About RSS
Search for: in 

Windows Watch - an XP & Vista blog

Trojan horse
CA's anti-spyware application refers to Sony's XCP as a Trojan horse
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

Computer Associates blacklists Sony DRM

Pressure mounts on Sony to abandon insecure technology

Tom Sanders in California, vnunet.com 10 Nov 2005
ADVERTISEMENT

Computer Associates has officially blacklisted the Sony BMG XCP Technology that the record label bundles with several of its audio CDs.

CA's PestPatrol anti-spyware application now offers users the ability to remove the application, which it refers to as a Trojan horse. 

The vendor justifies referring to the technology as a Trojan by pointing out on its spyware information website that XCP "installs without user permission, presenting only a vague and misleading end user licence agreement". 

XCP also changes the system configuration without the user's permission and silently modifies other program information or website content. CA has further alleged that Sony has failed to allow users to remove the tool.

The application is also accused of shortening the life span of the user's hard drive by performing a scan of system processes every 1.5 seconds.

Another widely publicised feature of the technology is a rootkit that hides the digital rights management technology from the system and the user.

The rootkit will actually hide any file, process or registry key that begins with the characters '$sys$', making it extremely easy for virus authors and hackers to hide malicious applications from virus and spyware scanners.

Sony has always denied that there are any security issues associated with the software.

The technology was designed by First 4 Internet, and is bundled with several of Sony's audio CDs. Roughly two million of the CDs have been shipped.

The Electronic Frontier Foundation has compiled a list of some of the offending CDs with instructions on how to prevent getting infected.

Users who seek to play the CD on their computer CDRom drive on a Windows machine are presented with a licence agreement.

While the licence discloses that software will be installed, it does not give details and falsely suggests that it can be uninstalled. Upon agreement, the rootkit and DRM technology is installed.

Sony has released a patch that removes the cloaking feature of the rootkit, but CA pointed out that the patch failed to resolve all security concerns.

To obtain the Sony uninstaller, users are also required to give out personal information that will be used by Sony BMG and undisclosed third parties.

IT securityRecord label backtracks after public outrage over cloaking technology  03 Nov 2005
Computer virusDodging the virus shield becomes big business as authors 'outsource' malware creation  19 Oct 2005

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Elstree, United Kingdom | NHS Blood and Transplant
  Operations Engineer, Bio Productory Laboratory,  £28,313 - £37,326 pa plus High Cost Area Supplement, Elstree About us The National Blood Service is an integral and vital part of the NHS. Our two million volunteer donors contribute ... more >
Chichester, United Kingdom | West Sussex County Council
  Principal Application Specialist - Application Developer, Chichester, £42,100 - £44,700 (includes Market Rate Supplement) IT Services at WSCC supports and manages a variety of systems based on Oracle databases that include third party and ... more >
United Kingdom | Swansea University
Programmer/Analyst (Content Management System), £25,135 - £28,290 pa Administrative Computing Unit   Joining an established team your role is to develop and enhance the University's use of the Terminal-Four Content Management System. Working closely with technical ... more >
United Kingdom | London Borough of Sutton
Business Relationship Manager (Finance), Based at Civic Offices, £ 41,790 - £ 44,373  (PO 7)   Fixed Term to 31st March 2009 The IT service has four Business Relationship Managers (BRM); each one responsible for delivering and developing ... more >
More job opportunities
Join our fight for a fair deal when shopping online
ADVERTISEMENT