MacDailyNews - Where Mac news comes first

Apple Store

5 Day Most Commented

Opinion Archive

Current Headlines

Latest Joy of Tech

  • Latest Joy of Tech!

MacNN

AppleInsider

MacMinute

Macworld UK

Yahoo! Finance AAPL

iTunes Top 10 Albums

Mac OS X Downloads

Sat, May 10, 2008 - 01:55 PM EDT  —  AAPL: 183.45 (-1.61, -0.87%) |  NASDAQ: $data[1] ($data[4], $percent)"; //close the filehandle $fp fclose ($fp); ?>

Boycott Sony products: Sony music CDs can install kernel extensions on Mac OS X
Thursday, November 10, 2005 - 05:22 PM EDT

"Darren Dittrich followed up on the discovery that Sony was playing a dirty trick on its customers, secretly installing a malware-style 'root kit' on their [Windows] computers via audio CDs," MacInTouch reports.

I recently purchased Imogen Heap's new CD (Speak for Yourself), an RCA Victor release, but with distribution credited to Sony/BMG. Reading recent reports of a Sony rootkit, I decided to poke around. In addition to the standard volume for AIFF files, there's a smaller extra partition for "enhanced" content. I was surprised to find a "Start.app" Mac application in addition to the expected Windows-related files. Running this app brings up a long legal agreement, clicking Continue prompts you for your username/password (uh-oh!), and then promptly exits. Digging around a bit, I find that Start.app actually installs 2 files: PhoenixNub1.kext and PhoenixNub12.kext.

Personally, I'm not a big fan of anyone installing kernel extensions on my Mac. In Sony's defense, upon closer reading of the EULA, they essentially tell you that they will be installing software. Also, this is apparently not the same technology used in the recent Windows rootkits (made by XCP), but rather a DRM codebase developed by SunnComm, who promotes their Mac-aware DRM technology on their site.


Links included in the MacInTouch article here.

Advertisements: The New iMac G5 - Built-in iSight camera and remote control with Front Row media experience. From $1299. Free shipping.
The New iPod with Video.  The ultimate music + video experience on the go.  From $299.  Free shipping.

MacDailyNews Take: Okay, we're fed up. We are boycotting all Sony products until this and other "copy-protected CD" issues are addressed appropriately by Sony and recommend that our 2.2+ million unique visitors per month from 136 countries worldwide do the same. How'd ya like them Apples, Sony?

A "Boycott Sony" petition, written by Jeremy Johnson, can be read and signed at Petition Online here.

Related articles:
Computer security firm: 'Stinx' virus hides within Sony's copy protection scheme - November 10, 2005
Sony sued over copy-protected CDs - November 10, 2005
SonyBMG antics may well cause public to turn on them and turn many people onto Apple Macs - November 06, 2005
Report: Sony copy-protected CDs may hide Windows rootkit vulnerability - November 01, 2005
Analyst: Sony BMG's boycott of Apple's iTunes Music Store Australia won't last long - October 24, 2005
Apple launches iTunes Music Store Australia - October 24, 2005
How to beat Apple iPod-incompatible Sony BMG and EMI copy-protected CDs - October 04, 2005
Japan music labels look to impose 'iPod Tax' while Sony, Warner still not signing with Apple iTunes - October 10, 2005
Why aren't Sony, BMG, Warner, Victor making their artists' music available on Apple's iTunes Japan? - October 06, 2005
Sony and Warner holding out on Apple iTunes Music Store Australia - September 08, 2005
Musicians stage mutiny against Sony, defiantly offer music via Apple's iTunes Music Store - August 10, 2005
Sony BMG and EMI try to force Apple to 'open' iPod with iPod-incompatible CDs - June 20, 2005
New Sony BMG copy-protected CDs lock out Apple iPod owners - June 01, 2005
Record company causes Apple to hit 'pause' on Australian iTunes Music Store - May 05, 2005

  • Social Web
  • E-mail






Always -- Free ground shipping with orders over $50 at the Apple Store.

Reader Feedback: ( = registered)

Nov 10, 05 - 06:36 pm Comment from: boycotter

We can still download Sony music off of Limewire though, right?

Nov 10, 05 - 06:37 pm Comment from: Me Too!

I have said before and will say again- I am boycotting all sony made products due to their childish tactics. Microsoft as well!!!

Nov 10, 05 - 06:37 pm Comment from: The Dude

This is totally unacceptable. Boycott of Sony is needed unit they reverse their practices.

