Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [ISN] Sony fixes security hole in CDs, again |
|---|---|
| Date: | Fri, 9 Dec 2005 00:38:08 -0600 (CST) |
http://news.com.com/Sony+fixes+security+hole+in+CDs%2C+again/2100-1002_3-5987776.html By John Borland Staff Writer, CNET News.com December 8, 2005 Sony BMG is replacing a patch for its CD copy protection software after Princeton University researchers found a security flaw in the update. Sony announced on Tuesday that a new risk had been found with a batch of 27 of its compact discs, which automatically install antipiracy software on hard drives when put into a computer's disc drive. Along with the Electronic Frontier Foundation, a digital rights group, the record label released a patch aimed at fixing that flaw. However, Princeton computer science professor Ed Felten wrote in his blog on Wednesday that the patch itself could open computers to attack by hackers. Sony executives said Thursday that they are working as closely as possible with security professionals to address the issues identified by Felten, and would have a new patch available by midday that day. "The security space is a dynamic one, as we have learned," said Thomas Hesse, president of Sony's global digital businesses. "Our goal is to be diligent and swift, and we have gone to experts to handle this issue." Sony's ongoing troubles with copy protection software highlight the delicate line that record labels and other content companies are walking in trying to protect their products from widespread duplication. On the one hand, labels have watched their revenues decrease over the past several years, as more people swap songs online and burn CDs for friends and acquaintances. However, the labels' technological attempts to create a copy-protected CD that retains compatibility with millions of old CD players have opened them up to the unfamiliar hazards of software development. Several of Sony's attempts to patch security holes in its antipiracy software over the past weeks have turned out to raise their own new problems, instead of quelling concerns. The current security flaw in Sony's discs is related to software produced by SunnComm Technologies and affects 27 titles that remain on the market. It's separate from an earlier vulnerability that affected 52 other titles and that related to antipiracy software written by another company, First 4 Internet. Those titles have been recalled from store shelves. The flaw found by Felten could allow Sony's original patch to trigger malicious software on a computer, if that software was already in place when the patch was installed. _________________________________________ Earn your Master's degree in Information Security ONLINE www.msia.norwich.edu/csi Study IA management practices and the latest infosec issues. Norwich University is an NSA Center of Excellence.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [ISN] Law Firms Not Liable in Alleged Web Hacking Case, InfoSec News |
|---|---|
| Next by Date: | [ISN] Residents' data at risk on state's computers, InfoSec News |
| Previous by Thread: | [ISN] Law Firms Not Liable in Alleged Web Hacking Case, InfoSec News |
| Next by Thread: | [ISN] Residents' data at risk on state's computers, InfoSec News |
| Indexes: | [Date] [Thread] [Top] [All Lists] |