Sony settles with FTC on rootkit fracas

Company to disclose the limits it imposes on use of CDs, pay US$150 for each damaged system

More than two years after a security researcher first called attention to Sony BMG's use of a stealth program to enforce digital rights management on its music CDs , the company reached a deal with the U.S. Federal Trade Commission over the incident, the FTC announced on Tuesday .

In a deal that was approved by a 5-0 vote by the FTC, Sony agreed to clearly disclose limitations on consumers' use of its music CDs and promised not to collect information for marketing or install software without consumers consent, the FTC said. The company also agreed to reimburse consumers up to US$150 for computers damaged by the program, the FTC said.

The settlement marks an end to a long and embarrassing incident for the company, which began when Mark Russinovich, an expert on Windows security of WinTernals Software, now part of Microsoft, published the results of his investigation into a rootkit that had infiltrated his Windows machine.

Russinovich's research uncovered a stealth program, dubbed "XCP," distributed on CDs from Sony BMG that silently installed and concealed itself on the machines of customers who played the CD. The revelation and Sony's awkward response to it -- first denying that there was any problem with the XCP program, then making halting efforts to release programs to remove XCP -- set of a chorus of criticism on blogs and in the mainstream press.

Subsequent investigation revealed that the XCP program was poorly conceived, hastily written and could be used by hackers to conceal their own malicious programs on systems that had the XCP program installed.

Eventually, Sony posted a software removal program for the XCP and conducted a widescale recall of XCP enabled CDs. But the incident was a watershed, prompting discussions of the competing interests of copy protection by corporations and consumers' right to privacy.

In the consent agreement announced today, the FTC said that "the installation of software without consumer consent that exposed consumers' computers to security risks was unfair and violated federal law." Hiding the software and failing to provide a way to remove it were also violations of U.S. law, the FTC said.

The company will have to offer its removal program for another two years and will have to continue allowing customers to exchange CDs with the concealed software purchased before December 31, 2006. The company will also have to provide retailers with financial inducements to return XCP infected CDs and allow the FTC to continue to monitor its compliance with the consent decree.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Paul F. Roberts

Show Comments


James Cook University - Master of Data Science Online Course

Learn more >


Sansai 6-Outlet Power Board + 4-Port USB Charging Station

Learn more >

Victorinox Werks Professional Executive 17 Laptop Case

Learn more >



Back To Business Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?