SonyBMG backtracks on buggy bug fix
Wearing out the rewind button
Posted in Software & Security, 9th December 2005 11:14 GMT
Free whitepaper – What Exchange can't do - and Dell can
SonyBMG’s efforts to regain some credibility with PC users came unstuck again after it admitted that a patch for flawed content protection software included with some its CDs actually creates more problems for users.
The academics who have uncovered the latest security hole say the only way Sony can dig itself out is to recall all the CDs that shipped with the flakey software.
The hapless media giant snuggled up to the Electronic Frontier Foundation earlier in the week to admit that Sunncomm MediaMax content protection software on some of its CDs could leave users’ PCs open to hijacking by unauthorised users. It instructed users to download a patch from MediaMax.
Now, academics at Princeton University have found that the patch itself suffers from the same bug, though in a slightly different way. They have advised users to not install the patch and indeed to not insert the affected disk in a PC under any circumstance, and the EFF and Sony have gotten behind them.
Professor Ed Felten and Alex Halderman the problem is “just as bad” as the DRM rootkit carried on other CDs and which caused a furore last month.
They go on to say that each CD sitting on a shelf is effectly a ticking timebomb, and the only way for Sony to really sort the problem is to recall all the affected disks.
Only the very paranoid would suggest that advice to not insert an audio CD into a PC delivers exactly the level of "content protection" Sony and the other music giants have been gunning for all this time.®
Free whitepaper – Managing desktop software for fun and profit
The Register Agile Data Center Summit
Straight Talk with Dell: Sending out an SaaS
Seven ways to optimize VMware server virtualization
Automating the Acquisition Process with Enterprise Level CRM

Sign up, sign up for The Register IT security newsletter
Microsoft's Windows 7 price gamble - and why it's flawed
Managing Desktop Software for fun and profit
Intel's flash new SSDs hit by bugs