Thu Feb 6 14:05:16 2025



NYLXS Mailing Lists and Archives
NYLXS Members have a lot to say and share but we don't keep many secrets. Join the Hangout Mailing List and say your peice.

DATE 2005-11-01


2025-02-06 | 2025-01-06 | 2024-12-06 | 2024-11-06 | 2024-10-06 | 2024-09-06 | 2024-08-06 | 2024-07-06 | 2024-06-06 | 2024-05-06 | 2024-04-06 | 2024-03-06 | 2024-02-06 | 2024-01-06 | 2023-12-06 | 2023-11-06 | 2023-10-06 | 2023-09-06 | 2023-08-06 | 2023-07-06 | 2023-06-06 | 2023-05-06 | 2023-04-06 | 2023-03-06 | 2023-02-06 | 2023-01-06 | 2022-12-06 | 2022-11-06 | 2022-10-06 | 2022-09-06 | 2022-08-06 | 2022-07-06 | 2022-06-06 | 2022-05-06 | 2022-04-06 | 2022-03-06 | 2022-02-06 | 2022-01-06 | 2021-12-06 | 2021-11-06 | 2021-10-06 | 2021-09-06 | 2021-08-06 | 2021-07-06 | 2021-06-06 | 2021-05-06 | 2021-04-06 | 2021-03-06 | 2021-02-06 | 2021-01-06 | 2020-12-06 | 2020-11-06 | 2020-10-06 | 2020-09-06 | 2020-08-06 | 2020-07-06 | 2020-06-06 | 2020-05-06 | 2020-04-06 | 2020-03-06 | 2020-02-06 | 2020-01-06 | 2019-12-06 | 2019-11-06 | 2019-10-06 | 2019-09-06 | 2019-08-06 | 2019-07-06 | 2019-06-06 | 2019-05-06 | 2019-04-06 | 2019-03-06 | 2019-02-06 | 2019-01-06 | 2018-12-06 | 2018-11-06 | 2018-10-06 | 2018-09-06 | 2018-08-06 | 2018-07-06 | 2018-06-06 | 2018-05-06 | 2018-04-06 | 2018-03-06 | 2018-02-06 | 2018-01-06 | 2017-12-06 | 2017-11-06 | 2017-10-06 | 2017-09-06 | 2017-08-06 | 2017-07-06 | 2017-06-06 | 2017-05-06 | 2017-04-06 | 2017-03-06 | 2017-02-06 | 2017-01-06 | 2016-12-06 | 2016-11-06 | 2016-10-06 | 2016-09-06 | 2016-08-06 | 2016-07-06 | 2016-06-06 | 2016-05-06 | 2016-04-06 | 2016-03-06 | 2016-02-06 | 2016-01-06 | 2015-12-06 | 2015-11-06 | 2015-10-06 | 2015-09-06 | 2015-08-06 | 2015-07-06 | 2015-06-06 | 2015-05-06 | 2015-04-06 | 2015-03-06 | 2015-02-06 | 2015-01-06 | 2014-12-06 | 2014-11-06 | 2014-10-06 | 2014-09-06 | 2014-08-06 | 2014-07-06 | 2014-06-06 | 2014-05-06 | 2014-04-06 | 2014-03-06 | 2014-02-06 | 2014-01-06 | 2013-12-06 | 2013-11-06 | 2013-10-06 | 2013-09-06 | 2013-08-06 | 2013-07-06 | 2013-06-06 | 2013-05-06 | 2013-04-06 | 2013-03-06 | 2013-02-06 | 2013-01-06 | 2012-12-06 | 2012-11-06 | 2012-10-06 | 2012-09-06 | 2012-08-06 | 2012-07-06 | 2012-06-06 | 2012-05-06 | 2012-04-06 | 2012-03-06 | 2012-02-06 | 2012-01-06 | 2011-12-06 | 2011-11-06 | 2011-10-06 | 2011-09-06 | 2011-08-06 | 2011-07-06 | 2011-06-06 | 2011-05-06 | 2011-04-06 | 2011-03-06 | 2011-02-06 | 2011-01-06 | 2010-12-06 | 2010-11-06 | 2010-10-06 | 2010-09-06 | 2010-08-06 | 2010-07-06 | 2010-06-06 | 2010-05-06 | 2010-04-06 | 2010-03-06 | 2010-02-06 | 2010-01-06 | 2009-12-06 | 2009-11-06 | 2009-10-06 | 2009-09-06 | 2009-08-06 | 2009-07-06 | 2009-06-06 | 2009-05-06 | 2009-04-06 | 2009-03-06 | 2009-02-06 | 2009-01-06 | 2008-12-06 | 2008-11-06 | 2008-10-06 | 2008-09-06 | 2008-08-06 | 2008-07-06 | 2008-06-06 | 2008-05-06 | 2008-04-06 | 2008-03-06 | 2008-02-06 | 2008-01-06 | 2007-12-06 | 2007-11-06 | 2007-10-06 | 2007-09-06 | 2007-08-06 | 2007-07-06 | 2007-06-06 | 2007-05-06 | 2007-04-06 | 2007-03-06 | 2007-02-06 | 2007-01-06 | 2006-12-06 | 2006-11-06 | 2006-10-06 | 2006-09-06 | 2006-08-06 | 2006-07-06 | 2006-06-06 | 2006-05-06 | 2006-04-06 | 2006-03-06 | 2006-02-06 | 2006-01-06 | 2005-12-06 | 2005-11-06 | 2005-10-06 | 2005-09-06 | 2005-08-06 | 2005-07-06 | 2005-06-06 | 2005-05-06 | 2005-04-06 | 2005-03-06 | 2005-02-06 | 2005-01-06 | 2004-12-06 | 2004-11-06 | 2004-10-06 | 2004-09-06 | 2004-08-06 | 2004-07-06 | 2004-06-06 | 2004-05-06 | 2004-04-06 | 2004-03-06 | 2004-02-06 | 2004-01-06 | 2003-12-06 | 2003-11-06 | 2003-10-06 | 2003-09-06 | 2003-08-06 | 2003-07-06 | 2003-06-06 | 2003-05-06 | 2003-04-06 | 2003-03-06 | 2003-02-06 | 2003-01-06 | 2002-12-06 | 2002-11-06 | 2002-10-06 | 2002-09-06 | 2002-08-06 | 2002-07-06 | 2002-06-06 | 2002-05-06 | 2002-04-06 | 2002-03-06 | 2002-02-06 | 2002-01-06 | 2001-12-06 | 2001-11-06 | 2001-10-06 | 2001-09-06 | 2001-08-06 | 2001-07-06 | 2001-06-06 | 2001-05-06 | 2001-04-06 | 2001-03-06 | 2001-02-06 | 2001-01-06 | 2000-12-06 | 2000-11-06 | 2000-10-06 | 2000-09-06 | 2000-08-06 | 2000-07-06 | 2000-06-06 | 2000-05-06 | 2000-04-06 | 2000-03-06 | 2000-02-06 | 2000-01-06 | 1999-12-06

