On mySimon: Meguiar's Gold Class Premium Car Wax
BNET Business Network:
BNET
TechRepublic
ZDNet

November 1st, 2005

Sony Music CDs surreptitiously install DRM Trojan horses on PCs

Posted by David Berlind @ 8:56 am

Categories: Digital Restrictions Management, Entertainment, General, Hardware Infrastructure, Mobile, Personal Technology, Software Infrastructure

Tags:

Reports are beginning to turn up around the Web that discuss how certain CDs from Sony Music come with a Trojan horse-based digital restrictions management (DRM) technology that surreptitiously installs itself as a rootkit on Windows PCs.   When software surreptitiously installs a rootkit, it’s usually doing so to cover its tracks — a technique commonly associated with malware such as viruses and Trojan horses.  Rootkits generally latch themselves onto the foundation or "roots" of an operating system in a variety of ways that not only prevent their detection, but also their extraction.  According to the Wikipedia’s definition," a rootkit is often used to hide utilities used to abuse a compromised system."

In a scary entry on his Sysinternals Blog posted yesterday (Halloween), Mark Russinovich provides an incredibly detailed account (many screen shots) of how his testing of the latest version of RootKitRevealer (a utility for exposing any installed rootkits) led to his own shocking discovery — that a rootkit had been surreptitiously installed on his own system. Wrote Russinovich of his surprise, "Given the fact that I’m careful in my surfing habits and only install software from reputable sources I had no idea how I’d picked up a real rootkit, and if it were not for the suspicious names of the listed files I would have suspected RKR to have a bug."

Upon further investigation Russinovich traced the installation to his usage of a Sony BMG music CD (Vant Zant Bros. Get Right with the Man) that he purchased through Amazon.com.  The CD’s listing page on Amazon.com says the CD is copy protected, but makes no mention that the copy protection is enforced by way of surreptitiously installed software.  According to some additional information regarding copy protection on Amazon’s site:

This product limits your ability to make multiple digital copies of its content, and you will not be able to play this disc or make copies onto devices not listed as compatible. Content/ copy protected CDs should allow limited burning, as well as ripping into secure Windows Media Audio formats for playback with most compatible media players and portable devices. In rare cases, these CDs may not be compatible with computer CD-ROM players, DVD players, game consoles, or car CD stereos, and often are not transferable to other formats like MP3.

In rare cases? DVD players? Car CD stereos? Is Sony BMG nuts? This is another DRM trainwreck just waiting to happen. In the Berlind household for example, CDs are played exclusively through the central 6-disc DVD player that’s a part of our whole-home theatre system. I can’t imagine buying a CD only to learn it doesn’t work.  By the way, have you ever tried to return a CD after you open it? (maybe the "R" in DRM should be for "Ripoff"?).

According to Russinovich, when played on a computer, the music can only be played using playback software that comes packaged with the CD (the implication is that usage of the media player is what resulted in the surrepititious installation of the rootkit).  Near the end of his thorough investigation Russinovich identifies at least one major problem that could result from Sony’s employment of DRM in this fashion:

The entire experience was frustrating and irritating. Not only had Sony put software on my system that uses techniques commonly used by malware to mask its presence, the software is poorly written and provides no means for uninstall. Worse, most users that stumble across the cloaked files with a RKR scan will cripple their computer if they attempt the obvious step of deleting the cloaked files.

Another question that comes to my mind is, given the way rootkits intercept certain system level functions, what will happen when some other music label uses a rootkit that’s different from the one used by Sony BMG. For example, if I already have one rootkit on my system that’s intercepting specific system level functions and another CD installs a different rootkit that attempts to intercept the same system level functions (essentially overwriting the first rootkit), will that interfere with my ability to listen any of my  DRM-protected CDs? 

Russinovich isn’t the only one who discovered the problem.  ZDNet reader Barry Ritholtz pointed me to his own account (see DRM crippled CD: A bizarre tale in 4 parts) of an encounter with a DRM protected CD (also from Sony): Morning Jacket’s Z.  In his tale of DRM woe, Ritholtz points out another restriction that turned up in with the CD’s Digital Restrictions Management technology. In what I’ll refer to as the third trainwreck of DRM, he can’t transfer the music to his iPod (I suspect that the same barrier to transferring music to the iPod will also prevent transfer to a Microsoft PlaysForSure-compliant device, but am not sure).  Ritholtz then discovers that the artists (Morning Jacket) aren’t exactly on-board with this idea and points to their official statement regarding the application of DRM technology to their music:

We at ATO Records are aware of the problems being experienced by certain fans due to the copy-protection of our distributor. Neither we nor our artists ever gave permission for the use of this technology, nor is it our distributor’s opinion that they need our permission. Wherever it is our decision, we will forego use of copy-protection, just as we have in the past. 

Z isn’t the only band that’s upset with the latest DRM developments.  Last month, CNN.com reported how a member of the band Switchfoot whose DRM-protected CD debuted at No. 3 on The Billboard 200 was equally disappointed.  Said Switchfoot guitarist Tim Foreman, "We were horrified when we first heard about the new copy-protection policy…. It is heartbreaking to see our blood, sweat and tears over the past two years blurred by the confusion and frustration surrounding new technology."

Even more demonstrative of the control points afforded to any market leading or dominating solution, the CNN story goes onto describe how Sony BMG is aware of the problems when it comes to transferring music from its DRM-protected CDs to iPods and is "urging people who buy copy-protected titles to write to Apple and demand that the company license its FairPlay DRM for use with secure CDs."  Even though Apple’s Fairplay may not have a monopoly yet, the company is behaving very monopolistically, an issue I discuss in another blog entry that I posted today.

