Neowin's Official Sony DRM/Rootkit Discussion


Recommended Posts

This is to be the only thread about the Sony Rootkit issues.

List of Affected Albums

From here:

Sony BMG will have a big job ahead of it as it tries to replace all copies of controversial copy protection software, according to a computer security expert, who says that he has evidence there are more than 500,000 versions of the program installed worldwide.

From here:

Yet more on the Sony/BMG rookit fiasco: Princeton professor Ed Felten over at Freedom to Tinker now claims the DRM's uninstaller opens up a security hole of its own. Sony/BMG stated they'd be removing the impacted CDs from store shelves yesterday, and released a statement saying they'd exchange affected CDs for DRM free versions. "Sony BMG deeply regrets any inconvenience to our customers and remains committed to providing an enjoyable and safe music experience," states the company.

From here:

The spyware that Sony installs on the computers of music fans does not even seem to be correct in terms of copyright law.

This software is licensed under the so called Lesser Gnu Public License (LGPL). According to this license Sony must comply with a couple of demands. Amongst others, they have to indicate in a copyright notice that they make use of the software. The company must also deliver the source code to the open-source libraries or otherwise make these available. And finally, they must deliver or otherwise make available the in between form between source code and executable code, the so called objectfiles, with which others can make comparable software.

Please add more news stories as posts inside this thread only. All other Sony DRM threads have been closed.

I swear after all this fiasco I'm not getting any of the Sony equipment, period! I am buying a crap load of hi-fi and video equipment for my new house and after this I'm not gonna give these losers a cent. This thing just cost them around $15k of revenue just from me. It might sound funny but I'm pretty certain that they will lose quite a bit of sales from people like me (techies with a good paycheck that liked Sony products once used them throughout generations). Who knows what they might be implementing in their TVs, audio/video receivers, cd players etc.

It's ridiculous. Who is running the show there. No wonder movie studios and other leeches are sticking with Sony solutions for PS3. I guarantee some kind of spyware being present on PS3.

Why have this all in one thread? this is crazy, what if there is a new article or update about it and it gets missed because it's going to be buried in a 100+ page thread.

586815816[/snapback]

Because staffed deemed it so.

Looks like they are finally going to recall the infected CDs. It's about damn time. :crazy:

Record label Sony BMG Music Entertainment said Tuesday that it will recall millions of CDs that, if played in a consumer's PC disc drive, will expose the computer to serious security risks.

Source

Looks like they are finally going to recall the infected CDs. It's about damn time.  :crazy:

Source

586815936[/snapback]

Considering just last week, they didn't seem the slightest bit concerned, it's pretty funny to see such a quick change of heart.

why is the list of albumns affected thread closed?

I wanted to post there that the list / link to the website idiotabroad.com or whatever wasn't the FIRST person to discover how to get a list of albumns affected. Xtracto on /. was the first person I believe.

http://slashdot.org/~xtracto/journal/121088

It is basically a google search of the amazon site.

http://www.google.co.uk/search?q=sony+site...D%5D%22&num=100

I am sure where that is where idiotabroad guy got his info from since it was like 10 days after xtracto made his post.

Oh, so this is where the Sony threads have been merged! I thought at first that the mods were trying to bury criticism of Sony on this key issue when they closed left and right several threads, but now I see this is not the case.

Frankly I'm heartened by the criticism Sony has come under. I'm all for their protecting their right to control their products, but they really crossed the line by destabilising computers (there is no other word for it) and rendering them more prone to viruses and other horrorwares. That's just not on.

I am boycotting Sony CDs and their other products. This isn't easy as they have bands I like, but I'm not going to give in for at least a year (or if meantime they do something significant to apologise and make amends for the grave attack on people's privacy and security).

:cat: :cat: :cat: :jump: :fun: :santa: :santa: :fun: :cat: :cat: :cat: :cat:

Very good idea and i am sure that will amek them think a bit more about what they do.

I think that big compagnies think they can do what they want.

Well to bad big boy's you just got the internet community now against you and i can assure you it will be war.

sorry about that but come to think about it is true that if we all put are self together then they wont have a choice, you need to remember that we are the one's that makes them live . If we dont buy they go down. it is that simple. i will not buy or even rent anything related to that compagnie until everything they did is fixed.

Just grow up and shut up about "boycotting Sony products." Your choice in products is going to be very limited if you boycott every company who ever did something stupid. Do any of you even realize how much you owe Sony? If you have a PlayStation, you owe it to Sony. If you have an Xbox, you owe it to Sony too, because without a competition as fierce as PlayStation, Microsoft would never have put so much effort into their console. Are you getting my drift? If you own any sort or digital camera, MP3 player, cell phone, game system, television, even a pair of god damn headphones, Sony has either made them or made someone else make them better.