Key: Value:

Key: Value:

DATE 2005-11-03
FROM Ruben Safir

Sony DRM is worse than you might think

Comment Active exploits and no help from Sony

By Charlie Demerjian: Thursday 03 November 2005, 09:40

Click to Visit

SONY SCREWED UP WITH its rights removal to protect its profit margins
philosophy and there is no way the use of rootkits can be justified.

Caught with its pants down, what did it do? Make things right? Heck no,
it blamed the user, and doesn't do anything more than window dressing to
deflect what are valid criticisms.

If you read the Sony PR spin masquerading as a FAQ here, the tepid
responses it give are laughable. Number one states that the technology
is used to prevent copying, but that is true for only Windows boxes, so
why the discrimination? It only affects legitimate users. If you want to
copy the music, all you need to do is hold down the shift key when
inserting it and you are free to copy. That or have a non-Windows

To make matters worse, a cursory check of the file trading networks
shows that the Van Zant album is available for download on a whim. The
pirates who don't want to pay will have no trouble getting it, but those
who abide by the law will get punished. Also, if you look at FAQ Number
4 under equipment compatibility, it cuts iPod users out of the mix. Hmm,
Sony only sells Windows based computers, and sells a competitor to the
iPod. Sense a conflict of interest there that you are paying for?

So to Number 2. "How do I know if a Sony/BMG disc is" DRM infected? It
says it is clearly marked on the label, and yup, it's right, it is. I
went over to Best Buy tonight and found it on the label plain and clear.
There was also absolutely no listing of rootkits being forcibly
installed on your PC, and not being uninstallable, however.

There was no warning that you had to play it through their player, or
that it would spit out the disc if you had programs open that it did not
like. If you don't like these terms and rights removals, and you try to
return it, those few places that will take back open recordings tend to
charge a restock fee. In the case of Best Buy tonight, it is 15%, I
asked. I don't think Sony will refund you that money.

Number four tells you to consult the EULA when you want to copy the
disc. Which madhouse did we step into that now means a CD needs a EULA?
I stopped buying CDs so I wouldn't have to give money to rapacious
weasels years ago, and none of the CDs I own have a EULA on them. It is
madness. So, at Best Buy tonight, I tried to consult the EULA before I
bought the Van Zant CD.

It wasn't on the CD package, not on the shelves near by, and the blue
shirted aisle trolls had no idea what I was talking about. No, they
could not provide me with one, I did ask though. So, if you are dumb
enough to buy a Sony CD, and don't want to rootkit your machine, you
can't find out beforehand, have to agree to a one sided contract that
you can't read before you say yes, and can't get your money back.
Wonderful, thank you Sony.

The last part of the FAQ is Number 6, which claims that its CDs are not
spyware/malware infected. The prefix 'mal-' according to Merriam-Webster
means 1) bad 2) abnormal 3) inadequate. -ware is short for software.
This means malware is defined as bad software.

If you look at the Sony rootkit, it does several things. It strips you
of your rights, it potentially causes your computer harm, it breaks your
computer if you remove it, and eats your CPU time. All of these things
are bad, no question there. It also does the end user no good in any
way, shape or form, not even by the most demented stretch of the
imagination. It only hurts those who spent money to buy it.

It does Sony no good either because the files are rippable on a whim by
anything more intelligent than a half-drunk monkey. So, you have
software that does you flat out harm, and no good for the producer. What
isn't malware about this, and how can Sony claim this? This is the
service pack from hell.

If you want to look at this another way, take a different example.
Imagine that you walked up to a person that you know and said: "Hey
friend, check out this new cool CD I made". He drops it in his computer,
and without his permission, it installs a rootkit on his machine. Good
joke, right?

Say you want to remove the Sony stuff. According to no less a source
than The Washington Post, the bare minimum you have to do to remove the
rootkitted DRM infection is give up your privacy. If you go to the Sony
page, here, you have to give Sony your email at the very least, and
according to the WP story, Sony then grills you about your reasons for
not liking being rootkitted.

So, if you want to remove it, go here and click the link. Don't use
Firefox though, it won't work, it's Internet Explorer only. If you are
concerned enough about security, you probably know enough not to use IE.
Once again, brilliant Sony, just brilliant.

The funniest part is that you don't actually remove the software with
this tool, only make it visible, and you are still infected up and down
with DRM. Should you be lucid enough to realise that you don't want this
crap within a few miles of your system, you have to go through the
grilling process above. Want to make it seem even more surreal? If you
remove the malware and DRM infection, you can't play the CD anymore.
Nope, the money you spent on Sony products is gone. Mal-way or the

If you try to remove it yourself, you risk breaking your optical discs,
or it kills them for you. Mark from Sysinternals is more than smart
enough to figure out how to fix this, but are you? Off the top of your
head, how do you do that again, no looking it up? To make matters worse,
it installs itself so it runs in safe mode, and if it conflicts with
something, you are really hosed. Sony's response? "This component is not
malicious and does not compromise security.". There are already exploits
out there that take advantage of this.

Sony compromised your system and will not directly allow you to remove
it without compromising your privacy. It also will not replace your
defective CDs with non-infected ones. If you hose your computer or
network with this infection, and want to play your music, do not pass
go, do not collect $200. Really, it won't help customers who simply
don't want this, read #3 in the FAQ.

Sony is generously working with anti-virus companies on this. Now, this
means to deal with the problem, you have to know it's there, and that's
kind of hard because the malware rootkit that Sony infects you with is
designed to prevent this.

