On TechRepublic: Windows 7: Slower to boot than Vista?
BNET Business Network:
BNET
TechRepublic
ZDNet

Posted on ZDNet News: Nov 18, 2005 5:17:00 AM

Reuters Logo Controversial copy-protection code used by music publisher Sony BMG on CDs appears to have tapped an open-source project, raising questions about copyright, software experts said Friday.

The "rootkit" piece of XCP software, developed by British applications maker First4Internet and used by Sony BMG to restrict copying and sharing of music CDs, is already highly controversial because it acts like virus software and hides deep inside a computer where it leaves the backdoor open for malicious hackers.

Sony BMG earlier this week said it would recall some 4.7 million CDs with the software, after the discovery of the first computer viruses last week that took advantage of the weakness.

Reader response
What should Sony do?
Debate how the debacle will
affect the label's policies.

The XCP program will installs itself on Windows-operated personal computers when consumers play one of 49 CDs from Sony BMG. The program forces consumers to use a music player that comes with the program.

This music player contains components from an open-source project, an MP3 player called LAME, it has emerged.

"Multiple software components on the CD have references to the LAME open-source MP3 code," Finnish software developer Matti Nikki said in an e-mail.

After unraveling the code, others found similar evidence.

"We can confirm that at least five functions in the XCP software are identical to functions in LAME," said Thomas Dullien at security software firm Saber Security in Bochum, Germany, which specializes in the analysis of complex software.

Open-source software, if used, needs to be identified as such, so that it can be freely shared with others. Developers on Slashdot.org and other Internet bulletin boards could not find an open-source reference in the copy-protection software.

If open-source software is tightly integrated into a single executable program, the whole application has to become open source software, even open source software such as LAME whose MP3 encoder is licensed under the more relaxed Lesser General Public License (LGPL), a lawyer said.

"That's the flipside of open source: If you don't respect the open-source rules, the old regime of copy protection comes back in full force," said attorney and Internet specialist Christiaan Alberdingk Thijm at law firm SOLV in the Netherlands.

There was LAME and other LGPL code in the program, and significant amounts were tightly integrated into the executable program, Saber Security said.

"We can confirm the existence of significant amounts of code from FAAC (which is LGPL) in the executable...These functions are part of ECDPlayerControl.ocx, thus directly integrated into the executable," Dullien said in an e-mail.

First4Internet, which sold the XCP software program used by Sony BMG on its CDs, declined to comment after repeated requests since Monday.

Sony BMG, which also declined to comment, has positioned itself as a defender of artists' rights.

It re-emphasized last week that copy-protection software is an "important tool to protect our intellectual property rights and those of our artists."

Responding to public outcry over the unsecure software, the music publishing venture of Japanese electronics conglomerate Sony and Germany's Bertelsmann said last week it would temporarily suspend the manufacture of music CDs containing XCP technology. This week, Sony BMG went a step further and announced it would recall millions of CDs with the rootkit.

Microsoft's antivirus team said Tuesday it would add a detection and removal mechanism to rid a PC of the Sony DRM copy-protection software, because it jeopardized the security of Windows computers.

Sony BMG last week was targeted in a class action lawsuit that asserts that company had not disclosed the true nature of its copy-protection software.

Story Copyright © 2005 Reuters Limited. All rights reserved.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 193 Talkback(s)
Sony destroys a mass of computers
Simple... yes. They stole the bullets. But, Sony/BMG shot the gun. Now let's move on to hotter issues.