Sony makes tons of good products, and adds a lot to the competitiveness of many electronics markets. But I guess now that they've put out a few dozen albums with a less than perfect DRM, all the decades of technology they've contributed to your sorry arse are forgotten. So go ahead, be a dumb@$$ kid, and respond with a quote of my previous sentense followed by a "HA!".

Don't touch that standalone patch remover before it is verified that it actually does what it is supposed to do.

There is several stories out about an earlier remover that opened up your system to vulnerbilities.

Sounds like a reasonable decision, since regardless how well Sony patch this up, they have so far never told anyone that their intents of crippling user experiences with DRM damaged CD's will change. For all we know, they may try again next year with XCP 2.0. All they've admitted to so far with their actions is that they made a mistake with this one, not that they want to keep risking corrupting their customers systems in the future. IMO, they'd at the very least need to start using open and verified DRM standards for that, not home-brewn closed source rubbish, and preferrably not DRM at all. The general security community need to gain an insight in their developments, and no good encryption scheme were dependant on being closed source anyway -- achieving security by obscurity is generally a poor idea.

That gov't agency's decision sounds logical to me, especially, as The Register says, rookits can be BAD for organizations involved in national security. :)

All they've admitted to so far with their actions is that they made a mistake with this one

Stable doors and bolted horses. It's already out there. All that's left to do is for some enterprising character to make a virus that also installs the rootkit, now that we all know how it works, so pretty much anything could get itself installed...

This isn't going to go away in a hurry. After all, how many CDs have been bought as presents for (say) (grand)parents who might well have a computer so they can be part of the Silver Surfer brigade but have no knowledge whatsoever about a) the workings of the computer, b) the fact that the rootkit exists and c) will compromise their security? Is the purchaser supposed to remember that they bought a CD from Sony BMG, subsequently gave it as a present and then also know to have to check it?

It smacks of the amazing amount of time before Code Red was properly patched. Systems were still being compromised months later.

i heard that some people have started to boycott sony products..

586816312[/snapback]

Boycotting works for me.

