About RSS
Search for: in 

Windows Watch - an XP & Vista blog

Trojan horse
CA's anti-spyware application refers to Sony's XCP as a Trojan horse
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

Computer Associates blacklists Sony DRM

Pressure mounts on Sony to abandon insecure technology

Tom Sanders in California, vnunet.com 10 Nov 2005
ADVERTISEMENT

Computer Associates has officially blacklisted the Sony BMG XCP Technology that the record label bundles with several of its audio CDs.

CA's PestPatrol anti-spyware application now offers users the ability to remove the application, which it refers to as a Trojan horse. 

The vendor justifies referring to the technology as a Trojan by pointing out on its spyware information website that XCP "installs without user permission, presenting only a vague and misleading end user licence agreement". 

XCP also changes the system configuration without the user's permission and silently modifies other program information or website content. CA has further alleged that Sony has failed to allow users to remove the tool.

The application is also accused of shortening the life span of the user's hard drive by performing a scan of system processes every 1.5 seconds.

Another widely publicised feature of the technology is a rootkit that hides the digital rights management technology from the system and the user.

The rootkit will actually hide any file, process or registry key that begins with the characters '$sys$', making it extremely easy for virus authors and hackers to hide malicious applications from virus and spyware scanners.

Sony has always denied that there are any security issues associated with the software.

The technology was designed by First 4 Internet, and is bundled with several of Sony's audio CDs. Roughly two million of the CDs have been shipped.

The Electronic Frontier Foundation has compiled a list of some of the offending CDs with instructions on how to prevent getting infected.

Users who seek to play the CD on their computer CDRom drive on a Windows machine are presented with a licence agreement.

While the licence discloses that software will be installed, it does not give details and falsely suggests that it can be uninstalled. Upon agreement, the rootkit and DRM technology is installed.

Sony has released a patch that removes the cloaking feature of the rootkit, but CA pointed out that the patch failed to resolve all security concerns.

To obtain the Sony uninstaller, users are also required to give out personal information that will be used by Sony BMG and undisclosed third parties.

IT securityRecord label backtracks after public outrage over cloaking technology  03 Nov 2005
Computer virusDodging the virus shield becomes big business as authors 'outsource' malware creation  19 Oct 2005

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
London, United Kingdom | MI5
Programme Managers - Project Managers -Project Support Staff - Competitive Salary + Excellent Benefits - London   Getting the best out of technology is critical to helping us protect the UK. Join MI5 and use ... more >
London, City of London, United Kingdom | Mulvaney Capital
 Senior SQL Developer - Hedge Fund - London  Experienced SQL based database developer sought to join systematic trading group. The role will focus on all aspects of automated data collection and database design, programming and ... more >
Oxford, Oxfordshire, United Kingdom | University of Oxford
Senior Business Analyst - Oxford University - £34,793 - £45,397   Business Services & Projects (BSP) Are you an experienced Business Analyst with the skills to improve the efficiency of Oxford University's business systems? The ... more >
Inverness, United Kingdom | NHS Scotland
CORPORATE SERVICES E-HEALTH DEPARTMENT  RAIGMORE HOSPITAL INVERNESS TECHNICAL DEVELOPMENT TEAM IT TECHNICAL SPECIALIST  £24,103 to £32,653 PA An exciting opportunity has arisen to join the technical development team within the eHealth Department. We are looking ... more >
More job opportunities
Join our fight for a fair deal when shopping online
ADVERTISEMENT