The Dude abides

Nov 10, 05 - 06:38 pm Comment from: John

Anyone else would like to join?

Nov 10, 05 - 06:39 pm Comment from: JadisOne

Sony will never get another dime from me. It's my damned computer and if I choose to burn a copy for myself or rip the tracks for my iPod then so be it.

Go to China and stop all that bootlegging instead of crippling legit consumers' computers.

Nov 10, 05 - 06:43 pm Comment from: ArchAngelNix

Does that mean we should boycott Blue-Ray? How about Sony's HDV camcorders or their Digital cameras? Are we just boycotting Sony Music endeavors or all Sony?

MW: Level "What level of Sony is to be boycotted?"

Nov 10, 05 - 06:44 pm Comment from: iTunes

Shame, that Imogen Heap CD is a great disc. My fave of the year. Glad I imported it from England with no Sony distro on it... but you can always just buy it from iTunes with the good old DRM we know and trust.

Nov 10, 05 - 06:44 pm Comment from: Holy Mac Kernel Extensions Batman!

Let this be a lesson to others that you should never give your username and password when running and/or installing an application on a Mac unless the application explicitly tells you what it is installing (I know in this case it did and the person who found this was experimenting/investigating). Just a reminder. I especially think any program that is going to install an kernel extension on my Mac better tell me in big, bold, red flashing type.

Nov 10, 05 - 06:44 pm Comment from: Rasmus

Found this at petionsonline.com

http://www.petitiononline.com/bcsony/petition.html

Nov 10, 05 - 06:45 pm Comment from: Lazy European

Count me in.

Nov 10, 05 - 06:45 pm Comment from: MacTunes

Well, all this crap about Sony has done ONE thing for me. Solidified the choices I will make when purchasing music.

1) I will ONLY buy from iTunes
2) If I can't buy it from iTunes, I'll get it off newsgroups or limewire.

SCREW YOU SONY!

Nov 10, 05 - 06:47 pm Comment from: Limewire

Who are some acts on Sony BMG?
I don't pay much attention to labels.
I will now...

Nov 10, 05 - 06:48 pm Comment from: Matt

Yes, Limewire is great way to safely download Sony material. I seem to have read a story on Google News this week about the president of SCEA instructing customers to use Gnutella or BitTorrent "until they get the whole DRM thing sorted out."

Nov 10, 05 - 06:56 pm Comment from: Dave H

I just like the way this highlights the difference between OSX and Windows.

I wasn't in the market for any Sony products anyway. Their stuff just doesn't warrant the extra cost anymore.

Nov 10, 05 - 07:01 pm Comment from: David A.

People, lest we forget, there's the rift growing between Apple and the major record labels over iTMS pricing, evidenced by their actions on the openings of the iTMS Japan and iTMS Australia. And how they want two/multi-tiered pricing on the iTMS as part of contract renewals with Apple in 2006.

Well, why stop with music? What about videos, movies at the local multiplex, TV shows, themeparks, et al, which are part of the multimedia goliaths? And, no, I'm not being funny, either. Would it really hurt us to boycott these rotten movies the studios vomit on us?

Their overhead on digital downloads from the iTMS (and the wannabes) is next to nil, yet they want to raise the price by 50-100%. And they already take approximately 65% of each sale Apple makes. While at the same time they demand that their artists swallow an even smaller royalty per digital download than they receive off a CD sale (something like 6-8% digital versus 12% or so for CDs).

The ideal is for the artists to break from the RIAA overlords and strike independent deals directly with Apple (50-50 would be a boon to both parties). I mean, in the growing digital world, why do we even need the record labels? I might have bought 5-6 CDs in the past 2 years, but have downloaded over 520 songs from iTMS.

One other change I would like to see with the iTMS: let it become a truly global music bazaar. Allow me to browse and shop from the Canadian, Australian, UK, French, Germaan, Japanese, Norwegian, Swedish, (and so on) iTMSs. Apple could offer it as a premium service - I pay an extra membership fee of $5-10 per month, and Apple handles the currency exchange rates... Or, better yet, add the service to .Mac membership, and enrollment would double, triple, even quadruple within a year.

Nov 10, 05 - 07:06 pm Comment from: Terry

How come no matter how often I come here I'm always the 1000,000th visitor and always win a cruise that I can't claim even if I tried?
GET RID OF THAT POP UP SHITE.

