This is topic Sony puts malware on its music CDs. in forum Film-Yak at Film-Tech Forum ARCHIVE.


To visit this topic, use this URL:
https://ft-forum.com/ft/cgi-bin/ubb/ultimatebb.cgi?ubb=get_topic;f=8;t=004359

Posted by Bobby Henderson (Member # 840) on 11-08-2005, 09:33 PM:
 
Here's a security watch bulletin from PC Magazine that may make you not want to ever load any Sony or BMG music CD into a Windows PC ever again.

Linky

quote:
Security Watch: Sony CDs Make Your PC Play the Blues

Top Threat:Sony DRM
Executive Summary
Name: Sony DRM
Affects: Windows XP/XP SP2/2000/2003/NT

What it does: As originally discovered by security researcher Mark Russinovich of Winternals Software, certain music CDs published by Sony BMG Entertainment contain DRM protection requiring that the user must install a proprietary music player in order to play the songs. The player contains a rootkit (click here for a definition) as part of an effort to conceal the DRM and prevent its removal.

The DRM software and the rootkit were written by a First 4 Internet of the UK. The rootkit conceals all access to files and registry entries prefixed with the string '$sys$' in order to hide itself, but this behavior could allow other malicious programmers to hide their own programs by using the same file naming scheme. First 4 Internet and Sony deny that the system presents a security problem.

That's not the only problem with the First 4 Internet software. According to Russinovich, the software inserts itself into the CD-ROM driver stack in a way that a naive attempt by a user to remove it could result in making the CD-ROM drive unusable. Furthermore, many of the drivers in the First 4 Internet product are installed to run even when the system boots into safe mode, meaning that if a bug in the drivers interferes with the system or makes it unbootable, it could be very difficult to remove.

How to avoid it: Don't play Sony BMG music CDs in a Windows computer.

How to remove it: First 4 Internet has made a program available that removes the rootkit functionality for hiding the program, but does not remove the player or DRM protection. Sony does not provide an uninstall program, but does provide a web-based form through which you can ask for help uninstalling the program. Sony says that they will e-mail instructions for uninstalling if you fill out the form, but the privacy policy linked to on the form also says that filling it out will allow Sony and their partners to contact you for marketing purposes.


 
Posted by David Stambaugh (Member # 1102) on 11-08-2005, 09:45 PM:
 
I'll bet this was the work of some mid-level manager at Sony Music. "Hey, look what we can do! Heh heh!"

Incredibly stupid, and if Sony corporate has any sense they'll distance themselves from this immediately.

They probably won't though.
 
Posted by Bobby Henderson (Member # 840) on 11-08-2005, 11:09 PM:
 
I agree, David. It was incredibly stupid. Especially stupid from an angle I just considered: it's accidental marketing for Apple products. Make customers scared of any Sony music label CD release as well as any of their BMG music club discs. Drive those customers into buying music from iTunes or even going so far as to buy a Mac. At the very least, it's another compelling reason to have a version of Linux installed on a PC.

Here's one thing that could seriously f**k up the works for Sony very quick on this thing: hopefully Symantec, McAfee and other anti-virus or anti-spyware vendors will quickly release blocks that prevent this Sony greed software shit from even working. When the CD refuses to play, there's a good chance lots of customers will take their infected CDs back to Wal-Mart and demand a refund.

I had a Columbia House music club membership that recently was tranferred to BMG when CH closed. Now I am seriously considering cancelling that membership, even though I have points built up for a number of free CDs. Even if they're free, the damned discs are a giant liability if they're going to infect your computer with malware.
 
Posted by Mike Blakesley (Member # 26) on 11-08-2005, 11:35 PM:
 
I got stuck with one of these disks. Stuck it in the computer and it immediately wanted to install something, so I took it back out. First I tried to "rip" one of the songs into CD Architect but could not do it -- the file comes through, but plays with a loud buzz over the music. Bastards. I haven't heard if there's any way around this other than to do an analog rip through a sound card.
 
Posted by Joe Redifer (Member # 3) on 11-08-2005, 11:43 PM:
 
I am so glad I have a Mac. Not only does this stuff not affect me in the least, but there is a program for the Mac (freeware) that will record any sound your computer makes and you can copy and e-mail and compress those files as many times as you want. Too bad Sony music sucks ass, so it doesn't even matter if I had a Mac or not.
 
Posted by Mike Blakesley (Member # 26) on 11-09-2005, 01:26 AM:
 
You don't even need the freeware -- supposedly these disks play fine in a Mac without any extra crap being installed. That's because they know that no actual music fans own Macs, I guess.

[Note to oversensitive Mac users: That was sarcasm.]
 
Posted by Joe Redifer (Member # 3) on 11-09-2005, 01:28 AM:
 
People who buy music that Sony puts out are not music fans.
 
Posted by Jon Miller (Member # 163) on 11-09-2005, 08:11 PM:
 
Speaking of Sony and Macs, I've heard that Sony's DRM scheme (rootkit or no rootkit) may have been designed to prevent playing Sony BMG music on Macs and prevent transferring the music to an iPod regardless of which OS you use. In a way, it's kind of an underhanded [fu] to Apple, and Sony deserves a [fu] in return for it. [evil]
 
Posted by Daryl C. W. O'Shea (Member # 1303) on 11-09-2005, 08:49 PM:
 
Wait till Sony figures out BSD. There are rootkits out there that affect Macs too, such as this one from last year...

quote: http://news.zdnet.com/2100-1009_22-5424883.html?tag=nl
Mac users face rare threat
By Munir Kotadia, ZDNet Australia
Published on ZDNet News: October 25, 2004, 6:20 AM PT

* ZDNet Tags: Viruses and worms
* Mac OS
* Apple Computer Inc

A script-based threat that spies on Mac users caught the attention of some security watchers last week.

The malware, which has been dubbed Opener by Mac user groups, has the potential to disable Mac OS X's built-in firewall, steal personal information or destroy data. At the moment, however, it seems to pose little danger.

Security experts say those threatening traits are common among the thousands of online threats targeting Microsoft's ubiquitous Windows operating system but are virtually unheard of on Apple Computer's Mac OS.

Paul Ducklin, Sophos' head of technology in the Asia-Pacific region, said that the software, which Sophos calls Renepo, is designed to affect Mac OS X drives connected to an infected system and that it leaves affected computers vulnerable to further attack.

Ducklin said Opener disables Mac OS X's built-in firewall, creates a back door so the malware author can control the computer remotely, locates any passwords stored on the hard drive, and downloads a password cracker called JohnTheRipper.

Opener is a "rootkit," or a set of software tools that intruders can use to gain access to a computer; it's installed either through a known vulnerability or password-cracking. Rootkits don't spread on their own, as viruses do, and require administrator access to be installed.

According to Ducklin, Opener could try to spread by copying itself to any drive that is mounted to the infected computer. This could be a local drive, part of a local network or a remote computer.

It could also be the start of a spate of attacks that use Mac OS X’s scripting features against its users, he said.

"The existence of Unix shells--such as Bash, for which this virus is written--and the presence of powerful networking commands opens up the game a little bit for Mac users. It is no longer necessary to know about Mac file formats or executables. You can write your malware in script. And if you really wanted to, you could probably write a portable virus that would run on many flavors of Unix" and Mac, said Ducklin.

Chris Waldrip, president of the U.S.-based Atlanta Macintosh Users Group, posted a detailed description of Opener on the MacInTouch Web site.

Waldrip, who acknowledges that the threat has him "a bit spooked," said Opener seems to have started out with a legitimate purpose but may yet be developed into something more dangerous.

Waldrip's site also cautions against overreacting to Opener and advises people to use proper security techniques: "As readers take pains to point out, the threat has not yet been incorporated into a widespread virus, worm or Trojan horse, but that's a fairly short step from what we've already seen, and it's important to implement good security procedures."

Mikko Hypponen, director of antivirus research at F-Secure, said that viruses targeting the Macintosh system virtually disappeared in the late 1980s.

"Things have been really quiet on Macintosh front, virus-wise. Back in the late 1980s, viruses used to be a much bigger problem on Macs than on PCs. We here at F-Secure used to have an antivirus product for Mac but discontinued it after the macro viruses died out," said Hypponen.

Symantec said users of Norton AntiVirus for Mac OS X were protected as long as they had updated their signatures over the weekend. A representative for the company said the relevant signature files had been available since Friday evening.

Munir Kotadia of ZDNet Australia reported from Sydney.


 
Posted by Bruce Hansen (Member # 281) on 11-09-2005, 09:47 PM:
 
Copyright law says that I have the right to make a copy for my own use. So, isn't this Sony crap a violation of copyright law?

