Original URL: http://www.theregister.co.uk/2006/12/20/sony_rootkit_drm_settlement/
Some CD buyers in Texas and California can claim up to $175 each from record company Sony BMG as a result of a legal settlement this week.
Both states took action against the music giant over its "rootkit-style" DRM, designed to prevent PC users from copying music CDs to their hard drives.
The complaints allege that Sony BMG failed to notify consumers of the presence of the DRM on the outer-packaging, and therefore loaded unauthorised software onto their PCs.
Sony used software called XCP (Extended Copy Protection) created for it by British company First4Internet Ltd to prevent copies being made. XCP was dubbed a "rootkit" (http://www.f-secure.com/v-descs/xcp_drm.shtml) because it took over basic system level functions, then concealed its presence. The DRM compromised users' security and knocked some CD drives out of action. Uninstallation was only possible by sending a request to Sony BMG's customer support line.
CDs with the DRM had been on the market for several months before a security consultant described its nefarious technical practices. Sony eventually issued an uninstallation tool, and settled a class action suit late last year (site here (http://www.sonybmgcdtechsettlement.com/)).
The lawsuits also compensate punters for CDs encumbered with SunComm's MediaMax's 3.0 and 5.0 DRM, which "phoned home (http://www.freedom-to-tinker.com/?p=925)" - transmitting user information back to SunnComm.
Sony agreed to pay each state $750,000 in costs, and individuals can claim from $25 to $175, depending on the damage the DRM incurred.
The settlement includes some interesting new disclosure obligations for Sony BMG. For the next 12 months, such DRM should be clearly labelled on the packaging, and also:
In Clear and Conspicuous language, the range of computer system resources, if any, which the DRM software may consumer after installation when the CD is not in use on the computer (e.g., "between .5 per cent and 3 per cent depending on the configuration of your computer");
So the settlement doesn't prevent Sony BMG from trying such tactics again - merely making them more obvious, and these disclosure requirements only lasts a meagre 12 months.
But it's the first time we've seen such a Bloatware Disclosure - unless readers know different? ®
Information for Californians (http://ag.ca.gov/newsalerts/release.php?id=1400&PHPSESSID=6f6122ebc423bb5ef6b1b893bfa95bed) and Texans (http://www.oag.state.tx.us/oagNews/release.php?id=1889); the latter includes lists of CDs. Last year's class action settlement (http://www.sonybmgcdtechsettlement.com/) expires on 31 December.
Software company fails to prove it wrote its own software (25 January 2007)
http://www.theregister.co.uk/2007/01/25/software_company_fails_to_prove_it_wrote_its_own_software/
Big labels are f*cked, and DRM is dead - Peter Jenner (3 November 2006)
http://www.theregister.co.uk/2006/11/03/peter_jenner/
MPs call for DRM warning labels (5 June 2006)
http://www.theregister.co.uk/2006/06/05/apig_report_ready/
Judge approves Sony rootkit settlement (23 May 2006)
http://www.theregister.co.uk/2006/05/23/sony_rootkit_settlement/
Homeland security urges DRM rootkit ban (17 February 2006)
http://www.theregister.co.uk/2006/02/17/rootkit/
Sony Rootkit: electronic Black Death (18 January 2006)
http://www.theregister.co.uk/2006/01/18/letters/
Sony 'rootkit' settlement clamps down on DRM (29 December 2005)
http://www.theregister.co.uk/2005/12/29/sony_settles_rootkit/
Sony BMG 'diligently re-evaluates' CD anti-piracy tech (12 December 2005)
http://www.theregister.co.uk/2005/12/12/sony_anti-piracy_review/
SonyBMG backtracks on buggy bug fix (9 December 2005)
http://www.theregister.co.uk/2005/12/09/sony_mediamax_problems/
Sony opens up over another CD security hole (7 December 2005)
http://www.theregister.co.uk/2005/12/07/sony_cd_security/
Sony's DRM woes worsen (30 November 2005)
http://www.theregister.co.uk/2005/11/30/sony_drm_spitzer/
Sony's rootkit drives squirrels to new careers in adult movies (18 November 2005)
http://www.theregister.co.uk/2005/11/18/letters_1811/
Sony DRM uninstaller 'worse than rootkit' (17 November 2005)
http://www.theregister.co.uk/2005/11/17/sony_drm_uninstaller_peril/
Sony pulls rootkit DRM CDs (16 November 2005)
http://www.theregister.co.uk/2005/11/16/sony_withdraws_xcp_cds/
Sony rootkit DRM: how many infected titles? (15 November 2005)
http://www.theregister.co.uk/2005/11/15/sony_bmg_bodycount/
Sony suspends rootkit DRM (12 November 2005)
http://www.theregister.co.uk/2005/11/12/sony_suspends_rootkit_drm/
First Trojan using Sony DRM spotted (10 November 2005)
http://www.theregister.co.uk/2005/11/10/sony_drm_trojan/
Sony digital boss - rootkit ignorance is bliss (9 November 2005)
http://www.theregister.co.uk/2005/11/09/sony_drm_who_cares/
Sony to offer patch for 'rootkit' DRM (3 November 2005)
http://www.theregister.co.uk/2005/11/03/sony_rootkit_drm/
Removing Sony's CD 'rootkit' kills Windows (1 November 2005)
http://www.theregister.co.uk/2005/11/01/sony_rootkit_drm/
© Copyright 2008