|
Posted by Jeff on 11/16/05 01:08
Sony could be in worse trouble over this than they realized. And
what they've done so far isn't enough to rectify the situation. The
damage has already been done.
A blog report from Brian Krebs of the Washington Post says that
Sony's patch for the XCP rootkit DRM opens a serious security
hole that allows any webpage the users visits to download, install
and run any code that it likes:
http://blogs.washingtonpost.com/securityfix/2005/11/sony_uninstall_.html
Also, a Seattle-based security researcher has estimated that there
could be more than a half a million networks infected by the XCP
rootkit:
http://wired-vig.wired.com/news/print/0,1294,69573,00.html
Although I feel for those who have gotten hit by this, or BMG/Sony's
"cure" (which IMO is almost as bad as the disease), I find a smug
satisfaction in knowing that the company could be up to their ears
in lawsuits for months, if not years, to come.
[Back to original message]
|