EFF and Sony Disclose New DRM Security Hole
Dotnaught writes "The Electronic Frontier Foundation (EFF) and SONY BMG Music Entertainment said on Tuesday that SunnComm is offering a patch to fix a security vulnerability with its MediaMax Version 5 content protection software on 27 SONY BMG CDs. Security firm iSEC Partners discovered the hole following a request by the EFF to examine the SunnComm software. The vulnerability involves a directory installed on users' computers by the MediaMax software that could allow a third party to gain control over the affected Windows PC. The EFF and iSEC delayed disclosing the problem until SunnComm could develop a fix."
I've never understood how any userland bullshit software could manage the complexities of opening up a hole *on accident*. Call me paranoid, but, when shit like this gets 'found', they call it being 'found' because someone put it there.
To install the software originally the user had to be an administrator (a lot of software requires admin rights because most of the system won't allow a basic user to install system-wide software. e.g. It could add files in your user directory and the like, but not in Program Files). From then on the software is running as System, operating as a part of the system (which is why it's called a root kit).
My guess is that the folder where the software is stored has the ACLs set to Everyone with Full Control, or something similar. Because this root kit is run as System when the system boots up, a simple user exploit could circumvent user isolation by overwriting some of the rootkit files, and on next boot it'll be running as System, with full local permissions.
Patience...
http://www.boycottsony.us/ has the latest news on developments in the Sony case, and www.sonysuit.com lists the lawsuits.
A New lawsuit for Candians is being opened by http://www.glynhotz.com/ an Ontario lawyer. The XCP CDs appear to still be on many store shelves, more than a week after the recall was announced in Canada.
Saskboy's blog is good. 9 out of 10 dentists agree.
why the new acts can't all sound like Lionel Richie or Billy Ocean.
I think that you missed the poster's point, since you mention old pop chart stars. The problem isn't that today's pop charts don't feature yesterday's pop chart music nor soundalikes --- expecting that would be totally dumb.
The problem is that today the music scene is ruled 99% by the pop charts as a result of the ruthless efficiency of the Big Business side of the music industry, to the extent that almost all other musical styles are marginalized to near extinction. Musicians no longer come out of art school wanting to do something novel for their own niche audience; greed has overcome artistic integrity.
Back in the day, the studios and labels were comparatively amateurish and ineffective, so public tastes were strongly influenced by radio station jockeys, through student union gigs/concerts, and by music tabloid reviews of live acts. These have almost no effect today. The image makers and immense marketting machine hold the scene in a vice-like grip.
So it's not old age, only. It's also that musical horizons have been slammed down tight all around us, with only a few wonderful exceptions to the rule offering a temporary escape.
"The question of whether machines can think is no more interesting than [] whether submarines can swim" - Dijkstra
**Clicky - Google - Clicky**
MediaMax titles @Sony BMG website
XCP titles @SonyBMG website