News

Sony Settles with U.S. FTC on Music CD Rootkits

In a five to zero vote of the U.S. FTC on Tuesday, a consent agreement was approved in the Sony music CD rootkit case. Sony agreed to clearly disclose limitations on future music CDs and pay customers up to US$150 for damage to their computers.

The incident started when a Windows security expert discovered last fall that music CDs from Sony BMG silently installed and concealed a program called "XCP" on the customer's PC. The rootkit compromised the PC's security.

The U.S. FTC filed a complaint against Sony which said, " the installation of software without consumer consent that exposed consumers' computers to security risks was unfair and violated federal law." The FTC also asserted that "hiding the software and failing to provide a way to remove it were also violations of U.S. law."

As part of the agreement, Sony will make its removal program available for two years. Customers will be able to take their infected CDs, purchased prior to December 31st, back to a retailer for replacement, and Sony will allow the FTC to monitor their compliance with the agreement.

While this PC rootkit did not directly affect Mac OS X users, Apple customers have continued to monitor this case closely and its implications for both Windows and their own Mac system security.

0 comments from the community.

You can post your own below.

+ show options

Your current settings, click to change: Sort Oldest First, Show Guest Posts, Hide Community Stats

Post Your Comments

  Remember Me

Not a member? Register now. You can post comments without logging in, but they'll show up as a "guest" post.


Please enter the word exactly as you see it in the image above. Registered users aren't prompted for this. Having trouble reading the image get a new one.