On TV.com: Top 15 TV THEME Songs
BNET Business Network:
BNET
TechRepublic
ZDNet

By John Borland
Posted on ZDNet News: Feb 17, 2005 12:15:00 AM

Microsoft said Tuesday that Japanese hackers had discovered a potential weakness in its copy protection technology but that the software company fixed the flaw before it was widely used.

The Redmond, Wash., giant on Tuesday introduced an update to its Windows Media Player, which included changes aimed at blocking the Japanese hackers' work, as well as a security update.

"No DRM is perfect. This is another example of somebody finding a way around the technology that we didn't think about."
--David Caulton
Manager, Windows Media

The copy protection changes mark the first time in nearly four years that Microsoft's digital rights management (DRM) protections have been publicly broken, even if largely in theory. As in an earlier case, the company says it was able to update its software before the flaws advanced much beyond the theoretical stage.

"No DRM is perfect," said David Caulton, group product manager in the Windows Media division. "This is another example of somebody finding a way around the technology that we didn't think about. We hear about it, and we effectively get a fix out to users before there's a widely distributed tool for removing digital rights management from files."

The update comes as renewed evidence that hackers and other independent programmers are scrutinizing Microsoft's Windows Media Player, as well as the Internet Explorer browser, for flaws or programming loopholes. Microsoft has released repeated security fixes for its Web-browsing software over the past year, as new risks for surfers continue to appear.

The Japanese hack emerged several weeks ago, when programmers on a public online bulletin board were found to be discussing ways to strip the copy protection off Windows Media files. The actual software that purportedly performed the trick was taken offline after a Japanese magazine wrote about the hack, but Microsoft said the company was able to identify the potential flaw.

The new update also addresses a problem exposed a month ago, in which the Media Player and its digital rights management software could be used to show ads--or even to lure unsuspecting Web surfers into downloading harmful software onto their hard drives, security researchers said.

The process exploited a feature of the Media Player content protection, which allows protected files to pop up a Web page with information about a video or song license. In such a case, that page could be loaded with automatic spyware download mechanisms, Spanish security company Panda Software said.

The new update to the Media Player software contains a setting that allows consumers to request that they be notified any time their computer is going onto the Internet to obtain a content license. By default, this option will be turned off, but computer users can turn it on, Caulton said.

With the associated security issues, however, once the computer does launch the online license acquisition process, a Web page could still be popped up--even with the update in place. That risk is shared by anyone surfing online, Caulton said, but it could be virtually eliminated by using the latest spyware blockers and Windows operating-system updates, which block automatic downloads of software.

The new Windows Media Player is available now on Microsoft's site and may be distributed to consumers through the company's automatic software update function in the future.

Microsoft said Tuesday that Japanese hackers had discovered a potential weakness in its copy protection technology but that the software company fixed the flaw before it was widely used.

The Redmond, Wash., giant on Tuesday introduced an update to its Windows Media Player, which included changes aimed at blocking the Japanese hackers' work, as well as a security update.

"No DRM is perfect. This is another example of somebody finding a way around the technology that we didn't think about."
--David Caulton
Manager, Windows Media

The copy protection changes mark the first time in nearly four years that Microsoft's digital rights management (DRM) protections have been publicly broken, even if largely in theory. As in an earlier case, the company says it was able to update its software before the flaws advanced much beyond the theoretical stage.

"No DRM is perfect," said David Caulton, group product manager in the Windows Media division. "This is another example of somebody finding a way around the technology that we didn't think about. We hear about it, and we effectively get a fix out to users before there's a widely distributed tool for removing digital rights management from files."

The update comes as renewed evidence that hackers and other independent programmers are scrutinizing Microsoft's Windows Media Player, as well as the Internet Explorer browser, for flaws or programming loopholes. Microsoft has released repeated security fixes for its Web-browsing software over the past year, as new risks for surfers continue to appear.

The Japanese hack emerged several weeks ago, when programmers on a public online bulletin board were found to be discussing ways to strip the copy protection off Windows Media files. The actual software that purportedly performed the trick was taken offline after a Japanese magazine wrote about the hack, but Microsoft said the company was able to identify the potential flaw.

The new update also addresses a problem exposed a month ago, in which the Media Player and its digital rights management software could be used to show ads--or even to lure unsuspecting Web surfers into downloading harmful software onto their hard drives, security researchers said.

The process exploited a feature of the Media Player content protection, which allows protected files to pop up a Web page with information about a video or song license. In such a case, that page could be loaded with automatic spyware download mechanisms, Spanish security company Panda Software said.

The new update to the Media Player software contains a setting that allows consumers to request that they be notified any time their computer is going onto the Internet to obtain a content license. By default, this option will be turned off, but computer users can turn it on, Caulton said.

With the associated security issues, however, once the computer does launch the online license acquisition process, a Web page could still be popped up--even with the update in place. That risk is shared by anyone surfing online, Caulton said, but it could be virtually eliminated by using the latest spyware blockers and Windows operating-system updates, which block automatic downloads of software.

The new Windows Media Player is available now on Microsoft's site and may be distributed to consumers through the company's automatic software update function in the future.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 14 Talkback(s)
youre joking, right? (nt)
no text is here, why are you reading this? quick, go to the next article or see what witty reply ensues :P... (Read the rest)
Posted by: linuxoverwindows Posted on: 02/19/05 You are currently: a Guest | | Terms of Use
Not that I  Linux User 147560 | 02/16/05
"No DRM is perfect"  rpmyers1 | 02/16/05
I second the nomination.  nucrash | 02/17/05
Of course not... DRM always provides a way to break it!  Root User | 02/17/05
Exactly!  tic swayback | 02/17/05
Curious....  rlodge@... | 02/17/05
Faster I'd bet  voska | 02/17/05
Money is always involved  Real World | 02/17/05
You took the words right out of my keyboard. (NT)  James T. Kirk | 02/17/05
Don't they on average......  dbrannan | 02/18/05
youre joking, right? (nt)  linuxoverwindows | 02/19/05
Oddly phrased  James T. Kirk | 02/17/05
Who cares about the hole. Use Ace Mega Codec Pack or K-lite Mega Codec Pack  GreatInca | 02/17/05
More info pleez  Loverock Davidson | 02/17/05

What do you think?

advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here