Now, let's just pretend we don't realise that the the antivirus
companies themselves are not complicit. If you want to mass-rootkit
people, just ask Symantec beforehand. Look at what Cnet had to say about
it. "The creator of the copy-protection software, a British company
called First 4 Internet, said the cloaking mechanism was not a risk, and
that its team worked closely with big antivirus companies such as
Symantec to ensure that was the case." But there are active exploits
already, as we pointed out earlier.

All this makes you wonder a lot about Microsoft's upcoming security
software, doesn't it?

So, rather than come clean, Sony minimises the problem, blames the user,
and refuses to help you out. If you have CDs infected with this rootkit
and DRM, Sony has to replace them. They are, flat out, a danger to
computing. Don't believe me? Look at that Washington Post article again.
The head of F-Secure says that the Sony malware, when running on Windows
Vista "breaks the operating system spectacularly". Nope, that can't be
right, just ask Sony, because it said so in the FAQ. It won't fix the
problem, they won't let you work around it legally and still listen to
the music you paid for, and won't help you.

As of four hours ago, these things were still on the shelf at Best Buy.

To end on an up note, just think about these two things. What you are
seeing is the light and happy side of rights removing DRM infections.
There is a bill going through congress to remove more of your rights.
Yes, they can't control the analogue hole, and can't legally force you
to bow to them, so they are buying government to change the laws and
accomplish both goals. No good will come to the end user because of
this, but it sure will make a lot of people rich.

More happy news? These merchants are designing the next generation
drives called Blu-Ray with much more DRM built into the hardware. It is
bad enough to make me back the views of Bill Gates on the subject with
absolute open arms. These are scary times people, and if we let Sony get
away with this now, it will only get worse and harder to stop later. ยต

  1. 2005-11-02 From: "Inker, Evan" <> Subject: [NYLXS - HANGOUT] Massachusetts' CIO defends move to OpenDocument
  2. 2005-11-02 Ruben Safir <> Subject: [NYLXS - HANGOUT] GNU/Linux Sysadmin Jobs for 60K
  3. 2005-11-02 From: "Inker, Evan" <> Subject: [NYLXS - HANGOUT] Sony Ships Sneaky DRM Software
  4. 2005-11-02 Ruben Safir <> Re: [NYLXS - HANGOUT] Sony Ships Sneaky DRM Software
  5. 2005-11-03 Ruben Safir <> Subject: [NYLXS - HANGOUT] Paris and Iraq
  6. 2005-11-03 Ruben Safir <> Re: [NYLXS - HANGOUT] Paris and Iraq
  7. 2005-11-03 Ruben Safir <> Re: [NYLXS - HANGOUT] Sony Ships Sneaky DRM Software
  8. 2005-11-03 Contrarian <> Subject: [NYLXS - HANGOUT] Senate to vote today on M$ sponsored HB visas
  9. 2005-11-03 Ruben Safir <> Subject: [NYLXS - HANGOUT] [Fwd: Still time to register: Tame the Data Explosion]
  10. 2005-11-03 Ruben Safir <> Subject: [NYLXS - HANGOUT] More Sony DRM
  11. 2005-11-03 Ruben Safir <> Subject: [NYLXS - HANGOUT] Content Reading/Intel and GNU/Linux
  12. 2005-11-03 Ruben Safir <> Subject: [NYLXS - HANGOUT] [Fwd: Linux Research - Request For Assistance]
  13. 2005-11-05 Ruben Safir <> Subject: [NYLXS - HANGOUT] [Fwd: JobCircle Weekly Summary of New Jobs]
  14. 2005-11-07 From: "Inker, Evan" <> Subject: [NYLXS - HANGOUT] Community: Why Is Novell Chopping Its SUSE Linux Workstation and
  15. 2005-11-07 From: "Steve Milo" <> Re: [NYLXS - HANGOUT] Community: Why Is Novell Chopping Its SUSE Linux Workstation and Desktop Product Line?
  16. 2005-11-08 From: <> Subject: [NYLXS - HANGOUT] Yahoo chat
  17. 2005-11-08 From: "J.E. Cripps" <> Re: [NYLXS - HANGOUT] Yahoo chat
  18. 2005-11-09 Ruben Safir <> Subject: [NYLXS - HANGOUT] [ E-Update for the Committee on Technology in Government]
  19. 2005-11-09 Ruben Safir <> Subject: [NYLXS - HANGOUT] [ Linux Applications Contest ? Win $50K]
  20. 2005-11-10 From: "Inker, Evan" <> Subject: [NYLXS - HANGOUT] New Worm Targets Linux Web Service Holes
  21. 2005-11-10 From: "Inker, Evan" <> Subject: [NYLXS - HANGOUT] Suse co-founder leaves Novell
  22. 2005-11-10 From: "Inker, Evan" <> Subject: [NYLXS - HANGOUT] Novell Tripping Over its Linux Strategy
  23. 2005-11-10 From: <> Re: [NYLXS - HANGOUT] New Worm Targets Linux Web Service Holes
  24. 2005-11-10 From: "Inker, Evan" <> RE: [NYLXS - HANGOUT] New Worm Targets Linux Web Service Holes
  25. 2005-11-10 Ruben Safir <> Subject: [NYLXS - HANGOUT] General Membership Meeting Tuesday Night 11-15-2005
  26. 2005-11-10 From: "Inker, Evan" <> RE: [NYLXS - HANGOUT] General Membership Meeting Tuesday Night 11
  27. 2005-11-10 Ruben Safir <> RE: [NYLXS - HANGOUT] General Membership Meeting Tuesday Night 11
  28. 2005-11-10 Ruben Safir <> Re: [NYLXS - HANGOUT] General Membership Meeting Tuesday Night
  29. 2005-11-10 From: <> RE: [NYLXS - HANGOUT] General Membership Meeting Tuesday Night 11-15-2005
  30. 2005-11-10 Ruben Safir <> Subject: [NYLXS - HANGOUT] Viruses exploit Sony DRM software
  31. 2005-11-10 Ruben Safir <> Subject: [NYLXS - HANGOUT] Even Better SONY's left and right hands
  32. 2005-11-11 From: "Inker, Evan" <> RE: [NYLXS - HANGOUT] Viruses exploit Sony DRM software
  33. 2005-11-11 From: "rc" <> Subject: [NYLXS - HANGOUT] Monitors
  34. 2005-11-15 From: "Inker, Evan" <> Subject: [NYLXS - HANGOUT] General Membership Meeting Thursday Night 11-17
  35. 2005-11-15 From: "Inker, Evan" <> RE: [NYLXS - HANGOUT] General Membership Meeting Tuesday Night 11
  36. 2005-11-15 From: "Inker, Evan" <> Subject: [NYLXS - HANGOUT] Europe and the US philosophically divided on open source?
  37. 2005-11-15 From: "Inker, Evan" <> Subject: [NYLXS - HANGOUT] Open source: Developing markets and anti-Americanism (Part 2)