If you turned the "auto start" off for your CD drive, would that stop this Sony crap from loading, and then you could do anything you want with the CD? (there was some key you could hit while loading a CD, and that would stop the "auto start" function from working. Was it the control key?)
 
Posted by Bobby Henderson (Member # 840) on 11-09-2005, 10:00 PM:
 
Apparently Sony is feeling the heat from their extremely stupid, arrogant move. So now they're making a patch available to end users and to anti-virus software vendors. The patch won't remove the rootkit malware, it will just make the rootkit shit visible on your hard drive.

Major downside however. If you choose to uninstall the DRM software it will probably kill your CD or DVD drive.

Sony's cloaking methods to hide its rootkit are already being exploited for other purposes. Online gamers have made a hack using Sony's rootkit to hide cheat software from the "Warden" in World of Warcraft gaming servers.

And we can expect a hell of a lot of virus writers to try the same shit.

Sony ought to be slapped with a very expensive class action lawsuit.
 
Posted by Dave Macaulay (Member # 813) on 11-09-2005, 10:16 PM:
 
That's the "enter" key.
Up to XP you could disable autorun by turning it off in device manager, in the properties for each drive. XP doesn't have that choice in the device properties, you can disable auto insert notification system-wide in "group policies manager" but not many users even know that exists.
If you can't rip the tracks off a Sony disk possibly the DRM system is actually installed. My understanding is that it is installed without asking permission the first time a "protected" disk is inserted (if autorun is active). I don't know how you can make CD music data that a CD player can read but cannot be copied, I suppose it's possible though...
According to Sony, "content protection technology" has been on every Sony/BMG disk produced since April 1, 2004. They don't specify whether it has always been the First 4 Internet system that used the "rootkit" cloaking technique that the current furor is focused on. The problem is that this software makes any file or program with its filename starting with $sys$ completely invisible to the system; it is invisible in file lists, searches, task manager, etc.
 
Posted by John Lasher (Member # 968) on 11-09-2005, 10:35 PM:
 
Okay. Here is how to get around this and convert the audio on these "silver discs" (Philips, co-inventor of the CD, says that they're not really CDs on account of the malware. Yay, Philips!) into mp3 and other compressed formats for illegal file-swapping and other questionable uses.

Let's go shopping:
First stop is circuitcity, where for $12.99 you can own this CD player
What's that? You already have a CD player? Great! Save yourself a trip and some money.

Now we'll go to RadioShack (the ones around here are OK, some of you may want to take along a pointed stick, just in case (just watched Monty Python, so excuse me)) where we'll pick up this adapter and this cable.

Now connect them as per the following illustration (you may need to modify this slightly for your own setup).

 -

You can now record any CD/Silver Audio Disc into your computer without fear of malware. The Disc itself never touches your computer.

(Edit: at some point I'll post a detail of the 1/8" plug insertion into the CPU)
 
Posted by Bobby Henderson (Member # 840) on 11-09-2005, 10:47 PM:
 
Most new music these days is shit. Most is not good enough for me to waste time listening to it, much less waste even more time downloading it for free or actually pay money to buy.

With that said, I don't feel like exploiting "the analog hole" to rip tracks from copy protected CDs. Why bother when the actual product is crap?

BTW, exploiting the analog hole also means introducing a generation loss in audio quality. May not matter if you're making MP3s with bit-crushing levels of data compression.
 
Posted by Joe Redifer (Member # 3) on 11-09-2005, 11:36 PM:
 
I bet you if I made an analog copy that you would be hard pressed to tell any difference by listening, Bobby. Maybe with a crappy sound card used for recording you could easily discern differences.

I will test this theory soon enough. Stay tuned to this thread!
 
Posted by Joe Redifer (Member # 3) on 11-10-2005, 01:05 AM:
 
OK this one is for you golden ears out there. Download this 11.3 MB ZIP file.

Decompress and you will find 5 test wavs. They are all about 12-15 seconds of the same exact tune. 3 of them are direct digital rips from the CD, which was recorded "DDD" for those of you who know what that means. 1 of the files is an analog rip, played from an external CD player and recorded via the analog cables into a computer. 1 of the files is a mix of digital and analog where it starts out as digital, hard cuts (no crossfades) to analog and then hard cuts back to digital. The length of the files has nothing to do with anything.

So tell me which is digital, which is analog, and which is a mix :

test1.wav = ?
test2.wav = ?
test3.wav = ?
test4.wav = ?
test5.wav = ?

Can you hear (not 'scope, you ass) a generation loss anywhere? I will post the answers soon. Good luck!
 
Posted by Adam Wilbert (Member # 1184) on 11-10-2005, 02:33 AM:
 
quote: Bruce Hansen
Copyright law says that I have the right to make a copy for my own use. So, isn't this Sony crap a violation of copyright law?
You may have the right to make the copy, but Sony doesn't have to make it easy. I have the right to copy my dvds too, but there's copy protection schemes there too. I have the right to copy a book that I own, but the publisher doesn't have to hand me a pdf file that I can print from. Theres nothing stoping you from making all of the analog copies that you want.
 
Posted by Monte L Fullmer (Member # 2797) on 11-10-2005, 03:44 AM:
 
I'll try this one and see what happens:

1-digital
2-digital
3-digital
4-mix
5-analog

All done 141Kbps @ 44mHz

-Monte
 
Posted by Joe Redifer (Member # 3) on 11-10-2005, 04:09 AM:
 
Hmmmm... nope.

Also, they're just a little bit more than 141kbps, and no, they are not 44mhz. [Razz]
 
Posted by Monte L Fullmer (Member # 2797) on 11-10-2005, 04:54 AM:
 
...worth a try anywho...yet, it was interesting, in as well as fun.
 
Posted by Paul Trimboli (Member # 1509) on 11-10-2005, 05:08 AM:
 
Hmmm- They are all the same?

That is a bit of a hard one, the music does not lend itself to hearing slight quality change. I am not sure how well tuned my ears are, I like to think I am pretty good when it comes to audio.
 
Posted by Monte L Fullmer (Member # 2797) on 11-10-2005, 12:44 PM:
 
I heard definite differences in quality - differences between brightness and "muddy" quality.

I was using the latest version of Winamp.

-monte
 
Posted by Joe Redifer (Member # 3) on 11-10-2005, 02:15 PM:
 
I want to give a hint, but you shouldn't need it. You should hear 3 that sound exactly the same and determine which are digital just by that. Then the two that are left have some analog about them. Determine which starts out sparkling digital clear and then transitions to muddy, generation-loss analog which is unbearable to listen to and then back to sparkling clear digital perfection again. That is the mix. The last one is the analog one by default.

It is interesting what Monte heard as "muddy". But the music does have a lot of high frequencies where generation loss would most likely be heard.
 
Posted by Bruce Hansen (Member # 281) on 11-10-2005, 05:08 PM:
 
Here is a way you should be able to make a digital copy of a CD with the Sony crap on it. If you have a stand alone CD recorder, and a CD player with a digital output, connect the digital out of the player to the digital in of the recorder. This way you can make a digital copy, without copying the Sony crap. Now you have a CD that can be put in any computer without fear of the Sony crap screwing with your computer, and you can make as many copies as you want of this new disc.
 
Posted by Daryl C. W. O'Shea (Member # 1303) on 11-10-2005, 06:23 PM:
 
You know you could skip all the making copies crap and just not let the software install itself.

Just one of many, many reasons why you shouldn't be using a privileged account for non-privileged tasks. If you're logged in as a restricted user, like you should be, the software won't be able to install itself.

I wonder how long it'll take for someone to launch a class action suit. I know installing software without consent AND without providing a means to fully remove it, is illegal in Canada, the US and the UK.
 
Posted by Leo Enticknap (Member # 534) on 11-10-2005, 06:51 PM:
 
As with all of these anti-copying systems, spyware and so on, Sony probably knows full well that anyone with relatively advanced IT skills will circumvent this sort of thing using either Daryl's or Bruce's method (or even copying the CD using a computer which runs an operating system other than Windows). But they also know that 99.99% of consumers are IT illiterate, and that most will end up with the malware on their PCs without knowing anything about it.

The software and entertainment industries worked out long ago that it simply isn't worth the investment needed to develop protection systems that will stop people who know what they're doing. Another example: it will take you about 10 seconds on Google to download software which will copy a DVD, stripping out CSS and/or Macrovision in the process. Both the Digital Millenium Copyright Act and the European Union Copyright Directive make it illegal for consumers to actually use it: so presumably the intention is to use those laws against anyone who does so on a significant scale and for profit.
 