I have boycotted the french for four years or more now.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • OpenAI is rolling out a major upgrade to ChatGPT memory by Pradeep Viswanathan OpenAI is rolling out a major upgrade to ChatGPT's memory, making the system more capable, current, and scalable across long-term use. Memory allows ChatGPT to remember useful details about users, including their preferences, projects, and constraints. Instead of starting every conversation from scratch, ChatGPT can use this context to provide more relevant responses in future chats. OpenAI first launched saved memories in February 2024. That feature allowed users to explicitly ask ChatGPT to save information into its memory, such as travel plans or writing preferences. However, this system had limits because it depended heavily on users giving clear instructions to remember something. Additionally, saved memories could become stale over time. In April 2025, OpenAI expanded memory by allowing ChatGPT to reference past chat context outside the saved memories list. This was powered by a background process called “dreaming,” which automatically curates memories from chat history. This made ChatGPT better at learning from natural conversation without requiring users to manually save every detail. Today, OpenAI announced a more capable and compute-efficient memory architecture built on top of dreaming. This new system improves ChatGPT’s ability to carry forward useful context, follow user preferences, and remain accurate as time passes. According to OpenAI’s internal evaluations, the new system improves factual recall from 67.9% in 2025 to 82.8% in 2026. Preference adherence improves from 55.3% to 71.3%, while accuracy over time improves from 52.2% to 75.1%. The best part of this new system is a new memory summary page where users can review ChatGPT's memories. Users can even update details, correct information, or give instructions on what topics ChatGPT should bring up and when. This new, improved memory system is available to ChatGPT Plus and Pro users in the US starting today. It will roll out to more countries, as well as Free and Go users, in the coming weeks.
    • I work for a video production company in Australia. The camera operators shoot footage and then pass the SD card over to the editors. Much easier than handing over the entire camera. Plus, on a busy day you can hand off the SD card and then pop another in for the next shoot. Or, you might have used multiple SD cards because you need the extra space for a long shoot. I also use USB cables and wifi for transferring footage, but in many cases an SD card reader is the easiest method.
    • Microsoft Edge 149.0.4022.52 by Razvan Serea Microsoft Edge is a super fast and secure web browser from Microsoft. It works on almost any device, including PCs, iPhones and Androids. It keeps you safe online, protects your privacy, and lets you browse the web quickly. You can even use it on all your devices and keep your browsing history and favorites synced up. Built on the same technology as Chrome, Microsoft Edge has additional built-in features like Startup boost and Sleeping tabs, which boost your browsing experience with world class performance and speed that are optimized to work best with Windows. Microsoft Edge security and privacy features such as Microsoft Defender SmartScreen, Password Monitor, InPrivate search, and Kids Mode help keep you and your loved ones protected and secure online. Microsoft Edge has features to keep both you and your family protected. Enable content filters and access activity reports with your Microsoft Family Safety account and experience a kid-friendly web with Kids Mode. The new Microsoft Edge is now compatible with your favorite extensions, so it’s easy to personalize your browsing experience. Microsoft Edge 149.0.4022.52 changelog: Migration to improved V2 architecture for Workspaces. Workspaces, introduced in Edge in 2022, allows users to create durable sets of tabs that can be saved and shared with others. In order to improve reliability and performance of this feature, the following changes are being made: Migrating data for saved Workspaces from OneDrive/SharePoint to Edge Sync service Removing the collaboration/share functionality of this feature For organizations who have disabled Sync through policy, the existing v1 Workspace data will still be migrated to the new architecture. New v2 Workspaces created after migration won't sync across devices and will remain local to each device. This update occurs on a progressive rollout beginning in Edge Stable v145 and will continue rolling out in Edge v149. For more information, see Getting started with Microsoft Edge Workspaces. Feature Updates Passkey Sync for Enterprise Users. Microsoft Edge is introducing support for passkey synchronization for enterprise users, enabling secure, passwordless authentication across devices. Passkeys created in Edge can now be synced seamlessly, improving sign-in experience while maintaining strong security standards. Note: This is a controlled feature rollout. If you don't see this change, check back as we continue the rollout. Enterprise WebView2 runtime downgrade via DowngradeVersion policy. Administrators can temporarily roll back specific applications to a previous WebView2 Evergreen Runtime version (N-1 or N-2) using the new DowngradeVersion policy in msedgewebview2.admx. The Downgrade Version policy allows enterprises to mitigate critical regressions by specifying per-application exe-to-version mappings. The Edge Updater installs the target version side-by-side, and the WebView2 Loader redirects targeted apps accordingly. Downgrades auto-expire with each new WebView2 release: apps pinned to N-1 remain on the same version (now becoming N-2) and will auto-update in the next release, while apps pinned to N-2 will revert to the current Evergreen version. The policy applies only to enterprise-managed devices (domain-joined or MDM-enrolled). For more information, see Microsoft Edge WebView2 Policy Documentation | Microsoft Learn. Collections retirement. Collections has been removed in this update. Users can no longer access or use the feature. To keep saved content, users can export it, or move all pages to Favorites before updating to Microsoft Edge Stable 149. For more information, see Organize your ideas with Collections in Microsoft Edge - Microsoft Support. Modern, unified, and updated Look and Feel. Microsoft Edge has updated the Look and Feel to give customers a unified experience across all of Microsoft AI surfaces including Copilot and Bing. This changes multiple elements of the UX such as spacing, corners, fonts, default colors, etc. Clarify choices surrounding third-party cookie settings. Language under Settings > Privacy, search, and services > Cookies are clarified to better describe the choices users have in managing third-party cookies. Custom primary password retirement. Users are no longer able to create a new