  38. 2005-11-15 Ruben Safir <> Subject: [NYLXS - HANGOUT] [Fwd: Press Release: Second Annual FDA Information Management
  39. 2005-11-15 From: "Inker, Evan" <> Subject: [NYLXS - HANGOUT] Suse 10.0 is Out!
  40. 2005-11-15 Ruben Safir <> Subject: [NYLXS - HANGOUT] Amy Harmon is at it again
  41. 2005-11-16 Contrarian <> Re: [NYLXS - HANGOUT] Monitors
  42. 2005-11-16 Contrarian <> Re: [NYLXS - HANGOUT] Amy Harmon is at it again
  43. 2005-11-16 From: <> Re: [NYLXS - HANGOUT] Suse 10.0 is Out!
  44. 2005-11-16 From: "Inker, Evan" <> Subject: [NYLXS - HANGOUT] Sony pulls copy-protected CDs from shelves
  45. 2005-11-16 From: <> Re: [NYLXS - HANGOUT] Sony pulls copy-protected CDs from shelves
  46. 2005-11-16 Contrarian <> Re: [NYLXS - HANGOUT] Monitors
  47. 2005-11-16 Mark Simko <> Re: [NYLXS - HANGOUT] Monitors
  48. 2005-11-16 Ruben Safir <> Subject: [NYLXS - HANGOUT] Re: New to Linux
  49. 2005-11-16 From: "J.E. Cripps" <> Re: [NYLXS - HANGOUT] Monitors
  50. 2005-11-16 From: <> Re: [NYLXS - HANGOUT] Monitors
  51. 2005-11-18 From: "rc" <> RE: [NYLXS - HANGOUT] Monitors
  52. 2005-11-18 Ruben Safir <> Subject: [NYLXS - HANGOUT] [Fwd: E-Update for the Committee on Technology in Government -
  53. 2005-11-18 Ruben Safir <> Subject: [NYLXS - HANGOUT] [Fwd: [nycsmalltalk] Presentation -- VisualWorks and algorithm
  54. 2005-11-20 Mark Simko <> Subject: [NYLXS - HANGOUT] (Fwd) Fwd: Review of Computer Vote Rigging: Video
  55. 2005-11-20 Ruben Safir <> Subject: [NYLXS - HANGOUT] [Fwd: JobCircle Weekly Summary of New Jobs]
  56. 2005-11-20 Ruben Safir <> Re: [NYLXS - HANGOUT] (Fwd) Fwd: Review of Computer Vote Rigging:
  57. 2005-11-20 From: "Steve Milo" <> Re: [NYLXS - HANGOUT] [Fwd: JobCircle Weekly Summary of New Jobs]
  58. 2005-11-20 From: "Steve Milo" <> Re: [NYLXS - HANGOUT] (Fwd) Fwd: Review of Computer Vote Rigging: Video
  59. 2005-11-20 Ruben Safir <> Re: [NYLXS - HANGOUT] [Fwd: JobCircle Weekly Summary of New Jobs]
  60. 2005-11-20 Mark Simko <> Re: [NYLXS - HANGOUT] (Fwd) Fwd: Review of Computer Vote Rigging: Video
  61. 2005-11-20 Ruben Safir <> Re: [NYLXS - HANGOUT] (Fwd) Fwd: Review of Computer Vote Rigging:
  62. 2005-11-21 Contrarian <> Re: [NYLXS - HANGOUT] (Fwd) Fwd: Review of Computer Vote Rigging:
  63. 2005-11-21 Contrarian <> Re: [NYLXS - HANGOUT] (Fwd) Fwd: Review of Computer Vote Rigging:
  64. 2005-11-21 From: "Steve Milo" <> Subject: [NYLXS - HANGOUT] =?utf-8?Q?Re:_[NYLXS_-_HANGOUT]_(Fwd)_Fwd:_Review_of_Compu?=
  65. 2005-11-21 Ruben Safir <> Re: [NYLXS - HANGOUT] (Fwd) Fwd: Review of Computer Vote Rigging:
  66. 2005-11-21 Contrarian <> Re: [NYLXS - HANGOUT] (Fwd) Fwd: Review of Computer Vote Rigging:
  67. 2005-11-21 From: <> Re: [NYLXS - HANGOUT] Re: [NYLXS - HANGOUT] (Fwd) Fwd: Review of Computer Vote Rigging: Video
  68. 2005-11-21 From: "Steve Milo" <> Re: [NYLXS - HANGOUT] (Fwd) Fwd: Review of Computer Vote Rigging: Video
  69. 2005-11-22 Ruben Safir <> Subject: [NYLXS - HANGOUT] General Membership Meeting Results
  70. 2005-11-22 From: "Inker, Evan" <> Subject: [NYLXS - HANGOUT] That's Linux on the Line
  71. 2005-11-25 From: "Inker, Evan" <> Subject: [NYLXS - HANGOUT] FSF keeps pushing for Microsoft server protocols
  72. 2005-11-26 From: "rc" <> RE: [NYLXS - HANGOUT] Suse 10.0 is Out!
  73. 2005-11-28 Ruben Safir <> Subject: [NYLXS - HANGOUT] Jobs
  74. 2005-11-30 From: "rc" <> RE: [NYLXS - HANGOUT] Suse 10.0 is Out!
  75. 2005-11-30 Contrarian <> Subject: [NYLXS - HANGOUT] Second anti-DRM demonstration today

NYLXS are Do'ers and the first step of Doing is Joining! Join NYLXS and make a difference in your community today!