Posted by Kyle McEachern (Member # 2250) on 11-10-2005, 09:55 PM:
 
http://news.ft.com/cms/s/16f8bba2-5219-11da-9ca0-0000779e2340.html

quote:
Sony BMG Music Entertainment, the world’s second largest music label, faces a slew of lawsuits in the US after PC security companies found that copy protection software included on some CDs made PCs vulnerable to hackers.

At least three lawsuits have been filed in California against the company, a joint venture between Japan’s Sony group and Germany’s Bertelsmann.

...

On Thursday Sophos claimed it had found the first “trojan” e-mail virus designed to exploit secret “rootkit” software that a number of Sony BMG music CDs install on owners’ computers when they are played.

This week the Electronic Frontier Foundation, a US-based consumer advocacy group, identified at least 19 Sony BMG music CDs that it claimed installed the software when played on a PC.


 
Posted by Bobby Henderson (Member # 840) on 11-10-2005, 11:03 PM:
 
quote:
test1.wav = ?
test2.wav = ?
test3.wav = ?
test4.wav = ?
test5.wav = ?

They all sound pretty much the same to me. But I'm also playing them on a laptop computer with tinny speakers. Tried some Sony headphones, which yielded quite a bit more detail. But still all the audio sounds very much the same.

"test2.wav" is the only one that has a hint of a bit more muddiness to it, but then I could just be imagining it. You sure this isn't some kind of a trick (such as all the tracks actually being the same)?
 
Posted by David Buckley (Member # 2600) on 11-11-2005, 12:03 AM:
 
That was unexpectedly really really hard, and I'm listening through reasonable equipment, SWG1000 sound card, Naim amp, Mission speakers. Mind you, my ears are a bit shot due to excessive rock and roll as a youth...

Anyway, the only thing I think I can hear is a change in the snare drum "airyness" about 4.something seconds into track four. So my guess would be thats the mix track. The others I cant tell apart.
 
Posted by Joe Redifer (Member # 3) on 11-11-2005, 12:58 AM:
 
Bobby, no tricks. That wouldn't be any fun.

David, nope, but good guess. I will post the answers tomorrow if I am not too damned lazy.
 
Posted by Monte L Fullmer (Member # 2797) on 11-11-2005, 03:16 AM:
 
..and I didn't even have DFX Winamp Enhancer on in hearing this - since we know that with MP3 crunching, there is some data loss with the compressing.

I should have clarified that the muddiness was in the mid-range with the highs still coming through. A little flat in the "middies."

Heard buzz that SONY laid off 8000 employees for a restructuring program of sort. This came from an individual who had a CANON DV digital and has a friend with a SONY DV Digicam. Friend wanted to play his SONY recorded DV tapes in his friend's CANON, but wouldn't. Took the cameras back to the store and found out that SONY has implemented a coding signal in the recording circuit of the camera and transferred to the tape so that the tape is invalid in other cameras. What the coding signal was doing is causing the CANON's 30FPS (something like that) count to go off-kilter and be irratic making the playback unviewable. Yet, CANON tapes could be played in the SONY with no problem.
 
Posted by Brian Michael Weidemann (Member # 2243) on 11-11-2005, 03:37 AM:
 
Numbers 1, 2, and 5 are the digital ones. 3 is the mix.

It's not a matter of quality loss. Analog rips, with a clean enough line and a decent sound card, will be, for all intents and purposes, the same sounding signal. I, for one, never claimed that there would be a discernable difference. My system, which is not too shabby, didn't lend any help hearing the difference. After monitoring the files at various EQ settings, the only real thing I perceived at all was that the mixed one had subtle changes in the bass that the others didn't. Or maybe I was trying to hard to hear the differences.

I admit, I cheated slightly. [Big Grin] [Razz]
 
Posted by Joe Redifer (Member # 3) on 11-11-2005, 04:47 AM:
 
Brian wins!

 -

test1.wav = digital
test2.wav = digital
test3.wav = mix
test4.wav = analog
test5.wav = digital

Good job.

PS - You suck.
 
Posted by Leo Enticknap (Member # 534) on 11-11-2005, 12:18 PM:
 
Sophos has released a removal tool for the Sony shite.

I did run it after remembering that I'd recently updated the file transfer software for my minidisc Walkman. But it came up clean, so presumably Sony is only putting the malware on its music CDs.
 
Posted by Daryl C. W. O'Shea (Member # 1303) on 11-11-2005, 04:09 PM:
 
Sony provided the top 5 vendors code to remove their crap the other day. They've probably all got tools out to take care of it now.
 
Posted by Bobby Henderson (Member # 840) on 11-11-2005, 06:37 PM:
 
Tools to take care of it without toasting your CD or DVD drive?

In a parallel story, several lawsuits against Sony and Bertlesman have been filed in California. A few have been filed in Europe as well.

I hope this arrogant hatred against customers costs them a shitload of money.
 
Posted by Daryl C. W. O'Shea (Member # 1303) on 11-11-2005, 10:38 PM:
 
quote: Bobby Henderson
Tools to take care of it without toasting your CD or DVD drive?
The tools currently only un-hide the crap so that trojans (like this one ) & viruses can't exploit it. AFAIK, they don't yet modify the cd-rom driver stack.
 
Posted by Bobby Henderson (Member # 840) on 11-15-2005, 09:25 AM:
 
quote: Daryl C. W. O'Shea
Wait till Sony figures out BSD. There are rootkits out there that affect Macs too, such as this one from last year...
Apparently Sony already figured out BSD, or rather, they hired another firm to do it. Here's a nice article that may shock some Mac users:
Sony DRM Mac Rootkit
quote:
Sony's DRM Rootkit Comes in Mac Flavor, Too
By Larry Loeb
November 11, 2005
Opinion: Sony says it will discontinue distribution of its DRM software, which could pose a "rootkit" security threat to users. But does that include the OS X version?

Sony is reportedly pulling its digital rights management "rootkit" from the market. But it isn't reporting everything.

"The Sony copy-protection software does not install itself on Macintosh computers or ordinary CD and DVD players," Reuters reported today. There's just one problem with that statement: it happens to be flat-out wrong. While the XCP version of copy protection is for Windows, there is another Mac-only version of copy protection installed by Sony/BMG CDs.

To establish this point, one simply has to refer to a poster on the popular Macintosh site MacInTouch. The poster notes that Imogen Heap's new CD, "Speak for Yourself," on RCA Victor (a BMG subsidiary), has an extra partition for "enhanced" content. Along with Windows files, there is a Mac file present called "Start.app."

When run, a EULA is first displayed (which does inform the user that software is going to be installed without saying exactly what that software will do).

The user then is prompted by the program for a user name and password. After that information is provided, the program seemingly quits. However, it actually installs two kernel extensions, PhoenixNub1.kext and PhoenixNub12.kext, in the OS X system files.

These turn out to be part of a DRM codebase developed by SunnComm.

According to the SunComm Web site, their MediaMax DRM allows for a limited amount of CD burns from the source material, and then will block further copying. The DRM also can make time-expiring (or number-of-play-expiring) copies of the tracks.

Repeated calls to SunComm for comment were not returned by the time this article was posted.

So, while Sony may be backing down from its acts regarding Windows modification, it is yet to be seen whether the recent firestorms will cause it to pull the DRM installed on Macs.

Apparently no operating system in existence can be considered a sure fire "security blanket."

quote: Daryl C. W. O'Shea
AFAIK, they don't yet modify the cd-rom driver stack.
Here's the passage from PC Magazine's first Security Watch bulletin "Sony CDs Make Your PC Play the Blues."
Linky

quote:
That's not the only problem with the First 4 Internet software. According to Russinovich, the software inserts itself into the CD-ROM driver stack in a way that a naive attempt by a user to remove it could result in making the CD-ROM drive unusable. Furthermore, many of the drivers in the First 4 Internet product are installed to run even when the system boots into safe mode, meaning that if a bug in the drivers interferes with the system or makes it unbootable, it could be very difficult to remove.
Further articles I've read suggest that if you know how to hack around in the registry really well you can fix what the Sony DRM software changes to properly restore all CD or DVD drive functions. But most ordinary users don't know how to do that. I wouldn't even know where to begin for fixing what it might damage on the Mac platform.
 
Posted by Daryl C. W. O'Shea (Member # 1303) on 11-15-2005, 12:02 PM:
 
I meant "AFIAK, they don't yet modify the cd-rom driver stack" when removing their crap. ie. the stack mods are left in place. The removal tools just un-hide the stuff so trojans can't hide behind it.
 