Folks like me, have spent a lot of dollars preventing software to enter our home/offices.... (Read the rest)
Posted by: maddog7 Posted on: 11/26/05 You are currently: a Guest | | Terms of Use
GPL Code too  rpmyers1 | 11/18/05
And they tell us it's the pirate stuff that's dangerous...  jinko | 11/21/05
I was wondering when ZDNet would get around to this.  Letophoro | 11/18/05
Better to release it on a slow news day  Michael Kelly | 11/18/05
When were they discovered?  Doc Farmer | 11/18/05
Last week  Letophoro | 11/18/05
Thanks...  Doc Farmer | 11/18/05
Well Sony has two good things going for them  Michael Kelly | 11/18/05
Don't think so...  DarbyOhara | 11/18/05
Depends...  John L. Ries | 11/18/05
This will be forgotten about in a year  Michael Kelly | 11/18/05
Maybe by some  regloff@... | 11/18/05
SONY Products  gregh_z | 11/18/05
Me too!  mrobzo | 11/19/05
Stop talking rubbish.  GetReal-mac.com | 11/19/05
using GPL code commercially is the same as copying Sony CDs!  arabicdes | 11/19/05
Falling on Sword  Too Old For IT | 11/18/05
This will be coming back in about a year.  msfletch | 11/18/05
Never buy another Sony Product.  tystoy1 | 11/18/05
Behind them quickly?  Mihi Nomen Est | 11/18/05
That is the most intelligent thing I've seen about this so far  gardoglee | 11/18/05
They will do it again in about a year  Baer | 11/18/05
And...  regloff@... | 11/18/05
So...  Michael Kelly | 11/18/05
Key word there is "usually"  dragosani | 11/18/05
Could still infect someone else  GregSalts | 11/18/05
Infected Rats  Aero1 | 11/22/05
would not have to publish evenn if gpl  LouS | 11/18/05
Actually, using GPL code binds you to the GPL  The King's Servant | 11/18/05
Sony Won't be on the hook for any GPL issues anyway...  AckItsMe2 | 11/18/05
wrong  STDog | 11/18/05
Ya think??  plumnilly | 11/19/05
I don't trust Sony anymore  Baer | 11/18/05
Most importantly...  Zinoron | 11/18/05
Which Tech Site?  MarkieMark | 11/18/05
Which Tech Site?  MarkieMark | 11/18/05
Is this for real?  Real World | 11/18/05
This is for real... Been for real for 2 weeks +  Neuromage | 11/18/05
Huh?  Real World | 11/18/05
Copyright  dragosani | 11/18/05
I won't be buying Sony CD's any time soon...  gijoevaldez | 11/18/05
I won't be buying ANYTHING from Sony again.  James T. Kirk | 11/18/05
Taking my Camcorder back  Baer | 11/18/05
Handycams and the like are the real point here  gardoglee | 11/18/05
Can We Really Trust ANYONE?  vashthestampede | 11/18/05
Sony wouldn't answer my email asking this very question.  enduser_z | 11/18/05
Oh, Yes!  vashthestampede | 11/18/05
Punishing those who abide by the law  tic swayback | 11/18/05
Punishing those who abide by the law  Ronisue | 11/18/05
Way off base  ShadeTree | 11/18/05
Waiting for the fix  Too Old For IT | 11/18/05
Exactly right  tic swayback | 11/18/05
At this stage of the game ....  Too Old For IT | 11/18/05
Amazon just earned a bit of respect  gardoglee | 11/18/05
Re: Way off base  none none | 11/18/05
pc's not damaged?  jimr_r | 11/18/05
I did read the article and if you had ...  ShadeTree | 11/21/05
Punishing those who abide by the law  Elf586 | 11/18/05
Wrong  tic swayback | 11/18/05
Au contraire...  The King's Servant | 11/18/05
I don't think so  tic swayback | 11/18/05
Who cares what people like you and me think?  The King's Servant | 11/18/05