Nov 10, 05 - 07:06 pm Comment from: Peter

Generally speaking, I don't buy any CD that does not have the appropriate CD label. If I get it home and it does contains that stuff, I return it to the store that I bought it from and ask for my money back (usually, I end up accepting the ol' "in store credit").

Nov 10, 05 - 07:09 pm Comment from: Dave the cook

I was planning to buy 5, yes five, digi cams for my kids for xmas and upgrade minr to a new 8meg . . . . they have just lost it!!

Nov 10, 05 - 07:10 pm Comment from: max

Apple legal should review what SONY has been doing with their OS and see if there is a case to answer in opening up their product to malicious attack by other modifying their underhand techniques.

Nov 10, 05 - 07:12 pm Comment from: Funny how on a Mac

Sony has to ASK before installing something!

Not that it's anything dangerous like they put on Windows anyway.

Nov 10, 05 - 07:15 pm Comment from: Mike A

To be fair though, this software does need your authentication to install. Yes, it installs an unnecessary Kernel Extension without really warning you, but the Authentication is a pretty good give-a-way that something important is going to happen.

Also, as far as I understand, this program doesn't auto-run, you do actually HAVE to run it in the first place.

Nov 10, 05 - 07:15 pm Comment from: woe is me

I can't sign the petition 'cause I gave up email. Could I just leave a bag of dog crap on their front porch or sumpin' instead?

Nov 10, 05 - 07:18 pm Comment from: DreamTheEndless

MDN - It would be helpful if someone would create and manage a list of all sony movies in theaters and artists associated with sony in order to help facilitate a boycott- maybe with a link off of the MDN home page...

Not buying sony speakers or sony car stereos is easy, but with the incestuous relationships in the entertainment industry, it's hard to tell who's in bed with whom....

thanks.

Nov 10, 05 - 07:25 pm Comment from: Eddy

Does it play the CD WITHOUT installing the kext stuff??

Nov 10, 05 - 07:25 pm Comment from: Mick

Well I reckon Cher is better off without him, I actually thought Sony Bono died, or was it Sony and Bono got another job in Ireland. I wish my brain would work.

Nov 10, 05 - 07:26 pm Comment from: MacMania

boycotter said "We can still download Sony music off of Limewire though, right?"

LOL
{MacMania holds his side in pain}

MDN Magic Word: still - damn my side still hurts.

Nov 10, 05 - 07:26 pm Comment from: boomboom

I'm with Mike A on this issue. I'd be highly pissed if Sony found a way to auto install their code but instead they give us a legal agreement then Mac OS in all it's glory won't install without authorization.

What does the code do exactly? It's a DRM codebase? I, for one, am glad to hear that the Mac is supported with just about any code. DRM is here to stay and I'd rather be included than excluded.

Still, Sony should give a better explanation about this particular software.

Nov 10, 05 - 07:29 pm Comment from: marko

I'll boycott with yous guys for as long as it takes to get this corrected.
Or atleast until the PS3 comes out then you're on your own LOL

Nov 10, 05 - 07:30 pm Comment from: MacMania

{After applying some deep heating rub to his side, MacMania replies to call to arms}

Yes, count me in! Can someone please set up a blog so users world wide can sign the boycott role?

BTW, you may want to disallow comments; remember the Glaser/iTunes blog debacle?

cool hmm

Nov 10, 05 - 07:48 pm Comment from: MacDude

AllofMP3.com

If you think Sony's rootkit is nasty wait until you see the sh*t that's going to happen with Intel chips and BlueRay DVD burners.

If you want to play, get a Quad now, a couple of EyeTV 500's and simply wait for the HDCP "black box" to appear to record HDCP encrypted content.

There will be Apple DRM from the HDCP DRMed Intel processors to Apple Monitors, ditto on Vista.

Welcome to the dungeon, we got fun and games. smile

Nov 10, 05 - 07:54 pm Comment from: Emil

There are other perfect ways of obtaining the music without sony's shit. Direct Connect works like a charm smile

Nov 10, 05 - 07:58 pm Comment from: ron

terry...terry...How come no matter how often I come here I'm always the 1000,000th visitor and always win a cruise that I can't claim even if I tried?
GET RID OF THAT POP UP SHITE.

NO popup stuff..get pithhelmet

http://culater.net/software/PithHelmet/PithHelmet.php

Nov 10, 05 - 08:06 pm Comment from: Andrew

Awww. I wanted a PS3. Please can I have just that one teeny Sony product.