Posted by Joe Redifer (Member # 3) on 11-15-2005, 02:05 PM:
 
quote: Bobby Henderson
Apparently no operating system in existence can be considered a sure fire "security blanket."
What about Mac OS 9? That still ships installed on new Macs.
 
Posted by Jason Burroughs (Member # 68) on 11-15-2005, 04:20 PM:
 
Apparently the Sony provided removal tools only make the security risk even worse. They open the computer up to accepting executable code from internet resources, without even attempting to restrict who can submit such code. Even then such restrictions are easy to subvert.

http://www.msnbc.msn.com/id/10053831/

Microsoft has also issued tools to remove the malware. Everyone that was effected by this gross invasion of privacy should band together and issue a class action lawsuit against Sony and First 4 Internet Ltd.

[fu] Sony
 
Posted by Joe Redifer (Member # 3) on 11-15-2005, 06:00 PM:
 
Class action lawsuits will only bring you a $5 coupon good towards any Sony music CD. They win either way. There is no way to stop corporate America from doing evil things like this and certainly no way to make companies regret doing such things.
 
Posted by Bobby Henderson (Member # 840) on 11-15-2005, 06:46 PM:
 
quote: Joe Redifer
What about Mac OS 9? That still ships installed on new Macs.
Really? I thought Apple stopped shipping System 9 with new Macs early last year. The classic OS is not mentioned as being available for any new Mac system. OSX Tiger seems to be the only option.
 
Posted by Kyle McEachern (Member # 2250) on 11-15-2005, 07:01 PM:
 
It didn't come installed on mine, but as a separate disc that could be used to install it if desired (This was this past February).
 
Posted by Cory Isemann (Member # 2517) on 11-16-2005, 07:53 AM:
 
From CNN Money


Sony BMG recalls copy-protected CDs
Computer viruses had emerged that took advantage of security holes in the copy protection software.
November 16, 2005: 5:56 AM EST

AMSTERDAM, The Netherlands (Reuters) - Music publisher Sony BMG, yielding to consumer concern, said Wednesday it was recalling music CDs containing copy-protection software that acts like virus software and hides deep inside a computer.

"We share the concerns of consumers regarding discs with XCP content-protected software, and, for this reason, we are instituting a consumer exchange program and removing all unsold CDs with this software from retail outlets," Sony BMG said in an statement.

The XCP software used by Sony BMG, which was developed by British software developers First4Internet, leaves the back door open for malicious online hackers.

Sony BMG, in a separate statement, also announced it would distribute a program to remove the software from a PC where it jeopardizes security.

"We deeply regret any inconvenience this may cause our customers. Details of this (recall) program will be announced shortly," Sony BMG said.

The withdrawal is set to affect millions of compact discs from artists such as Celine Dion and Sarah McLachlan but Sony did not give exact figures or the names of the artists affected.

Sony reiterated that the copy-protection software only installs itself on personal computers and not on ordinary CD and DVD players.

Microsoft Corp.'s anti-virus team said Tuesday it would add a detection and removal mechanism to rid a personal computer of the Sony's DRM copy-protection software. The software installs itself only on PCs running Microsoft's Windows operating system.

Viruses emerge
The flaws of the copy-protection software became acute last week, when the first computer viruses emerged that took advantage of the security holes left by the program.

Responding to public outcry over the software, the music publishing venture of Japanese electronics conglomerate Sony Corp. (Research) and Germany's Bertelsmann AG had said Friday it would temporarily suspend the manufacture of music CDs containing XCP technology.

It then provided a patch to make the hidden program more visible. At the time it did not recall the CDs or offer a program to remove it from computers. The initial measures still left PCs vulnerable, according to software engineers.

The program will have installed itself on a Windows-operated personal computer when consumers wanted to play certain Sony BMG music CDs. The program forces consumers to use a music player that comes with the program.

Sony BMG has positioned itself as a defender of artists' rights. It re-emphasized Friday that copy-protection software is "an important tool to protect our intellectual property rights and those of our artists."

Sony BMG last week was targeted in a class action lawsuit complaining that it had not disclosed the true nature of its copy-protection software.
 
Posted by Bobby Henderson (Member # 840) on 11-16-2005, 09:20 AM:
 
quote: Cory Isemann
The withdrawal is set to affect millions of compact discs from artists such as Celine Dion and Sarah McLachlan but Sony did not give exact figures or the names of the artists affected.
If Sony isn't going to be specific on which titles are affected how will customers know which discs to exchange? Doh!
[Roll Eyes]

Remember the good old days when a disc exchange was made to fix low to non-existent bass (DTS Jurassic Park DVD) or wrongly matted widescreen (Back to the Future II & III discs)?
 
Posted by David Stambaugh (Member # 1102) on 11-16-2005, 01:22 PM:
 
This is a pretty embarrassing (and costly) blow to Sony. Dumb shits! I said earlier in this thread that they needed to distance themselves from this. Looks like that's what they're doing, albeit it a little late. [Roll Eyes]

I'm not usually a big fan of class-action suits because most of them seem frivolous. In this case though I hope Sony gets its clock cleaned. [fu] But the "victims" will probably get coupons for $2 off on their next CD purchase. [Mad]
 
Posted by Mike Blakesley (Member # 26) on 11-16-2005, 01:46 PM:
 
quote:
If Sony isn't going to be specific on which titles are affected how will customers know which discs to exchange? Doh!

There is a logo on the upper left corner of each "protected" disk box, plus all the usual "system requirements" crap on the back.
 
Posted by Daryl C. W. O'Shea (Member # 1303) on 11-16-2005, 06:23 PM:
 
This non-media article demonstrates the scale of Sony's infections, which rival some worm's infection rates. With images showing infections across the globe! Interestingly, the infections are only significant in North America.

quote: http://www.doxpara.com/?q=sony
Welcome To Planet Sony
Submitted by Dan Kaminsky on Tue, 2005-11-15 09:28.

Sony.

Sony has a rootkit.

The rootkit phones home.

Phoning home requires a DNS query.

DNS queries are cached.

Caches are externally testable (great paper, Luis!), provided you have a list of all the name servers out there.

It just so happens I have such a list, from the audits I've been running from http://deluvian.doxpara.com.

So what did I find?

Much, much more than I expected.

It now appears that at least 568,200 nameservers have witnessed DNS queries related to the rootkit. How many hosts does this correspond to? Only Sony (and First4Internet) knows...unsurprisingly, they are not particularly communicative. But at that scale, it doesn't take much to make this a multi-million host, worm-scale Incident. The process of discovering this has led to some significant advances in the art of cache snooping. Here are some of the factors I've dealt with:

* Just because you *request* the disabling of recursion, doesn't mean it'll actually happen. A full 353,200 name servers had to be excluded from the final tally because not only would recursive queries emit from them whether or not they were desired, but they'd also notify their neighbors of the results.
* Low TTL names exist, and are rather difficult to catch by cache snooping (they expire before you can find proof of life). However, they may be hosted by names that last much longer -- updates.xcp-aurora.com has a lifespan of an hour, but xcp-aurora.com's NS link to resolver1.first4internet.co.uk will last 150,000 seconds.
* Some hosts lie -- captive portals, I'm looking at you. Simply filtering TTL's that are divisible by 100 has a way of eliminating most of them; after that, you're left with surprisingly few NS's that lie about IP.

I also have an IP->Geographic data, courtesy of Mike Schiffman's libipgeo and the fine folks at IP2Location, who have a very impressive database. So, the first thing I did was geolocate the data. After dispensing with the raw stats gather...

What can I say? Pretty pictures. Ugly data, but pretty pictures!

* USA
* Asia
* Europe

And the tool used to make this? Welcome To Planet Sony! (based on Partiview in general and the always awesome PlanetLab's work in particular)


 
Posted by James R. Hammonds, Jr (Member # 673) on 11-17-2005, 02:46 PM:
 
Sony published a list but I question how comprehensive it is.
It does not list "Z" by My Morning Jacket but the band has information on their website addressing the issue.
It's too bad.
I like the My Morning Jacket album and would like to buy the latest from The Coral as well.
I guess Sony will just have to deal with me pirating them instead.
 
Posted by Bobby Henderson (Member # 840) on 11-18-2005, 02:00 PM:
 
Tom's Hardware website has a nice chronology article on the whole XCP thing at this link.

The latest embarassing wrinkle is First 4 Internet apparently repurposed a number of software libraries from other applications, such as LAME, in the XCP and CD multimedia package. Some libraries were open source and had legal requirements that stipulated any applications reusing that code also had to be open source. Obvious copyright infringement there. Look for more lawsuits to be filed.

