ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Office applications Toolkit

Sony rootkit prompts clampdown on CD use

Ingrid Marson and Graeme Wearden ZDNet.co.uk

Published: 14 Nov 2005 13:50 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Sony's ill-fated decision to include rootkit-like copy-restrictions on some of its music CDs is prompting some companies to review whether they allow their staff to use personal CDs at work.

Andrew Yeomans, vice-president for global information security at investment bank Dresdner Kleinwort Wasserstein, told ZDNet UK that he is already assessing whether his firm need to tighten up their controls. Last week, Trojan horses emerged that avoid detection by using the digital rights management (DRM) software used by Sony on some of its audio CDs. This software uses the same techniques used by rootkit malware to hide itself from the operating system, which makes it particularly difficult to detect.

"I'm reviewing the autorun settings for music CDs, but not planning to ban their use," said Yeomans. "We certainly don't want arbitrary software to be installed."

Yeomans added that it cannot prevent all its employees from running executable programs from a CD or download, as some users have to be given administrator rights to use certain applications — which would allow them to override such restrictions.

Richard Starnes, president of the Information Systems Security Association (ISSA), told ZDNet UK that other companies should consider whether they need a policy on CD use.

"This is certainly something that would trigger a review of policies. I would advise companies to review the situation," said Starnes.

"If it's solely a Sony issue, it is easier for a company to make a decision that it will not allow particular Sony CDs, but if it becomes widespread then it becomes difficult to decide what CDs are allowed or not allow," added Starnes, who was speaking before Sony announced it had stopped producing CDs containing the rootkit-like software, called XCP.

Other companies have confirmed that they are also watching the situation closely.

"Something that can get in and hide itself would have the security people screaming their heads off," said the capacity manager at one major financial firm, who asked to remain anonymous.

"Up until now they thought that audio CDs are safe. I think that will change, and I wouldn't be surprised if every major bank changed their policy. The fact that this software can be used to hide other stuff means that the possibilities for getting at customer data are horrendous," he added.

Opposition to Sony's behaviour has been fierce, with threats of boycotts and even legal action.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
62 out of 131 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Flash developer - Action script version

Are you a technically focused Flash developer with strong AS2/3 development skills, OOP and flash animation and video experience? If so I would love ...

Desktop voice and Audio Visual support analyst- investment banking

Desktop voice and Audio Visual support analyst; I have a great new opportunity working for a leading hedge fund based in the city. This role involves ...

IT Support with AUDIO VISUAL Contract Oppurtunity For An IT Graduate

To apply you must have experience in the following: Desktop Support Windows XP Microsoft Office Audio -Visual Experience The rate will largely depend ...

Vista Upgrade Blog

The game's up for Vista

I got an interesting invite last night to the media launch of a dedicated gaming centre housed in an HMV store in central London. Resplendent with around 80 Quad core PCs and Dual... More

1 comment

Windows Driver Updates

Because of my recent adventures with Windows Vista on my Lifebook, I've had to learn about and deal with the differences between Vista and XP in third-party device driver distribution... More

2 comments

Windows XP SP3 Installed

I have downloaded and installed Service Pack 3 for Windows XP Professional on my Fujitsu Lifebook S6510. Everything went smoothly, and it seems to work just fine. I don't see anything... More

Post a comment

Discussions

mytrader mytrader

welcome to www.007trader.com

Saturday 17 May 2008, 5:07 PM

1 post
mytrader mytrader

welcome to www.007trader.com

Saturday 17 May 2008, 5:02 PM

1 post

Featured Talkback

"We don't recommend specific technologies — we promote the use of technology per se." What sort of nonsense is this?? Every Becta endorsed IT supplier to schools is a Microsoft shop. Every single one.

By: 1000193068

Read full story:
Becta takes Microsoft to the OFT