ghacks Technology News

Sony, the rootkit and the internet community


No matter which internet page you open this days you are guaranteed to find at least one article mentioning the Sony rootkit affair. Instead of providing you with the latest news on the case customer vs. Sony BMG I´d like to analyse an interesting aspect of it.

In the beginning, there was one guy, who found out about the rootkit software, analysed it in depth and wrote an entry in his blog named Mark’s Sysinternals Blog on a well frequented site. Then the ball got rolling, the news was copied and commented on other sites, big portals like slashdot.org and digg.com had articles that soon became the most popular ones for the day.

The news spread like fire in the world wide web, people from all over the world read the news. It was soon clear that there were only a few who supported Sony´s move, the majority was clearly against it.

News got worth for Sony the following days, Mark again identified some additional “features”. First, the rootkit software was phoning home to Sony. Second, it was almost impossible for the average user to uninstall it. Third, the rootkit possed a cloaking ability that other executables could use to hide inside, a perfect hiding place for viri and trojans.

Sonys reaction was to provide an update to the rootkit software that disabled the cloaking feature. Unfortunatly it was again almost impossible for the average user to find the uninstaller on their webpage. Still, Sony in its shining glory denied that the rootkit posed a security threat and that most users didn´t care wether a rootkit was installed on their system. The patch unfortunatly had the nasty habit to crash windows on some machines.

The internet community created lists of cd´s that contained the software, boycott websites went into existance and had to deal with a massive amount of visitors who were looking for information or wanted to join the boycott.

With lots of News Coverage from respected institutes like BBC Sony presented a statement on monday that they would cease the production of music cd´s containing First 4 Internet’s XCP technology, for now.

Yesterday Dan Kaminsky presented the first figures of rootkit infections analysing the rootkits phone home traces in the dns cache of nameservers. This lead to the conclusion that at least half a million networks are infected with it. He created a graphic showing infections on a map of north america.

sony infection usa rootkit

Today Sony finally announced that it would institute an exchange program for already purchased cd´s and pull the rest from the market.

Now, what conclusion can we draw from this ? It´s pretty obvious to me that Sony underestimated the “might” of the internet community. From a single website the story spread into the whole world in no more than one day. It became so popular that big internet portal sites like wired.com, cnn.com and theregister.co.uk reported on it. The traditional media became aware and soon the story was also making headlines in newspapers, radio shows and even television.

Sony: 0
Internet Community: 1

What i learn from this ? We have a tremendous power in our hands and can use it to force even multinational corporations to yield, even countries ? That question remains to be answered.

Technorati Tags: , , , , , ,




Tags: ,
Categories: Spyware



Related posts:

Sony and the rootkit, the story continues
Sony halts production of ‘rootkit’ CDs
How to remove the Sony – XCP DRM Rootkit
World of Warcraft hackers using Sony BMG rootkit
First Trojan using Sony DRM spotted
Dvd Rootkit on the way
Sony DVD does not play on Sony DVD Player because of DRM
Rootkits: Sony does it again

6 Responses to “Sony, the rootkit and the internet community”

  1. mandy says:

    Very well written and thought out.
    Makes ya go “Hmmmm.” doesn’t it. :)

  2. I think it highlights far more on the state of security for most users. You can only install the sony rootkit with admin rights, and yet we have heard stories of the military being affected by it, whole company network being affected after IT tried to remove the rootkits etc etc. All of these things were caused by the rootkit, but they were only allowed to happen by bad security setups; allowing users to work with admin rights etc.

  3. Martin says:

    oliver we all know that many computers are vulnerable because of people who don´t know or care, even in security workplaces like the military or science. But thats another story :P

  4. Hoopy says:

    It also highlights the fact that windows lets you run as administrator out of the box, and most people, not understanding the implications, just leave it that way.

  5. Martin says:

    Hoopy what would you suggest then, I think it´s a complicated matter.. maybe something like a driving license for the internet and computers ;)

Trackbacks/Pingbacks

  1. click here says:

    click here

    Occasionally, you will become stunned by the colossal sum of sony audio intelligence available.

Leave a Reply   Follow Ghacks   Subscribe To Comment Rss

© 2005-2009 Ghacks.net. All Rights Reserved. Privacy Policy - About Us