Controversial copy-protection software used by music publisher Sony BMG on music CDs appears to have tapped an open source project, raising questions about copyrights, software experts said on Friday. The XCP program, developed by British software firm First4Internet and used by Sony BMG to restrict copying and sharing of music CDs, is already highly controversial because it acts like virus software and hides deep inside a computer where it leaves the backdoor open for malicious hackers.
Sony BMG earlier this week said it would recall some 4.7 million CDs with the software, after the discovery of the first computer viruses last week that took advantage of the weakness. The XCP program will have installed itself on a Windows-operated personal computer when consumers want to play 49 title CDs from Sony BMG. The programme forces consumers to use a music player that comes with the program. This music player contains components from an open source project, an MP3 player called LAME, it emerged.
View: The full story
News source: eWeek
Sony BMG earlier this week said it would recall some 4.7 million CDs with the software, after the discovery of the first computer viruses last week that took advantage of the weakness. The XCP program will have installed itself on a Windows-operated personal computer when consumers want to play 49 title CDs from Sony BMG. The programme forces consumers to use a music player that comes with the program. This music player contains components from an open source project, an MP3 player called LAME, it emerged.
To all you Xbox holders...will you be rushing to the stores to get your copy of HL:2?
-Enan Hawk

Please do not bypass the swear filter
Last edited by 36818 on 18 Nov 2005 - 18:11
I smell hypocracy
Disclaimer: I'm very very tired so if that didn't make sense, sorry.
"Rolf from Sabre Security was kind enough to point out that we had missed a giant copyright string.
000C48C0 4641 4143 202D 2046 7265 6577 6172 6520 FAAC - Freeware
000C48D0 4164 7661 6E63 6564 2041 7564 696F 2043 Advanced Audio C
000C48E0 6F64 6572 2028 6874 7470 3A2F 2F77 7777 oder (http://www
000C48F0 2E61 7564 696F 636F 6469 6E67 2E63 6F6D .audiocoding.com
000C4900 2F29 0A20 436F 7079 7269 6768 7420 2843 /). Copyright (C
000C4910 2920 3139 3939 2C32 3030 302C 3230 3031 ) 1999,2000,2001
000C4920 2020 4D65 6E6E 6F20 4261 6B6B 6572 0A20 Menno Bakker.
000C4930 436F 7079 7269 6768 7420 2843 2920 3230 Copyright © 20
000C4940 3032 2C32 3030 3320 204B 727A 7973 7A74 02,2003 Krzyszt
000C4950 6F66 204E 696B 6965 6C0A 5468 6973 2073 of Nikiel.This s
000C4960 6F66 7477 6172 6520 6973 2062 6173 6564 oftware is based
000C4970 206F 6E20 7468 6520 4953 4F20 4D50 4547 on the ISO MPEG
000C4980 2D34 2072 6566 6572 656E 6365 2073 6F75 -4 reference sou
000C4990 7263 6520 636F 6465 2E0A 0000 312E 3234 rce code....1.24
Yeah. Apparently FAAC code was used too. I positively identified several functions myself. For starters: The function at virtual offset 0x1007BA80 is known as WriteFAACStr in the file bitstream.c of the FAAC project. You can work yourself through other FAAC functions from there. I don't know for sure if that's GPL or LGPL. I think it's LGPL though.
And while we're at it. Matti found mpg123 references. In his opinion this is how the mpglib code made it into the OCX. It still needs to be determined if there's more mpg123 code in the OCX except the mpglib stuff. If that's the case another GPL infringement can be added to the list."
tututututututut.
That's a lawyer stampeed.
There's going to be some serious lawsuits over this stuff....cool.
Just a little note for all the people who have made statments akin to yours thus far -> Not all music is released by sony. thank you for listening and goodnight.
There are artists out there that do not publish their works via Sony, or any one of their related labels, so to suddenly say I won't buy any albums just because of one label's screw up is wrong.
Granted, after this, I will DEFINATELY pay much closer attention to ANY music CD I consider purchasing from now on, which is I think something all of us need to do in this day and age of DRM and corporate greed.
And what is just a sick, is that there are plenty of people who do nothing but stick up for these companies.
I'm also sick of the stupid excuse they use for their cold hearted attitudes. Claiming they have lost some made up imaginary dollar amount of money that they never even had in the first place. In my opinion, THEY are the ones that belong in jail.
This news isn't good either, what a mess...
Please do not bypass the swear filter
Last edited by 36818 on 19 Nov 2005 - 12:47
In an attempt to make up with CONSUMERS......
There is really no make up with developers. Sony licensed the code and therefore loses rights granted under those licenses. Discontinuing distribution is a start.
Last edited by 40343 on 19 Nov 2005 - 21:52
And no, stopping the distribution won't help, they have to release the sources as soon as the derived work gets released - and it got released, even if they swap the CDs now...!
1) Sony CAN NOT be trusted.
2) All copy protection is BS. Instead of making life better for the paying consumer and harder for the pirates - legit consumers are left with unsecured systems. And has any if this stopped Sony/BMG music being on P2P sites or (hush hush) newsgroups? No!
I received an email the next day stating a customer service representative had received my email.
No response as of yet, this was Saturday I received the email.
Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!
Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.