I'm wondering if any of those Hollywood lawyers and various business types shaping Blu-Ray and HD-DVD are watching this story develop. It's fairly certain the XCP debacle could influence the final shipping versions of Blu-Ray and HD-DVD.
 
Posted by Christian Appelt (Member # 1067) on 11-20-2005, 03:27 PM:
 
Here's another link with a list of CDs:

Welcome to the Sony BMG XCP Exchange program [Big Grin]
 
Posted by Bruce Hansen (Member # 281) on 11-20-2005, 09:35 PM:
 
I hope that Sony's incredible greed ends up costing them big time. It's just too bad that Sony, and other greedy corporations will not learn from this. Their overwhelming greed makes them stupid.
 
Posted by Adam Wilbert (Member # 1184) on 11-21-2005, 01:43 AM:
 
quote: Bobby Henderson
Some libraries were open source and had legal requirements that stipulated any applications reusing that code also had to be open source. Obvious copyright infringement there.
oh the irony. Copyright infringement to prevent copyright infringement. [Big Grin]
 
Posted by Monte L Fullmer (Member # 2797) on 11-21-2005, 05:01 AM:
 
(Sorry Brad ..whoops, forgot to add in the story..Monte)

[ 11-22-2005, 02:46 AM: Message edited by: Monte L Fullmer ]
 
Posted by Paul Mayer (Member # 355) on 11-21-2005, 05:08 PM:
 
I love it. [evil] The State of Texas is suing Sony for violations of the new Texas Anti-Spyware Law:

quote:
Texas Sues Sony Under Anti-Spyware Law
Texas Sues Sony BMG Music Entertainment Under Its New Anti-Spyware Law

The Associated Press

AUSTIN, Texas Nov 21, 2005 — The state sued Sony BMG Music Entertainment on Monday under its new anti-spyware law, saying anti-piracy technology the company slipped into music CDs leaves huge security holes on consumers' computers.

The lawsuit is over the so-called XCP technology that Sony had added to more than 50 CDs to restrict to three the number of times a single disc could be copied.

After a storm of criticism, Sony recalled the discs last week.

To enforce the restrictions, the CD automatically installed the copy-protection program when discs were put into a PC a necessary step for transferring music to iPods and other portable music players.

Attorney General Greg Abbott accused Sony BMG of surreptitiously installing "spyware" in the form of files that mask other files Sony installed as part of XCP.

This "cloaking" component can leave computers vulnerable to viruses and other security problems, said Abbot, echoing the findings of computer security researchers.

"Sony has engaged in a technological version of cloak-and-dagger deceit against consumers by hiding secret files on their computers," Abbott said in a statement.

The term "spyware" has been used broadly to cover programs that are installed without users' full knowledge and consent, whether or not they actually spy on a user's activities.

A Sony BMG spokesman didn't immediately return a call Monday morning.

Sony BMG initially rejected the uproar over XCP as technobabble.

But after security experts discovered that XCP opened gaping security holes in users' computers as did the method Sony BMG offered for removing XCP Sony BMG agreed last week to recall the discs.

Some 4.7 million had been made and 2.1 million sold. CDs that had XCP included releases by Van Zant, The Bad Plus, Neil Diamond and Celine Dion.

Abbott said some CDs remained in Texas stores as of Monday morning.

The Texas spyware law allows the state to recover damages of up to $100,000 in damages for each violation.

Abbott said there were thousands of violations, and that any money would go to the state.


 
Posted by Louis Bornwasser (Member # 3063) on 11-21-2005, 07:13 PM:
 
Speaking as a person who actually still buys DVD/CD at the store....I guess I will wait a year or so for all the garbage discs to be returned. Can you spell market recession?

A $5 off coupon will never be accepted as a settlement in any law suit. That is a promotion; not a payment. Louis
 
Posted by Adam Wilbert (Member # 1184) on 11-21-2005, 07:56 PM:
 
quote:
to restrict to three the number of times a single disc could be copied.

Hold on, who the heck has to put the cd into their computer three times to make multiple copies? Isn't that the beauty of digital files, no generation loss?
 
Posted by Monte L Fullmer (Member # 2797) on 11-22-2005, 02:46 AM:
 
Let's try it again: - Monte

CNET page

quote:
It was a grand experiment that failed miserably: As a means of copy-protecting its music, Sony employed a piece of software from First4Internet. But the technology, as used by Sony, did two bad things: First, it hid itself on computers by using root-kit technology; and second, it opened a remote access connection that called out to Sony (or one of its agencies). This exposed users' computers to worms that took advantage of the stealth technology.

Sony has agreed not to put root-kit technology on future music CDs as a means of protecting its copyrights. But this story is far from over. There are at least two lawsuits pending. There are also viruses poised to take advantage of already-infected PCs worldwide, the number of which may be much higher than anyone previously thought. Worse, Sony's fix for the problem may not be any more secure than the original root kit.

In case you missed it
Here's how users get stuck with the Sony root kit: When they first inserted certain CD titles from Sony BMG onto a desktop or laptop PC, a brief End User License Agreement flashed on the screen before they could listen to the music. Most people just agreed to the EULA so that they could get to the music. But by agreeing, they also consented to having additional software installed on their computer. That software, produced by First4Internet, hid itself and opened the remote connections.

The problem with root kits is that they are well known to criminal hackers (crackers), and they are all but invisible to most off-the-shelf antivirus apps available today.

By definition, that's a root kit. The problem with root kits is that they are well known to criminal hackers (crackers), and they are all but invisible to most off-the-shelf antivirus apps available today. The infected Sony CDs have been out in the world since last spring, but researchers such as Mark Russinovich at SysInternals and more recently, antivirus vendor F-Secure began wondering whether virus writers would soon exploit this in some fashion.

Exploited
They did. Word of the Sony root kit surfaced in the first week of November, and starting on November 10, several viruses began to appear. Breplibot.c is one of several that attempted to go undercover using the Sony root kit. While a serious threat nonetheless, coding errors (perhaps because the criminal hackers worked in great haste) prevented the malicious part of the code from activating.

There is now hard data available
Now that Sony has agreed to stop producing CDs with a stealthlike DRM software embedded, one would think the threat would go away. It won't. Security Researcher Dan Kaminsky, a frequent speaker at Black Hat, has done some fascinating research into Domain Name Service servers and the related security threats potential to them. Recently, Kaminsky posted what the Sony root kit might mean in terms of sheer numbers of people infected. The data isn't good from a security standpoint.

Kaminsky started with a very basic premise: Sony has a root kit; all root kits phone home; phoning home requires a DNS query; DNS queries are cached. From this simple theory, Kaminsky was able to query roughly 3 million Domain Name Service servers to find traces or signatures of Sony root kits calling from their desktop and laptop PC clients back home to Sony (or some other agency) host servers. He didn't find a few thousand, nor a hundred thousand. Kaminsky found roughly 568,200 DNS servers that have signatures of the Sony root kit calling home. He states that from this figure, he can't conclusively determine how many hosts that translates into--only Sony and First4Internet know that number.

"0wned" by Sony
Kaminisky has translated his data into a satellite image of Earth; here's a graphic of Sony-owned North American PCs. As mentioned, Sony has stopped production of music CDS and has offered to replace CDs already purchased with CDs sans DRM software, but the company has yet to state how it proposes to remove the remote-access Trojans from the roughly half-million infected PCs.

Also, the patch, offered by Sony, apparently causes more harm than good. Finnish security researcher Muzzy reported that in removing the First4Internet root kit, new ActiveX code is installed. The new code, called CodeSupport, doesn't restrict itself to Sony or First4Internet; instead, someone could write an exploit for CodeSupport that directs new traffic to a cracker's domain. First4Internet is apparently aware of this and may soon offer a fix to its patch.

But wait, there's more
While First4Internet's root kit has enjoyed the lion's share of media, there's a secondary software package used by Sony to protect its assets, SunComm's MediaMax. The site Free to Tinker has reported that MediaMax uses spywarelike behavior, although it does not hide itself the way the First4Internet software does. And security company ISS is reporting new vulnerabilities for those still infected with the original Sony root kit.

Perhaps someday vendors will understand that my PC is a temple, and I (and only I) decide what should be running on it.

