DRM Hole Sets Patch Speed Record For Microsoft
puppetman writes "Wired columnist Bruce Schneier has an article up called 'Quickest Patch Ever', about a patch that was issued within three days to fix a vulnerability in Windows Digital Rights Management (DRM)." From the article: "Now, this isn't a 'vulnerability' in the normal sense of the word: digital rights management is not a feature that users want. Being able to remove copy protection is a good thing for some users, and completely irrelevant for everyone else. No user is ever going to say: 'Oh no. I can now play the music I bought for my PC on my Mac. I must install a patch so I can't do that anymore.' But to Microsoft, this vulnerability is a big deal. It affects the company's relationship with major record labels. It affects the company's product offerings. It affects the company's bottom line. Fixing this 'vulnerability' is in the company's best interest; never mind the customer."
So this is going to be the least installed patch for windows ever. untill they make it mandatory
I often have trouble remembering which way is out of bed in the morning.
What's their excuse going to be the next time a user vulnerability that has exploits in the wild has to wait for the next release cycle?
No matter what anyone in your company tries to tell you, this kind of rapid response is EXACTLY what we are clamoring for when we ask that you take security seriously. Please tell your bosses. Thanks...
W..w..W - Willy Waterloo washes Warren Wiggins who is washing Waldo Woo.
From the article:
"It should surprise no one that the system didn't stay patched for long. FairUse4WM 1.2 gets around Microsoft's patch, and also circumvents the copy protection in Windows Media DRM 9 and 11beta2 files."
So it's not totally horrible... though I'm sure (and the article agrees here) that M$ will be quick to fix their fix.
This leads me to 2 questions: "can patching be regulated?" and "should patching be regulated?". It seems obvious the free market can't keep our computers secure. I've been wrong before though. I guess maybe it could if people didn't already have the expectation that they shouldn't have to pay for patches b/c Microsoft should fix their own faulty software.
I guess it's all pretty moot since open source is going to take over the world anyway.
Does this sig remind you of Agatha Christie?
For a second there, I thought it was Tuesday.
Reviewing just the first hour of video games.
"ut to Microsoft, this vulnerability is a big deal. It affects the company's relationship with major record labels."
what relationship? why is it important?
Do the get money from them? Is Steve B. banging a secretary in the RIAA office?
I just don't get it.
The Kruger Dunning explains most post on
DRM Hole Sets Patch Speed Record For Microsoft & Gets cracked again!!
Wincopy
fatal holes in the browser? whatever
allowing spyware to take over? who cares
DRM? we're on it!
The fast fix suggests that rapidness of response might be a function of "whose ox is being gored".
As TFA says, it's simple. A normal security hole costs the user money, not Microsoft. This "security hole" (indirectly) costs MS money so it gets fixed ASAP. MS is, if nothing, good at protecting its bottom line.
So this is going to be the least installed patch for windows ever. untill they make it mandatory
Actually, this is a very serious question: is the patch marked critical, or not? This is important, because:
1. If the patch is critical, it will get criticized for being, in effect, mandatory degradation of capability (by the tech-savvy). Also, this will make light of Microsoft's security policy, to call this sort of patch 'critical'.
2. If the patch is not critical, then - oh, the irony - by default, it will not be installable on computers failing WGA. Perhaps Microsoft will get around this. But, as WGA currently works, only critical patches are allowed to systems marked as 'non-genuine'. This would be amusing - pirated copies of Windows would not receive this unwanted patch, but paid-for copies would.
I can't find, in TFA or the sources it cites, any mention of the severity of the patch. Anyone know the answer to this?
I have an idea. Let's embrace and extend DRM in Windows. From now on, the operating system will not allow anything to read any information from anywhere. Your own files on your hard drive? Sorry, you can't access them, because you might accidently pirate your English class essay that you wrote last night, and Windows, being much, much, much smarter than you could ever dream of being in your wildest dreams, is therefore charged with the duty of making sure you don't do something illegal like that.
Microsoft is serving its customers' best interests. Their customers are system builders such as Dell, purchasing managers at businesses, and media companies.
The guy at the keyboard of a Windows Vista box, using Microsoft Office at work, and Windows Media Player at home is not the customer, he is the product.
This sort of story indicates something about Microsoft's priorities. It doesn't mean they're evil and/or going to software hell. It just indicates something about their priorities.
My turnips listen for the soft cry of your love
When the summary says "Within three days" they mean "three days after it was reported in engadget".
