of CDs with that technology,and pulled CDs with that technology from store shelves. Seems very responsible to me. How many times that software applications created the same problem? Lots. I wonder whether they've taken as aggressive steps as SonyBMG has when those vulnerabilities were discovered, or did they just post a patch on the Internet?"

Note the semantic redefinition of XCP as bad coding, simply a bad implementation of a good idea.

Expect more XCPs. You only have to follow the money. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
The 'fun-nification' of computer education – good idea?
Compulsory code schools, luvvies love it, but what about Maths and Physics?
Ex-US Navy fighter pilot MIT prof: Drones beat humans - I should know
'Missy' Cummings on UAVs, smartcars and dying from boredom
Facebook, Apple: LADIES! Why not FREEZE your EGGS? It's on the company!
No biological clockwatching when you work in Silicon Valley
Happiness economics is bollocks. Oh, UK.gov just adopted it? Er ...
Opportunity doesn't knock; it costs us instead
'Cowardly, venomous trolls' threatened with TWO-YEAR sentences for menacing posts
UK government: 'Taking a stand against a baying cyber-mob'
Sysadmin with EBOLA? Gartner's issued advice to debug your biz
Start hoarding cleaning supplies, analyst firm says, and assume your team will scatter
Doctor Who's Flatline: Cool monsters, yes, but utterly limp subplots
We know what the Doctor does, stop going on about it already
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.