Looking ahead, what would happen if rival companies started installing root kits on consumer's PCs--say, you buy one CD from Sony and another from Warner. According to F-Secure's blog site, in order for any root kit to hide itself, it must interface with the operating system kernel on a very low level, one that leaves no room for error. But what happens if you buy CDs from two competing manufacturers? Installing one root kit on top of another could lead to a very unstable situation. I say could, because this is all theoretical at this point. News.com has collected a variety of "what this might mean" stories regarding the Sony root-kit fiasco here.

I suspect we'll see more exposure of business practices like this in the near future. Antivirus companies are getting better at finding and exposing root kits, and brand-name vendors may find themselves, like Sony, having to answer for their past actions. Perhaps someday vendors will understand that my PC is a temple, and I (and only I) decide what should be running on it.

By Robert Vamosi
Senior editor, CNET Reviews
November 18, 2005



 
Posted by Leo Enticknap (Member # 534) on 11-22-2005, 03:42 AM:
 
quote: Daryl C. W. O'Shea
Interestingly, the infections are only significant in North America.
The infected CDs were only officially sold in the US, according to one newspaper report I read. Some batches did find their way into Europe via specialist importing record shops and individual consumer orders through online retailers (e.g. Amazon): but not that many, if these infection rate stats are an accurate indication.

Edit (to avoid replying to myself): The Electronic Frontier Foundation of California is joining the party and also taking Sony to court. Story here (link to BBC Online story of 22 Nov 05 reporting the EFF's court action).

[ 11-22-2005, 07:09 AM: Message edited by: Leo Enticknap ]
 
Posted by Joe Redifer (Member # 3) on 11-22-2005, 07:56 AM:
 
quote:
The problem with root kits is that they are well known to criminal hackers (crackers), and they are all but invisible to most off-the-shelf antivirus apps available today.
I take much offense to this sentence! It is extremely racist and I am calling it out. To insinuate that all hackers are white is racist enough as it is, but to use the derogatory term "crackers" is extremely hateful and contemptuous! Just because my people used to "crack" the whip unto the black man is no reason to refer to us as "crackers" in this day and age. Ever notice how any non-black person is highly admonished and/or beaten when they use the word "nigger"? I think any non-white individual who uses the term "cracker" should have their computers hacked in to!
 
Posted by Jeremy Fuentes (Member # 2135) on 11-22-2005, 08:34 AM:
 
 -
 
Posted by Bruce Hansen (Member # 281) on 11-22-2005, 11:31 AM:
 
I have to wonder if Sony pre-loaded this software on their computers? Just in case the answer is yes, I don't think I will be buying a Sony computer any time soon.

When I checked my email just now, I found about 20 emails that were made to look like they came from the FBI, the CIA, and ISPs trying to get me to open an attachment. I would guess that these attachments contain a virus or worm or spyware that will use the Sony "hole" to do some nastyness to my computer. It looks like the "stuff" is just beginning to hit the fan. I hope that Sony is just about put out of business over this crap. They deserve it.
 
Posted by Jason M Miller (Member # 2597) on 11-22-2005, 01:53 PM:
 
Tape works: InformationWeek

quote:
Sony BMG Music's controversial copy-protection scheme can be defeated with a small piece of tape, a research firm said Monday in a demonstration of the futility of digital rights management (DRM).
According to Gartner analysts Martin Reynolds and Mike McGuire, Sony's XCP technology is stymied by sticking a fingernail-size piece of opaque tape on the outer edge of the CD.

That, the pair said in a brief posted online, renders "session 2 -- which contains the self-loading DRM software — unreadable. The PC then treats the CD as an ordinary single-session music CD, and the commonly used CD 'rip' programs continue to work as usual."

Such simple work-arounds, said Reynolds and McGuire, make Sony's decision to copy protect is music CDs an even bigger mistake. "Sony BMG's DRM technology will prevent neither informed casual copiers nor high-volume 'pirates' from doing whatever they like with the content the disc," the analysts continued. "It does, however, load 'stealth' software — software that has been demonstrated to have suspect effects — on uninformed users' machines.

"The bottom line: Sony BMG has created serious public-relations and legal issues for itself, and for no good reason."

Only after 10 days of mounting criticism about its surreptitious installation of a hacker-style "rootkit" to users' PCs did Sony announce that it would end the copy-protection; a week later it said it would recall all unsold CDs and exchange those already in consumers' hands with unprotected discs.

Sony's exchange program also gives buyers of the 52 in-question CDs the option of receiving unprotected MP3 files of the album's tracks, in large part because the disc exchange process takes three to six weeks.

Those users will receive an e-mail directing them to a site where they can download the MP3 files, Sony said on its exchange program Web page.

This isn't the first time that simple methods have defeated a Sony copy-protection plan. An earlier technology that Sony used could be circumvented by using a black marker to draw a line near the edge of the disc.

"After more than five years of trying, the recording industry has not yet demonstrated a workable DRM scheme for music CDs," concluded the Gartner analysts. "It will never achieve this goal as long as CDs must be playable by stand-alone CD players."


 
Posted by Scott Norwood (Member # 30) on 11-22-2005, 02:08 PM:
 
None of this would be an issue of people would just turn off Windows' stupid autorun "feature." The last thing you want when inserting a CD into your computer is for some random (and possibly malicious) software to run without user intervention. Since many people have set up their Windows user accounts to have full administrator-level permissions, the problem is just that much worse.
 
Posted by Bobby Henderson (Member # 840) on 11-22-2005, 06:23 PM:
 
Another recommendation is to do most general computing work using a login with limited permissions. Most Windows machines are setup by default with logins featuring full admin rights. Kinda risky.

But back to the Sony DRM thing. These entertainment companies have been told by critics until the critics were blue in the face that playing "prevent defense" by using DRM schemes is going to get them nowhere. You're only going to get more customers to buy a product by putting more value into it. A bare bones music CD just doesn't seem worth $20 when other kinds of products in the same price range offer so much more.

I remember when vinyl records were sold the customer would often get some additional stuff with the purchase, such as posters and other goodies. You don't get that with a CD. Naturally you can't physically fit a big poster into a CD case. But some added value needs to be included to provide more incentive for customers to buy the legit CD. Penalizing customers who actually bought the disc with malware style DRM software is a very stupid manuver. Even if the software itself doesn't turn out to be very harmful, it sends out an extremely hateful anti-customer message.
 
Posted by David Stambaugh (Member # 1102) on 11-22-2005, 06:50 PM:
 
I bet almost none of the people who frequently copy music care about extras like posters or cover art. All they want is free music and they don't understand or care what the big deal is with piracy or intellectual property rights. "I can copy it for free so why the hell should I pay for it? End of discussion." They might throw out the line "I wouldn't buy it anyway, so I'm not stealing it by copying it." Ethics registers a perfect "0".

In very rare cases they might actually buy a CD but it has to be an artist they're really fanatical about, not just "routine" music that they happen to like.
 
Posted by Leo Enticknap (Member # 534) on 11-23-2005, 02:02 AM:
 
A while back the music industry floated the idea of releasing 'light' versions of music CDs at a reduced price. The idea was that they'd cost £2-3. The CD itself would be exactly the same pressing as the full price version, but it would come in a cardboard sleeve with only basic artwork and a track listing. Meanwhile, the full price version would have glossy packaging and extra crap thrown in, thereby giving consumers two product options for each release. The hope was that people who had previously made their own copies would henceforth buy the legit 'light' version. AFAIK the idea never went anywhere - probably because even £3 is around six times the cost of a blank. So, if you're the prepared to rip a CD off in principle, you're going to need more of an incentive than that to change your ways.

The root cause of this problem, IMHO, is that when the CD format was launched in the early '80s, no-one had any idea how easy it would become to make digital clones. Even in the late '80s, your typical PC at a high street store would have a hard disc capacity of 10-20mb: so in 1983, when the CD audio format was launched, the idea of PCs that could deal with 650mb at a time must have seemed like science fiction. In hindsight, we know that if the developers had paid any attention to Moore's Law, they'd have seen this coming. Making analogue copies of commercial music recordings and radio broadcasts had gone on ever since magnetic recording technology had been sold to domestic consumers. But the copies were usually of significantly lower quality, and could only be made in real time, thereby limiting the scale of the economic loss to the industry. Put simply, no-one ever foresaw a situation in which consumers would be able to 'clone' albums in 2-3 minutes and at virtually no up-front cost.

Two other factors are also clear: (i) that domestic copying of commercially published audio and video recordings is widely perceived to be a victimless crime; and (ii) that the technological approach to stopping it only works with a limited, technically less literate group of consumers.