Nov 10, 05 - 08:16 pm Comment from: Danny

Play the CD on your normal stereo, it won't affect that, and record it through a griffin iMic or some other line in device. It takes a bit of tweaking to get the quality and sound levels right. Actually if you have a DVD recorder (stand alone, not a DVD Burner for computers) and you still have a VCR kicking around, you could probably do this.
Play CD on stereo which is plugged into the audio in jacks (red/white) on VCR. Record the CD to video which I'm told gives an as good as CD quality. Record that to a DVD in your stand alone DVD Recorder, then rip the DVD as normal to your HD and extract the audio mp2 ac3? files and convert them in iTunes or re record them with WireTap and reconvert them.
I think this is doable but yeah, who the hell wants to go through all that.

Nov 10, 05 - 08:20 pm Comment from: Micheal

So does anyone have any idea as to what the .kext files ACTUALLY do? Suncomm's site is deplorable and I can't tell what exactly they do.

Are they useless or do they do something?

Nov 10, 05 - 08:32 pm Comment from: DreamTheEndless

Uh - Danny -

There are better ways to cirumvent DRM than that mess you just proposed.....

Nov 10, 05 - 08:33 pm Comment from: hiproductionsdotcom

It sounds like some kind of "copy nanny" software...not good

Andrew Hamilton
Videographers in Las Vegas
http://www.hiproductions.com

Nov 10, 05 - 09:00 pm Comment from: Rasterbator

I have sent the following email throughout my company and suggest that you do the same immediately. Especially thos in the IT field:

Hi all,

As you may have read in tech news (or not), Sony Music CDs (possibly even movie DVDs) are being shipped with an application that installs itself and is hidden from Windows. This software is not secure. A virus exploiting this insecurity has been found on the net, called Stinx-E. This is a copy-protection scheme gone awry, and could damage our network.

The CDs (or DVDs) are also affecting Macintoshes by installing extensions into OS X System directory (but the virus does not affect Macs).

Please refrain from putting ANY Sony music CD/DVD into your computers, as they are now outlawed on our network. This includes laptops that are taken off site, since it could spread the virus once it is plugged back into the Matrix.

Nov 10, 05 - 09:04 pm Comment from: spyware this

From the article:
"Running this app brings up a long legal agreement, clicking Continue prompts you for your username/password (uh-oh!), and then promptly exits. Digging around a bit, I find that Start.app actually installs 2 files:"

Shame on Sony for trying such a stunt. They should be above trojan wares, and they should be called to answer for this.

And shame on anyone who blindly authenticates their system. Would you give your house address & keys to anyone on the street? Then why authenticate whatever app asks for it? Apple should do a UI change to reflect which app is requesting authentication, and why.

Nov 10, 05 - 09:28 pm Comment from: person

there's nothing wrong with sony. it's just their music part that's bad. their consumer electronics/av stuff is great.

Nov 10, 05 - 09:35 pm Comment from: fudgepacker

I've had no problems with Windows XP and my Sony CDROMS. You folks are making way to big a deal out of this. Sony is just trying to protect their investment.

Nov 10, 05 - 09:48 pm Comment from: The Grim

I am in also. Don't buy Sony product. I am piss after all the CD players and Walkman Cassette player I bought all these years. Good thing I have iPod now, so I do not need Sony. I am going to buy Sony mini dvd camcorder, but no more I am go with Panasonic that $700 up your A$$. Everybody do not support BD-DVD and that is include PS3. I am go with Toshiba for next HD-DVD. I think Job having a second thought too about BD-DVD.

Nov 10, 05 - 09:51 pm Comment from: Paris Hilton

Yum, fudge...
That's hot!

Nov 10, 05 - 09:57 pm Comment from: Wha

I'm gonna buy the Sony PS3 for it's the lesser of the two evils named Sony & Microsoft with their XBox360. I used to buy CDs from Sony but now I don't wish to. I'll download it for free instead if they try to mess with Tori Amos's CDs and other bands CDs that I like.

Other than the PS3, I'm not touching Sony product until they befriend iPod-using consumers.

Nov 10, 05 - 10:03 pm Comment from: aussiebob

Sony's consumer electronics/av stuff used to be great at one time.. now it just doesnt work as well as it did, has gone down on quality and has way too much propriety goods. I was planning on buying a Sony video cam mainly because of the touch screen LCD control feature.. but I have boycotted Sony. I will never in my life buy anything that has Sony on it.

anyhow, ive found a much better video camera, the JVC Everio G series, uses a hard drive, so no messing around with tapes or discs which is a much better feature then Sonys touchscreen lcd's (especially when you have dirty/wet fingers)

Nov 10, 05 - 10:03 pm Comment from: mike

Fuck you Sony!!!

