ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Microsoft patches two DRM holes

John Borland and Stefanie Olsen CNET News.com

Published: 17 Feb 2005 09:55 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft said on Tuesday that Japanese hackers had discovered a potential weakness in its copy protection technology but that the software company fixed the flaw before it was widely used.

The Redmond, Washington-based giant on Tuesday introduced an update to its Windows Media Player, which included changes aimed at blocking the Japanese hackers' work, as well as a security update.

The copy protection changes mark the first time in nearly four years that Microsoft's digital rights management (DRM) protections have been publicly broken, even if largely in theory. As in an earlier case, the company says it was able to update its software before the flaws advanced much beyond the theoretical stage.

"No DRM is perfect," said David Caulton, group product manager in the Windows Media division. "This is another example of somebody finding a way around the technology that we didn't think about. We hear about it, and we effectively get a fix out to users before there's a widely distributed tool for removing digital rights management from files."

The update comes as renewed evidence that hackers and other independent programmers are scrutinising Microsoft's Windows Media Player, as well as the Internet Explorer browser, for flaws or programming loopholes. Microsoft has released repeated security fixes for its Web-browsing software over the past year, as new risks for surfers using the browser continue to appear.

The Japanese hack emerged several weeks ago, when programmers on a public online bulletin board were found to be discussing ways to strip the copy protection off Windows Media files. The actual software that purportedly performed the trick was taken offline after a Japanese magazine wrote about the hack, but Microsoft said the company was able to identify the potential flaw.

The new update also addresses a problem exposed a month ago, in which the Media Player and its digital rights management software could be used to show ads -- or even to lure unsuspecting Web surfers into downloading harmful software onto their hard drives, security researchers said.

The process exploited a feature of the Media Player content protection, which allows protected files to pop up a Web page with information about a video or song license. In such a case, that page could be loaded with automatic spyware download mechanisms, Spanish security company Panda Software said.

Microsoft originally denied that Media player contained a security vulnerability, claiming that it would only allow a social engineering attack -- where a user is fooled into downloading malware. It subsequently admitted that it would issue a patch to fix the problem.

The new update to the Media Player software contains a setting that allows consumers to request that they be notified any time their computer is going onto the Internet to obtain a content licence. By default, this option will be turned off, but computer users can turn it on, Caulton said.

With the associated security issues, however, once the computer does launch the online license acquisition process, a Web page could still be popped up -- even with the update in place. That risk is shared by anyone surfing online, Caulton said, but it could be virtually eliminated by using the latest spyware blockers and Windows operating-system updates, which block automatic downloads of software.

The new Windows Media Player is available now on Microsoft's site and may be distributed to consumers through the company's automatic software update function in the future.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
68 out of 166 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Pre-Sales/ Business Consultant (Banking packages), various locations

Identify potential software license opportunities and liaise with the Sales team. Language: English Skills: Experience of implementing software at ...

Test Analyst - kNOWLEDGE of Asset Classes / FIX / OMS / Trading

One of the leading global Software houses based in the city is currently looking to add a business Test Analyst into their testing team. To be ...

Exception Java Developer Hedgefund Algo Execution Trading - DMA/FIX

Links/messaging protocols for order execution both direct to exchanges and via prime brokers through FIX connectivity. Exception Algorithmic Trading. ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment