Help - Search - Members - Calendar
Full Version: Sony BMG's copy protection shows rootkit-behavior
Hydrogenaudio Forums > Hydrogenaudio Forum > Validated News
Pages: 1, 2
level
QUOTE(Brink @ Nov 9 2005, 03:40 PM)

The solution to this big abuse is clear:
DON'T BUY ANY PROTECT CD's!! from Sony or any disc label.
We, the consumers, don't deserve to be mistreated this way.
In the moment that more and more people reject these criminals and arrogant actions from these big corporations (as Sony), then, and only in that moment the problem will begin to have solution.
Danimal
QUOTE(level @ Nov 11 2005, 02:38 PM)
QUOTE(Brink @ Nov 9 2005, 03:40 PM)

The solution to this big abuse is clear:
DON'T BUY ANY PROTECT CD's!! from Sony or any disc label.
We, the consumers, don't deserve to be mistreated this way.
In the moment that more and more people reject these criminals and arrogant actions from these big corporations (as Sony), then, and only in that moment the problem will begin to have solution.
*



Sony has "temporarily" decided to stop making cds with this technology (I wonder what they'll come up with next that they won't tell us about): http://us.rd.yahoo.com/mymod/hdln/vm/sty/*...pyprotection_dc
Andavari
QUOTE(cbsantos @ Nov 11 2005, 11:50 AM)
three vulnerabilities in the Windows graphics rendering engine
*


So is that report referring to GDI, most notibly GDI.exe and/or the already patched for vulnerabilities gdiplus.dll?
emr
That's it - I'm not buying any CDs any more. I've had my doubts before due to all the previous DRM methods, loudness race etc. but this was the final straw. Don't know how I'll get my music from now on, but certainly not the old CD way.
Jojo
The paranoia of the music industry is getting ridicules...somehow they don't understand that people that buy CD's are not the enemy and not the ones that share music...how else can it be that many releases are available on the internet even before they hit stores...maybe cleaning out in their own rows would be just as efficient rolleyes.gif How can they fight against someone that supports them?!

Anyway, Sony is the one that gets punished heavily for this…hopefully it teaches the other labels a lesson here so they don't even think about implementing something similar…
Lyx
QUOTE(emr @ Nov 12 2005, 11:37 PM)
That's it - I'm not buying any CDs any more. I've had my doubts before due to all the previous DRM methods, loudness race etc. but this was the final straw. Don't know how I'll get my music from now on, but certainly not the old CD way.
*


There is no life outside of hollywood - we're all doomed!

Hint: more than 90% of albums released worldwide do not come from major labels. However, most of the albums sold worldwide do come from major labels.
JeanLuc
QUOTE(Jojo @ Nov 13 2005, 06:12 AM)
... how else can it be that many releases are available on the internet even before they hit stores ... maybe cleaning out in their own rows would be just as efficient


A little conspiracy theory here ... this could as well be free advertising for them.
evereux
QUOTE(JeanLuc @ Nov 13 2005, 09:56 AM)
QUOTE(Jojo @ Nov 13 2005, 06:12 AM)
... how else can it be that many releases are available on the internet even before they hit stores ... maybe cleaning out in their own rows would be just as efficient


A little conspiracy theory here ... this could as well be free advertising for them.
*


Naah. 99% of the time I believe it's the music press or friends the music press have passed the CDs onto.
plonk420
QUOTE(Sony)
3. Can I get a copy of the disc without the content protected technology?

No. We manufacture only one commercial version of each new release, a content protected version.

QUOTE(Sony @ later)
1. I have an Apple Macintosh computer. Will the disc work on my MAC?

Yes. This disc will behave like a traditional CD in a Mac.


oh the hypocricy! that cracks me up tongue.gif

we won't even touch the other points... wink.gif

http://cp.sonybmg.com/xcp/english/faq.html
AgentMil
Just a little note to all HA users, that there have been trojans and viruses found out in the wild that uses this exploit to propagate itself and hide from view. Currently the risk is low as it is slow spreading. Can't remember the source but I am sure I read it from CNet news. Just update your virus scanners to get new definitions or check whether the virus scanner can detect the DRM rootkit.

Regards
GeSomeone
We're nearing the final chapter of this horror story tongue.gif

Sony recalls the CDs with this version of the XCP protection from the shops and offers customers to exchange bought disc with a non XCPed one.

Meanwhile it has turned out that the ActiveX plugin (from first4Internet), that was used to remove the 'rootkit' upon request of the user (through Sony support), was more dangerous than the rootkit itself! shock1.gif
It stays on the computer (in Internet Explorer) and leaves the computer with a wide open backdoor blink.gif

Full story on many places on the Internet like here

At the very least, this has created a healthy mistrust towards what in the name of DRM can be done.
zima
I don't think we're near the end of it. Yeah, Sony perhaps is recalling the Cds...but just look at those maps...

http://www.doxpara.com/
MachineHead
http://cp.sonybmg.com/xcp/english/titles.html


A list of cds with this garbage.
Josef K.
QUOTE(MachineHead @ Nov 17 2005, 04:39 PM)
http://cp.sonybmg.com/xcp/english/titles.html
A list of cds with this garbage.
*
Strange. I've got this CD from the list:
8. Bob Brookmeyer Bob Brookmeyer & Friends CK94292 827969429228
and there is no copy protection. It's pretty new and it's purchased 3 weeks ago. ???

And what more: the list is missing Santana new CD All That I Am, which is even announced as [CONTENT/COPY-PROTECTED CD] ???
kritip
QUOTE(Josef K. @ Nov 17 2005, 04:13 PM)
QUOTE(MachineHead @ Nov 17 2005, 04:39 PM)
http://cp.sonybmg.com/xcp/english/titles.html
A list of cds with this garbage.
*
Strange. I've got this CD from the list:
8. Bob Brookmeyer Bob Brookmeyer & Friends CK94292 827969429228
and there is no copy protection. It's pretty new and it's purchased 3 weeks ago. ???

And what more: the list is missing Santana new CD All That I Am, which is even announced as [CONTENT/COPY-PROTECTED CD] ???
*



I think only US releases had this DRM stuff, UK didn't, and as your from "universe" i guess yours is unaffectd tongue.gif

Kristian
k.eight.a
QUOTE(level @ Nov 11 2005, 11:38 AM)
The solution to this big abuse is clear:
DON'T BUY ANY PROTECT CD's!! from Sony or any disc label.
We, the consumers, don't deserve to be mistreated this way.
In the moment that more and more people reject these criminals and arrogant actions from these big corporations (as Sony), then, and only in that moment the problem will begin to have solution.
Yeah! mad.gif
QUOTE(emr @ Nov 12 2005, 01:37 PM)
That's it - I'm not buying any CDs any more. I've had my doubts before due to all the previous DRM methods, loudness race etc. but this was the final straw. Don't know how I'll get my music from now on, but certainly not the old CD way.
Well you can always borrow some CD'S from your friends. Anyway for me this is also a final straw I'll never buy a copy protected CD anymore! mad.gif
QUOTE(Jojo @ Nov 12 2005, 10:12 PM)
The paranoia of the music industry is getting ridicules... somehow they don't understand that people that buy CD's are not the enemy and not the ones that share music... how else can it be that many releases are available on the internet even before they hit stores... maybe cleaning out in their own rows would be just as efficient rolleyes.gif How can they fight against someone that supports them?!
Yep, it seems that the music industry managers don't have at least a little piece of brain in their heads... dry.gif
QUOTE(Jojo @ Nov 12 2005, 10:12 PM)
Anyway, Sony is the one that gets punished heavily for this… hopefully it teaches the other labels a lesson here so they don't even think about implementing something similar…
I really doubt about it, the end is nowhere IMO... crying.gif
Duble0Syx
DRM's concept makes sense to a very small point. But adding DRM to CD's is just plain dumb. They want to stop piracy, so what do they do? They punish the people who are actuall still buying the music like a bunch of idiots. The "pirates" don't care about copy protection because they are rarely the ones buying the discs in the first place. Sony has no brains.
DickxLaurent
QUOTE(rjamorim @ Nov 2 2005, 08:30 AM)
Matti Nikki at lame-dev mailing list bought the Van Zant CD, and noticed one of the files (\Contents\GO.EXE) Contains the following string:

"http://www.mp3dev.org  0.90    LAME3.95"

So, besides breaking several costumer rights with that CD, they are also probably breaking the LGPL.
*


I also heard about this in a Podcast today. Any new information on how it could affect Sony or LAME devs?

It's just sooo sleazy.
GeSomeone
QUOTE(MachineHead @ Nov 17 2005, 04:39 PM)
14. The Coral . . The Invisible Invasion

This title gave away what they were doing tongue.gif
kennedyb4
This situation has actually helped me a bit.

I was dithering back and forth about getting my son an X Box 360 for Christmas or waiting for a PS3.

X Box it is.

The decision to get a Blue Ray or HD-DVD player is now equally easy.

I hope they are roundly censured for this,and that ultimately new laws protecting our rights will result.

It will be interesting to see how Sony's lawyers explain how collecting and transmitting info on listening habits without the users permission helps them protect their content.
wuzza
It appears they ripped off DVD John, too.

Sony's DRM woes expand to include copyright infringement


SONY=Software pirates dry.gif
MachineHead
http://blogs.washingtonpost.com/securityfi...bmg_has_ju.html

The exchange part is rather funny.


ameyer17
QUOTE(ChuckSplatt @ Nov 8 2005, 03:14 PM)
If you avoid installing the rootkit, has anyone tried ripping from one of these CDs?  Does it work?
*


Yes, it does work if you use EAC. Real Player (ugh) and probably most other low-end Windows CD rippers (AKA WMP, iTunes, etc.) saw absolutely nothing.
JunkieXL
You sure about that? I just bought a used copy of the Sarah McLachlan - Bloom Remix Album tonight and I couldn't do anything with it really. The minute you don't accept the disclaimer that pops up it will eject the CD. And when I tried running EAC on it with the pop-up just sitting there I kept getting sync errors on both of my drives. I have JLMS & a Lite-On (which are both made by the evil empire).
The other thing I noticed is that right after inserting the disc a window popped up that said it was scanning and updating my component library...WTF?
I haven't noticed anything unusual since then, but I'm still a bit uneasy about this. I have been able to insert other discs and copy them with EAC to FLAC and then convert the FLAC to mp3 using foobar. And the resulting files sound and seem to be completely normal...
Is there anything I should be worried about here?
JXL <---Seriously pissed off consumer mad.gif
sh1leshk4
Have you tried disabling Autorun (temporarily)?
Just hold the Shift key when inserting the CD 'til the LED on your drive stops blinking.

Most copy protection b0rks out when Autorun is disabled.
JunkieXL
I don't have autorun enabled...I just double checked my registry too and its set to 0 like I thought.
I also saw a new line in there though....
Regedit -> HKEY_LOCAL_MACHINE -> System -> ControlSet001 -> Services -> Cdrom
called AutoRunAlwaysDisable with a bunch of listings for drives I dont have
Here's data listing for it
CODE
NEC     MBR-7  
NEC     MBR-7.4
PIONEER CHANGR DRM-1804X
PIONEER CD-ROM DRM-6324X
PIONEER CD-ROM DRM-624X
TORiSAN CD-ROM CDR_C36

JXL
sh1leshk4
To make sure it's disabled, check under CurrentControlSet rather than ControlSet001.
(most of the time, it's probably the same, but I can never be too sure...)

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom

Anyway, that AutoRunAlwaysDisable key, I think it's normal.
JunkieXL
Ya, I changed it to '0' on all 3 tabs Control001, Control003, & CurrentControlSet just to be safe.

