On CNET: 10 absurd and useless iPhone apps
BNET Business Network:
BNET
TechRepublic
ZDNet

By Liam Tung, ZDNet Australia
Posted on ZDNet News: Aug 31, 2007 5:49:00 AM

Sony says the rootkit-like behavior of a device driver used to run its biometric Micro Vault USM-F thumb drive was unintentional.

Sony Sweden spokesman Fredrik Fagerstedt told local press this week that sometimes even actions undertaken with "good will" can go wrong.

Fagerstedt's comments came the same day that antivirus firm McAfee joined the growing chorus of companies criticizing Sony for compromising its customers' security. The Micro Vault drive is a USB device featuring fingerprint-reading software intended to add an extra layer of security for PC users. The software needed to be installed on the PC for the USB to work contains the rootkit technology.

The criticism is reminiscent of that directed at Sony BMG Music Entertainment in November 2005, when a programmer revealed that a technique designed to cloak the company's copy-protection software for music CDs also could be used by virus writers to hide malicious software.

McAfee reported that Taiwan's FineArt Technology, which makes encryption software for PCs and laptops, was responsible for creating the offending USB software.

"The authors apparently did not keep the security implications in mind" when designing the installation method, McAfee security specialists Aditya Kapoor and Seth Purdy wrote in a blog.

Kapoor and Purdy cataloged the incident as one of the worst examples of "nasty rootkits that use blended techniques to hide or protect themselves."

Echoing concerns expressed by another security specialist, F-Secure's Patrik Runald, the McAfee bloggers said the default installation path does nothing to stop malicious-software authors from copying code to a directory of their choice and executing it in that location.

They added that another easy hack for malicious-software authors would be to launch code from their chosen directory and add a start-up entry for the software to ensure it is hidden immediately as the PC boots up.

Sony Australia has not responded to multiple requests for comment.

Liam Tung of ZDNet Australia reported from Sydney.

  • Talkback
  • Most Recent of 16 Talkback(s)
And besides...
MOST fingerprint readers - be they hardwired into the box or of the USB fob type - are UTTERLY USELESS.

There's a dirty little secret with them. They're extremely easy to defeat - assuming you ... (Read the rest)
Posted by: Wolfie2K3 Posted on: 09/04/07 You are currently: Logged In | Log out
Too many screwups for Sony lately BitTwiddler   | 08/31/07
It's not just Sony... Linux User 147560   | 08/31/07
Boo! Shelendrea   | 08/31/07
Was any security gained? jinko   | 09/01/07
No security was gained CobraA1   | 09/01/07
And besides... Wolfie2K3   | 09/04/07
Unintentional? That's even worse. John E Wahd   | 08/31/07
I'm surprised all the Softies... jasonp@...   | 08/31/07
Not really.... techboy_z   | 09/04/07
S/W design incompetence and lowest cost resources terry flores   | 08/31/07
Just Say NO to Sony fwfulton   | 08/31/07
AMEN TO THAT kokuryu   | 09/04/07
Also used to like Sony Boot_Agnostic   | 09/03/07
Sony can zuk my dic-tation unit, heh... tek_heretik   | 09/03/07
When Are People Just Going To Ditch Sony? itanalyst   | 09/03/07
Sun Boot_Agnostic   | 09/04/07

What do you think?

advertisement
advertisement
advertisement
Click Here