P2P-Zone  

Go Back   P2P-Zone > Peer to Peer
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Peer to Peer The 3rd millenium technology!

Reply
 
Thread Tools Search this Thread Display Modes
Old 07-11-05, 11:38 PM   #1
TankGirl
Madame Comrade
 
TankGirl's Avatar
 
Join Date: May 2000
Location: Area 25
Posts: 5,587
NoSmiley Sony's rootkit DRM is also spyware

Mark Russinovich, the SysInternals guy who revealed Sony's rootkit to the world, has kept digging deeper into Sony's DRM. Now he has been able to verify that Sony's DRM also has a call-home feature which secretly reports back to Sony every time a DRM-protected CD is played in a computer, allowing Sony to track precisely which CDs are being played in which IP numbers. In other words, the DRM software was not only designed to take root level control of the computer - it was also designed to serve as well-cloaked spyware.

From Mark's blog:

Quote:
EULAs and Disclosure: Sony’s Player Phones Home

There’s more to the story than rootkits, however, and that’s where I think Sony is missing the point. As I’ve pointed out in press interviews related to the post, the EULA does not disclose the software’s use of cloaking or the fact that it comes with no uninstall facility. An end user is not only installing software when they agree to the EULA, they are losing control of part of the computer, which has both reliability and security implications. There's no way to ensure that you have up-to-date security patches for software you don't know you have and there's no way to remove, update or even identify hidden software that's crashing your computer.

The EULA also makes no reference to any “phone home” behavior, and Sony executives are claiming that the software never contacts Sony and that no information is communicated that could track user behavior. However, a user asserted in a comment on the previous post that they monitored the Sony CD Player network interactions and that it establishes a connection with Sony’s site and sends the site an ID associated with the CD.

I decided to investigate so I downloaded a free network tracing tool, Ethereal, to a computer on which the player was installed and captured network traffic during the Player’s startup. A quick look through the trace log confirmed the users comment: the Player does send an ID to a Sony web site. This screenshot shows the command that the Player sends, which is a request to an address registered to Sony for information related to ID 668, which is presumably the CD's ID:

In response the Sony web site reports the last time a particular file was updated:

I dug a little deeper and it appears the Player is automatically checking to see if there are updates for the album art and lyrics for the album it’s displaying. This behavior would be welcome under most circumstances, but is not mentioned in the EULA, is refuted by Sony, and is not configurable in any way. I doubt Sony is doing anything with the data, but with this type of connection their servers could record each time a copy-protected CD is played and the IP address of the computer playing it.

The media has done a great job of publicizing this story, which has implications that extend beyond DRM to software EULAs and disclosure, and I hope that the awareness they’re creating will result in Congressional action. Both the software industry and consumers need laws that will clearly draw lines around acceptable behaviors.
TankGirl is offline   Reply With Quote
Old 09-11-05, 10:29 PM   #2
multi
Thanks for being with arse
 
multi's Avatar
 
Join Date: Jan 2002
Location: The other side of the world
Posts: 10,343
Default

CD's with rootkit

Trey Anastasio, Shine (Columbia)
Celine Dion, On ne Change Pas (Epic)
Neil Diamond, 12 Songs (Columbia)
Our Lady Peace, Healthy in Paranoid Times (Columbia)
Chris Botti, To Love Again (Columbia)
Van Zant, Get Right with the Man (Columbia)
Switchfoot, Nothing is Sound (Columbia)
The Coral, The Invisible Invasion (Columbia)
Acceptance, Phantoms (Columbia)
Susie Suh, Susie Suh (Epic)
Amerie, Touch (Columbia)
Life of Agony, Broken Valley (Epic)
Horace Silver Quintet, Silver's Blue (Epic Legacy)
Gerry Mulligan, Jeru (Columbia Legacy)
Dexter Gordon, Manhattan Symphonie (Columbia Legacy)
The Bad Plus, Suspicious Activity (Columbia)
The Dead 60s, The Dead 60s (Epic)
Dion, The Essential Dion (Columbia Legacy)
Natasha Bedingfield, Unwritten (Epic)
Ricky Martin, Life (Columbia) (labeled as XCP, but, oddly, our disc had no protection)


More info here
__________________

i beat the internet
- the end boss is hard
multi is offline   Reply With Quote
Old 16-11-05, 01:52 AM   #3
Drakonix
Just Draggin' Along
 
Drakonix's Avatar
 
Join Date: Apr 2000
Posts: 1,210
Default

LOL, Sony's buns continue to bake under heat from consumers, experts on root kit DRM debacle.

Microsoft Anti-Spyware will recognize and report Sony's DRM rootkit as spyware and (supposedly) remove it. Also to be detected and removed by Malicious Software Removal Tool.

http://www.foxnews.com/story/0,2933,175649,00.html
http://www.informationweek.com/story...leID=173602634
__________________
Copyright means the copy of the CD/DVD burned with no errors.

I will never spend a another dime on content that I can’t use the way I please. If I can’t copy it to my hard drive and play it using the devices I want, when and where I want, I won’t be buying it. Period. They can all take their DRM, broadcast flags, rootkits, and Compact Discs that aren’t really compact discs and shove them up their bottom-lines.
Drakonix is offline   Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump






All times are GMT -6. The time now is 11:48 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
© www.p2p-zone.com - Napsterites - 2000 - 2024 (Contact grm1@iinet.net.au for all admin enquiries)