I still can't do anything with the cd though. It will go to about 1% and then start doing constant read and sync errors no matter what I do or which drive I run it on.
Stupid Sony...

Correction...I can rip it with the oh so great WMP dry.gif
Lets see how windows media lossless sounds at the highest settings.

Haha...omg this is so retarded its funny. It was nothing but skips and little bits of the actual music. Thought I might get a seizure or some shiz...
sh1leshk4
QUOTE(JunkieXL @ Dec 4 2005, 02:08 PM)
I still can't do anything with the cd though.  It will go to about 1% and then start doing constant read and sync errors no matter what I do or which drive I run it on.
*


Some protected CDs won't work well w/ EAC's Secure Mode.
Try Fast or even Burst Mode.
The same thing happened w/ my copy of Coldplay - X&Y, but Fast Mode did its job.

Anyway, have Sony released a real remover of its rootkitted DRM?
JunkieXL
Nope, burst and fast mode didn't work either. The sound still cuts in and out like it did with the WMP rips. Just going to take the CD back tomorrow and tell them to set fire to it...
sh1leshk4
Well, if you're actually patient enough, you might get proper rips out of it.
When Secure Mode is very slow due to the (very) frequent read & sync error, just let it finish.
Sometimes the resulting rip'd sound just fine; try it w/ ripping a track first, not the whole album rightaway.
I had one of those 'hard-to-rip' Audio CDs that behaved like that.

And OMG, I'm really getting OOT here...sorry guys... =/
JunkieXL
Hehe...it's all good people have been asking about this in the thread. Thanks for the info though. I'll give secure mode another try and see how it turns out.
JXL
sh1leshk4
It's just that I'm afraid to tick someone off by getting somewhat OOT. wink.gif

Well, any way, good luck.
If it turns out bad, you can always try analogue recording... tongue.gif
kritip
Just found this artile from yesterday over on the BBC site. May be of interest to people smile.gif

LINK

Kristian
sh1leshk4
And don't forget to read Mark's blog, people. =)
Lyx
QUOTE
As for notifying consumers of the problem, Ben Edelman has researched the phone-home behavior of the Sony Player software that comes on the CDs and found that, if it wanted, Sony could inform every infected customer that a recall is in place.


oh dear... together with the rootkit behaviour.... wouldn't that basically mean that sony made it so that they could hijack any PC which has the DRM installed, if they wanted to? Boys, if one year ago, someone would have warned about such a thing happening .... most would have called him a "paranoid conspiracy-freak".

Lyx
sh1leshk4
QUOTE(Lyx @ Dec 10 2005, 12:43 AM)
... together with the rootkit behaviour.... wouldn't that basically mean that sony made it so that they could hijack any PC which has the DRM installed, if they wanted to? ...
*

Exactly.
That's why any 'victory declaration' should be postponed until Sony BMG really undo all of their mishaps.

~likeThatWouldHappen... rolleyes.gif
rjamorim
"Free downloads end Sony CD saga

Millions of music fans will be given free music downloads or money to compensate for flawed anti-piracy software on CDs from label Sony BMG "

http://news.bbc.co.uk/2/hi/technology/5007578.stm
Andavari
Well the original rootkit can be blocked from installation using SpywareBlaster using customblocking.txt.
Cartman_Sr
This is really interesting. But I can't find out how I'd claim the compensation for the Velvet Revolver cd I bought a while ago. Has anyone got any more info?
spoon
QUOTE(Cartman_Sr @ May 23 2006, 18:41) *

This is really interesting. But I can't find out how I'd claim the compensation for the Velvet Revolver cd I bought a while ago. Has anyone got any more info?


Email sony, let them do the work, the more customer support they have to give for their wrong doing the better.
aguacaliente
According to the Sony BMG Settlement Page, consumers have until December 31 to file a claim.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2008 Invision Power Services, Inc.