I can't see any immediate hope of (i) changing any time soon. Sometimes public attitudes can be changed: for example, a friend of mine recalls that when he learnt to drive in the mid-60s, his instructor told him that 'it's probably best to leave the car at home if you're planning to have 5 or 6 pints, otherwise you may end up having to push it out of a ditch.' Now, of course, drink-driving is perceived as a taboo. If you casually mention over a coffee break that you drove home after drinking five pints the previous night, the reaction will probably be one of shock and hostility. But if you say that you listened to a CD which a friend copied for you, the response you'll probably get is: 'Oh, that sounds good; could you burn one off for me, too?'. But whereas public opinion was gradually convinced by the anti drink-drive arguments, they simply don't believe the music industry's claims that making one or two copies of a CD for friends or relatives damages artists' careers or supports drug smuggling and international terrorism.

So, given that neither technology nor PR is likely to significantly reduce domestic piracy any time soon, the industry is either just going to have to live with it and factor it in to its business planning, or come up with more attractive alternatives - it's as simple as that, as far as I can see.
 
Posted by Mike Blakesley (Member # 26) on 11-23-2005, 12:11 PM:
 
quote: Leo Enticknap
more attractive alternatives
There's the root of the problem. Can't beat "free."
 
Posted by Bobby Henderson (Member # 840) on 11-23-2005, 12:46 PM:
 
Yeah, but what are they getting for "free?"

Typically "free" means a lossy data compressed music file with fidelity hardly any better than what you hear over the radio airwaves. Often, uploaded and shared music files have the front and ends clipped and other nonsense mucking up the audio. Then you have the risk of getting various newly released trojans.

Still, a great deal of people see those compromises (and risks) as being no big deal compared to spending upwards of $20 for what they see as a plain, bare bones music only CD. And even these days, the LPCM audio quality on many of today's CDs is horrible. This is especially true for many rock and pop music recordings where the tracks are badly overdriven. You can open one of these tracks in an audio editor like Sound Forge and clearly see the audio clipping the red all over the place.

So, DRM? Nah. The music industry has a crappy product on average that badly needs improvement. For $15 to $20, I want a very good quality recording and other bonuses to go with it. The DualDisc format has a lot of great potential for its ability to combine standard CD content with DVD-V, DVD-A and SACD content. Unfortunately, the music industry isn't doing enough to promote good music production and disc mastering practices within its industry. It is doing absolutely nothing to educate customers about higher quality audio formats and the value they bring to a disc. The music industry could use that DualDisc format to make music discs seem worth buying again and make downloading MP3s suck by comparison.
 
Posted by David Stambaugh (Member # 1102) on 11-23-2005, 02:05 PM:
 
The general public has no interest in audio quality any better than what an iPod can do. Seriously, everyone where I work carries an iPod, and *nobody* is the least bit (heh) concerned that the audio quality isn't good enough. SACD etc. had their chance and failed miserably in the marketplace. Hell, I'm interested in audio quality and I don't own a single SACD. What would be the point in SACD unless I invest in a high-end audio system and acoustical room treatments (which my living room desperately needs).

There are a lot of good ideas being thrown around here, but the public has made it very clear that they don't care much about high quality, and they won't pay for anything they can get for free. [Shrug]
 
Posted by Daryl C. W. O'Shea (Member # 1303) on 12-07-2005, 09:54 AM:
 
More crap:

quote: cNet

New Sony CD security risk found
By John Borland, CNET News.com
Published on ZDNet News: December 6, 2005, 4:58 PM PT

Sony BMG Music Entertainment and the Electronic Frontier Foundation
digital rights group jointly announced Tuesday that they had found,
and fixed, a new computer security risk associated with some of the
record label's CDs.

The danger is associated with copy-protection software included on
some Sony discs created by a company called SunnComm Technologies. The
vulnerability could allow malicious programmers to gain control of
computers that have run the software, which is typically installed
automatically when a disc is put in a computer's CD drive.

The issue affects a different set of CDs than the ones involved in the
copy-protection gaffe that led Sony to recall 4.7 million CDs last
month, and which has triggered several lawsuits against the record
label.

"We're pleased that Sony BMG responded quickly and responsibly when we
drew their attention to this security problem," EFF staff attorney
Kurt Opsahl said in a statement. "Consumers should take immediate
steps to protect their computers."

The announcement is the latest result of the detailed scrutiny applied
by the technical community to Sony's copy-protected discs, after a
string of serious security issues were found to be associated with the
label's antipiracy efforts.

The record label's copy-protected discs have been on the market for
more than eight months. But in late October, blogger Mark Russinovich
discovered that they surreptitiously installed a "rootkit" programming
tool. Rootkit tools are typically used by hackers to hide viruses on
hard drives, so Sony's move opened up a potentially serious security
hole.

The controversy escalated as other researchers discovered new security
flaws associated with the copy-protected CDs, which used technology
from British company First 4 Internet. Virus writers began
distributing malicious code that took advantage of the holes. The
label recalled all the discs with the First 4 Internet technology
installed, offering an exchange program for consumers who had
purchased any of the 52 CDs affected.

Following those revelations, the EFF asked computer security company
iSec Partners to study the SunnComm copy protection technology, which
Sony said has been distributed with 27 of its CDs in the United
States. iSec found the hole announced Tuesday and notified Sony, but
news of the risk was not released until SunnComm had created a patch.

Sony said another security company, NGS Software, has tested the patch
and certified that it addresses the vulnerability.

The patch can be downloaded from Sony's site. A list of the CDs
affected in the United States, and a slightly different list in
Canada, is also posted on the site.

Sony said it will notify customers though a banner advertisement
directly in the SunnComm software, as well as through an Internet
advertising campaign.


 
Posted by Bobby Henderson (Member # 840) on 12-07-2005, 10:33 PM:
 
Great. More rootkit shit from Sony. SunnComm even had a MacOSX version of that nonsense. Pushing around customers who actually bought the damned CD is just freaking insane. It gives people even more reason to download music illegally -or just buy the one good song off a disc from iTunes for just 99 cents.

quote: David Stambaugh
There are a lot of good ideas being thrown around here, but the public has made it very clear that they don't care much about high quality, and they won't pay for anything they can get for free.
If that turns out to be true, then the music industry is doomed no matter what. They can fold up their tents, but be justified in shooting a pretty hateful middle finger at the general public for playing a huge role in allowing it to happen.

Still, I think the music industry can reverse some of those trends of they will bother to make efforts in the right places to do it. For now, they just don't get it. Until they do, the music industry will continue its slow and steady decline.
 
Posted by Bruce Hansen (Member # 281) on 12-08-2005, 06:12 PM:
 
Everything they put out today is crap, and it is all the same. It is all the same crap. On top of that, the recording quality is pure s**t. It is way over recorded, and very distorted. Add to that, the price is WAY too high. This is the resipe for the death of the industry. Now they are screwing around with people's computers. I hope Sony Music is put out of business over this. They deserve it.
 
Posted by Brian Michael Weidemann (Member # 2243) on 12-10-2005, 05:12 AM:
 
Music should just be banned altogether. No good has ever come from it. Look at all the difficulty and controversy involved. Books, too! Nothing created by anyone is ever going to be worth anything, so why even bother?

(Sorry, I think I was possessed by Joe for a second there!) [Big Grin]
 
Posted by Joe Redifer (Member # 3) on 12-10-2005, 11:21 AM:
 
Nah man. There is good music these days, but much of it comes from Japan in the form of videogame soundtracks. They beat the crap out of US movie soundtracks and US music.
 
Posted by Frank Angel (Member # 248) on 12-10-2005, 06:47 PM:
 
iTunes....hmmm. I have a friend who claims that when you purchase iTunes and load them from the player into your computer, the firmware writes the computer's ID into the iTunes pod. He had amassed a library of a few hundred tunes that he had no trouble synchronizing between the pod and the computer. His hard drive subsequently failed, but no problem, the tunes were all nicely copied on his pod.

So he bought a new computer and when he tried to upload the tunes back to new computer, he found to his surprise and a bit of a dismay, they wouldn't transfer from the pods back to the new computer. The pod knew it was not the computer which it was originally synced to, and it refused to upload his already bought-and-paid-for-in-full iTunes. So you say, OK, that's understandable, they don't want everyone going around giving off all those bought tunes to someone else's computer who didn't buy them.

Ah, but the Gestapo tactics don't stop there -- when he tried to upload them a second time, the iTunes pod said "Illegal Transfer" and ERASED ALL HIS TUNES!! Now he has no tunes on either his computer or his pod. All gone, in the name of copyright protection.

You see, shit like this kinda gives you a bit of an insight into the mind of the schlub who walks into a music conglomerate's corporate headquarters brandishing an Uzi and just starts spray firing anything and everything in sight.
 