What’s even more ironic about the application of copy protection to music CDs is how the record label is now providing a workaround to defeat it. In Part IV of his personal saga, Ritholtz provides the text of a workaround that was sent to him via email.  Of course, workarounds from the same people who applied the copy protection in the first place beg the question, why bother?  

In response, Ritholtz is apparently doing more than declaring inDRMpendence as I have been urging ZDNet’s readers to do.  He taking the economic punishment I’m suggesting one step further by refusing to buy some of Sony’s other products: namely a notebook and a big screen.  Now if only the rest of us could follow suit….

  • Talkback
  • Most Recent of 75 Talkback(s)
RE: Sony Music CDs surreptitiously install DRM Trojan horses on PCs
Best DVD Creator help you convert movies to DVD and burn DVD movie to DVD disc.... (Read the rest)
Posted by: gm52 Posted on: 08/26/09 You are currently: a Guest | | Terms of Use
Nice to see artists starting to rebel  tic swayback | 11/01/05
But wait, it gets worse  tic swayback | 11/01/05
you're blog well researched and thought out  alandee4 | 11/02/05
I would think...  lawryll@... | 11/01/05
Arrest the person repsonsible  voska | 11/01/05
Just make recordings on cassette tapes from the audio output.  Update victim | 11/01/05
They Want To Plug The Analog Hole Also  Edward Meyers | 11/01/05
Just curious: why is your handle hyperlinked?  Jeff Spicoli | 11/01/05
Because ZDNet is incapable of managing their own technology  tic swayback | 11/01/05
read story closer  alandee4 | 11/02/05
So who's getting criminally charged here  voska | 11/01/05
Yup  IT Scion | 11/01/05
Hmmm,  maldain | 11/02/05
What, no comment by No Ax yet  DarthRidiculous | 11/01/05
I'll definitely avoid Sony CDs  voska | 11/01/05
I enjoy buying many cd's today...  ju1ce | 11/01/05
Forget about Sony CDs.. What about...  Wolfie2K3 | 11/02/05
It gets. much, much worse - rootkit can disable your PC!  svanvuuren@... | 11/01/05
Here Come The Lawsuits  itanalyst | 11/01/05
Hardly  James T. Kirk | 11/01/05
Sony MUST be sued tro they last penny  Mectron | 11/01/05
wouldn't work  alandee4 | 11/02/05
Lawsuits  jbroche18 | 11/02/05
You should also provide  ordaj@... | 11/01/05
Sony: Public Enemy #1  otokichi | 11/01/05
Helpful Website - Please Read  itanalyst | 11/01/05
Even better  tic swayback | 11/01/05
hey tic  alandee4 | 11/02/05
James Sokolove, Where are you?  Update victim | 11/01/05
Swatting a fly with a sledgehammer...  jbroche18 | 11/01/05
So now they make CD not worth buying  voska | 11/01/05
Re: So now they make CD not worth buying  jbroche18 | 11/02/05
DMCA + Other laws anyone? Read for list: Class action lawsuit  Ironiclife | 11/01/05
Wanna clear example of just how GREEDY the media cartels are?  Jeff Spicoli | 11/01/05
Sony just turn in trash  Mectron | 11/01/05
It's a shame too..  Wolfie2K3 | 11/02/05
No need for workaround - use IsoBuster  FirstNLastN | 11/01/05
copyprotection as never worked  Mectron | 11/01/05
Remember when they tried to copy protect software?  maldain | 11/02/05
When no one buys copy protected software - there will be no ...  N5GAR | 11/05/05
They can't put MP3s on the disk  voska | 11/02/05
not a problem  shraven | 11/04/05
Bad Move.......  Andromedat6 | 11/01/05
Message has been deleted.  Andromedat6 | 11/01/05
Bad Move.......  Andromedat6 | 11/01/05
Bad Move.......  Andromedat6 | 11/01/05
Boycott Sony Music  TrustMe_z | 11/02/05
No Sony!! BAD SONY!!!  Moodog | 11/02/05
Another reason to boycott the whole industry.  b8zs4@... | 11/02/05
Isn't this a crime...?  ZzSmirKzZ | 11/02/05
Not enough  movie-crew | 11/02/05
We are reeping what we have sown  dcagle9891@... | 11/02/05
Contact Sony  b_bz@... | 11/02/05
The insanity just keeps going...  dcagle9891@... | 11/02/05
CDs?  raelalt | 11/02/05
i still use vinyl  alandee4 | 11/02/05
p.s.  alandee4 | 11/02/05
Word of this is spreading like wildfire!  dcagle9891@... | 11/02/05
Bad Sony!  RDavidD | 11/02/05
Record Labels Don't Care  papatator | 11/02/05
aghhhh  kevsan | 11/02/05
SonyBmg Fix Tool  conniedon1988@... | 11/02/05
If you believe that...  gopher_byrd | 11/04/05
So, is any of this illegal?  always-a-geek | 11/02/05
Sony is already running scared...  user905 | 11/02/05
where is the justice?  shraven | 11/04/05
This is illegal -- report it to the FBI  bblackmoor@... | 11/04/05
not just sony  diamondmask | 11/04/05
Complain to the FTC at http://www.ftc.gov  N5GAR | 11/05/05
One more reason to use VM  grillin_man | 11/09/05
Sony Music CDs  young-ed@... | 12/02/05
BEWARE of ANYthing Sony!!!  btljooz | 12/02/05
It?s not reaping what we sow?  b8zs4@... | 12/05/05
SONY trojan horse spyware  qcummer@... | 12/29/05
RE: Sony Music CDs surreptitiously install DRM Trojan horses on PCs  gm52 | 08/26/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here