Businesses view Sony DRM as 'security threat'

Nearly all business PC users believe Sony's DRM copy protection to be a security threat, according to a new survey.

The poll of more than 1,500 business PC users, conducted by Sophos, revealed that 98 percent believed Sony's controversial digital rights management (DRM) software, which installs a rootkit-like application on computers, thus hiding the copy protection from the operating system, is a security threat.

The news came as Sony announced that it is suspending production of any further CDs which contain the technology. Only 2 percent of users polled felt that it was a fair way to fight music piracy.

The technology caused concern after trojan horses were discovered exploiting the DRM's functionality in an attempt to hide themselves from anti-virus products. Any file with $sys$ in its name has been automatically hidden by the copy-protection code, making it invisible on computers which have used CDs carrying Sony's software.

Microsoft also classified the software as malicious software. It is planning to include detection and removal tools in its next update to its anti-spyware product.

"In taking aim at the music pirates, Sony succeeded only in shooting itself in the foot," said Graham Cluley, senior technology consultant at Sophos. "Business PC users have a very low opinion of any code which endangers the safety of their networks, and they have sent a loud and clear message to Sony and other companies that this kind of code is unacceptable to them."

Sophos has issued a tool to detect the existence of Sony's DRM copy-protection on Windows computers.

www.sophos.com
www.microsoft.com

More in News

Privacy-bolstering "Apps Act" introduced in House

The bill would provide consumers nationwide with similar protections already enforced by a California law.

Microsoft readies permanent fix for Internet Explorer bug used in energy attacks

Microsoft is prepping a whopper of a security update that will close 33 vulnerabilities, likely including an Internet Explorer (IE) flaw that has been used in targeted website attacks against the U.S. government.

Weakness in Adobe ColdFusion allowed court hackers access to 160K SSNs

Up to 160,000 Social Security numbers and one million driver's license numbers may have been accessed by intruders.