custom primary password in Edge Settings edge://settings/autofill/passwords/settings. Any users who are still using a custom primary password will be automatically migrated to device authentication. Additionally, the PrimaryPasswordSetting policy will no longer support the WithCustomPrimaryPassword option. For more information, see Keep your saved passwords private in Microsoft Edge | Microsoft Support. Unifying Copilot Chat policy controls. The Microsoft365CopilotChatIconEnabled policy is the standard for configuring Copilot Chat. Previously, this behavior was controlled by blocking the Copilot extension, either explicitly or by using the * wildcard via the ExtensionSettings or ExtensionInstallBlockList policies. Extension and sidebar policies no longer affect the appearance or functionality of Copilot Chat. Copilot address bar suggestions were also tied to extension policy settings. Starting in Microsoft Edge version 149, admins can use the CopilotAddressBarSuggestionsEnabled policy to manage this behavior. Intune MAM Protected Downloads. The protected downloads feature for Intune MAM is now available for BYOD (Bring Your Own Device) devices, which aren't managed by a tenant. Policy Updates / New policies CopilotAddressBarSuggestionsEnabled - Enable Copilot address bar suggestions CpuPerformanceTierOverride - Override for the CPU performance tier DataUrlInWebWorkerOpaqueOriginEnabled - Enable opaque origins for data URLs in Web Workers DefaultLocalFontsSetting - Default Local Fonts permission setting ForceForegroundPriorityForUrls - Force foreground priority for specific URLs LocalFontsAllowedForUrls - Allow Local Fonts permission on these sites LocalFontsBlockedForUrls - Block Local Fonts permission on these sites Deprecated policies WalletDonationEnabled - Wallet Donation Enabled (deprecated) EdgeWalletEtreeEnabled - Edge Wallet E-Tree Enabled (deprecated) Additional policy changes ForceForegroundPriorityForUrls - ForceForegroundPriorityForOrigins is renamed to ForceForegroundPriorityForUrls OnSecurityEventEnterpriseConnector - Add macOS platform support ProtectedContentIdentifiersAllowed - Remove macOS platform support Download: Microsoft Edge (64-bit) | 193.0 MB (Freeware) Download: Microsoft Edge (32-bit) | 170.0 MB Download: Microsoft Edge (ARM64) | 188.0 MB View: Microsoft Edge Website | Release History Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • User: "But is it good?" Microsoft: "Well, no. But it is less bad."
    • Media Player Classic - Home Cinema 2.7.2 by Razvan Serea Media Player Classic - Home Cinema (MPC-HC) is a free and open-source video and audio player for Windows. MPC-HC is based on the original Guliverkli project (which is no longer maintained) and contains many additional features and bug fixes. As the continuation of the original Media Player Classic, MPC-HC isn’t flashy but it works with nearly any media format. MPC-HC uses DXVA technology to pass decoding operations to your modern video card, enhancing your viewing experience. And MPC-HC supports both physical and software DVDs with menus, chapter navigation, and subtitles. Overview of features A lot of people seem to be unaware of some of the awesome features that have been added to MPC-HC in the past years. Here is a list of useful options and features that everyone should know about: Dark interface Menu > View > Dark Theme When using dark theme it is also possible to change the height of the seekbar and size of the toolbar buttons. Options > Advanced Video preview on the seekbar Options > Tweaks > Show preview on seek bar Adjust playback speed Menu > Play > Playback rate The buttons in the player that control playback rate take a 2x step by default. This can be customized to smaller values (like 10%): Options > Playback > Speed step Adjusting playback speed works best with the internal audio renderer. This also has automatic pitch correction. Options > Playback > Output > Audio Renderer MPC-HC can remember playback position, so you can resume from that point later Options > Player > History You can quickly seek through a video with Ctrl + Mouse Scrollwheel. You can jump to next/previous file in a folder by pressing PageUp/PageDown. You can perform automatic actions at end of file. For example to go to next file or close player. Options > Playback > After Playback (permanent setting) Menu > Play > After Playback (for current file only) A-B repeat - You can loop a segment of a video. Press [ and ] to set start and stop markers. You can rotate/flip/mirror/stretch/zoom the video Menu > View > Pan&Scan This is also easily done with hotkeys (see below). There are lots of keyboard hotkeys and mouse actions to control the player. They can be customized as well. Options > Player > Keys Tip: there is a search box above the table. You can stream videos directly from Youtube and many other video websites You can stream videos directly from Youtube and many other video websites Put yt-dlp.exe or youtube-dl.exe in the MPC-HC installation folder. Then you can open website URLs in the player: Menu > File > Open File/URL You can even download those videos: Menu > File > Save a copy Tip: to be able to download in best quality with yt-dlp/youtube-dl, it is recommended to also put ffmpeg.exe in the MPC-HC folder. Several YDL configuration options are found here: Options > Advanced This includes an option to specify the location of the .exe in case you don't want to put it in MPC-HC folder. Play HDR video This requires using madVR or MPC Video Renderer. After installation these renderers can be selected here: Options > Playback > Output Ability to search for and download subtitles, either automatically or manually (press D): Options > Subtitles > Misc Besides all these (new) features, there have also been many bugfixes and internal improvements in the player in the past years that give better performance and stability. It also has updated internal codecs. Support was added for CUE sheets, WebVTT subtitles, etc. Media Player Classic - Home Cinema 2.7.2 changelog: Updated LAV Filters to version 0.81-23-g6fadb Updated MPC Video Renderer to version 0.10.2.2540 Updated MediaInfo DLL to version 26.05 Updated MPC Audio Renderer Several crash fixes, bug fixes and small improvements. Download: MPC-HC 2.7.2 (x64) | Standalone | ~20.0 MB (Open Source) Download: MPC-HC 2.7.2 (x86) | Standalone Links: MPC-HC Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Very Popular
      s0nic69 earned a badge
      Very Popular
    • Collaborator
      Asgardi earned a badge
      Collaborator
    • Conversation Starter
      mobandz earned a badge
      Conversation Starter
    • Apprentice
      fernan99 went up a rank
      Apprentice
    • One Month Later
      nothanks earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      471
    2. 2
      PsYcHoKiLLa
      247
    3. 3
      Skyfrog
      80
    4. 4
      FloatingFatMan
      67
    5. 5
      Michael Scrip
      60
  • Tell a friend

    Love Neowin? Tell a friend!