Feeds

RealPlayer dinged by software watchdog group

RealNetworks promises changes

Internet Security Threat Report 2014

A software watchdog group has branded the two most recent versions of the RealPlayer media program "badware" because they don't give users adequate control over software components that are activated during installation.

RealNetworks, maker of the program, has pledged to fix the issue relating to its most recent version and says a separate issue in the earlier version has already been corrected.

StopBadware.org's objection with version 11 of the media program relates to the installation of a slimmed-down version of the Rhapsody Player, which is needed to play songs from a subscription music service that just happens to also be owned by RealNetworks. Thing is, when users uninstall RealPlayer, the Rhapsody software remains, and there's no easy way for average Joe users to know that.

"We believe that there is a strong responsibility on software producers that when a user consents to install something they know what they're consenting to," says Maxim Weinstein, manager of StopBadware.org. The failure to remove the Rhapsody Player "means now somebody has a piece of software on their computer that they didn't know about."

That, of course, has security implications. Given that security bugs are a fact of life, it's important users know for sure what programs are on their machines. More fundamentally, it comes down to this bedrock principle: People have the right to know exactly what is installed on their machines and to have an easy means of removing it.

RealNetworks spokesman Ryan Luckin issued a mea culpa, saying the RealPlayer's failure to uninstall the Rhapsody software was an oversight. He said engineers are working on an update that will fully remove the components.

According to Luckin, Version 11 is one of the only media players to natively run a wide variety of proprietary formats, including those based on Microsoft's Windows Media Player and Apple's QuickTime player. The Rhapsody software is installed so that RealPlayer can natively play music from the service seamlessly.

"RealPlayer is not doing anything malicious or putting users at risk," he said.

StopBadware's other beef with RealPlayer relates to version 10.5, which is still available Real's website. It turns on a feature known as Message Center, which pushes alerts concerning sports scores, videos and other content to a user's desk top. By default, all the options are turned on for users who don't register their personal information with RealNetworks.

Luckin said Message Center was substantially reworked in Version 11. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Why did it take antivirus giants YEARS to drill into super-scary Regin? Symantec responds...
FYI this isn't just going to target Windows, Linux and OS X fans
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Home Office: Fancy flogging us some SECRET SPY GEAR?
If you do, tell NOBODY what it's for or how it works
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
Syrian Electronic Army in news site 'hack' POP-UP MAYHEM
Gigya redirect exploit blamed for pop-rageous ploy
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
prev story

Whitepapers

10 ways wire data helps conquer IT complexity
IT teams can automatically detect problems across the IT environment, spot data theft, select unique pieces of transaction payloads to send to a data source, and more.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Choosing a cloud hosting partner with confidence
Download Choosing a Cloud Hosting Provider with Confidence to learn more about cloud computing - the new opportunities and new security challenges.