Tag: Privacy
-
Does Sony's Copy Protection Infringe Copyrights?
The Sony copy protection debacle has so many angles that the mainstream press is having trouble keeping track of them all. The rootkit. The spyware. The other spyware. The big security hole. The other big security hole. It’s not surprising, then, that at least one important angle has gone nearly undiscussed in the mainstream press:…
-
Not Again! Uninstaller for Other Sony DRM Also Opens Huge Security Hole
I have good news and bad news about Sony’s other CD DRM technology, the SunnComm MediaMax system. (For those keeping score at home, Ed and I have written a lot recently about Sony’s XCP copy protection technology, but this post is about a separate system that Sony ships on other CDs.) I wrote last weekend…
-
Immunize Yourself Against Sony's Dangerous Uninstaller
Jeff Dwoskin and Alex Halderman have developed a simple tool that can immunize a Windows system against the dangerous CodeSupport ActiveX control that we have written about over the past few days. The immunization tool should disable CodeSupport if it is already on your system, and it should prevent any future reinstallation or reactivation of…
-
Update: Sony Uninstaller Hole Stays Open
Earlier today Ed Felten and I reported a serious security hole opened by the uninstaller that Sony provides to users who want to remove the First4Internet copy protection software. Further testing has confirmed that computers remain vulnerable even after the uninstall process is complete. Sony’s web-based uninstaller is a three step process: You fill out…
-
Sony's Web-Based Uninstaller Opens a Big Security Hole; Sony to Recall Discs
[This post was co-written by J. Alex Halderman and Ed Felten.] Over the weekend a Finnish researcher named Muzzy noticed a potential vulnerability in the web-based uninstaller that Sony offers to users who want to remove the First4Internet XCP copy protection software. We took a detailed look at the software and discovered that it is…
-
Don't Use Sony's Web-based XCP Uninstaller
Alex Halderman and I have confirmed that Sony’s Web-based XCP uninstallation utility exposes users to serious security risk. Under at least some circumstances, running Sony’s Web-based uninstaller opens a huge security hole on your computer. We have a working demonstration exploit. We are working furiously to nail down the details and will report our results…
-
Sony Shipping Spyware from SunnComm, Too
Now that virus writers have started exploiting the rootkit built into Sony-BMG albums that utilize First4Internet’s XCP DRM (as I warned they would last week), Sony has at last agreed to temporarily stop shipping CDs containing the defective software: We stand by content protection technology as an important tool to protect our intellectual property rights…
-
SonyBMG DRM Customer Survival Kit
Here’s a handy bag of tricks for people whose computers are (or might be) infected by the SonyBMG/First4Internet rootkit DRM. The instructions here draw heavily from research by Alex Halderman and Mark Russinovich. This DRM system operates only on recent versions of Windows. If you’re using MacOS or Linux, you have nothing to worry about…
-
SonyBMG "Protection" is Spyware
Mark Russinovich has yet another great post on the now-notorious SonyBMG/First4Internet CD “copy protection” software. His conclusion: “Without exaggeration I can say that I’ve analyzed virulent forms of spyware/adware that provide more straightforward means of uninstall.” Here’s how the uninstall process works: The user somehow finds the obscure web page from which he can request…
-
RFID, Present and Future
One of the advantages of teaching in a good university is the opportunity to hear smart students talk to each other about complicated topics. This semester I’m teaching a graduate seminar in technology and privacy, to a group of about ten computer science and electrical engineering students. On Monday the class discussed the future of…