Trojan horse
Sony BMG's anti-piracy software is allegedly based on stolen code

Sony rootkit accused of licence violation

Nightmare darkens for troubled record label

Tom Sanders in California

The technology used by Sony BMG to prevent piracy of audio CDs is allegedly based on stolen code, according to Sebastian Porst and Matti Nikki, two individuals from Germany and Finland who looked into the application. 

First 4 Internet, the English developer of the controversial XCP anti-piracy technology deployed on some of Sony's audio CDs, is believed to have included software that is governed by the General Public Licence (GPL). 

Advertisement

Under terms of that licence, First 4 Internet is obliged to release the software that uses the GPL code. It did not do so.

"Sony is infringing on open source programmers' copyrights by distributing code which they have no right to use. Even though the code in question was developed by [First 4 Internet], Sony has still been distributing it," Nikki wrote on a webpage where he explained the licence violations

The duo examined the binaries for the XCP software and claim to have found numerous references to functions that were taken from an application called mpg123 as well as other applications governed by open source licences. 

Mpg123 is a media player developed in part by John Lech Johansen, the famous DVD cracker. The application is governed by the GPL and parts of it have been made available under the Lesser GPL, which gives developers more liberty when reusing the code. 

The XCP technology came under fire after security experts unmasked the anti-piracy technology as a major security risk. After weeks of pressure Sony said last Friday that it would stop shipping CDs with the technology and would take back any CDs that consumers had purchased.

The record label has provided a list of 52 titles and item numbers to help consumers identity infected CDs. 

When a user inserts an infected audio CD in a Windows system, the CD installs a new media player, digital rights management technology and a so-called rootkit which hides the technology from the user and the system. The GPL code was found in the media player.

Sony BMG did not respond to a request for further information. First 4 Internet was unable to respond due to the time difference between California and the UK where the firm is headquartered. First 4 Internet has declined in the past to comment on the case.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Trojan horse

Sony backs out of rootkit anti-piracy scheme

Record label caves in under intense pressure

Zombie

vnunet.com analysis: Sony CD rootkit could spell doom

Sony accused of undermining system stability in its crusade to protect copyright

Computer Associates blacklists Sony DRM

Pressure mounts on Sony to abandon insecure technology

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

IT white papers

Search white papers

Top categories

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file...

Dell Adamo XPS

Dell launches ultra-thin Adamo XPS

World's thinnest laptop will be available by Christmas

Top 10 articles, 6 November 2009

The worst Microsoft products of all time, and a USB...

Iain Thomson

Pirate Bay shutdown could be inspiring online militancy

Recent Swedish attacks raise worrying possibility

Primary Navigation