Coz,FairUSE4Wm was released on August 19th in the forum.Microsoft patched it on August 28th.So 9 Days.
Wincopy
Microsoft did not really "patch" their DRM. This wasn't a code change. Their DRM was designed to be updateable in the event that it was compromised.
There is a big difference in how fast you can roll out what ammounts to a configuration change and how fast you can roll out a code change.
That said, it didn't seem to do much good given that it was cracked again in a matter of days.
The KB891122 patch wasn't developed in response to FairUse4WM 1.0 -- MS started working on it after seeing an earlier bunch of tools (drmdbg and friends) that were released on the cover CD of a Japanese magazine a few months ago, but were too cumbersome in operation to gain widespread use.
FairUse4WM "merely" wrapped up the techniques used by these tools in a neat package, and got to the frontpage of Engadget. It was pure luck that MS had a patch available at the time, even though it took extraordinary effort on the behalf of its DRM partners to implement, and denied "legacy" OS users, as well as users of the latest Media Center version, the use of new DRM-protected tracks.
A patch for FairUse4WM 1.2 still isn't available, even though the tool was released last weekend.
BTW, if you think MS is getting screwed by class breaks like this, think again. Content providers (think: RIAA members) will call in their non-refundable advances (usually over $25K per label!) received from distribution partners (think: music stores) for "material breach of contract". MS will fix the issue, the RIAA gets richer, and the guys that actually try to get music to you get screwed. Oh, well, they're used to it...
First of all, the DRM code is most likely pretty self-contained, and is only interfaced with by a limited amount of code. (All the files run through some version of the Windows Media Encoder engine, remember?). So on that front, it's a hell of alot easier to patch an issue contained to DRM-land than it is to deal with something like IE, which has to interact with a much messier set of incoming files (the Web).
Even then, the reason you don't release a patch in three days is that you're probably going to screw it up and not actually fix the problem. Amazingly enough, that appears to be exactly what happened.
First of all, it's been cracked again. Look up FairUse4WM 1.2.
Second of all, from what I've seen, it's not pushed out via windows update, but rather the client you are using for music. For instance, Napster pushed out the new version via a tiny patch when I launched the client. There IS a way to trick your client into believing that you already have the latest version (thus preventing the forced update). Look it up in the doom9 forums.
This should keep the crack working until Napster pushes out a completely new version of the client that explicitly checks the version, or Micrsoft issues a regular update.
-T
P.S. Napster provided free of charge by my university. Hell, as a grad student, I guess I get paid to use it...
And isn't it sad that the quickest patch they ever release is for a hole no user cares about? More proof that MS cares more about their corporate friends than users.
Is it proof that MS doesn't care enough about users, or is it (by extension) proof that users don't care much about OS vulnerabilities? Sure, they may complain, but do they actually take action and demonstrate that they care, by switching to more secure OS's (by moving to Apple or Linux)?
After all, MS reacts to what its customers and business partners care about. The music companies go apeshit over stuff like this, but users (both corporate and personal) haven't really demonstrated that they'd rather take their business somewhere else, so why should MS give them anything more than lip service?
Stop by my site where I write about ERP systems & more
People seem to be overlooking who the customer REALLY is here. The bottom line lies in corporate back scratching for multi-$$$$ contracts and agreements
One business contract with a large label, Dell, or Sony is worth more than the mutterings and begrudging updates from Windows consumers. Most of us are not the customers, we're the consumers. Most people don't buy windows from microsoft, they buy it from Dell, or Gateway, or whoever else sold them their computer. The Dells, Gateways, etc are the customers. The game companies writing for xbox 360s, the phone vendors embedding wince, they're the customers.
Bottom line, If you're bitching about this update, you're a consumer. If you think it's a good thing, then you're the customer.
That article is completely misleading. This "Vulnerability" has been known about since January 2005, the tools to bypass it were available since then, they just didn't have a fancy GUI to make it easier. This is actually one of the LONGEST periods Microsoft took to patch something.
+1 IDisagreeSoHeMustBeATrollOrAnAstroturferOrAShill
Its all about money. The DRM is key to their relationship with media partners. If DRM is broken then all Windows users will suddenly, uncontrollably start pirating their media; we can't help it, apparently, and without the DRM firmly in place, we mind end up like Sweden.
I'm sure they're more "worried" about DRM breaking than the everyday security holes that merely allow someone to glom your computer onto their botnet, since there's money and contracts that depend on the DRM. The EULA is probably the only agreement that might be impacted by a security flaw, but we all know those are meaningless.
blog