All the latest UK technology news, reviews and analysis

Sony rootkit accused of licence violation

by Tom Sanders in California

18 Nov 2005

Comment: 1

  • Tweet this
Trojan horse
Sony BMG's anti-piracy software is allegedly based on stolen code

The technology used by Sony BMG to prevent piracy of audio CDs is allegedly based on stolen code, according to Sebastian Porst and Matti Nikki, two individuals from Germany and Finland who looked into the application. 

First 4 Internet, the English developer of the controversial XCP anti-piracy technology deployed on some of Sony's audio CDs, is believed to have included software that is governed by the General Public Licence (GPL). 

Under terms of that licence, First 4 Internet is obliged to release the software that uses the GPL code. It did not do so.

"Sony is infringing on open source programmers' copyrights by distributing code which they have no right to use. Even though the code in question was developed by [First 4 Internet], Sony has still been distributing it," Nikki wrote on a webpage where he explained the licence violations

The duo examined the binaries for the XCP software and claim to have found numerous references to functions that were taken from an application called mpg123 as well as other applications governed by open source licences. 

Mpg123 is a media player developed in part by John Lech Johansen, the famous DVD cracker. The application is governed by the GPL and parts of it have been made available under the Lesser GPL, which gives developers more liberty when reusing the code. 

The XCP technology came under fire after security experts unmasked the anti-piracy technology as a major security risk. After weeks of pressure Sony said last Friday that it would stop shipping CDs with the technology and would take back any CDs that consumers had purchased.

The record label has provided a list of 52 titles and item numbers to help consumers identity infected CDs. 

When a user inserts an infected audio CD in a Windows system, the CD installs a new media player, digital rights management technology and a so-called rootkit which hides the technology from the user and the system. The GPL code was found in the media player.

Sony BMG did not respond to a request for further information. First 4 Internet was unable to respond due to the time difference between California and the UK where the firm is headquartered. First 4 Internet has declined in the past to comment on the case.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Java developer (J2EE/Web) - Nr Warrington (off M6)

Java / J2EE analyst programmer with experience of building...

Crystal Reports Developer London or Dublin £340 per day

Crystal Reports Developer London or Dublin £340 per day...

Systems Administrator

Our client is a major Broadcasting company seeking a...

Support Engineer - Linux/ Windows

Support Engineer required to work for leading Online...

To send to more than one email address, simply separate each address with a comma.