Seems like a grey area  tic swayback | 11/18/05
Ergo the copyright laws.  The King's Servant | 11/18/05
That's not a license  tic swayback | 11/18/05
Two wrongs, don't make a right  wrench_ninja | 11/18/05
Common sense  tic swayback | 11/18/05
RE: Common Sense  ShadeTree | 11/21/05
Less of a chance though  tic swayback | 11/21/05
IP Irony  scrgeek | 11/18/05
I was waiting for someone to see that irony.  The King's Servant | 11/18/05
Nobody listens to me sad  johns_z | 11/18/05
Sorry, did you say something? I wasn't listening.  The King's Servant | 11/18/05
Contact the Owner  Yensi717 | 11/18/05
Sony & iPod Sucks  Coors4bob | 11/18/05
Two bucks would about do it.  Too Old For IT | 11/18/05
Not worth the price  Baer | 11/18/05
More Sony and Apple Garbage  Baer | 11/18/05
RAID drive failures suck  Mr_Dave | 11/19/05
100% download  adobes | 11/18/05
Message has been deleted.  rafe01 | 11/21/05
pot, kettle, black  rafe01 | 11/21/05
Exactly  Machina_z | 11/22/05
Hypocrits  regloff@... | 11/18/05
Agree 1000%  Edward Meyers | 11/18/05
SONY PRODUCTS  ananaki@... | 11/18/05
Good Use for Sony Products  normanrondeau@... | 11/18/05
Is the music on the CD now GPL???  Sxooter_z | 11/18/05
No  Yensi717 | 11/18/05
Re: No  none none | 11/18/05
You might have something there...  techboy_z | 11/18/05
The questions now becomes...  The King's Servant | 11/18/05
Shouldn't this mean all Sony music is now "open source"?  NeverLift | 11/18/05
No - all it means is that Sony violated a copyright  LouS | 11/18/05
Re: No - all it means is that Sony violated a copyright  none none | 11/18/05
No. only the rootkit is now FOSS  wrench_ninja | 11/18/05
Not just the rootkit  The King's Servant | 11/18/05
half agree, but not about the music  wrench_ninja | 11/19/05
Re: half agree, but not about the music  none none | 11/19/05
agree about player, and rootkit, but not music  wrench_ninja | 11/19/05
Cry me a river  Anthony S. | 11/18/05
DMCA as no stand  Mectron | 11/18/05
DCMA  cheungnt@... | 11/19/05
The courts have to decide  fromthehip | 11/18/05
Not Really  Edward Meyers | 11/18/05
Only one problem with your theory: NO decompilation is neccessary  CobraA1 | 11/18/05
corporate suicide  Andromedat6 | 11/18/05
Already slipping  Baer | 11/18/05
Hang'Em; Hang'Em High  lbattis@... | 11/18/05
This Raises Bigger Problem with Patent Law  wildranger | 11/18/05
It isn't about patent infringement so much...  The King's Servant | 11/18/05
Sony = baloney  rlandman@... | 11/18/05
Sony = baloney  plumnilly | 11/19/05
It is M$ propaganda again!  Linux Geek | 11/18/05
Boy and I thought I was baiting earlier. (NT)  The King's Servant | 11/18/05
UMMM  mobrien_12@... | 11/19/05
Message has been deleted.  MrAmazing1 | 11/18/05
BMG  MrAmazing1 | 11/18/05
Easy to boycott Sony...  Allstar_z | 11/19/05
Message has been deleted.  Allstar_z | 11/19/05
Message has been deleted.  Allstar_z | 11/19/05
So is this funny or what?  George Mitchell | 11/18/05
respect of artistic and creative rights  wrench_ninja | 11/18/05
Ummm, hang on a second, What is really in it?  No_Ax_to_Grind | 11/18/05
Actual Code and Copyright Notices  Edward Meyers | 11/18/05
Then I say hang'em  No_Ax_to_Grind | 11/18/05
I suspect that step is coming ...  George Mitchell | 11/18/05
bet SCO wishes they had that sort of evidence  wrench_ninja | 11/18/05