Posted by Daryl C. W. O'Shea (Member # 1303) on 12-10-2005, 07:42 PM:
 
He can re-download them from iTunes or whatever it's called.

Unfortunately they have to do something to protect their content, otherwise there wouldn't be too many people licensing the stuff.
 
Posted by Bobby Henderson (Member # 840) on 12-10-2005, 10:09 PM:
 
But here's the rub:

In going too far with copy protection efforts, lots of customers just won't feel like buying the product in the first place.

That's how I feel with a lot of music CDs now. It's also how I feel with the upcoming next-gen DVD formats (Blu Ray and HD-DVD). All of the copy protection measures put into the product make them a liability to buy. I think I'll just spend my money on something else, or better yet just save it.
 
Posted by Randy Stankey (Member # 64) on 12-10-2005, 10:53 PM:
 
iTunes does, indeed, use "Digital Rights Management" on their downloadable music but:

1) Apple admits it up front.
2) No software is loaded onto the user's computer without consent.

The protection scheme that Apple uses does look at the serial number of the computer that's attempting to play the music but I doubt that anything in iTunes or the downloaded music files actually erases anything on the user's computer.

I have heard that, if iTunes malfunctions in a certain way, it can take out the music library but:

1) It's not intentional.
2) It's often recoverable.
3) I've never seen it happen, myself.

I have managed music on about a dozen computers using iTunes... Both Mac & Windows. I have seen some pretty STOOPIT people do some pretty brain-dead things to their computers. The two most common causes of problems with iTunes involve:

1) People moving or renaming the folder(s) that hold their music library.
2) Corruption/moving/renaming of the XML file that iTunes uses to keep track of the music library.

In every case, restoring the files to their original locations solved the problem. In the case of the XML file getting lost, it can be rebuilt in a pretty short time. The only things that REALLY get lost are the user's playlists and the playcount information.

As to iTunes not allowing files to be transferred between computers, you ARE allowed to do it but ONLY if the computer you are transfering to is "Authorized". When your friend bought the new computer he should have de-authorized the old one and authorized the new one. That problem wouldn't have happened, then. I.I.R.C. you are allowed to have up to 3 computers authorized at the same time. I don't believe that there is an overall lifetime limit to the number of times you may autorize and de-authorize any particular computer.

iTunes D.R.M. isn't that hard to crack, either. You can hit Google and find out how to do it in a fairly short time. However, few people even waste the time to crack the code because it's not as restrictive as most other kinds of D.R.M. Furthermore, simply burning the song to a CD then re-importing it removes the protection once and for all with only a negligable loss of quality.

The way I was told, Apple didn't even want to have D.R.M. on their downloads at first but they had to do it or else thee record companies wouldn't allow their stuff to be sold on iTunes.

So, whether you agree with iTunes' form of D.R.M or not, it all comes back to the record companies.
 
Posted by Mike Blakesley (Member # 26) on 12-11-2005, 12:20 AM:
 
You can also burn a CD from your iTunes library, and then you can 'rip' that music back to your hard drive and it's a plain ol' wav file, you can make as many copies of it (or of your burned CD) as you want.
 
Posted by Brian Michael Weidemann (Member # 2243) on 12-11-2005, 01:28 AM:
 
.mp3's to .wav sound just like .mp3's, and then converting them back to .mp3 makes them even more icky. I'm stickin' with store bought CD's, listened to on a CD player. Even when I rip them, I rip straight to .wav to make back-up CD's.
 
Posted by Bobby Henderson (Member # 840) on 12-22-2005, 12:08 PM:
 
Here's another new development on the Sony/BMG story:

Texas expands lawsuit against Sony/BMG

quote:
AUSTIN, Texas (AP) - Texas Attorney General Greg Abbott expanded his lawsuit against Sony BMG Music Entertainment on Wednesday, alleging that a second form of anti-piracy technology used by the label violates the state's spyware and deceptive trade practices laws.

Abbott sued Sony BMG in November, saying the world's second-largest music label surreptitiously included spyware on millions of CDs through technology known as XCP. That technology, included on 52 Sony BMG titles, could leave computers vulnerable to hackers, he said.

The new allegations involve an unrelated CD copy-protection technology known as MediaMax, which was loaded on 27 Sony BMG titles, including Alicia Keys' "Unplugged" and Cassidy's "I'm a Hustla."

"We keep discovering additional methods Sony used to deceive Texas consumers who thought they were simply buying music," Abbott said in a statement.

BMG officials said in a statement that they are working with Abbott's office and believe they can prove they have responded appropriately to his concerns.

"The security issues with MediaMax are not uncommon and are completely addressed by a software update which we already have made available, as is standard practice when problems with consumer software are identified," the statement said.

Anti-piracy technology restricts the number of times a single disc can be copied and can make it extremely inconvenient to transfer songs into the format used by Apple Computer Inc.'s iPods.

The MediaMax technology limits how many backup copies can be made of the CD on a computer or how the tracks can be shared with other users.

The Electronic Frontier Foundation, an online civil liberty group, discovered that, like XCP, MediaMax could allow an outsider to gain unauthorized access to a computer. Two weeks ago, Sony BMG began urging consumers to download a patch that would plug the potential security breach. About 5.7 million CDs were shipped with the software.

Abbott said MediaMax violates Texas law because some versions secretly install files when the CD is inserted into a computer, before the consumer has a chance to accept or decline a license agreement. The files can lead to the security breach.

Sony BMG misleads consumers by saying no files will be installed if the agreement is rejected, Abbott said, when, in reality, the installation already has occurred. It is difficult for consumers to remove the files, he added.

Sony BMG, which rejects the spyware description, said it has provided consumers with a one-click "uninstall" application that lets them remove MediaMax from their computers.

The label recalled the discs with XCP in November and released a way to remove the files from users' computers. Some 4.7 million CDs had been made with the technology and 2.1 million had been sold.

The state can recover up to $100,000 in damages for each violation of the spyware law and $20,000 in damages for each violation of the deceptive trade practices law. Individuals whose computers were affected by the anti-piracy technology also can recover damages.

Abbott has said that any money recovered by the state would go to Texas' general revenue fund.

Sony BMG is a joint venture of Sony Corp. and Bertelsmann AG.

Since several weeks have passed since this Sony rootkit scam first hit the news, I'm wondering if any business publications that track music industry sales have seen a noticeable downturn in sales over this problem.

The two camps in the HD-DVD and Blu-Ray format battle are trying to finalize their copy protection schemes. I'm wondering how those -cough- pay per view infrastructure -cough cough- I mean copy protection systems are going to be changed in light of the lawsuits.

No matter what scheme is developed, people on there in "cyberspace" will quickly crack the system. Piracy will still continue and the only people adversely affected by this stuff will be honest customers who actually bought the product. And that just makes me not want to buy at all.

Here's an analogy on it. I have a legitimately purchased upgrade of Adobe's Creative Suite 2 Premium package. It has all sorts of activation schemes in it that prevent me from running it on more than one computer simultaneously. It is limited to two installations and both computers have to be in my name. Compare that to a cracked version of Adobe CS2. I know people who have that on CD-R. They didn't pay for it, and they can install it on as many computers as they like. So, I, the honest customer, get lots of inconvenience out of the deal.

Usually bad customer service equals downturns in sales. Maybe that's why all those music companies have been merging with each other. Elminate competition so you can get away with bad customer service. But they're forgetting a critical thing. I make a living using Adobe's software. The music industry's product OTOH is not a necessity at all. I can do without it just fine.
 
Posted by Randy Stankey (Member # 64) on 12-23-2005, 09:59 AM:
 
So, let's just imagine:

I sell a product to people that somehow releases anthrax into the population without people knowing it. Later on, the authorities figure it out and take action against me so I recall the product. I throw my hands up and say, "Oops!"

I am threatened with legal action so, in an effort to cover my ass, I give out coupons for free doses of Ciprofloxacin. "All better!", I say to the public with a smile.

The difference is that people don't usually die when their computer gets a virus. But, the virus threat is out there and it's real. Not everybody who bought one of those infected disks knows they were exposed. Some people might not discover the problem for YEARS! Not everybody who knows they were exposed will seek the "antidote". Those disks will persist in the population for DECADES, lying dormant until some unsuspecting person sticks one into their computer! It's just like the way anthrax spores can lie dormant in the environment until a victim breathes them in!

I think the government should force Sony to recall EVERY copy and account for every single one of them at their own expense.

If it breaks the company... So be it!
 




Powered by Infopop Corporation
UBB.classicTM 6.3.1.2