Sony’s copy-protected XCP music discs contain Apple FairPlay DRM compatibility code

“For weeks, the blogosphere has been abuzz with tales of intrigue about Sony’s XCP copy protection system. Among the strangest revelations was that XCP itself infringes on the copyrights to several open source software projects. In one case, Sam Hocevar found conclusive evidence that part of XCP’s code was copied from a program called DRMS, which he co-authored with DVD Jon and released under the terms of the GPL open source license,” J. Alex Halderman reports for Freedom to Tinker. “What made this finding particularly curious is that the purpose of DRMS is to break the copy protection on songs sold in Apple’s iTunes Music Store. Why would XCP rip off code intended to defeat another vendor’s DRM?”

Halderman reports, “The answer is that XCP utilizes the DRMS code not to remove Apple DRM but to add it. I’ve discovered that XCP uses code from DRMS as part of a hidden XCP feature that provides iTunes and iPod compatibility. This functionality has shipped on nearly every XCP CD, but it has never been enabled or made visible in the XCP user interface. Despite being inactive, the code appears to be fully functional and was compatible with the current version of iTunes when the first XCP CDs were released. This strongly suggests that the infringing DRMS code was deliberately copied by XCP’s creator, First4Internet, rather than accidentally included as part of a more general purpose media library used for other functions in the copy protection system.”

“Intriguingly, the FairPlay compatibility code in XCP is not limited to converting files from XCP CDs. The code appears to support conversion into FairPlay of files in a wide variety of input formats — MP3s, WAV files, RAW audio files, and standard unprotected audio CDs — in addition to XCP-protected discs. It’s also strange that the FairPlay compatibility code is shipped but not made available for use by applications, not even XCP’s own player software. (Technically, the code is not exported from the shared library where it is stored.) This might indicate that First4Internet decided to remove the feature at the very last minute, shortly before XCP CDs started to ship,” Halderman reports. “In any case, the code is present and still works. It’s possible to execute it by jumping to the right memory location after performing some basic setup. I’ve used this method to test various aspects of the software.”

Full article, including a screenshot of iTunes playing a protected file that Halderman made from a regular MP3 file using the hidden XCP functionality, here.

Advertisements: The New iMac G5. Built-in camera and remote control. From $1299. Free shipping.
Apple USB Modem. Easily connect to the Internet using your dial-up service. $49.00.
The New iPod with Video. The ultimate music & video experience on the go. From $299. Free shipping.
Connect iPod to your television set with the iPod AV Cable. Just $19.00.

Related articles:
Texas sues Sony BMG for ‘spyware’ on CDs – November 21, 2005
Fingernail-sized piece of opaque tape defeats Sony BMG CD copy-protection DRM scheme – November 21, 2005
Retailers report Sony BMG, EMI copy-protected CDs turning off music buyers – November 20, 2005
Sony Boycott continues: Sony recalls XCP-tainted music discs, offers Red Book compliant CD exchanges – November 17, 2005
Sony BMG infected music CDs could be good for consumer rights – November 16, 2005
Microsoft to remove Sony BMG malware – November 15, 2005
Sony BMG infected music CDs could lead Sony into ‘big-league legal trouble’ – November 15, 2005
EFF publishes open letter to Sony-BMG calling for recall of all infected Sony-BMG CDs – November 15, 2005
Boycott Sony – November 14, 2005
Sony BMG ‘temporarily suspends’ production of music CDs with copy-protection scheme – November 11, 2005
Boycott Sony products: Sony music CDs can install kernel extensions on Mac OS X – November 10, 2005
Computer security firm: ‘Stinx’ virus hides within Sony’s copy protection scheme – November 10, 2005
Sony sued over copy-protected CDs – November 10, 2005
SonyBMG antics may well cause public to turn on them and turn many people onto Apple Macs – November 06, 2005
Report: Sony copy-protected CDs may hide Windows rootkit vulnerability – November 01, 2005
Analyst: Sony BMG’s boycott of Apple’s iTunes Music Store Australia won’t last long – October 24, 2005
Apple launches iTunes Music Store Australia – October 24, 2005
How to beat Apple iPod-incompatible Sony BMG and EMI copy-protected CDs – October 04, 2005
Japan music labels look to impose ‘iPod Tax’ while Sony, Warner still not signing with Apple iTunes – October 10, 2005
Why aren’t Sony, BMG, Warner, Victor making their artists’ music available on Apple’s iTunes Japan? – October 06, 2005
Sony and Warner holding out on Apple iTunes Music Store Australia – September 08, 2005
Musicians stage mutiny against Sony, defiantly offer music via Apple’s iTunes Music Store – August 10, 2005
Sony BMG and EMI try to force Apple to ‘open’ iPod with iPod-incompatible CDs – June 20, 2005
New Sony BMG copy-protected CDs lock out Apple iPod owners – June 01, 2005
Record company causes Apple to hit ‘pause’ on Australian iTunes Music Store – May 05, 2005


  1. That could mean that Sony/First4Internet’s XPC code now falls under the GPL as a derivative work, and they may have to provide the source code to anyone who wants it.

  2. ソニーは熱を感じたにちがいない 彼らは悪いないそれを実現するなる 市場占有率を心配してはいけない、 Apple をしなさい、 BMW かFerrari か。

  3. ソニーは熱を感じたにちがいない 彼らは悪いないそれを実現するなる 市場占有率を心配してはいけない、 Apple をしなさい、 BMW かFerrari か。

    This is not a translaton that you are looking for.
    It says:

    As for SONY heat was felt as for them who are not different is bad, it implements that it is not being worried about the share which becomes, it is not good, do Apple, BMW or Ferrari?

    this is what you are looking for – a bit stronger – but what you asked for:

    MW: that as in “and that is that”

Reader Feedback

This site uses Akismet to reduce spam. Learn how your comment data is processed.