The Web Realm
     Marc Chadwick's Weblog
 Local: Home About Contact
Wishlists: Books DVDs Thinkgeek 
Syndicate: RSS RSD Atom

 Sony's Rootkit
Security 

Try as I might, my limited free time has hindered all attempts at keeping up with the Sony Rootkit scandal. I knew bits and pieces. I was aware of the rootkit their CDs automatically installed on Windows systems. I knew that there was a kernel extension installed on OS X systems, but that it required the user to enter their administrative password to do so. I'd heard that the copy protection code illegally used LAME's libraries.

In the back of my mind I was asking some questions: how does it work, why will it damage Windows if you remove it, and why has it taken this long to be exposed? Bruce Schneier wrote a column for Wired News that outlines the entire debacle. It's thorough, and filled with links explaining the things he mentions. And, most importantly for me, he addresses the greatest concern: why has it taken this long for security companies to notice and do something about it? Is anyone actively working to find a way to remove the code without damaging Windows?

 Comments:
smeg said:

Working for one of those security companies, I can tell you why most haven't done much.

Simply put, the Rootkit it's malicious. Like it or not, agree with it or not, it isn't malicious.

Rootkits, as a rule, simply hide something else. What that "something else" does may or may not be malicious, and we pick up a trojan than exploits this, for example.

But Rootkits themselves are simply annoying and frustrating, not malicious. The rootkit doesn't do anything bad to your computer.

Sony used a rootkit to hide a piece of software that supposedly stopped CDs from being copied. It was a dirty tactic that PUA ("Potentially Unwanted Application") style detectors likely would have or should have picked up. But speaking from a virus company perspective, it wasn't a virus.

November 17, 2005 4:17 PM
Marc said:

I do appreciate getting an answer from you. It's a legitimate, logical answer. I sort of wonder whether or not it's posted in as many words on the major security sites?

November 17, 2005 4:25 PM
smeg said:

It's probably not. It was a hot subject, and no one wanted to be the ones to say "hey, this is the deal"

We had an update against the Trojan that used the rootkit, and we developed and released a standalone tool that would scan for, disable and remove the rootkit for those who thought they may have it ... but detection for it was never roled into the actualy AV engine, as it wasn't really relevant.

We did a survey, and 98% of respondents thought it was a genuine security threat, but so are Windows holes, and AV software doesn't scan for them :)

I dunno how I feel about it ... I think blurring the lines between vulnerabilities, viruses, adware, malware, spyware should be avoided. We product Anti *virus*, and will be introducing "PUA" detection next year, but the PUA stuff will be at the administrators descretion, and kept seperate to the AV detection. They are two seperate problems.

November 17, 2005 6:24 PM

Leave a comment

 

February 2008
Sun Mon Tue Wed Thu Fri Sat
          1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29  


Recent Entries
# links for 2008-02-10
# Biofuels Do More Harm Than Good
# del.icio.us
# That'll do it
# Under Construction
# Revamp
# GooSync
# Trusting Google
# Play AACs on your TiVo with TiVo Desktop from a Mac
# My Once and Future Cloud
Flickr Photostream
www.flickr.com
Categories
Apple
Aquarium
Banking
Blog Stuff
Bookmarks
Books
Boston
Comedy
Comics
Development
Drama
Entertainment
For the Mac
Hacks
Hardware
In The News
Internet
Linux
Mobile Phones
Movies
Music
Open Source
OS X
Politics
Red Sox
Science
Security
Software
Sports
Stuff 'n Junk
Sysadmin Stuff
Technology
Television
Testing
Thoughts
UNIX
Vermont
Virii
Windows
Tags
blog  cloud  development  bookmarks  google  code  email  global warming  gmail  google calendar  news  organization  politics  science  study  symbian  tags  test  web 2.0 
Archives
February 2008
January 2008
December 2007
November 2007
October 2007
September 2007
August 2007
July 2007
March 2007
February 2007
January 2007
December 2006
November 2006
September 2006
August 2006
July 2006
June 2006
May 2006
April 2006
March 2006
February 2006
January 2006
December 2005
November 2005
October 2005
September 2005
August 2005
December 2004
November 2004
October 2004
September 2004
August 2004
July 2004
June 2004
May 2004
April 2004
March 2004
Guest Posts
Blog for America
Boston Metroblogs
Links
802 Online
Blog for America
Boston Metroblogs
Dream Theater Info Network
Dr. Mosh
Engadget
Gizmodo
Lukwam
Mac OS X Hints
The Register
SAGE
Skadz
Slashdot
Kevin Smith
Powered by Movable Type Publishing Platform
This blog is licensed under a Creative Commons License.