Trojan horse
CA's anti-spyware application refers to Sony's XCP as a Trojan horse

Computer Associates blacklists Sony DRM

Pressure mounts on Sony to abandon insecure technology

Written by Tom Sanders in California, vnunet.com

Computer Associates has officially blacklisted the Sony BMG XCP Technology that the record label bundles with several of its audio CDs.

CA's PestPatrol anti-spyware application now offers users the ability to remove the application, which it refers to as a Trojan horse. 

The vendor justifies referring to the technology as a Trojan by pointing out on its spyware information website that XCP "installs without user permission, presenting only a vague and misleading end user licence agreement". 

Advertisement

XCP also changes the system configuration without the user's permission and silently modifies other program information or website content. CA has further alleged that Sony has failed to allow users to remove the tool.

The application is also accused of shortening the life span of the user's hard drive by performing a scan of system processes every 1.5 seconds.

Another widely publicised feature of the technology is a rootkit that hides the digital rights management technology from the system and the user.

The rootkit will actually hide any file, process or registry key that begins with the characters '$sys$', making it extremely easy for virus authors and hackers to hide malicious applications from virus and spyware scanners.

Sony has always denied that there are any security issues associated with the software.

The technology was designed by First 4 Internet, and is bundled with several of Sony's audio CDs. Roughly two million of the CDs have been shipped.

The Electronic Frontier Foundation has compiled a list of some of the offending CDs with instructions on how to prevent getting infected.

Users who seek to play the CD on their computer CDRom drive on a Windows machine are presented with a licence agreement.

While the licence discloses that software will be installed, it does not give details and falsely suggests that it can be uninstalled. Upon agreement, the rootkit and DRM technology is installed.

Sony has released a patch that removes the cloaking feature of the rootkit, but CA pointed out that the patch failed to resolve all security concerns.

To obtain the Sony uninstaller, users are also required to give out personal information that will be used by Sony BMG and undisclosed third parties.

Tags:

Reader comments

More from Computeractive

News

The latest home computing news

Downloads

The best PC tools, applications and more

Reviews

Independent opinions on new hardware and software

Step-by-step guides

Easy-to-follow projects with pictures

PC Help

Solve PC problems with our Q&A

Videos

PC projects demonstrated and product reviews

Articles

An in-depth look at how to get the best from your PC

Magazine

What's coming up in Computeractive

Forums

Get help with your PC problems from our readers

Competitions

Your chance to win computing prizes

Shopping

Great deals on products, services and more

Computeractive Back Issue CD-Rom 12
All 26 issues of Computeractive from 2009 on one CD-Rom.

Ultimate Guide to Free Computing
Find out how you can get free software, services and more!

Learn to use Windows 7
Learn to use Windows 7
Everything you need to know about using Windows 7!

Computeractive - Issue 280Computeractive Back Issues
Missed an issue? Click here to find a back issue

Blogs

Windows Watch

Windows Watch

Keeping an eye on the latest XP and Vista news

Norton Smartphone Security for Android: First Photos

Exclusive first photos of Symantec's Smartphone Security for Android, taken at Symantec's headquarters. Story here .

Download Junkie

Download Junkie

Your daily dose of download discussion

It's live! Get AVG Anti-Virus 9, worth £26.99, FREE for one day only!

Probably our biggest giveaway for a while, we're offering you the full current AVG Anti-Virus 9 [1-PC, 1-Year], worth £26.99, completely FREE...

Advertisement

Free email newsletters

Techno babble demystified...

[Display all definitions]

Or type in any computer-related word and click "Go"

Advertisement

Computeractive is not reponsible for content of Google adverts

Primary Navigation

© Incisive Media Investments Limited 2010, Published by Incisive Financial Publishing Limited, Haymarket House, 28-29 Haymarket, London SW1Y 4RX, are companies registered in England and Wales with company registration numbers 04252091 & 04252093

Search computeractive.co.uk
opfine.com - markets sentiment analysis