Bet SCO wishes they any sort of evidence.  mobrien_12@... | 11/19/05
How deliciously lazy  wrench_ninja | 11/18/05
Did the Sony rootkit have any  Boot_Agnostic | 11/18/05
Wow, what wonderful advertisement for the PS3  Boot_Agnostic | 11/18/05
Sony is not the only one to hide...  sykandtyed | 11/18/05
And that is as it should be.  No_Ax_to_Grind | 11/18/05
My point is...  sykandtyed | 11/18/05
No_Ax is right on this one ...  George Mitchell | 11/18/05
Re: No_Ax is right on this one ...  none none | 11/18/05
You Can't be Serious  DaChSa | 11/18/05
Really, show me how then.  No_Ax_to_Grind | 11/19/05
Debatable? You Don't Write S/W Then for A Living  PMC-CON | 11/19/05
Re: Debatable? You Don't Write S/W Then for A Living  none none | 11/19/05
Sorry none none, you are wrong on this one.  No_Ax_to_Grind | 11/19/05
Re: Sorry none none, you are wrong on this one.  none none | 11/19/05
Maybe this goes without saying  mobrien_12@... | 11/19/05
I agree  opensourcepro | 11/22/05
No more CD's  cdiazh | 11/18/05
Wal-Mart  doc_cotton | 11/23/05
see dem hypocrites  corticus | 11/18/05
Is Microsoft a cohort?  DaChSa | 11/18/05
Bill Gates & Mr. Softee @ it again!  u2in99 | 11/18/05
Okay, then. As if I did not have enogh reasons...  The King's Servant | 11/18/05
The wages of Greed.  Gravitas@... | 11/18/05
Can't afford?....lol  techboy_z | 11/21/05
The DMCA  Anthony S. | 11/18/05
Huh?  James T. Kirk | 11/18/05
Re: Huh?  none none | 11/19/05
See my previous post  CobraA1 | 11/18/05
Sony is Violating The DMCA  Edward Meyers | 11/18/05
Sony didn't do anything wrong.  plumnilly | 11/19/05
Boycott Sony  jamestoothman | 11/18/05
Sony Rootkit. The ultimate irony...  bqwer | 11/18/05
Exactly  Fred Fredrickson | 11/19/05
Business is BUSINESS  PMC-CON | 11/19/05
You're kidding, right?  marketmaven | 11/19/05
Re: Business is BUSINESS  none none | 11/19/05
Two wrongs don't make a right  marketmaven | 11/20/05
you're all a bunch of yahoos  sbj | 11/19/05
retort  drew1313 | 11/19/05
Message has been deleted.  drew1313 | 11/19/05
You must be a First4Internet code-tard.  James T. Kirk | 11/19/05
SHAME ON SONY  fakir005@... | 11/19/05
Message has been deleted.  fakir005@... | 11/19/05
Fancy Ripping off DVD JON as well too!  heystoopid | 11/20/05
Not ONLY Sony? Who else belongs to www. IFPI.org?  sierrarancher | 11/20/05
Sony isnt the only one  jimk_z | 11/20/05
Fun, fun, fun  opensourcepro | 11/22/05
Let's see SONY in court  nichols14304@... | 11/21/05
Message has been deleted.  nichols14304@... | 11/21/05
Message has been deleted.  nichols14304@... | 11/21/05
Sony ain't what it used to be  Mike2575 | 11/21/05
Sony hopes to make the public domain extinct  Hanuman67 | 11/21/05
rootkit easily defeated with scotch tape  ChazzMatt | 11/22/05
Message has been deleted.  ChazzMatt | 11/22/05
rootkit easily defeated with scotch tape  ChazzMatt | 11/22/05
rootkit easily defeated with scotch tape  ChazzMatt | 11/22/05
rootkit easily defeated with scotch tape  ChazzMatt | 11/22/05
rootkit easily defeated with scotch tape  ChazzMatt | 11/22/05
sorry!  ChazzMatt | 11/22/05
sorry!  ChazzMatt | 11/22/05
What a load!  opensourcepro | 11/22/05
Sony -  doc_cotton | 11/23/05
Sony destroys a mass of computers  maddog7 | 11/26/05
Sony destroys a mass of computers  maddog7 | 11/26/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and