Slashdot Mirror


EFF and Sony Disclose New DRM Security Hole

Dotnaught writes "The Electronic Frontier Foundation (EFF) and SONY BMG Music Entertainment said on Tuesday that SunnComm is offering a patch to fix a security vulnerability with its MediaMax Version 5 content protection software on 27 SONY BMG CDs. Security firm iSEC Partners discovered the hole following a request by the EFF to examine the SunnComm software. The vulnerability involves a directory installed on users' computers by the MediaMax software that could allow a third party to gain control over the affected Windows PC. The EFF and iSEC delayed disclosing the problem until SunnComm could develop a fix."

7 of 258 comments (clear)

  1. Quick Question... by parsnip11 · · Score: 5, Interesting

    Who in their right mind would voluntarily install something from SunComm or SonyBMG given their track record?

    Their software phones home and cripples your computer. Would anyone here actually trust them?

  2. I wonder.. by LilWolf · · Score: 5, Interesting

    ..did they also fix that little issue where the DRM installs itself even if the user doesn't accept the EULA?

  3. Re:Thank you Sony! by morgan_greywolf · · Score: 5, Interesting

    Yes, but the one thing they haven't been successful in is pointing out the danger of DRM to Joe Sixpack. A number of people I've spoken with have never heard of the Sony 'rootkit' case and had no idea that playing a recent Sony DRM-protected CD on a Windows PC could be dangerous to their computer system.

  4. Funny but I feel safer with "disreputable" sources by guidryp · · Score: 4, Interesting

    Corporations are sometimes their own worse enemy. It has gotten to the point that I feel safer downloading my music from complete strangers on the internet than buying it in a store.

    The other farce in this fiasco is that these methods of protection are so easy to defeat that "anyone" who actually uploads music would not be slowed down for even a second.

    So we have an extreme example of a rights denial system that penalizes in the extreme the clueless who never were going to upload anyway, and does nothing, not one iota, to stop uploaders.

    Earth to idiots at corp HQ. Sony will feel the pain for years to come on this one. If I were an artist, I would be looking for a "no DRM" clause in my contracts when dealing with these morons.

  5. Sony Software by Ankou · · Score: 4, Interesting

    This may be a little off topic, but with this whole Sony root kit thing has anyone checked their Sony software lines for the same exploits? I had been an avid user of Sony Vegas software since they bought out Sonic Foundry, but now I am scared to install it again. There goes about 400 dollars just cuase I lost trust for Sony. It was great software much faster and more stable than Premier Pro, probably becuase Sony didn't write it. It makes you wonder what else they have corrupted in their control game.

  6. Re:Perhaps not (Was Re:Useful indeed) by Anonymous Coward · · Score: 5, Interesting

    Don't be surprised in Sony divests itself of BMG music at some point in the future, to keep from losing customers for its home electronics business.

    They already lost me. And when a company loses my business, they lose it permanently.

    I had a Technics CD player in the mid-80's that had to be fixed repeatedly for the same problem under warranty. When the problem recurred shortly after the unit went out of warranty and they refused to fix or replace it, I sent a polite letter to the head of Panasonic USA explaining the situation and telling them that if they didn't replace the unit I'd never buy a another Panasonic product. They declined to fix or replace the unit and twenty years later, I still don't have another Panasonic product.

    You can be sure that there will never be a Sony product in my house in the future.

    Of course, this could be their attempt to implement DRM by fear. If your PC gets compromised every time you put a Sony audio disk in the drive, maybe you'll stop doing it. If you don't put the CD in your PC, they don't have to worry about you copying it.

  7. Confusing the Consumer by micron · · Score: 4, Interesting

    I walked in to my local record store TWO DAYS ago with the Sony/BMG list of XCP titles. I asked the counter clerk if they had pulled the titles yet.

    The response was, "Which one do you want".

    The clerk knew of the issue. He even helped me confirm that the catalog number for the disk was a match. The titles were still on the shelves for sale. The store was replacing the disks as new disks came in from Sony.

    Two out of three record stores that I checked that day had the titles available for purchase.

    This is a recall?

    Also, it is not as if you can look on the spine of the CD to find out that it is a Sony disk. These disks are sold under other label names. I believe that the one I got was an Electra. Sony/BMG is in the really fine print on the back, as well as the XPC URL.