You never were a software company, and never will be. Stick to TV's and overhyped game systems that can display framerates 3X detectable by the human eye.

Don't ever try to infect Macs with this shit.

You'll burn in court for this..

Nov 10, 05 - 10:05 pm Comment from: Nick

Mac users - remember, Sony audio CDs work fine on Macs. They cannot install any software without your administrator password, and iTunes will rip the songs as usual...

This is still a Windows-only issue.

Nov 10, 05 - 10:29 pm Comment from: Less is More

ATTENTION: SONY BMG Artists

You could probably get out of your SONY contract.

Call your lawyer.

Nov 10, 05 - 10:33 pm Comment from: chuy

SOME ONE SHOLD MAKE A BANNER AND WE SHOULD ADVERTISE THE BOYCOT, SO IT SPREADS ON ALL SITES THAT CONDEM MODIFICATION OF OUR COMPUTER SYSTEMS. INCLUDE A LINK TO THE PETITION
-------------
I Have several freinds there should be a text around the banner so it can be measured, by a search in google, and the news should spread faster
(sorry for the english, and the capps, not yelling, emphatizing)

Nov 10, 05 - 10:36 pm Comment from: chuy

ups, some text got deleted
I have friends that have blogs and I will tell them to spread the word.

Reader feedback page 1 of 2 pages:  1 2 >

Always -- Free ground shipping with orders over $50 at the Apple Store.

Add Your Feedback:

Register or Login

Name:

Email: (optional)

Emoticons | Allowed HTML Tags

Remember my personal information   Notify me of follow-up comments?

Please enter the "MDN Magic Word" you see in the image below:








Current MacDailyNews Stories:

iPhone ‘Currently Unavailable’ via U.S. Apple Store online
Saturday, May 10, 2008 - 09:17 AM EDT
Continuous reboots plague Windows XP SP3 sufferers
Saturday, May 10, 2008 - 09:03 AM EDT
O2: Apple iPhone no longer available in UK
Saturday, May 10, 2008 - 08:49 AM EDT
AT&T’s Wi-Fi for Apple iPhone coming sooner or later
Friday, May 09, 2008 - 04:57 PM EDT
.Mac is Apple’s next big thing; will become as important to Apple as Outlook is to Microsoft
Friday, May 09, 2008 - 03:21 PM EDT
Should Apple release a game console?
Friday, May 09, 2008 - 03:03 PM EDT
Zune a joke that gets funnier as time goes by (unless you’re Microsoft)
Friday, May 09, 2008 - 02:43 PM EDT
‘Back to My Mac’ catches Apple MacBook thieves
Friday, May 09, 2008 - 12:36 PM EDT
Apple slammed over failure to help solve ‘climate crisis’
Friday, May 09, 2008 - 12:14 PM EDT
RUMOR: Apple preps major revamp of .Mac to coincide with iPhone 2.0 launch
Friday, May 09, 2008 - 10:19 AM EDT
RIM’s BlackBerry 9000 Apple iPhone-lookalike: It’s no iPhone
Friday, May 09, 2008 - 09:31 AM EDT
Apple offers $45 store credit to Canucks who own older iPods
Friday, May 09, 2008 - 09:16 AM EDT
AT&T abruptly pulls free Wi-Fi for Apple iPhone info from site
Friday, May 09, 2008 - 08:50 AM EDT
Apple to refund customers to resolve replacement power adapter lawsuits
Thursday, May 08, 2008 - 06:22 PM EDT
Hands-on with ‘Mac Cloner’ Psystar’s Open Computer running Mac OS X Leopard 10.5.2
Thursday, May 08, 2008 - 04:56 PM EDT
Spring Medical Systems and MacPractice partner to provide solution for Mac-based medical practices
Thursday, May 08, 2008 - 04:18 PM EDT
NY Times’ Pogue reviews Apple’s Time Capsule: Takes network hard drive into a higher realm
Thursday, May 08, 2008 - 03:59 PM EDT
Will your iPhone destroy the Internet?
Thursday, May 08, 2008 - 02:09 PM EDT
Orb streams live TV and more to Apple iPhone and iPod touch
Thursday, May 08, 2008 - 01:30 PM EDT
What will Apple name their next cat?  Mac OS X 10.6 Lion?
Thursday, May 08, 2008 - 01:07 PM EDT